I Need IT Support Now
Managed Service ProviderHouston Cybersecurity
Shane

Huntress 2025 Cyber Threat Report: What West Houston Businesses Need to Know 

Protecting Your Business Identity: Essential Security Strategies – Why Most Businesses Discover Attacks Too Late

Report Findings
Hackers Are Not Breaking In Anymore. They Are Logging In.

The Huntress 2025 Managed ITDR report says identity is the new security perimeter - stolen logins, not broken firewalls. Here is what West Houston small and mid-size businesses need to know.

TL;DR
Huntress, a cybersecurity firm, published its 2025 Managed ITDR (Identity Threat Detection and Response) report, and the theme is clear: attackers have shifted from breaking into networks to stealing identities. Identity-related incidents rose for 67% of organizations over three years, business email compromise hit 51% in the past year, and 32% of affected businesses lost more than $100,000. Attackers use infostealers to grab credentials and session tokens, then walk past MFA and endpoint tools. Only about a third of organizations catch these attacks at the initial compromise. For Houston SMBs, the takeaway is that MFA and passwords alone are no longer enough - you need identity monitoring and detection (ITDR), phishing-resistant MFA, and tighter control over Microsoft 365 and Google Workspace.

The perimeter is no longer your network - it is your logins. Attackers who steal a valid credential look just like a legitimate user.

Huntress specializes in security for small and mid-size businesses, so its 2025 report is one of the most relevant reads for a company your size. The headline: identity has become the primary way in. Instead of hacking through defenses, attackers steal credentials and session tokens and simply sign in. Here is what the data shows, why multi-factor authentication is no longer enough on its own, and what to do about it.

The shift in one line: attackers stopped attacking the network and started attacking the account.
Watch: CinchOps on the Huntress 2025 Managed ITDR report.

The Headline Findings

Identity attacks are up, expensive, and caught too late.

Identity-related incidents rose for two in three organizations, business email compromise leads, losses are steep, and most attacks are found only after the damage is done.

HUNTRESS 2025 ITDR BY THE NUMBERS +67% more identity attacks 51% hit by BEC last year 32% lost over $100K 68% detect it too late
Headline findings from the Huntress 2025 Managed ITDR report.

Business email compromise led at 51% of organizations, followed by rogue or malicious applications (45%), VPN abuse (43%), credential theft and stuffing (39%), and account takeover (34%). And detection is slow: only about a third of organizations catch these attacks at the initial compromise, while the rest find out after attackers have moved laterally or stolen data.

Why MFA Alone No Longer Stops It

Multi-factor authentication is necessary - and no longer sufficient.

Attackers now steal the session itself, which lets them walk past MFA and endpoint tools without setting off alarms.

  • Infostealers grab the keys. Malware lifts credentials, session cookies, and access tokens in seconds - no password-guessing required.
  • Stolen sessions skip MFA. With a valid session token, an attacker is already "logged in," so MFA never gets asked again.
  • MFA itself gets bypassed. SIM swapping, MFA-fatigue prompts, and adversary-in-the-middle attacks defeat SMS and push-based MFA.
  • Cloud is the target. About half of organizations said more than 40% of their identity incidents involved Microsoft 365 or Google Workspace.
  • Rogue apps hide in plain sight. By default, any user can install apps into a Microsoft 365 tenant - a quiet path to persistent access.

What Houston SMBs Should Do

Move from "block the login" to "watch the account."

The fix is identity monitoring plus phishing-resistant MFA and tighter cloud controls - not just more passwords.

  • Add ITDR. Identity Threat Detection and Response watches for abnormal logins, impossible-travel, new-device MFA enrollments, and suspicious mailbox rules - and responds fast.
  • Use phishing-resistant MFA. Move from SMS codes to app- or hardware-key based methods that resist interception.
  • Lock down Microsoft 365. Turn off default user app installs, review connected apps, and alert on new forwarding rules.
  • Shrink detection time. The goal is minutes, not days - which takes monitoring built for identity, not just endpoints.
  • Train for BEC. Since business email compromise leads the pack, teach staff to spot payment and login lures.

Worried a Stolen Login Could Walk Right In?

CinchOps adds identity monitoring, phishing-resistant MFA, and Microsoft 365 hardening - so a compromised credential does not become a six-figure incident.

Talk to CinchOps
100% Free

Free Cybersecurity Assessment

Would you catch a stolen login before it caused damage? Get a FREE review of your identity security and Microsoft 365 setup.

Get Your Free Assessment

The scariest attacker is not the one breaking down the door - it is the one who logged in with a stolen password and looks exactly like your employee. That is why MFA alone is not the finish line anymore.
Shane Stevens, CEO, CinchOps - LinkedIn

Identity Protection Built for Small Business

CinchOps gives Houston-area SMBs identity threat detection, phishing-resistant MFA, and Microsoft 365 and Google Workspace monitoring - part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, delivering identity protection built for smaller teams.

  • Identity threat monitoring. Continuous watch for abnormal logins, credential theft, and account takeover - in real time.
  • ITDR implementation. Detection and response that goes beyond MFA, with behavioral analysis and automated containment.
  • Microsoft 365 and Workspace protection. Monitoring for rogue apps, suspicious email rules, and unauthorized access.
  • Rapid incident response. Fast containment to stop lateral movement before it becomes a big loss.
  • Phishing-resistant MFA and training. Stronger authentication plus staff awareness for BEC and credential theft.

Do not wait to become another statistic. Contact CinchOps for identity protection that actually works.

Frequently Asked Questions

What is the Huntress 2025 Managed ITDR report?

It is Huntress's 2025 report on Identity Threat Detection and Response, focused on how attackers now target identities - logins, sessions, and tokens - rather than breaking through network defenses. Huntress specializes in security for small and mid-size businesses.

How much did identity attacks rise?

Identity-related incidents increased for 67% of organizations over the past three years. Business email compromise hit 51% in the last year, and 32% of affected businesses reported losses exceeding $100,000.

Why is MFA no longer enough?

Attackers steal session tokens and credentials with infostealer malware, which lets them appear already logged in and bypass MFA. Techniques like SIM swapping, MFA-fatigue prompts, and adversary-in-the-middle attacks also defeat SMS and push-based MFA.

What is ITDR?

Identity Threat Detection and Response - security that monitors for abnormal login behavior, impossible-travel, new-device MFA enrollments, and suspicious mailbox rules, then responds automatically before an attacker can do serious damage.

What should a small business do first?

Add identity monitoring (ITDR), switch to phishing-resistant MFA, and lock down Microsoft 365 by disabling default user app installs and alerting on new forwarding rules. A managed IT provider can run all of it for you.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506