DATABREACH STATS & NEWS

28,433,149,823

COMPROMISED DATA TO DATE

STAY INFORMED

STAY SECURED

Cyber incidents continue to increase in frequency, scale, and business impact, driven by financially motivated threat actors targeting high-value data assets. Despite advancements in security technologies, many organizations remain underprepared to effectively prevent, detect, and respond to evolving threats.

Metrics

Key trends highlight escalating financial impact, expanding attack surfaces, and growing third-party risk exposure, reinforcing the need for enhanced investment, modernized controls, and mature incident response capabilities.

  • Global average breach cost: ~US $4.44M / U.S. average breach cost: ~US $10.22M
  • Multi-environment breaches (cloud + on-prem): ~US $5.05M average cost
  • PII involved in ~53% of breaches
  • AI-related risks emerging: ~16% attacker use; ~20% shadow AI exposure
  • Average dwell time: ~241 days
  • Third-party involvement in ~30% of breaches

ThreatScape

Cyber threat activity remains persistent and diverse, with widespread website compromise, insider involvement, financially driven attacks, ransomware prevalence, concentrated industry impact, and strong links to organized cybercrime groups.

  • 4,800 websites/month are compromised with formjacking.
  • 34% of breaches involve internal actors.
  • 71% of breaches are financially motivated.
  • 24% of malware incidents involve ransomware.
  • 95% of breached records** come from government, retail, and technology.
  • 36% of external actors** are linked to organized crime.
Post Breach Costs Incurred
0%
Cost Per Record Breach Increase
0%
Cloud Storage Breach
0%
Human & Social Attack Breach
0%
5 Year Ransomware Breach Increase
0%
Compromised Vendor Breach
0%

  CyberPulse

  • Google Vertex AI SDK Flaw Let Attackers Hijack...
    on June 16, 2026 at 12:05 pm

    A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving […]

  • ClickFix Campaigns Expand Malware Delivery With...
    on June 16, 2026 at 10:41 am

    Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, […]

  • New Rokarolla Android Malware Steals PINs, SMS...
    on June 16, 2026 at 6:10 am

    Security researchers at Zimperium's zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they […]

  • Survey: 94% of Incidents Involve Anonymized...
    on June 16, 2026 at 4:30 am

    Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing […]

  • Attackers Exploit Three Fortinet FortiSandbox...
    on June 16, 2026 at 3:30 am

    Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed […]

  • China-Linked SprySOCKS Backdoor Expands to...
    on June 16, 2026 at 2:44 am

    Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally […]

  • Fake Microsoft Alerts Used to Deploy North Korean...
    on June 16, 2026 at 1:14 am

    The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware […]

  • Cisco Releases Security Updates for Actively...
    on June 15, 2026 at 11:05 pm

    Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, […]

  • CISA Flags LiteSpeed cPanel Plugin Flaw Exploited...
    on June 15, 2026 at 10:41 pm

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal […]

  • Chinese Hackers Abused Google Workspace Rules to...
    on June 15, 2026 at 12:44 pm

    A China-linked espionage group hid inside North American medical, academic, and military research networks for more than a year, quietly stealing sensitive research and defense email. The way in was […]

  • North Korean Hackers Are Turning Developer Tools...
    on June 15, 2026 at 12:32 pm

    Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, […]

  • LiteLLM Vulnerability Chain Lets Low-Privilege...
    on June 15, 2026 at 9:39 am

    A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a […]

  • One-Click Microsoft 365 Copilot Flaw Could Have...
    on June 15, 2026 at 8:09 am

    A single click on a trusted Microsoft link could have let an attacker pull emails, calendar details, and indexed files out of Microsoft 365 Copilot Enterprise Search. Researchers at Varonis Threat […]

  • ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits,...
    on June 15, 2026 at 6:49 am

    Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: […]

  • The Onboarding Password Mistake That Creates...
    on June 15, 2026 at 4:30 am

    Employee onboarding is a busy time for IT teams. New starters need devices, accounts, access permissions, and passwords, all delivered within a tight timeframe. That usually means sharing a […]

  • 152 Chrome Wallpaper Extensions with 105K...
    on June 15, 2026 at 4:07 am

    Cybersecurity researchers have discovered a network of 152 Google Chrome extensions that act as new tab live wallpaper add-ons to distribute a potentially unwanted program (PUP) family. The cluster […]

  • Popular WordPress Plugin Scripts Tampered to...
    on June 15, 2026 at 2:59 am

    An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site […]

  • Sniper Dz Scams Target MENA Users via Fake...
    on June 14, 2026 at 11:30 pm

    Cybersecurity researchers have disclosed details of fraudulent activity targeting users across the Middle East and North Africa by employing various fraudulent Facebook accounts impersonating […]

  • Palo Alto Warns of Active Exploitation of PAN-OS...
    on June 14, 2026 at 11:17 pm

    Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect […]

  • Critical Splunk Enterprise Flaw Lets Attackers...
    on June 13, 2026 at 6:23 am

    Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The […]

  • U.S. Orders Anthropic to Suspend Fable 5 and...
    on June 12, 2026 at 10:42 pm

    Anthropic said on Friday it will "abruptly disable" its most advanced artificial intelligence (AI) models, Claude Fable 5 and Mythos 5, for all users after the U.S. government ordered it to suspend […]

  • Over 400 Arch Linux AUR Packages Hijacked to...
    on June 12, 2026 at 12:33 pm

    Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is […]

  • Google Sues Chinese Smishing Network Accused of...
    on June 12, 2026 at 11:59 am

    Google on Friday said it's pursuing legal action against a Chinese cybercrime network, accusing it of using its Gemini artificial intelligence (AI) agent to send phishing text messages targeting […]

  • China-Linked Hackers Backdoored Linux Login...
    on June 12, 2026 at 11:17 am

    Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as […]

  • Agentjacking Attack Tricks AI Coding Agents Into...
    on June 12, 2026 at 5:04 am

    Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called […]

  • Rethinking MDR as Attackers and Defenders Embrace...
    on June 12, 2026 at 4:00 am

    For most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn't staff around the clock, couldn't hire enough analysts, and needed someone else to […]

  • LangGraph Flaw Chain Exposes Self-Hosted AI...
    on June 12, 2026 at 2:50 am

    Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. […]

  • INTERPOL Operation Takes Down Sniper Dz Phishing...
    on June 12, 2026 at 1:52 am

    An INTERPOL-led operation last month resulted in the disruption of Sniper Dz, a decade-long phishing-as-a-service (PhaaS) platform, Group-IB said Thursday. The effort, codenamed Operation Ramz, took […]

  • Europol Disrupts AudiA6 Crypto Laundering Service...
    on June 11, 2026 at 11:38 pm

    Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of […]

  • ShinyHunters Exploits Oracle PeopleSoft Zero-Day...
    on June 11, 2026 at 1:29 pm

    The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities […]