According to Flashpoint’s 2024 Global Threat Intelligence Report, there has been a concerning trend in data security, indicating a significant rise in reported data breach incidents by 34.5% in 2023.Â
The report highlights that over 17 billion personal records were compromised throughout the year, marking a substantial increase in cyber threats globally. The firm also recorded a staggering 6,077 publicly reported data breaches last year, exposing sensitive information such as names, social security numbers, and financial data.Â
Further analysis from Flashpoint reveals a startling 429% spike in stolen or leaked personal data in the first two months of 2024 compared to the same period last year, with a staggering 1,897 billion personal records and credentials compromised.
Alarmingly, over 70% of these incidents were the result of unauthorised access originating from external sources outside the affected organisations.Â
Ransomware attacks emerged as a major driver behind the surge in data breaches, with Flashpoint reporting an 84% increase in documented incidents in 2023. Notably, the number of public ransomware attacks continued to escalate, growing by approximately 23% in the first two months of 2024 compared to the same period in 2023, totaling 637 attacks.
The report also highlighted the notorious LockBit gang, which claimed 1,049 victims in 2023, representing over a fifth of all known ransomware attacks. However, the gang’s operations faced disruption in February 2024 during Operation Cronos, a coordinated effort by global law enforcement agencies.
Recommended reading
- Who Hacks the Hackers? Dark Web Cybercrime Forums Taken Down
- NCSC and ICO Sign Agreement to Partner on Cyber Threat Intelligence
- How Vital is Threat intelligence Data to a Successful Cyber Strategy?
Flashpoint researchers also underscored the impact of the Clop ransomware group’s exploitation of the MOVEit Transfer file application vulnerability, which significantly contributed to the data breach landscape in 2023. The MOVEit attack alone accounted for 19.3% of all reported breaches, affecting organisations across various sectors, including those within their supply chains.
The construction and engineering sector emerged as the most targeted by ransomware attacks in 2023, accounting for 18.7% of incidents, followed by professional services (13.7%), internet software and services (13.2%), and healthcare providers and services (12.29%).
Moreover, the report highlights a record high in vulnerability disclosures, reaching 33,137 in 2023. Over half of these disclosures scored high to critical severity under the Common Vulnerability Scoring System (CVSS), providing fertile ground for cyber attacks like ransomware.
Flashpoint researchers cautioned that organisations solely relying on Common Vulnerabilities and Exposures (CVEs) may overlook a significant portion of vulnerability risks, estimating that over 100,000 vulnerabilities were not adequately addressed by CVEs, posing a significant challenge to cybersecurity efforts worldwide.





