Picus Security Finds 46% of Enterprise Passwords Vulnerable to Cracking — 2X Increase From 2024
More Than 160 Million Attack Simulations in Live Production Environments Reveal Valid Credentials Are Easy to Steal and Nearly Impossible to Stop
SAN FRANCISCO, Aug. 11, 2025 (GLOBE NEWSWIRE) -- Picus Security, the leading security validation company, today released the Blue Report™ 2025, based on more than 160 million real-world attack simulations in live production environments. Now in its third year, the report provides a data-driven assessment of how well security controls perform against today’s threats — and this year’s findings are the most concerning to date.

While cyberattacks grow in both volume and sophistication, defensive effectiveness is declining. This year’s data paints a particularly grim picture: In 46% of environments, at least one password hash was successfully cracked, and data exfiltration attempts were only stopped 3% of the time, down from 9% in 2024. Combined, these trends show how quickly a single compromised credential can open the door to lateral movement and large-scale data theft. With infostealer malware tripling in prevalence and attackers increasingly bypassing defenses using valid logins, organizations face escalating risk from persistent and nearly invisible threats.

“We must operate under the assumption that adversaries already have access,” said Dr. Süleyman Ozarslan, co-founder of Picus Security and VP of Picus Labs. “An ‘assume breach’ mindset pushes organizations to detect the misuse of valid credentials faster, contain threats quickly, and limit lateral movement — which requires continuous validation of identity controls and stronger behavioral detection.”

Key Findings:
- Passwords cracked in nearly half of environments: In 46% of tested environments, at least one password hash was cracked — up from 25% in 2024 — highlighting continued reliance on weak or outdated password policies.
- Stolen credentials are practically unstoppable: Attacks using valid credentials were successful 98% of the time, making techniques like Valid Accounts (MITRE ATT&CK T1078) one of the most reliable ways to bypass defenses undetected.
- Data exfiltration prevention is near zero: Only 3% of data theft attempts were blocked — down 3x from 2024 — even as ransomware operators and infostealers ramped up double-extortion attacks.
- Ransomware remains a top concern. BlackByte continues to be the hardest strain to prevent, with a prevention effectiveness rate of just 26%. BabLock and Maori followed at 34% and 41%, respectively.
- Early detection is a significant blind spot. Discovery techniques like System Network Configuration Discovery and Process Discovery scored below 12% in prevention effectiveness, exposing gaps in detection efforts.
The Blue Report 2025 also reveals that prevention effectiveness declined from 69% in 2024 to 62% in 2025, reversing last year’s gains. And while logging coverage held steady at 54%, only 14% of attacks generated alerts, meaning that most malicious activity still goes unnoticed. Failures in detection rule configuration, logging gaps, and system integration continue to undermine visibility across security operations. The decline highlights how quickly defenses can degrade without continuous oversight and validation of security controls.
Methodology
The Blue Report offers empirical evidence of how well security controls perform in real-world conditions. Findings are based on millions of simulated attacks executed by Picus Security customers from January to June 2025. The simulations were conducted safely in live production environments using Picus’ Security Validation Platform and analyzed by the Picus Labs and Picus Data Science teams. The report also includes ecosystem and industry-specific findings and recommendations that can help companies reduce exposure and improve threat readiness.
To read the full findings and recommendations, download the Blue Report 2025.
About Picus Security
Picus Security, the leading security validation company, gives organizations a clear picture of their cyber risk based on business context. Picus transforms security practices by correlating, prioritizing and validating exposures across siloed findings so teams can focus on critical gaps and high-impact fixes. With Picus, security teams can quickly take action with one-click mitigations to stop more threats with less effort. Offering Adversarial Exposure Validation with Breach and Attack Simulation and Automated Penetration Testing, working together for greater outcomes, Picus delivers award-winning, threat-centric technology that allows teams to pinpoint fixes worth pursuing.
Follow Picus Security on X and LinkedIn.
Media Contact
Jennifer Tanner
Look Left Marketing
picus@lookleftmarketing.com
Images accompanying this announcement are available at
https://www.globenewswire.com/NewsRoom/AttachmentNg/3399fa33-7e80-494c-8d70-150c14da6698
https://www.globenewswire.com/NewsRoom/AttachmentNg/387b8fcd-aac8-4593-be9d-79985703484a
https://www.globenewswire.com/NewsRoom/AttachmentNg/a94c5fa9-32ce-499c-b863-3a0e8497a6ea
- 森赫电梯助力安徽池州城市进阶,85台高品质电梯焕新人居空间
- 读由法国学者罗舍撰写,曾觉之老师翻译的《清季云南回民起义始末》:历史的镜鉴与深思
- 用第一做第一,晶科能源的发展逻辑
- 夏杰语音商用版免费啦!新一轮技术浪潮,将颠覆智能语音交互发展
- 摩登纳(Modula):智能仓储引领者,共创智慧物流新时代
- Market participants see greater signs of improvement in their outlook for alternative assets in 2025
- 开放融合 聚势共享”2025年山石网科生态合作伙伴大会顺利举办
- 中国十大鼻炎馆排行
- 苏州企哆哆财税解读:注册资本认缴与实缴的区别
- 子衿服饰(广东)有限公司——服装定制为你开启独特时尚之旅
- 以舞之名激活新疆文旅新图景
- 发展醇氢电动汽车 最大化促进现有资产保值增值
- Asahi Group Launches Global Sustainability Initiative: The Challenge Calls for Startups and Scaleups
- 华贵保险召开2024年度防范电信网络诈骗工作部署专项会议
- 海外媒体宣发的重要性与策略/FANS实验室
- 第六届乡村振兴研讨会暨中绿生态农业科学院中原分院成立大会在河南召开
- 东莞市科讯精密仪器有限公司 恒温仪器:试验箱与试验机,科技进步的重要助力
- 产品才是硬道理,Healthy Grow汉思格瑞用以功效赢得口碑
- 中华国粹献礼世界|“鼓风泉”品牌入选“一带一路十周年·国礼品牌”
- 中国信达旗下南商银行蝉联香港中国金融 协会“卓越跨境金融服务大奖”特等奖
推荐
-
产业数字化 为何需要一朵实体云?
改革开放前,国内供应链主要依靠指标拉动,其逻
资讯
-
中央气象台连发四则气象灾害预警
暴雪橙色预警+冰冻橙色预警+大雾黄色预警+
资讯
-
周星驰新片《少林女足》在台湾省举办海选,吸引了不少素人和足球爱好者前来参加
周星驰新片《少林女足》在台湾省举办海选,吸
资讯
-
王自如被强制执行3383万
据中国执行信息公开网消息,近期,王自如新增一
资讯
-
私域反哺公域一周带火一家店!
三四线城市奶茶品牌茶尖尖两年时间做到GMV
资讯
-
男子“机闹”后航班取消,同机旅客准备集体起诉
1月4日,一男子大闹飞机致航班取消的新闻登上
资讯
-
新增供热能力3200万平方米 新疆最大热电联产项目开工
昨天(26日),新疆最大的热电联产项目—&md
资讯
-
大家一起关注新疆乌什7.1级地震救援见闻
看到热气腾腾的抓饭马上就要出锅、村里大家
资讯
-
国足13次出战亚洲杯首次小组赛0进球
北京时间1月23日消息,2023亚洲杯小组
资讯
-
中国减排方案比西方更有优势
如今,人为造成的全球变暖是每个人都关注的问
资讯


