2023 is already the worst year for hacks—and we’re not out yet

Cyberattacks are becoming more prevalent in 2023—and it’s no longer a matter of whether this year will record a record number of data breaches, it’s more a question of how high that number will be.

As of the end of September, corporations had reported 2,116 data compromises for the year, according to the Identity Theft Resource Center (ITRC). That’s already higher than the previous annual record of 1,862, set in 2021. And the fourth quarter is already off to a rollicking start, with the high-profile hack of 23andMe, which could impact millions of the company’s customers.

The third quarter saw 733 total reported compromises, affecting 66,658,764 people. Financial services was the most-attacked sector, topping healthcare for the first time since Q2 2022. That could be because the number of financial institutions reporting data compromises spiked in the third quarter. All totaled, 204 notices were issued, which is more than the 135 total of reported compromises in financial service businesses in the past two years.

Healthcare companies reported 113 data compromises in Q3. No other Industry reported compromise rates in triple digits.

“While setting a record for the number of data breaches is attention-grabbing, unfortunately, it is not surprising,” ITRC president and CEO Eva Velasquez said in a statement. “There are a handful of reasons for the rise in data compromises, ranging from the drastic uptick in Zero-Day attacks to a new wave of ransomware attacks as new ransomware groups enter the criminal identity marketplace.”

One piece of good news: Despite a record number of breaches, the total number of victims, so far, is well off a record pace. Through the first three quarters of the year, there have been 233.9 million estimated victims versus the 425 million at this time in 2022. (2022 included some very large breaches, including Twitter and AT&T.)

Increasing risks

The data breaches in the ITRC’s report range from ransomware to phishing attacks to malware infections. Those can result in everything from companies being shut out of their systems—such as the MGM ransomware attacks that severely impacted Las Vegas—to financially impacting individuals whose identities are sold on the Dark Web.

But the war in Israel is bringing out a potential new type of threat. The 23AndMe hack targeted users of Jewish ancestry. One online post offering data for sale bragged of having a huge database of Ashkenazi Jews, including people whose ties with that ancestry are less than 1%.

Given the growing Anti-Semitic rhetoric against Jewish people online and the very real physical threats both at home and abroad, that posting has raised concerns among 23AndMe members about their own safety.

What’s even more worrisome is that the actual number of breaches and victims is likely much higher than the ITRC’s data shows. Officials at the ITRC note that transparency about attacks continues to get worse. And data breach notices, when filed, often lack details about how companies were compromised and victim details.

“Underreporting and a lack of transparency continues to be a concern, as demonstrated by the fact that more than half (53%) of breach notices in Q3 did not include actionable information about the compromise,” says James Lee, ITRC’s COO. “We also have new, clear evidence that companies are simply making a decision to not report a breach when they do not believe a person is at risk—a decision nearly all state breach-notice laws allow the breached entity to make. If they determine there is no risk, then, generally, no notice is required.”

To put the data into perspective, there have been about 18,000 reported data breach notices in the U.S. since data breach laws went into effect 20 years ago. In the European Union, where the General Data Protection Regulation (GDPR) requires data breach notices, there are about 350,000 notices issued each year.

https://www.fastcompany.com/90966633/2023-breaking-records-hacks-cyberattacks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Creată 2y | 13 oct. 2023, 04:50:10


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

AI coding tools could bring us the ‘one-employee unicorn’

Welcome to AI DecodedFast Company’s weekly newsletter that breaks down the most important news in the world of AI. You can sign up to receive this newsletter every week 

24 apr. 2025, 18:40:03 | Fast company - tech
Bot farms invade social media to hijack popular sentiment

Welcome to the world of social media mind control. By amplifying free speech with fake speech, you can numb the brain into believing just about anything. Surrender your blissful ignorance and swall

24 apr. 2025, 13:50:11 | Fast company - tech
The economic case for saving human jobs

Few periods in modern history have been as unsettled and uncertain as the one that we are living through now. The established geopolitical order is facing its greatest challenges in dec

24 apr. 2025, 13:50:11 | Fast company - tech
Patreon’s rivalry with Substack is growing. Who will win over creators?

Substack and Patreon are vying to become creators’ primary revenue stream.

For most influencers, payouts from platforms like Meta or Google aren’t enough to build a sustainable career. R

24 apr. 2025, 11:40:04 | Fast company - tech
TikTok’s ‘SkinnyTok’ trend is under fire from EU regulators

The European Commission is coming for “SkinnyTok.”

EU regulators are investigating a recent wave of social media videos that promote extreme thinness and “tough-love” weight loss advice,

24 apr. 2025, 00:10:04 | Fast company - tech
The subreddit r/AITA is headed for the small screen

The infamous “Am I The A**hole?” subreddit is making its way to the small screen.

Hosted by Jimmy Carr, the new game show for Comedy Central U.K. will feature members of the public appea

23 apr. 2025, 19:30:03 | Fast company - tech
Ex-OpenAI workers ask state AGs to block for-profit conversion

Former employees of OpenAI are asking the top law enforcement officers in California and Delaware to s

23 apr. 2025, 17:10:06 | Fast company - tech