Security

Attackers Now Break Out in 29 Minutes. Most Defenders Still Take Two Weeks to Notice.

CrowdStrike's 2026 Global Threat Report says the average eCrime breakout time fell to 29 minutes last year, a 65% jump in attacker speed. Mandiant's M-Trends 2026 says the median detection dwell time went the other way, rising to 14 days.

September 18, 2026 · Security
A row of server racks in a data centre aisle with cabling running overhead

Key Takeaways

  • CrowdStrike's 2026 Global Threat Report found the average eCrime breakout time, the gap between initial access and lateral movement onto a second system, fell to 29 minutes in 2025, a 65% jump in speed over 2024, with the fastest observed breakout clocked at 27 seconds.
  • Mandiant's M-Trends 2026 report found the median handoff time between an initial access broker's foothold and a ransomware affiliate taking over collapsed to 22 seconds in 2025, down from more than eight hours as recently as 2022.
  • Global median dwell time, how long attackers sit undetected inside a network, rose to 14 days in 2025 from 11 the year before, stretching to a 25-day median when the victim only learned of the breach from an outside party.
  • Just over half of organizations, 52%, caught the intrusion themselves in 2025, up from 43% in 2024, yet Check Point's 2026 Cloud Security Report found only 5% of organizations have full visibility into how AI tools are being used across their own environment.

Twenty-nine minutes is not a lot of time. It is roughly the length of a status meeting, and according to CrowdStrike's 2026 Global Threat Report, it is now the average window an eCrime actor needs to go from initial access to moving laterally onto a second machine. Fourteen days, by contrast, is how long the median enterprise took to even notice an intruder was inside at all last year. The two numbers describe the same industry, and the distance between them is not shrinking, it is widening.

Breakout Time Just Fell 65% in a Single Year

CrowdStrike's own definition of breakout time is specific: the interval between an adversary's initial compromise and their first attempt to move beyond the original foothold. In 2025 that average fell to 29 minutes, down from roughly 48 minutes the year before, a 65% acceleration that the report ties directly to AI-enabled tradecraft. Threat actors who integrated AI into reconnaissance, credential theft, and evasion increased their attack volume by 89% year over year, and in the fastest documented case, an adversary began exfiltrating data within four minutes of initial access.

The report's other headline figure is arguably more unsettling than the speed itself. Eighty-two percent of the detections CrowdStrike's team investigated in 2025 were malware-free, meaning the intrusion looked, to most conventional tooling, like a legitimate user doing legitimate things with valid credentials. Adversaries also directly targeted the AI layer, injecting malicious prompts into generative AI tools at more than 90 organizations. A security stack built to catch a dropped executable is not built to catch any of this.

The Access Economy Made the Handoff Nearly Instant

If breakout time measures how fast an attacker moves once inside, Mandiant's M-Trends 2026 report measures something upstream of that: how fast one attacker hands a compromised environment off to another. In 2022, the median gap between an initial access broker establishing a foothold and a secondary group, often a ransomware affiliate, taking it over exceeded eight hours. In 2025, that median collapsed to 22 seconds, with the hand-off pattern itself appearing in 9% of investigations, more than double its 4% share in 2022.

Detection did not keep pace. Global median dwell time rose to 14 days in 2025 from 11 the year before, and the source of detection mattered enormously: organizations that caught the intrusion internally had a median dwell time of about 9 days, while those who only learned about it from an external party, a law enforcement notification or a ransomware note, took a median of 25 days. Just over half, 52%, of victims detected the activity themselves in 2025, up from 43% in 2024, a real improvement that still leaves roughly half of all victims finding out from someone else. Mandiant's Jurgen Kutscher summarized the resulting posture bluntly in comments carried by CSO Online: financially motivated groups are now "optimized for immediate impact and deliberate recovery denial," deliberately targeting backup infrastructure and identity services so that victims face a binary choice between paying and rebuilding.

Visibility Is the Bottleneck, Not Intent

Most security teams do not lack urgency about any of this. What they lack, according to Check Point's 2026 Cloud Security Report, is a consistent view of their own environment. The report found that only 5% of organizations have full visibility into how AI tools are being used across their operations, and that AI workloads routinely cross cloud, SaaS, and on-premises boundaries where existing security controls simply stop following them, creating exactly the kind of blind spot a 22-second handoff is built to exploit. Check Point's response is architectural rather than procedural: defining policy once and enforcing it consistently across every environment through what it calls a hybrid mesh model, rather than reconciling a different rule set at every boundary.

None of this points to a single missing product. It points to three compounding gaps arriving at once: adversaries moving in minutes rather than hours, handoffs between attacker groups measured in seconds rather than a workday, and defenders who still cannot see the full shape of their own infrastructure. Closing any one of those gaps helps. Closing only one of them does not.

Twenty-nine minutes, 22 seconds, and 14 days are not three separate statistics competing for attention. They are the same threat landscape described at three different layers, and each one is moving in the direction that favors the attacker. The organizations narrowing that gap are not the ones with the most tools. They are the ones that can already see what is happening across their environment, and can act on it before the meeting-length window closes.

Share

More in Security

All Resources →