Mandiant reported that enterprise intrusions are accelerating sharply, with handoffs between initial access brokers and follow-on operators dropping from more than eight hours in 2022 to an average of 22 seconds in 2025. Exploit-based intrusions remain the leading entry vector, while attackers are increasingly using highly interactive voice phishing against IT help desks to bypass MFA and gain access to SaaS environments. The company also said zero-day exploitation is happening faster, with attackers often moving within about seven days before vendors can publish patches, and that AI is being used to support reconnaissance, social engineering, malware development, and credential theft rather than serving as the primary cause of most breaches.
The findings show financially motivated groups prioritizing immediate impact through ransomware, while espionage actors favor stealth and persistence, with median dwell times reaching 122 days in espionage cases. Ransomware operators are increasingly trying to cripple recovery by deleting cloud backup objects, encrypting hypervisor datastores, and targeting virtualization infrastructure. Mandiant said internal detection improved to 52% of 2025 investigations, up from 43% a year earlier, and urged organizations to strengthen identity-centric defenses, train employees and help-desk staff, protect Tier-0, backup, and virtualization assets, extend log retention, and centralize identity governance across SaaS platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
By March 2026, Mandiant publicly released its findings on the 2025 enterprise security landscape, highlighting faster intrusions, increased social engineering, compressed zero-day timelines, and recommendations for stronger identity, backup, and SaaS security controls.
According to Mandiant, organizations detected malicious activity internally in 52% of 2025 investigations, up from 43% in 2024. This indicated some defensive progress despite the broader acceleration in attacker operations.
Mandiant reported that financially motivated attackers increasingly targeted recovery infrastructure in 2025, including deleting cloud backup objects and encrypting hypervisor datastores. The goal was to destroy victims' ability to recover quickly from ransomware incidents.
Mandiant found that highly interactive voice phishing against IT help desks became a major method for bypassing MFA and gaining access to SaaS environments during 2025. The activity reflects attackers' growing focus on identity-centric intrusion paths.
In its M-Trends 2026 findings, Mandiant reported that vulnerability exploitation was the most common initial intrusion vector in 2025, accounting for 32% of investigated cases for the sixth straight year. The report said many of these access vulnerabilities were exploited as zero-days, underscoring the pressure on patching and remediation programs.
The report says attackers in 2025 were exploiting zero-days on average within seven days, often before vendors could publish patches. Exploit-based intrusions remained the leading initial access vector.
Mandiant's 2025 enterprise security findings describe a sharply accelerated threat environment, with compromise hand-offs between attackers shrinking from more than eight hours in 2022 to an average of 22 seconds in 2025. The report also notes wider use of division-of-labor models among cybercriminals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourceresilientcyber.io
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.