Site navigation

Data Breach Incidents Surged by Over a Third in 2023

Michael Edgar

,

Data breach surge
New Flashpoint report reveals that reported data breach incidents surged by over a third last year.

According to Flashpoint’s 2024 Global Threat Intelligence Report, there has been a concerning trend in data security, indicating a significant rise in reported data breach incidents by 34.5% in 2023. 

The report highlights that over 17 billion personal records were compromised throughout the year, marking a substantial increase in cyber threats globally. The firm also recorded a staggering 6,077 publicly reported data breaches last year, exposing sensitive information such as names, social security numbers, and financial data. 

Further analysis from Flashpoint reveals a startling 429% spike in stolen or leaked personal data in the first two months of 2024 compared to the same period last year, with a staggering 1,897 billion personal records and credentials compromised.

Alarmingly, over 70% of these incidents were the result of unauthorised access originating from external sources outside the affected organisations. 

Ransomware attacks emerged as a major driver behind the surge in data breaches, with Flashpoint reporting an 84% increase in documented incidents in 2023. Notably, the number of public ransomware attacks continued to escalate, growing by approximately 23% in the first two months of 2024 compared to the same period in 2023, totaling 637 attacks.

The report also highlighted the notorious LockBit gang, which claimed 1,049 victims in 2023, representing over a fifth of all known ransomware attacks. However, the gang’s operations faced disruption in February 2024 during Operation Cronos, a coordinated effort by global law enforcement agencies.


Recommended reading


Flashpoint researchers also underscored the impact of the Clop ransomware group’s exploitation of the MOVEit Transfer file application vulnerability, which significantly contributed to the data breach landscape in 2023. The MOVEit attack alone accounted for 19.3% of all reported breaches, affecting organisations across various sectors, including those within their supply chains.

The construction and engineering sector emerged as the most targeted by ransomware attacks in 2023, accounting for 18.7% of incidents, followed by professional services (13.7%), internet software and services (13.2%), and healthcare providers and services (12.29%).

Moreover, the report highlights a record high in vulnerability disclosures, reaching 33,137 in 2023. Over half of these disclosures scored high to critical severity under the Common Vulnerability Scoring System (CVSS), providing fertile ground for cyber attacks like ransomware.

Flashpoint researchers cautioned that organisations solely relying on Common Vulnerabilities and Exposures (CVEs) may overlook a significant portion of vulnerability risks, estimating that over 100,000 vulnerabilities were not adequately addressed by CVEs, posing a significant challenge to cybersecurity efforts worldwide.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data