Three Attacks from 2025 That Show Why Alerts Alone Are No Longer Enough

CyTwist Research Team

How missed signals, silent progression, and alert fatigue enabled some of last year’s most damaging breaches

In 2025, organizations across industries invested heavily in security tools, monitoring platforms, and managed detection services. Endpoint Detection & Response (EDR), SIEM, and SOC operations have never been more mature.

And yet, some of the most damaging cyber incidents of the year did not happen because attackers were invisible.
They happened because the signals that mattered were missed, misread, deprioritized, or closed too early.

Across multiple high-profile incidents, the same pattern emerged:

  • Telemetry was collected
  • Early indicators existed
  • Some malicious behaviors may have been observable
  • Initial reviews were sometimes possible


But attacker progression was never fully understood.

Instead, attackers exploited legitimate tools, trusted credentials, and normal operating system behavior to move quietly through environments, until the damage was already done.

This blog examines three major incidents from 2025 that illustrate this growing detection gap, and what they reveal about the future of cyber defense.

1. M&S: How Identity Abuse Became a £300M Breach

In early 2025, Marks & Spencer suffered one of the most disruptive retail cyberattacks in recent years. Public reporting revealed that attackers first gained access months before the ransomware was deployed. The entry point was identity abuse.

The attackers impersonated an employee and convinced a third-party contractor to reset credentials. With valid access in hand, they entered M&S systems without triggering alerts that clearly required escalation.

From there, the attackers:

  • Accessed internal systems using legitimate credentials
  • Performed reconnaissance using standard administrative tools
  • Expanded privileges gradually
  • Prepared infrastructure for ransomware deployment
  • Ultimately deployed DragonForce ransomware in April


More than 1,000 stores were affected. Online sales were suspended. Core operational systems were encrypted. M&S later estimated losses of nearly £300 million.

What Went Wrong
This was not a failure of logging.
This was not a failure of tooling.

EDR and identity platforms captured the activity. Authentication systems logged access. Privilege changes were recorded. System commands were executed in plain sight.

The failure occurred at the interpretation layer.

Each individual action appeared legitimate:

  • A user logged in
  • An admin command executed
  • A system query ran
  • A credential was used

None of these events, viewed in isolation, were inherently malicious.

Without behavioral correlation, SOC teams lacked a unified signal that these activities were part of an evolving attack.

By the time the ransomware was deployed, the attackers had already achieved deep, persistent access.

2. Jaguar Land Rover: When Lateral Movement Shuts Down Production

In September 2025, Jaguar Land Rover was forced to shut down major production facilities following a cyberattack.

Multiple plants across the UK and abroad were impacted. Manufacturing lines stopped. Suppliers were disrupted. Tens of thousands of employees were affected. The UK government later provided financial guarantees to support recovery.

Investigations suggested that the attack originated from the same threat group that previously targeted M&S. This indicates a broader campaign rather than an isolated incident.

The Anatomy of the Attack

While detailed technical disclosures were limited, reporting and industry analysis point to a familiar progression:

  1. Initial access via compromised credentials or supplier access
  2. Silent reconnaissance across IT and OT environments
  3. Privilege escalation using legitimate administrative mechanisms
  4. Lateral movement between sites and systems
  5. Disruption of operational technology


Again, the attackers did not rely on zero-day exploits or obvious malware.

They relied on:

  • Valid authentication
  • Trusted tools
  • Standard protocols
  • Native management utilities


What Went Wrong

JLR’s environment generated vast amounts of telemetry.
Endpoints logged activity. Authentication systems recorded access. Network connections were visible.
But the broader progression was not clearly visible in real time.

The attack unfolded across:

  • IT systems
  • Manufacturing systems
  • Supplier integrations
  • Remote management platforms


Each domain was monitored independently.
No unified view existed to reconstruct attacker intent across domains. As a result, attackers were able to pivot across systems until disruption was unavoidable.
By the time impact occurred, remediation required weeks of recovery.

3. European Airports: When Detection Gaps Disrupt Critical Infrastructure

In September 2025, several major European airports – including Brussels, Heathrow, and Berlin Brandenburg – experienced significant operational disruptions following a cyberattack.

Check-in systems failed. Boarding processes reverted to manual procedures. Flights were canceled or delayed.

While the technical details were not fully disclosed, authorities confirmed that the attack targeted interconnected operational systems.

Why Airports Are Especially Vulnerable

Modern airports operate as digital ecosystems:

  • Passenger systems
  • Airline integrations
  • Baggage handling
  • Border control systems
  • Third-party vendors
  • Ground operations


All are connected. All are interdependent. A compromise in one subsystem can propagate rapidly.

What Went Wrong

There was no dramatic “breach moment.”
No publicized ransomware.
No mass data leak.
Instead, operational systems degraded quietly until service continuity collapsed.

The likely pattern:

  • Initial access through a supplier or service account
  • Low-noise reconnaissance
  • Gradual manipulation of operational systems
  • Coordinated disruption


Security teams continued routine monitoring of their environments.

But fragmented visibility and complex dependencies limited early recognition of attacker progression.

This incident illustrates a critical reality: in highly interconnected environments, silent attacks can cause societal-scale disruption before security teams realize what is happening.

The Common Pattern: Signals Without full Context

Across all three cases – M&S, JLR, and European airports – the same pattern appears:

1. Early Signals Were Present

Authentication anomalies
Administrative commands
Unusual access patterns
System activity

These activities were logged, however, they did not consistently receive sufficient context or escalation to reveal the full scope of attacker progression.

2. Activity Looked Legitimate

These are standard enterprise tools.

They are used every day by IT teams.

Security platforms are designed to tolerate them.

3. Investigations Were Fragmented

SOC analysts worked with:

  • Isolated alerts
  • Limited context
  • Tight SLAs
  • Heavy workloads


Reconstructing attacker logic requires time, experience, and cross-platform correlation.
Many SOCs struggle to consistently maintain all three.

4. Automation Often Prioritizes Rapid Closure

Modern SOCs rely heavily on:

  • Automated triage
  • Rule-based closure
  • Risk scoring
  • Alert suppression


This improves efficiency, but also suppresses weak signals.

As a result, many investigations are closed before patterns emerge.

Why Traditional Detection Models Struggle

Most security tools still operate on three primary models:

  1. Signatures and IOCs
  2. Statistical anomalies
  3. Event correlation rules


These models work well when attackers behave in predictable ways.
They fail when attackers behave like administrators.

Modern adversaries design campaigns to remain inside “normal. They often do not trigger clear alarms. They assemble attacks from legitimate components. They spread activity over time. They adapt in real time. This defeats detection models focused on isolated events.

What Is Needed: From Detection to Understanding

To address these threats, organizations must shift from:

“Is this event bad?”
to
“What is this behavior trying to achieve?”

This requires:

  • Sequence analysis
  • Intent modeling
  • Behavioral profiling
  • Cross-domain correlation


Security teams must understand:

  • Why commands are executed
  • Why credentials are used
  • Why access patterns change
  • Why systems are queried


Not just that they happened.

This represents a strategic shift from event detection to progression analysis.

How CyTwist Addresses the Gap

The CyTwist Profiler was built specifically to address this structural gap.
Instead of generating more alerts, CyTwist focuses on:

  • Analyzing low-level OS evidence and existing alerts
  • Modeling attacker intent
  • Identifying progression patterns


By combining these signals, CyTwist determines whether isolated events form a coherent attack sequence. A weak signal or a low-severity alert becomes meaningful when it is part of a larger progression.

Preventing False Confidence

One of the most dangerous states in security is false confidence.

Dashboards may appear healthy.

Alerts are closed.

KPIs are met.

Meanwhile, attackers are active.

CyTwist identifies:

  • Hidden relationships between signals
  • Early-stage attack chains
  • Alerts that should be reopened
  • Investigations closed prematurely


This prevents silent compromise.

Reducing Dwell Time Without Adding Noise

CyTwist does not flood analysts with more alerts.

It elevates the right ones.

With context.

With narrative.

With intent.

This shortens dwell time while reducing alert fatigue.

Why This Matters in 2026

Attackers are becoming:

  • More automated
  • More patient
  • More adaptive
  • More business-oriented

AI-assisted malware, living-off-the-land techniques, and identity abuse are becoming standard.

Encryption is no longer necessary.

Disruption is optional.

Data theft, operational manipulation, and reputational leverage are enough.

In this environment, having “alerts” is not enough.

Understanding progression is decisive.

Conclusion: The Breach Was Visible. The Meaning Was Not.

The major attacks of 2025 were not invisible – They were misunderstood.
One credential misuse, one admin command misinterpreted, one low-severity alert closed too soon.

That is often all it takes.

M&S lost hundreds of millions.

JLR halted production.

Airports disrupted millions of travelers.

Not because tools failed.

Because attacker intent was not recognized in time.

The future of cyber defense belongs to organizations that can understand attacker logic before impact.
That is the next inflection point. And it is where CyTwist is focused.

Share

Ready to stop
stealth targeted
attacks?

Three Attacks from 2025 That Show Why Alerts Alone Are No Longer Enough

CyTwist Research Team

Share

Ready to stop
stealth targeted
attacks?

More posts like this

Skip to content