DATABREACH STATS & NEWS

28,433,149,823

COMPROMISED DATA TO DATE

STAY INFORMED

STAY SECURED

Cyber incidents continue to increase in frequency, scale, and business impact, driven by financially motivated threat actors targeting high-value data assets. Despite advancements in security technologies, many organizations remain underprepared to effectively prevent, detect, and respond to evolving threats.

Metrics

Key trends highlight escalating financial impact, expanding attack surfaces, and growing third-party risk exposure, reinforcing the need for enhanced investment, modernized controls, and mature incident response capabilities.

  • Global average breach cost: ~US $4.44M / U.S. average breach cost: ~US $10.22M
  • Multi-environment breaches (cloud + on-prem): ~US $5.05M average cost
  • PII involved in ~53% of breaches
  • AI-related risks emerging: ~16% attacker use; ~20% shadow AI exposure
  • Average dwell time: ~241 days
  • Third-party involvement in ~30% of breaches

ThreatScape

Cyber threat activity remains persistent and diverse, with widespread website compromise, insider involvement, financially driven attacks, ransomware prevalence, concentrated industry impact, and strong links to organized cybercrime groups.

  • 4,800 websites/month are compromised with formjacking.
  • 34% of breaches involve internal actors.
  • 71% of breaches are financially motivated.
  • 24% of malware incidents involve ransomware.
  • 95% of breached records** come from government, retail, and technology.
  • 36% of external actors** are linked to organized crime.
Post Breach Costs Incurred
0%
Cost Per Record Breach Increase
0%
Cloud Storage Breach
0%
Human & Social Attack Breach
0%
5 Year Ransomware Breach Increase
0%
Compromised Vendor Breach
0%

  CyberPulse

  • Coldcard Hardware Wallet Flaw Linked to $70...
    on August 1, 2026 at 10:17 am

    An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in […]

  • Hackers Poison Adform Script to Swap Crypto...
    on August 1, 2026 at 2:03 am

    Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident […]

  • Adobe Campaign Classic CVSS 10.0 Flaw Could Run...
    on August 1, 2026 at 12:12 am

    Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code […]

  • Hijacked Hotel Wi-Fi Pushes Fake Updates to...
    on July 31, 2026 at 11:29 pm

    A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft […]

  • Suspected Chinese-Speaking Hackers Target Central...
    on July 31, 2026 at 11:52 am

    A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, […]

  • HollowFrame Loader Deploys Matryoshka Backdoor in...
    on July 31, 2026 at 9:39 am

    Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint […]

  • Cheap Android TV Boxes Pose as Phones and Turn...
    on July 31, 2026 at 7:45 am

    Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same […]

  • Three Recent Chrome Releases Fix 1,442 Flaws,...
    on July 31, 2026 at 5:51 am

    Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones […]

  • Researchers Report 84 Flaws in 4G and 5G Cores,...
    on July 31, 2026 at 4:55 am

    An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and […]

  • 6 Reasons Why Device Code Phishing is the...
    on July 31, 2026 at 4:24 am

    Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. […]

  • Chinese Hacker Commands DeepSeek via Telegram to...
    on July 31, 2026 at 4:21 am

    Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, […]

  • Anthropic Says Claude Mistook the Open Internet...
    on July 30, 2026 at 11:41 pm

    Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three […]

  • DPRK-Linked macOS Malvertising Uses Fake Updates...
    on July 30, 2026 at 11:18 am

    Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent […]

  • ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws,...
    on July 30, 2026 at 8:25 am

    A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. […]

  • Azure Cosmos DB Flaw Exposed Platform-Wide Key...
    on July 30, 2026 at 6:34 am

    A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, […]

  • Microsoft Copilot for Word Can Copy Hidden...
    on July 30, 2026 at 4:54 am

    Hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report, then copy the same instructions into the finished file. Håkon Måløy disclosed the technique on […]

  • The Network Has Become the Control Plane for AI...
    on July 30, 2026 at 4:32 am

    Network firewalls are the workhorses of modern cybersecurity. They are trusted to protect the network, blocking malicious traffic and preventing intrusions and breaches. And for decades, network […]

  • Hackers Exploit AnySign4PC via Hacked Korean...
    on July 30, 2026 at 3:33 am

    South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed […]

  • SilverFox Targets Japanese Manufacturer with...
    on July 30, 2026 at 3:32 am

    The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial […]

  • Russian Hackers Exploit Microsoft OWA Flaw to...
    on July 30, 2026 at 12:40 am

    The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access […]

  • FCC Blocks New Foreign-Produced Robots and Power...
    on July 30, 2026 at 12:28 am

    The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving […]

  • Amazon Links Debug and Chalk npm Hijack to North...
    on July 29, 2026 at 11:05 pm

    Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a […]

  • Cisco FMC Zero-Day Actively Exploited, Static...
    on July 29, 2026 at 10:08 pm

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known […]

  • Critical Rails Flaw Could Let Unauthenticated...
    on July 29, 2026 at 11:10 am

    Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. […]

  • Ruflo MCP Flaw Lets Unauthenticated Attackers Run...
    on July 29, 2026 at 8:39 am

    Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated […]

  • Three Critical VMware Flaws Allow Auth Bypass,...
    on July 29, 2026 at 8:31 am

    Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The […]

  • Coordinated Cyberattack Targets 30+ Minnesota...
    on July 29, 2026 at 6:48 am

    A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South […]

  • Nine-Year Fraud Campaign Clones Russian Company...
    on July 29, 2026 at 6:42 am

    Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international […]

  • Mythos Asks the Right Question. It Doesn't Answer...
    on July 29, 2026 at 5:15 am

    AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The […]

  • Researchers Show a Single Malicious Webpage Visit...
    on July 29, 2026 at 4:57 am

    Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides […]