April saw a shocking figure of breached records, totalling over 5.3 billion, arising from 652 publicly disclosed security incidents, according to research compiled by IT Governance.
The number of records in April, 5,336,840,757, was high compared to last month, but still did not top the mammoth figure from January 2024 of 26 billion records.
The figure, however, does bring the total number of data records leaked to over 35 billion for 2024 so far.
Two outlier events largely contributed to April’s high figures, according to Alan Calder, founder and executive chairman of IT Governance.
Firstly, a data-scraping website called Spy.pet was found to be selling 4,186,879,104 Discord messages for sale.
Data scraping is typically automated, extracting information from websites enabling criminals to compile personal data to later sell.
The effective method secure over 4.1 billion records, but Discord banned the affiliated accounts, and Spy.pet has been taken offline.
Next, critical vulnerabilities in nine pinyin keyboard apps affected up to a billion users in China. Criminals could eavesdrop on users’ keystrokes on these cloud-based keyboard apps, allowing them to collect passwords, usernames and other personal information.
In addition, the report revealed differing trends in the most breached sectors, varying depending on known records breached and the total number of actual incidents.
IT services and software had the most records breached in April, accounting for over 5.2 billion breaches. This is followed by manufacturing (18.3m) and insurance (15.3m).
For actual number of incidents, however, education took the top spot, facing 160 confirmed and publicly disclosed incidents of data breaches. Healthcare (90) and the public sector (61) followed behind.
Recommended reading
- UK Gov Data Breaches Exposed 10K Customers’ Data, FOI Reveals
- Who Was Behind the Ministry of Defence Hack?
- UK Gov Cyber Breaches Survey 2024 | Key Stats and Data
“The spike in data breached this month is really concerning,” said Calder. “It’s a reminder of the persistent challenges we face in safeguarding sensitive information. Organisations need to be one step ahead in protecting our privacy and implement tighter security measures to prevent these kinds of breaches.
“Boards need to lead the charge in prioritising cyber security, weaving it into every aspect of their business strategies,” he added. “This commitment goes beyond protecting against cyber threats; it’s about compliance, safeguarding corporate assets and ensuring directors fulfil their responsibilities to uphold organisational integrity.
“Investing in robust security measures is a must. We need to allocate resources, train staff and stay up to date on the latest threats. When it comes to cyber security, an ounce of prevention is worth a pound of cure.”





