Skip to main content
Has your work email already leaked?Run the 10-second check
Threat intelligence

Twenty-nine minutes. That is the whole window.

CrowdStrike tracked the average time an intruder needs to get off the first machine and into the rest of your network. In 2025 it was 29 minutes. The fastest case was 27 seconds. Below is what we think those findings mean if you do not have someone watching at three in the morning.

All figures on this page are from the CrowdStrike 2026 Global Threat Report, published by CrowdStrike, covering January to December 2025. The report is CrowdStrike’s research and is hosted on CrowdStrike’s site. The commentary is ours.

The short version

In 2025 the average eCrime breakout time, meaning the time between an intruder compromising one machine and reaching others, fell to 29 minutes. The fastest observed case was 27 seconds. Five years ago the average was 98 minutes.

At the same time 82% of detections involved no malware at all, up from 51% in 2020. Intruders increasingly arrive with valid credentials and use the administrative tools already installed, which leaves preventive controls nothing to block.

Together those two findings describe a problem that tooling alone does not solve. Detection has to happen in minutes, by someone qualified, at whatever hour it occurs. Source: CrowdStrike 2026 Global Threat Report.

2025 in six figures

What changed, and by how much.

29 minutes
Average eCrime breakout time

Down from 48 minutes in 2024, and from 98 in 2021. Breakout time is how long an intruder takes to move from the first machine they land on to the rest of your estate. It is the clock your security program is actually racing.

27 seconds
Fastest breakout observed

The fastest recorded case in the 2025 data. In a separate intrusion, exfiltration began four minutes after initial access. Neither number leaves room for a ticket queue.

82%
Of detections were malware-free

Up from 51% in 2020. Most intrusions now arrive with no file for a scanner to find: valid credentials, native administrative tools, approved SaaS integrations. Antivirus is watching for something that increasingly is not there.

89%
Increase in AI-enabled adversary activity

Attacks involving adversary use of AI rose sharply year over year, alongside a 563% increase in fake CAPTCHA lures. The tooling that speeds up defenders speeds up the other side first, because they have no change control.

35%
Of cloud incidents involved valid account abuse

Identity is the way in. A working credential defeats a perimeter, and it does not trip the controls built to catch code.

42%
Increase in zero-days exploited before disclosure

Exploitation ahead of public disclosure grew, and newly disclosed flaws were weaponized within days. Cloud-conscious intrusions rose 37%, with a 266% increase among state-linked actors.

Source: CrowdStrike 2026 Global Threat Report, covering January to December 2025.

Our reading

The number that should change a budget is the 82%.

Breakout time gets the headline, and it deserves it. But 29 minutes mostly tells you that a plan built around business hours was already failing. The finding that should actually move money is that 82% of detections involved no malware, because that one invalidates a purchase most organizations have already made and still believe in.

A scanner looks for a file. When the intruder signs in with a real credential, opens the remote administration tool your own IT team uses, and copies data to a cloud storage account your staff are permitted to use, there is no file. Every individual action is authorized. What makes it an intrusion is the pattern, the timing and the fact that the person holding the credential is not the person it was issued to. Recognizing that is not a detection problem a product solves by itself. It is a judgment call, and judgment has to be on shift.

This is the uncomfortable part for a mid-market IT team, and it is worth saying plainly rather than selling around. The gap is not usually tooling. Most organizations we assess already own more capability than they have configured. The gap is that at 2am on a Sunday the alert fires into an empty room, and by the time someone reads it on Monday the 29 minutes elapsed about two thousand times over.

There are two honest answers. Staff a rotation, which means enough analysts to cover nights, weekends and holidays without burning them out, plus the training to keep them current. Or have somebody else hold the pager. We do the second one, so treat that as the interested opinion it is. What we would argue regardless is that intending to fix it later is not a third option, because the report describes adversaries who are already faster than the meeting where you would decide.

Where it landed

Interactive intrusions by industry.

Share of interactive intrusions in 2025, meaning hands-on-keyboard activity rather than automated malware. North America accounted for 55% of them globally.

Technology
23%
Retail
12%
Telecommunications
9%
Government
7%
Industrials and engineering
6%
Academic
4%
Media
3%

Source: CrowdStrike 2026 Global Threat Report. Bars are scaled to the largest value, not to 100%.

A worked example

Four minutes, at a law firm.

The report documents an adversary it tracks as CHATTY SPIDER, which spent 2025 primarily targeting law firms. The method was a phone call: persuade an employee to grant remote access through a legitimate support tool, then use a standard file transfer utility to move data out. In the documented case the attempt to exfiltrate began four minutes after access was granted. A firewall blocked the first route, so the adversary switched to a consumer cloud drive within seconds.

Nothing in that chain is malware. The remote tool is one that IT departments install on purpose, the transfer utility is a legitimate download, and the cloud drive is a service most staff are allowed to use. What caught it was hunting, not blocking.

Where we would start

Measure your own estate before you buy anything.

Every figure above is an average across somebody else’s environments. The useful question is narrower: in your estate, what is actually running, which identities can reach what, and how long would it take anyone to notice.

Through our CrowdStrike partner licensing we can answer that at no license cost. You choose up to three assessments, we run them on CrowdStrike Falcon™ in your environment for a defined sixty day window, and you keep the findings whether or not you buy anything afterwards. The licensing ends when the window does, and we would like you to keep the platform. That is the arrangement, said out loud.

Questions

About the report, and about us.

What is breakout time?

Breakout time is how long an intruder takes to move from the machine they first compromised to other systems on the network. It matters more than almost any other measurement because it sets the deadline: contain the intrusion inside that window and it stays one machine, miss it and it becomes an estate-wide incident. The CrowdStrike 2026 Global Threat Report puts the 2025 average for eCrime intrusions at 29 minutes.

How fast was the fastest attack in 2025?

27 seconds from initial access to lateral movement, according to the CrowdStrike 2026 Global Threat Report. The report also documents an intrusion in which data exfiltration began four minutes after the adversary obtained access, using a remote access tool the victim was persuaded to install.

What does malware-free mean, and why does it matter?

It means the intrusion involved no malicious file for a scanner to detect. The adversary used valid credentials, legitimate remote administration tools and approved integrations instead. The CrowdStrike 2026 Global Threat Report puts malware-free detections at 82% of the 2025 total, up from 51% in 2020. It matters because signature-based antivirus is built to find files, and most intrusions no longer bring one.

Does this mean antivirus is useless?

No, and overstating it would be its own mistake. Prevention still stops the commodity attacks that make up most of the noise, and stopping them cheaply is worth doing. What the figures say is that prevention alone leaves the majority case uncovered, because you cannot block an action that is indistinguishable from legitimate administration. That gap is covered by detection and response, and by somebody watching at the hour it happens.

What can a company without a 24/7 security team actually do about 29 minutes?

Realistically, one of two things. Build the coverage, which means staffing enough analysts to hold a rotation through nights and weekends and keeping them trained. Or buy it, which is what a managed detection and response service is. What does not work is intending to do it later: the failure mode is not a lack of tooling, it is that the alert arrives at 2am on a Sunday and nobody is holding the pager.

Is this report Vijilan research?

No. The CrowdStrike 2026 Global Threat Report is CrowdStrike's research, published by CrowdStrike, and every figure on this page is attributed to it. The commentary is ours. We are a CrowdStrike Powered Service Provider and we operate the platform the report describes, which is why we read it closely, but we did not write it and we do not host it. The download link goes to CrowdStrike.

Which industries were hit hardest?

Technology led at 23% of interactive intrusions in 2025, followed by manufacturing at 15%, retail at 12%, financial services at 11% and healthcare at 10%. North America accounted for 55% of interactive intrusions globally. Figures from the CrowdStrike 2026 Global Threat Report.

Attribution. All statistics on this page are drawn from the CrowdStrike 2026 Global Threat Report, published by CrowdStrike, Inc. and covering January to December 2025. The report, its findings and the adversary names it uses are CrowdStrike’s. Vijilan is a CrowdStrike Powered Service Provider; we did not contribute to the research and we do not host the report. The analysis and opinions on this page are Vijilan’s own and should not be read as CrowdStrike’s position. CrowdStrike, Falcon and the adversary designations are trademarks of CrowdStrike, Inc.