Attackers have always moved quickly once they gain access to an environment. But recent threat research suggests that window is getting even smaller.
In one incident, attackers moved from account takeover to data exfiltration in less than five minutes. More broadly, among the fastest intrusions, the time from initial compromise to data exfiltration fell from 285 minutes in 2024 to 72 minutes in 2025.
At the same time, compromised credentials remain a meaningful path into organizations. Even as AI enables more sophisticated phishing, impersonation and other attacks, stolen credentials and account takeover have not disappeared.
For security teams, the implications are significant. When attackers can move from initial access to impact in minutes, there may be little time to identify and contain malicious activity after a compromise begins. Reducing known credential risk before attackers can use it becomes increasingly important.
Attack techniques continue to evolve, but attackers do not always need a sophisticated exploit to gain access. Sometimes, they can simply use credentials that already work.
Previously compromised credentials accounted for 13% of initial access in a recent analysis of incident response cases. While that percentage was lower than the heightened levels observed in previous years, compromised credentials remained a meaningful initial access vector. More broadly, 65% of initial access was driven by identity-based techniques, including social engineering, credential misuse, brute force, IAM misconfigurations and insider threats.
In cases involving previously compromised credentials, attackers used valid accounts obtained through previous breaches or underground markets to access VPNs, remote access gateways and cloud portals. In other words, credentials compromised somewhere else can become a way into an organization where those credentials still provide access.
This risk persists even as the threat landscape changes. As AI enables new forms of phishing, impersonation and identity fraud, stolen credentials and account takeover remain established threats. Emerging attack techniques are adding to the fraud landscape, not replacing existing credential risks.
Having a compromised credential is one thing. How quickly can an attacker actually use it?
In one recent incident, the answer was almost immediately.
Credentials were captured through an adversary-in-the-middle page at 00:00. At 00:01, the attacker successfully authenticated using those stolen credentials. By 00:04, the attacker had registered its own MFA device.
The sequence illustrates how quickly credential theft can become authenticated access. There may be very little time between the moment a usable credential reaches an attacker and the moment it is put to work.
Not every compromised credential will be used this quickly, and not every credential attack follows the same path. But the case demonstrates why the time between credential compromise and remediation matters.
Getting in can also be just the beginning.
In another incident, CrowdStrike observed the eCrime group SNARKY SPIDER move from account takeover to data theft in less than five minutes. The group was among threat actors CrowdStrike observed compromising SSO-integrated SaaS applications for data exfiltration.
That compressed timeline changes the challenge for defenders.
Once an attacker has authenticated, security teams may need to identify malicious behavior, determine that the legitimate account is being misused and respond before the attacker reaches sensitive systems or data.
Five minutes does not leave much room.
These rapid incidents are part of a broader acceleration in attack speed.
Among the fastest 25% of intrusions, attackers reached data exfiltration in 72 minutes in 2025, compared with 285 minutes in 2024. The percentage of incidents reaching exfiltration in under an hour also increased from 19% to 22%.
That means the fastest quarter of attacks went from taking nearly five hours to reaching data exfiltration in just over an hour.
Unit 42 describes the result as a shrinking window for detection and containment. The faster attackers can progress from initial access to data theft, the less time defenders have to intervene after a compromise has already occurred.
When the time between initial access and impact is measured in minutes, detection and response remain essential, but they are working against an increasingly compressed timeline.
That makes it important to address risks earlier, wherever possible.
For credential-based attacks, that means reducing the opportunity for known compromised credentials to become authenticated access. Passwords that are already known to be compromised should be prevented from being used, while existing credentials should be monitored for new exposure.
This matters because credential risk is not static. A password that was safe when it was created can later become compromised through a third-party breach, infostealer infection or other exposure.
Identifying that change before the credential is used can remove one path to initial access altogether.
The latest research shows just how compressed the timeline can be.
Previously compromised credentials accounted for 13% of initial access in Unit 42’s 2025 incident response cases. CrowdStrike observed stolen credentials being used to authenticate in one minute and, in another incident, account takeover progressing to data theft in less than five minutes. Among Unit 42’s fastest quarter of intrusions, time to data exfiltration fell from 285 minutes in 2024 to 72 minutes in 2025.
The lesson isn’t that detection and response matter less. It’s that organizations have less time to rely on them once an attacker has access.
The more credential risk that can be identified and addressed before authentication, the fewer opportunities attackers have to turn compromised credentials into access and access into impact.