CrowdStrike's 2026 Global Threat Report says the average eCrime breakout time fell to 29 minutes last year, a 65% jump in attacker speed. Mandiant's M-Trends 2026 says the median detection dwell time went the other way, rising to 14 days.
Key Takeaways
Twenty-nine minutes is not a lot of time. It is roughly the length of a status meeting, and according to CrowdStrike's 2026 Global Threat Report, it is now the average window an eCrime actor needs to go from initial access to moving laterally onto a second machine. Fourteen days, by contrast, is how long the median enterprise took to even notice an intruder was inside at all last year. The two numbers describe the same industry, and the distance between them is not shrinking, it is widening.
CrowdStrike's own definition of breakout time is specific: the interval between an adversary's initial compromise and their first attempt to move beyond the original foothold. In 2025 that average fell to 29 minutes, down from roughly 48 minutes the year before, a 65% acceleration that the report ties directly to AI-enabled tradecraft. Threat actors who integrated AI into reconnaissance, credential theft, and evasion increased their attack volume by 89% year over year, and in the fastest documented case, an adversary began exfiltrating data within four minutes of initial access.
The report's other headline figure is arguably more unsettling than the speed itself. Eighty-two percent of the detections CrowdStrike's team investigated in 2025 were malware-free, meaning the intrusion looked, to most conventional tooling, like a legitimate user doing legitimate things with valid credentials. Adversaries also directly targeted the AI layer, injecting malicious prompts into generative AI tools at more than 90 organizations. A security stack built to catch a dropped executable is not built to catch any of this.
If breakout time measures how fast an attacker moves once inside, Mandiant's M-Trends 2026 report measures something upstream of that: how fast one attacker hands a compromised environment off to another. In 2022, the median gap between an initial access broker establishing a foothold and a secondary group, often a ransomware affiliate, taking it over exceeded eight hours. In 2025, that median collapsed to 22 seconds, with the hand-off pattern itself appearing in 9% of investigations, more than double its 4% share in 2022.
Detection did not keep pace. Global median dwell time rose to 14 days in 2025 from 11 the year before, and the source of detection mattered enormously: organizations that caught the intrusion internally had a median dwell time of about 9 days, while those who only learned about it from an external party, a law enforcement notification or a ransomware note, took a median of 25 days. Just over half, 52%, of victims detected the activity themselves in 2025, up from 43% in 2024, a real improvement that still leaves roughly half of all victims finding out from someone else. Mandiant's Jurgen Kutscher summarized the resulting posture bluntly in comments carried by CSO Online: financially motivated groups are now "optimized for immediate impact and deliberate recovery denial," deliberately targeting backup infrastructure and identity services so that victims face a binary choice between paying and rebuilding.
Most security teams do not lack urgency about any of this. What they lack, according to Check Point's 2026 Cloud Security Report, is a consistent view of their own environment. The report found that only 5% of organizations have full visibility into how AI tools are being used across their operations, and that AI workloads routinely cross cloud, SaaS, and on-premises boundaries where existing security controls simply stop following them, creating exactly the kind of blind spot a 22-second handoff is built to exploit. Check Point's response is architectural rather than procedural: defining policy once and enforcing it consistently across every environment through what it calls a hybrid mesh model, rather than reconciling a different rule set at every boundary.
None of this points to a single missing product. It points to three compounding gaps arriving at once: adversaries moving in minutes rather than hours, handoffs between attacker groups measured in seconds rather than a workday, and defenders who still cannot see the full shape of their own infrastructure. Closing any one of those gaps helps. Closing only one of them does not.
Twenty-nine minutes, 22 seconds, and 14 days are not three separate statistics competing for attention. They are the same threat landscape described at three different layers, and each one is moving in the direction that favors the attacker. The organizations narrowing that gap are not the ones with the most tools. They are the ones that can already see what is happening across their environment, and can act on it before the meeting-length window closes.
Guide
A 22-second handoff between attacker groups only works if lateral movement is easy. This is the sequenced roadmap for closing that path before the next breakout starts.
Download
Report
A fragmented security stack adds minutes an analyst does not have against a 29-minute breakout window. This covers what a consolidated detection and response platform actually removes from the response path.
Download
Whitepaper
Only 5% of organizations have full visibility into their own cloud workloads. This is the guidance on automated, runtime threat response built to keep pace with an attacker that moves in minutes.
Download
A month earlier, one macOS flaw Apple had already fixed was still being used to plant cryptocurrency miners.
Moonlock Lab found unique malicious macOS samples up roughly 40% year over year, and that two stealer families now dominate detections.
A sweeping analysis of incident data across 500 enterprises asks whether zero trust has delivered on its promise.