Phishing has declined as a method of initial access in 2024 and is now behind credential theft and vulnerability exploitation, according to Mandiant’s M-Trends 2025 Report.
This continues a trend observed over several year, with email phishing falling from 22% to 14% for initial access from 2022 to 2024.
Vulnerability exploitation was the most common method of infiltrating targets in 2024, making up 33% of cases. However, this marks a significant decline from 38% in 2023.
The use of stolen credentials for initial access jumped from 10% to 16% from 2023 to 2024, making it the second most common technique.
No tags.