Cloud Threats Escalate as Cybercriminals Exploit Identity Weaknesses
A new global analysis uncovers a troubling reality: cloud environments are under relentless attack, with 9 out of 10 cybersecurity and IT leaders confirming incidents over the past year. Experts warn this is not an isolated issue—it’s a rapidly expanding crisis affecting organizations worldwide as they shift toward hybrid cloud models.
The research, spanning 1,600 professionals across ten countries, paints a stark picture. Despite surging investments in cloud security, attackers continue to bypass defenses with alarming efficiency. Traditional malware is being left behind in favor of stealthier, identity-driven methods that exploit legitimate access paths rather than brute force entry.
Today’s threat actors are using real logins—not malware—to infiltrate systems. This shift has led to a surge in “malware-free” breaches, now accounting for 79% of all known intrusions—nearly double the rate from just five years ago. These breaches often involve credential abuse, insider manipulation, and targeted social engineering—tactics that blend into everyday user behavior and evade detection.
Perhaps most disturbing is how fast these intrusions unfold. In some cases, attackers go from initial access to full lateral movement across systems in under a minute. The average breakout time has shrunk to just 48 minutes, emphasizing how little time defenders have to react. The fastest recorded? A mere 51 seconds.
Organizations are struggling to contain the damage. Among those hit with ransomware, 86% ended up paying the ransom—either to recover critical data or to stop further compromise. Alarmingly, in 74% of cases, attackers also managed to cripple backup and recovery mechanisms, stripping victims of their last line of defense.
Rubrik Zero Labs researchers describe this as a strategic evolution in attacker behavior. Instead of breaking down the door, cybercriminals are simply walking in—often unnoticed.
The data shows a clear trend: identity is now the primary attack vector in cloud breaches. Whether through phishing scams or purchased credentials from access brokers (whose activity has surged by 50% year-over-year), adversaries are exploiting the weakest link in modern infrastructure—human access.
A typical cloud intrusion now follows a chillingly simple sequence:
Stolen Credentials → Unauthorized Cloud Access → Tool-Based Lateral Movement → Privilege Escalation → Data Theft or Ransom
Microsoft’s own telemetry supports this narrative, blocking over 600 million identity-based threats each day.
To keep up, organizations must rethink their cloud defense posture. The report recommends a multilayered approach: deep visibility across cloud workloads, real-time identity threat detection, and hardened, ransomware-resilient backup strategies. The old perimeter-based playbook won’t cut it anymore.
In an era where speed, stealth, and stolen identities define cyber threats, only those with adaptive, unified protection strategies will be prepared for what’s next.




