the number that mattered most in Mandiant's seventeenth annual M-Trends report has nothing to do with artificial intelligence. Global median dwell time, the stretch between an attacker's first foothold and the moment a defender notices, rose to 14 days in 2025, up from 11 the year before. That reversal breaks a run of steady improvement Mandiant has tracked for close to a decade.
Security marketing this year is built around a different story: attackers wielding large language models to write better phishing lures and evade detection mid-execution. Mandiant's own researchers document that activity. A credential stealer called QUIETVAULT now checks compromised machines for local AI command-line tools and runs prompts against them to hunt for secrets. That is real, and it is new.
The dwell time increase traces to hardware, not software sophistication
Mandiant attributes the longer dwell times largely to two adversary types optimizing for persistence rather than speed: long-horizon cyber espionage operators and North Korean IT worker schemes that embed people inside target organizations under false identities. Both groups favor edge devices, the routers, VPN appliances, and firewalls sitting at a network's perimeter that typically ship without the logging depth security teams expect from servers and endpoints.
A firewall with no audit trail cannot tell an incident responder anything. Mandiant's report puts it plainly: if you cannot prove the scope of an intrusion because the logs never existed, you are left assuming and disclosing a worst-case data theft, whether or not one occurred. That is a governance problem before it is a technology problem. Someone in every enterprise approved a purchasing standard for edge hardware that never asked whether the device could produce evidence during a breach.
Cybercrime groups moved in the opposite direction from the espionage actors. Mandiant found ransomware operators shifting emphasis from stealing data to what the report calls deliberate recovery denial, destroying or encrypting backups so restoration itself becomes the leverage.
Speed for the criminal groups, patience for the espionage groups.
Both exploit the same underlying gap: telemetry that was never built to catch them.
Mandiant is threading a message that cuts against its own AI product roadmap
The assumption running through most vendor coverage of this year's threat data is that AI changes the math for defenders and attackers roughly in step, so the response is to buy AI-powered defense to match AI-powered offense. Mandiant's report resists that framing. It states that the vast majority of successful intrusions still stem from fundamental human and systemic failures, the same failures the dwell time numbers point to: unmonitored devices, trust relationships nobody reviewed, identity verification that a fake remote employee walked through unchallenged.
That is a notable position for Google Cloud to publish. Its own security portfolio, the Secure AI Framework and the AI-powered agents inside Google Security Operations, gets marketed on the premise that AI defense is the current moment's central requirement. The report's authors are telling customers, in effect, that the fundamentals still explain most breaches and that an AI purchase does not substitute for closing telemetry gaps on hardware many organizations have not audited in years.
Mandiant does recommend organizations start incorporating AI-driven techniques, prompt injection among them, into their own red team exercises, and treat AI-powered defense as a force multiplier once the basics are covered. The sequencing in the report matters: fundamentals first, AI layered on top, not the reverse.
The cybercrime ecosystem is specializing the way legitimate industries do
Mandiant also flags growing specialization inside the criminal economy itself. Initial access brokers, malware developers, and ransomware operators increasingly function as separate businesses trading with each other rather than a single group running an attack start to finish. That division of labor mirrors how legitimate software supply chains fragmented over the past decade, and it means a defender who blocks one stage of an intrusion is not necessarily blocking the group responsible for the next stage.
Google Cloud. "M-Trends 2026 Report: Executive Edition." Mandiant, 2026, cloud.google.com.
