The biggest shift the IBM X-Force® team observed in 2023 was a pronounced surge in cyber threats targeting identities.

Based on the input from 170 countries worldwide, the IBM X-Force Threat Intelligence Index report for 2024, has identified the main cyber-attack trends of 2023 that revolved around four key areas: identity and access management, data security, applications, and generative AI. While these trends pose significant challenges, the report also offers recommendations on how to prevent and mitigate these threats.
Identity and Access Management (IAM)
Initial access vector
In 2023, valid accounts stood out as the primary target for attackers, comprising 62% of incidents. Notably, the abuse of these valid accounts, along with phishing attacks, constituted the top threat. Each of these attack types contributed to 30% of identity theft cases, marking a significant 71% increase from 2022.
Credential theft methods
Credential theft primarily occurred through two methods: phishing and info stealers, accounting for 30% and 28% of incidents, respectively. Phishing was further categorised into two groups – bogus links and malware-containing attachments – both aimed at collecting user credentials, thus facilitating access credential theft.
IAM-related recommendations
Recommendations related to Identity and Access Management (IAM) emphasize the inefficiency of relying solely on single-login systems with usernames and passwords. Thus, it is crucial to implement multi-factor authentication (MFA) and utilize passkeys to bolster identity protection. A passkey is a unique code or token used for authentication purposes to provide an additional layer of security beyond traditional passwords.
Data security
Impact on organisations
Data theft and leakage emerged as the most significant impact on organizations, affecting 32% of them—a troubling 19% increase from the previous year, indicating a lack of improvement in data protection efforts. This trend is largely attributed to a malicious application known as “info styler,” with incidents related to info stealers surging by an alarming 266%, primarily targeting sensitive data and contributing significantly to the rise in data theft incidents.
What is an Info Styler?
For those not familiar with this malicious software, Info stealers are malicious software programs designed to covertly collect sensitive information from infected systems. They typically target personal and financial data, such as login credentials, credit card numbers, and banking details.
Once installed on a victim’s device, info stealers operate stealthily in the background, harvesting data without the user’s knowledge. The stolen information is then exfiltrated to remote servers controlled by cybercriminals.
Info stealers often propagate through phishing emails, malicious websites, or compromised software, which clearly links this type of cyber-attack to previously discussed identity and access management issues.
Data security mitigation strategies
Mitigation strategies for combating info stealers include prioritising encryption and maintaining immutable backups to secure critical data. Encryption ensures that sensitive information remains unreadable and unusable to unauthorized parties, even if it’s intercepted by info stealers.
Additionally, maintaining immutable backups – copies of data that cannot be altered or deleted – provides a safeguard against data loss or corruption caused by info stealer attacks.
By implementing these measures, organizations can enhance their resilience against info stealers and mitigate the risk of data theft and leakage.
Application security
Common vulnerabilities
Misconfigurations following system setup are identified as the primary failure, comprising 30% of all application-related cyber-attacks. The second security issue pertains to identity and authentication failures, accounting for 21% of application security issues, while access control issues closely follow, contributing to 15% of successful application-related attacks.
However, when identity and authentication failures are combined with access control issues, it reveals a concerning 36% of IAM security problems, underscoring identity and access management as the top cybersecurity concern in 2023, a trend that persists into 2024.
Zero-Day attacks and Ransomware
While zero-day attacks decreased significantly by 72%, it’s premature to celebrate, as this decline may be attributed solely to the increase in IAM attacks. In other words, attackers find it easier to achieve their goals through simpler identity theft methods than through more sophisticated zero-day attacks. Therefore, we must remain vigilant, as these attacks still pose a significant threat.
Ransomware incidents also experienced a slight decrease of 12% in 2023. This reduction may be due to many organisations refusing to pay ransom, thereby discouraging attackers from carrying out such attacks. However, other reports warn that ransomware attacks remain and will continue to be the most dangerous threats in the foreseeable future.
Application best-protecting practices
Best practices for application protection stress the importance of regularly patching, hardening, and updating applications to thwart exploits.
Patching entails applying updates from software vendors to fix known vulnerabilities and security weaknesses, while hardening involves configuring applications to minimise their attack surface and enhance defences against potential threats. This may entail disabling unnecessary features, implementing access controls, and tightening security configurations.
Furthermore, updating applications ensures they are equipped with the latest security features and defence against emerging threats. By adhering to these best practices, organisations can greatly diminish the likelihood of successful exploits targeting their applications, thereby enhancing their overall cybersecurity posture.
Generative AI
Emerging threat
Although chatbots and generative AI were introduced in 2022, they gained prominence in 2023. While some cybersecurity professionals view them as a potential new attack vector, major cyber-attacks leveraging these technologies have not yet materialised.
This could be due to built-in protections against generating harmful content, including malicious codes. However, there is a growing concern about the emergence of chatbots capable of generating anything users desire, including malicious codes.
Dark Web interest
While cybersecurity professionals are keen on leveraging technologies to safeguard digital assets, malicious actors are also exploring the use of generative AI and chatbots for nefarious purposes. Dark web forums have displayed a significant interest in AI’s potential for conducting attacks, evidenced by the registration of approximately 800,000 relevant topics.
Preparedness
Since we still lack comprehensive knowledge about the attack and defence capabilities of these technologies, it’s essential to remain informed about AI developments to effectively prepare for future threats.
In a nutshell
In conclusion, proactive security measures are paramount in safeguarding against the evolving landscape of cyber threats. Implementing industry best practices, such as regular patching, hardening applications, and staying informed about emerging technologies, is crucial. Additionally, maintaining vigilance and adhering to recommended strategies are key components of a robust cybersecurity posture. By staying ahead of potential threats and continuously improving security protocols, organisations can effectively mitigate risks and protect sensitive data from malicious actors. Ultimately, a proactive approach to cybersecurity is essential in today’s dynamic and complex digital environment.