Cloud environments continue to be a prime target for cyber adversaries, with compromised credentials being the most common attack vector according to new research from IBM Security X-Force.

In its 2023 Cloud Threat Landscape Report, X-Force reported that more than 35% of the cloud security incidents it responded to in the last year involved the use of compromised – but valid – credentials by attackers. With credentials making up nearly 90% of assets for sale on underground dark web marketplaces, it's clear that cybercriminals see big value in gaining access to usernames and passwords.

Outlook Cloud credentials are particularly popular on dark web marketplaces, accounting for over 5 million mentions, according to X-Force. The average price for stolen credentials is around $10, which X-Force whimsically equates to a dozen doughnuts.

Among the key findings in the report:

  • Over 35% of cloud security incidents involved compromised credentials.
  • Outlook Cloud credentials had over 5 million mentions on dark web markets.
  • Nearly 200% increase in new cloud-related vulnerabilities in 2023.

“There’s been a lot of fear spreading about how cybercriminals will advance with the rise of AI [artificial intelligence], but our data still points to tried-and-true tactics being attackers’ weapon of choice," Chris Caridi, cyber threat analyst at IBM X-Force, told SDxCentral.

Why compromised credentials continue to be a cloud risk

Caridi noted that compromised credentials are the top threat vector IBM X-Force saw used against cloud environments.

Looking at the broader cybercrime ecosystem, he noted that it's also possible to see the scale of this trend with attackers utilizing illicit marketplaces at very accessible price points.

“If there’s one thing we can all agree on it’s that you don’t know what you don’t know," Caridi said. "In order to implement a security strategy, you need to first know what it is you're defending against and what the report shows us is that compromised credentials is a very active threat vector that organizations need to manage."

He added that it’s not enough to be who you say you are — you have to act like it, too, which is why leveraging AI-enabled identity access management tools is important. In his view, security tools need to become as dynamic as threats are, as it’s not sufficient to rely on static identity verification with credentials.

"Organizations need to lean on behavioral analytics to more effectively detect anomalies and trigger failsafes when users aren’t acting as they typically do online," Caridi said.

Cloud vulnerabilities are on the rise overall

The IBM report identified a dramatic spike in the number of cloud vulnerabilities counted as CVEs (common vulnerabilities and exposures) in 2023, with a 200% year over year increase.

While cloud security incidents can happen anywhere in the world, the majority (64%) that X-Force responded to were actually in Europe.

"Regarding the higher percentage of cloud incidents observed in Europe, it’s possible that the increasing tensions in the region and uptick in backdoor deployments are factors indirectly related to the higher activity observed," he said.