The Managed XDR Global Threat Report

Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit

Based on Barracuda Managed XDR’s unique dataset of more than two trillion IT security incidents in 2025, this report helps businesses understand how attackers target potential victims and the vulnerabilities they try to exploit.

malicioius QR codes
100%
of security incidents involved at least one unprotected or rogue endpoint
html-attachments
96%
of incidents involving lateral movement ended with the release of ransomware
account-takeover
66%
of incidents involved the supply chain or a third party (up from 45% in 2024)
bitcoin sextortion scams
3 hours
the fastest ransomware attack detected, from breach to encryption
Breakdown of how attackers gain entry

How attackers gain entry to the network

Attacks targeting identity security top the list of the most detected threats against organizations in the last 12 months. These attacks include unusual or unexpected logins to a user account that do not correspond to the user’s typical behavior pattern in terms of device, location or time.

Breakdown of how attackers tamper with privilege rights

How attackers tamper with privilege rights once inside the system

Using privilege escalation, attackers turn limited access into full administrative control, enabling them to disable defenses, move laterally across systems and access sensitive data. The result can be large-scale compromise and the release of ransomware.