Dozens of organizations including law enforcement agencies such as the Federal Bureau of Investigations (FBI), contributed security incident and breach data to Verizon’s 2023 Data Breach Report (DBIR).

The DBIR offers insights into the nature of current threat landscape through the analysis of more than 16,000 security incidents, 5,199 of which were confirmed data breaches. What the report reveals is an environment dominated by profit-motivated bad actors who continue to advance techniques in areas like social engineering that exploit human susceptibilities. 

Human vulnerabilities

The DBIR reports that 74% of all breaches play into human vulnerabilities either through error, privilege misuse, credential theft or social engineering. Most breaches – 83% – are carried out by people outside of the attacked organization. 95% of all breaches are profit-driven.

The DBIR points out that the number of Business Email Compromise (BEC) attacks have almost doubled in the last six years as percentage of all breaches. These incidents which are effectively pretexting in which cybercriminals use a fictious story to manipulate the targeted end user into sharing confidential or high value data; download malware; transfer money to the bad actor or otherwise do harm to the preyed upon organization, can be highly profitable and scale easily.

Credential theft was the most popular threat actor action type applied in more than 47% of all incidents.  Ransomware remains a major element in breaches.  While the number of ransomware incidents didn’t increase, it is still 24% of all breaches, and 15.5% of all incidents. 

Ransomware is used against organizations across all industries, but healthcare is targeted at the highest rate.

How well do you really know your competitors?

Access the most comprehensive Company Profiles on the market, powered by GlobalData. Save hours of research. Gain competitive edge.

Company Profile – free sample

Thank you!

Your download email will arrive shortly

Not ready to buy yet? Download a free sample

We are confident about the unique quality of our Company Profiles. However, we want you to make the most beneficial decision for your business, so we offer a free sample that you can download by submitting the below form

By GlobalData
Visit our Privacy Policy for more information about our services, how we may use, process and share your personal data, including information of your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.

Analysis conducted on the FBI’s Internet Crime Complaint Center (IC3) found that the median loss has more than doubled over the last two years. However, there was a silver lining in that the FBI data showed that only 7% of incidents cost the targeted organization anything in financial terms. 

DBIR offers broad insights

Log4j was responsible for 90% of the identified exploit vulnerability attacks. Nearly a third of Log4j activity occurred within the first month of its release. This demonstrates that fast action on vulnerability patching alleviated what could have been an even more widespread and devastating impact.

With a tone that is not without a fair dose of levity without being dismissive, the DBIR offers broad insights and a fair level of detail into the threat environment during a recent window in time. Examining not just breaches but also attempted attacks provides a more nuanced view of tactics of the bad actors and the defences of those targeted.