Executive Summary
In 2025, Unit 42 responded to over 750 major cyber incidents across various industries and countries. A significant trend observed was the rapid acceleration of attack timelines, with some adversaries moving from initial access to data exfiltration in just 72 minutes—a fourfold increase from the previous year. This surge is largely attributed to the integration of AI by threat actors, enhancing their speed and efficiency. Additionally, identity-based attacks have become predominant, with 65% of initial accesses driven by techniques such as social engineering and credential misuse. (paloaltonetworks.com)
The current cybersecurity landscape underscores the urgency for organizations to adapt to these evolving threats. The rise in AI-driven attacks and the exploitation of identity vulnerabilities necessitate a reevaluation of security strategies. Implementing robust identity and access management, enhancing monitoring capabilities, and adopting AI-driven defense mechanisms are crucial steps to mitigate these accelerated and sophisticated threats.
Why This Matters Now
The rapid acceleration of cyberattack timelines, driven by AI and identity-based techniques, poses an immediate and significant threat to organizations. Without swift adaptation and reinforcement of security measures, businesses risk severe data breaches and operational disruptions.
Attack Path Analysis
The attacker gained initial access through compromised credentials, escalated privileges by modifying authentication processes, moved laterally across cloud services, established command and control channels, exfiltrated sensitive data, and caused significant operational disruption.
Kill Chain Progression
Initial Compromise
Description
The attacker obtained valid user credentials, possibly through phishing or credential stuffing, to access the cloud environment.
MITRE ATT&CK® Techniques
Valid Accounts
Modify Authentication Process: Hybrid Identity
Valid Accounts: Cloud Accounts
Use Alternate Authentication Material: Application Access Token
Remote Services: Remote Desktop Protocol
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Risk Management Framework
Control ID: Article 6
CISA Zero Trust Maturity Model 2.0 – Identity Governance and Administration
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Identity-based attacks with 72-minute compromise timelines threaten critical financial systems, requiring enhanced zero trust segmentation and real-time threat detection capabilities.
Health Care / Life Sciences
Rapid privilege escalation and lateral movement attacks compromise patient data systems, necessitating HIPAA-compliant encrypted traffic monitoring and anomaly response solutions.
Information Technology/IT
Multi-cloud environments face east-west traffic security risks from identity manipulation attacks, demanding comprehensive visibility and automated correlation across hybrid infrastructures.
Government Administration
Compressed attack timelines exploiting administrative credentials threaten critical government systems, requiring immediate implementation of egress security and policy enforcement frameworks.
Sources
- Inside the Modern SOC: The 72-Minute Racehttps://unit42.paloaltonetworks.com/soc-72-minute-race/Verified
- 2026 Unit 42 Global Incident Response Report — Attacks Now 4x Fasterhttps://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/Verified
- Unit 42 Report: AI and Attack Surface Complexity Fuel Majority of Breacheshttps://www.paloaltonetworks.com/company/press/2026/unit-42-report--ai-and-attack-surface-complexity-fuel-majority-of-breachesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to escalate privileges, move laterally, establish command and control channels, and exfiltrate data, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial credential compromise, it would likely limit the attacker's subsequent actions within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely limit the attacker's ability to escalate privileges by enforcing strict access controls and minimizing trust between workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit the attacker's lateral movement by enforcing strict segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely limit the establishment of command and control channels by providing comprehensive monitoring and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic.
While Aviatrix Zero Trust CNSF may not prevent all forms of operational disruption, its comprehensive security measures would likely reduce the scope and severity of such impacts.
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- IT Help Desk Operations
- Cloud Infrastructure Management
- Data Security and Compliance
Estimated downtime: 3 days
Estimated loss: $500,000
Compromised credentials leading to unauthorized access and potential data exfiltration of sensitive corporate information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust multi-factor authentication (MFA) to prevent unauthorized access through compromised credentials.
- • Regularly audit and monitor authentication processes to detect and prevent unauthorized modifications.
- • Enforce strict least privilege access controls to limit lateral movement within the cloud environment.
- • Deploy advanced threat detection systems to identify and respond to command and control activities.
- • Establish comprehensive data loss prevention (DLP) measures to monitor and control data exfiltration attempts.



