2025 Global Threat Report with CrowdStrike’s Cristian Rodriguez
CrowdStrike Field CTO Cristian Rodriguez dives into a 2025 Global Threat Report that finds there’s been a major spike in the number of cybersecurity breaches involving stolen credentials that never required cybercriminals to go through the trouble of first creating malware to steal data.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Christian Rodriguez, who is field CTO for CrowdStrike, and we're talking about a new report they have about the threat landscape, and in particular, what's going on with all these attacks against their identities.
Christian, welcome to the show. Hey, thanks for having me. What exactly is the challenge with identities?
Because we've been using passwords for as long as anybody can remember, to identify a friend from FOE, and here we are in 2025, and basically people are realizing that that's not working anymore. But why? Well, I mean, identities are the path of least resistance for the bad guys.
If a, if an adversary gets a hold of an identity, it ultimately means that, uh, the adversary can blend in the environment, uh, as much as possible, that they can emulate a legitimate user. They don't necessarily have to drop a piece of malware in an effort to gain their initial access or, or, or stay persistent. Um, and it's just very easy.
It's, it's, it's just a very simple way to get yourself into an environment as the bad guy and, and stay for as long as possible while not alerting a defender to your presence. To your point, are the bad guys, they don't break in anymore. They simply log in, right?
Yeah, exactly. They're just logging in and they're, they're trying to, they're trying to be like an everyday user. So how pervasive is this?
I mean, you guys did this report, but how big a problem is this? Yeah, I mean, it's, it's been an increasing issue. I mean, from, from everything from, you know, access brokers that are, that are basically selling that initial, you know, list of identities or the actual access into these environments, there's been a, uh, a, a 50% year over year increase in the amount of access broker advertisements, which basically allows for a bad guy to kind of waltz into the environment with, again, without having to drop a piece of malware.
So that's been an increase, uh, an interesting, uh, increase, uh, year over year where, um, you know, identities are kind of the focal point of in, in an interesting in ECR ecosystem or marketplace of, of allowing someone to basically buy that access. And so that's an interesting trend that we've noticed. And then we've noticed also that there's been a major increase in, uh, the amount of, uh, of voice phishing or vishing attacks that we've seen where there's a roughly 442% increase, uh, that we saw between the first and second half of 2024.
And what that ultimately means is that, uh, adversaries are calling in to enterprises under the guise of a legitimate user that is having problems resetting their passwords, and they're emulating, or they're pretending to be this specific user and they're asking for credentials to be reset. You, you mentioned ask words and, and that's an interesting way, way or, or method that adversaries are, you know, again, just kind of pretending, you know, social engineering their, their way into an environment in an effort to gain access to those legitimate credentials so that they can log in and, and then kind of have free rein of, of access to anything that that user has access to. Ultimately, what is the cure for all this?
'cause we see everybody tossing around things from, uh, pass keys to biometric authentication involving your eyeball. There seems to be a lot of choices, and I'm not quite clear. Everybody knows, uh, what to do or, and when to do it, You know, so I think it's a multi-pronged approach of, of first and foremost having the ability to, in real time understand who's accessing or authenticating into what resource, understanding what your policies are around, um, uh, who, who should have access to different resources, but more importantly, in real time, having the, the ability to understand what an outlier is.
If I, if I see someone, for example, trying to authenticate to a system that they've historically logged into from, let's just say Miami, Florida, and all of a sudden they're, they're trying to log in to that system from Oxford, for example, within an hour's timeframe. That's, that's what's called an impossible travel, for example. And so there are use cases where you can emulate, or you can ultimately create real time, uh, analysis that says like, this is not legitimate or this is suspicious at, uh, at least.
And from there, doing things like step up authentication or having the ability to even assess the endpoint and the system that the user is making that authentication request from in an effort to, to in real time stitch together what is real authentication versus what could be stolen credential versus what is, you know, maybe even a service account or some outlier, uh, authentication attempt that you could ultimately start to, to mitigate against or prevent. I also feel like in a lot of ways, we are our own worst enemy because we seem to give end users access to everything. And some of that is just kind of being lazy and somebody says, well, here's my new hire.
What should he have access to? I don't know. He is probably gonna need this and this someday.
So give him everything. And then the next thing you know, their credentials go missing and the blood guys have access to everything. So are we a little sloppy in how we grant privileges?
Yeah, I mean there's, there's a hygiene issue. Undoubtedly. We see this every day when enterprises call us in and they, for example, even use our technology to do an assessment of like active directory.
What's interesting about, um, an authentication system like active directory is that no one, no one built it yesterday, right? Like usually active directory is inherited. And there are, to your point, there's an excessive amount of privileges that are granted to users over the course of their careers.
And then a lot of times those privileges are just simply copied into, uh, these roles. And these roles are then kind of issued down into users as they're onboarded. And that has historically created this problematic hygiene issue where, um, users just have just excess permissions into resources or roles that they really shouldn't in the grand scheme of, for example, like a zero trust framework.
And so because of that, um, there are lots of issues where, uh, no one's really assessing or reassessing and reevaluating the, the permission sets and the hygienes of those users, or things like even password expiration dates or, you know, the fact that maybe a user that should, that is accessing certain servers, um, you know, that's not really part of their job and maybe they, there needs to be a new policy that ultimately enforces control around, you know, what those resources are. And then even what happens after they authenticate in terms of authorizing access to other applications. And so that's something that a lot of enterprises are being, uh, challenged with, is ensuring that there's a hygiene of the users, their identities, their permissions, and then, uh, a list of available resources that, um, that the user should have access to.
I also feel like we obsess a lot about onboarding 'cause we're trying to make somebody productive, but, um, I would suspect that you and I probably still have access to any number of systems from previous jobs that nobody off boarded us from. And so is that also part of the issue here? Sure.
I mean, I think it goes back to that hygiene issue of saying, when's the last time someone did a reassessment of that user's, uh, I identity and their, their role that they've been assigned. And, um, we, we have this amazing capability of, of understanding, um, what those permissions are, is that ultimately excessive? And what is the user actually doing in real time, right?
Once, once once they authenticate onto a system, and then where, where could they possibly go? And so I think, you know, the offboarding concept, it's, it's harder for larger enterprises that have, you know, you know, tens if not hundreds of thousands of employees, uh, that they need to revisit each of those different business units and do analysis of, again, the identity of the user, what those permissions are, where they should have access to, how they should have access to. But then even enforcing multifactor across those, uh, those applications I think is a really big, uh, you know, step up in terms of, of how they can control or have some compensating controls around that hygiene problem.
Because if I can enforce in real time additional, uh, uh, multifactor and conditional access controls, I can, I can force that user to validate that they are who, who they say they are in real time as they're making those requests, you know, uh, to, to those different resources. So you guys have this report, and I know you've been around the block a couple of times. Anything in here that kind of surprised you that you went, wow, I, I I thought we were better than that?
Uh, I would say, um, that's a, that's a really, really great question. Um, so there's some really interesting points around the amount of vulnerabilities that we've seen. There's a 52%, uh, you know, uh, really 52% of the vulnerabilities that we observed rather were tied to like initial access, which basically means that adversaries are trying to find their way into your environment by any means necessary.
And so that includes a, obviously an identity that includes also vulnerability. But I think the, the major, the major number or the major, you know, uh, factoid if you will, that that really stands out is this concept of breakout time. And we've been tracking this breakout time, uh, number for probably since 2016 when we started to do analysis on how much time it takes for an adversary to move, uh, from the, the, the system of compromise into a neighboring machine.
Basically, think of lateral movement, right? So how long does it take an adversary to move, you know, once they've compromised one system onto another set of machines? And there was at one point, the average time would be roughly like four hours, and that number started to decrease substantially.
This, uh, last year we, we averaged out based upon an assessment and observations of various at, uh, attacks, hundreds of them, uh, it breakout time was roughly 48 minutes, right? And so think of the amount of time that, you know, it takes for an adversary to now move from a system, uh, that's compromised into neighboring devices or even cloud assets or anything that they essentially have connectivity to. It's roughly 48 minutes, which is a staggering number, but the fastest time that we saw was 51 seconds.
And so that's a pretty substantial increase in, in terms of speed and velocity, which, which from a defender perspective, you also need to become faster, right? So I think that's a very staggering and, and very worrisome number that we're observing and we're keeping an eye on. And there's so many different, um, facets that contribute to that, that increase in velocity.
AI could be one area. Identities are a massive area where that initial access is simply gained by having a list of ident identities that can be used for further authentication. Um, you know, the velocity at which adversaries are running their scripting on these systems, these are all major contributors to that number being smaller and smaller every year.
When we get to the point where we can track from the moment the breach to remediation, what the actual cost was to the organization, and we could have this like little meter that's just going click, click, click, click, click while we've looked for this particular resolution. Yeah, I think, you know, I think this could have begs or, or leads us into conversations around like even AI where like how does a defender get faster? I think there's like AI that can help augment and, uh, help give a little more context around the impact of, of a series of events, right?
Whether it's a breach or whether it's a initial endpoint that gets compromised. And I think as with every business, there needs to be, uh, an assessment and understanding of what risk means and what is your appetite for risk, and then what is the impact of the business throughout a variety, variety of different attack types. So there's everything from ransomware costs to the cleanup of identities being compromised to things like data theft and intellectual property being stolen.
And those are all, um, you know, is this varying, uh, attack types that ultimately have very different figures, uh, attached to them. And I think that we can probably leverage AI to help us get to those answers a lot faster. To your point, we are rapidly moving to an era where the bad guys are using AI to launch attacks in volume and sophistication that no mere mortal is ever gonna be able to defend against.
Sure. And so we need AI to defend against that, but, um, we also need people who know how the AI works. So are we getting to a point soon where maybe most organizations should just rely on some sort of AI driven service rather than trying to fight the fight themselves because they're just never gonna win it on their own?
I, I don't think there's a concept right now of, of solely relying on ai. I think that AI is there to augment the SOC analyst experience. It, it's there to increase the velocity at which you can defend.
I think it's there for providing a lot more context into things like identities and the misuse of identities and the fact that, uh, someone logging into one system trying to authenticate against applications that they've historically not accessed that can be, uh, supplemented, if you will, with AI specific intelligence and kind of like an overlay that, that helps a defender get their arms around things like outliers and what's anomalous. And essentially think of a combination of AI and machine learning. So I think in the grand scheme of the defender, you know, there's a saying here at Crosscheck that you don't have a malware problem, you have an adversary problem, which means that there is a human on the other side of that keyboard launching the attack.
Ensure they may have AI as part of their tool set, but I think as a defender, you know, you'll have AI as part of, you know, the list of, of, of tools in your tech stack that will help you respond faster. I don't think we're getting to a point anytime soon where it will be, uh, just ai. Um, but there's gonna be dependencies that that will help you as a human respond to the events that require a lot more prioritization.
And I think that's where AI will, will start to learn some help. But to your point, as an organization, should I invest in getting my own SOC analysts or should I just rely on somebody else's to do that who is being augmented by ai? And maybe, you know, we still need cybersecurity people.
It's just a question of who they're gonna work for. Yeah, that's a great, that's a great question actually. I think, um, I think, you know, when you are building out your own soc I think that you are going to be challenged with, um, you know, how, how much you can stretch a resource, right?
I mean understanding, I mean, the crowd in CrowdStrike, for example, is us crowdsourcing this telemetry from over 2 trillion events every single day that we get to analyze and apply machine learning and AI models against. And ultimately that also, uh, includes a huge human element of threat hunters and threat researchers and intelligence analysts that, um, can understand this data and can do a lot with that information in the form of behavioral patterns and machine learning patterns and, uh, understanding new trade craft and techniques that adversaries employ in their respective campaigns. And so if you're building out your own soc yeah, you, you will have someone that is locally available to help prioritize and help respond.
But I think leveraging a resource that understands globally, for example, at the scale that for example, crowd site could, could, could analyze these events at, I think that naturally benefits you as a defender to have access to that information versus having someone that is gonna be very focused on activity that's within your respective environment, which is still good. But as an extension of that, you still need this top of the funnel perspective into everything that's happening globally. Uh, you know, a a way to help operationalize the intelligence that's being captured.
And, and, and a lot of times enterprises are challenged with having the right resources to accommodate that type of scale. And of course, the bad guys are weaponizing this stuff into various services and it's all highly automated. And from their perspective they're kinda like, why would I do anything more complicated when what we have today works just fine?
But are there any particular new threats on the horizon that you're looking at that go, wow, we need to pay more attention to this? Yeah, I think one, one of the biggest areas we're seeing now is tied to insider, uh, uh, risk and insider threat, right? We, there's, um, you know, if identities are being a major focal point of, of adversaries in an effort to stay, you know, sticky and, and, and get quick access, we've also seen an increase in insider threat use cases where from a nation state perspective, countries like North Korea have been embedding agents into enterprises in the form of employees that are software developers.
And so we're seeing an interesting increase where these nation states may place, may have someone go through, uh, an interview process and they may leverage things like AI to build fake profiles on, uh, job posting sites like LinkedIn for example. And they will go through these interview processes using fake identities, and they will ultimately, um, you know, go through a very rigorous interview process where once they get the job, they will have their laptop sent to like a laptop farm. You know, there's a whole process behind essentially how they gain access onto the system using, um, remote management and monitoring tools.
And then from there they have the ability to embed, you know, malware or something malicious into the code that they're developing on behalf of that enterprise that hired them. And so we're seeing that ai, for example, is being used to, uh, weaponize hiring processes so that there's an actual people component to, you know, getting into an enterprise and then having access to sensitive data or, you know, or just being on a payroll to, you know, further, uh, you know, send those funds into something like new North Korea's, you know, weapons program. And so that's, that's an interesting trend that we, we probably anticipate seeing more of, uh, this year And other countries will probably follow suit.
Absolutely. Lemme ask you, is there something that you see organizations doing that just makes you shake your head a little bit and go, folks, we need to be a little smarter than that? Yeah, I think any organization that is depending if we're thinking, if we're talking about identities, I think any organization or enterprise that has defaulted to like a, a text-based, uh, or SMS based two-factor authentication schema, um, I think that is, is antiquated at this point, especially given the way that adversaries can leverage sim swapping as a mechanism for stealing your identity.
Meaning that they will call up your cell phone provider and they will pretend to be you and they will get, uh, that cell phone provider to convert your SIM or your eim into their phone, and now they have access to all of your text messages and your phone calls. And if you have that as your multifactor authentication mechanism, then it's very easy for, for someone to call up and, or reset a password, get that MFA prompt on their phone as a bad guy or bad girl and, you know, and then actually gain access to the resources that you have access to, um, based upon your identity. So I think any, any organization that is still leveraging an SMS based MFA tool, um, I think needs to really start looking into things like hardware, tokens and, um, you know, something that is a little more, you know, individualized to the, to the end user.
So what is your best advice for folks who, I think everybody nods their head and says, yeah, zero trust, we need to get to zero trust. Yeah. But the, the journey between where they are today and achieving zero trust, which may never be perfect, um, is very far.
So how do I kind of get down this path in a way that I think a lot of folks look at this and they just get overall and they do nothing. Yeah, I think it's, it's having a technology that can start to stitch together in real time. You know, what does an attack really look like these days?
And it's, it's gonna be identity based naturally as kind of your initial access. Um, but it's also this ability to understand that adversaries are, um, becoming enterprising. There's this theme that we have in our report of the enterprising adversary, and it ultimately means that adversaries are, are very opportunistic and they will find their way into your environment given the resources that you've invested in.
And so understanding that an adversary may target your endpoint or your cloud infrastructure, or once they have access to that identity, they have the ability to navigate, you know, everything that's in your enterprise. I think that organizations need to invest in capabilities that can stitch that in real time, those data points, that what is my, what are my identities doing? What are my endpoints doing?
What are my cloud assets? Doing? What, what do I see from a third party perspective?
And then how do I start to add behavioral analysis to understanding what's real versus what's an outlier versus maybe what's a broken business process or a process that needs improvement? And, uh, and then re and understanding every business unit in terms of, you know, how they access data and where that data should go to and who are your actual partners and business partners. So I think, you know, if I were to, to to say let's, let's be a little, uh, you know, consultative, I think it's really more of ensuring that you have a technology that bridges and, and brings all that data together in a cohesive fashion, but more importantly, can in real time give you that visibility into what is, what is an outlier, what's bad, um, how do you mitigate against it in real time naturally.
And then ultimately, how do I start to build a trending view into what, what did I see a week ago versus where am I going, you know, in the next, in the next few weeks. Alright, folks, you heard in here, it's a never ending battle and the tactics and the techniques used by the bad guys continue to evolve. So so do we.
And if we don't, bad things are gonna happen. Christian, thanks for being on the show. Thanks for having me, Michael.
All right. And back to you guys in the studio.