Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Over 15.1 Billion Records Exposed in Data Breaches in 2019

More than 15.1 billion records were exposed in 2019 as part of the data breaches that were publicly reported, Risk Based Security reveals.

The number of exposed records registered a massive 284% spike compared to the previous year (which had 5.3 billion records exposed), and also marked a 91% increase compared to 2017 (7.95 billion records).

More than 15.1 billion records were exposed in 2019 as part of the data breaches that were publicly reported, Risk Based Security reveals.

The number of exposed records registered a massive 284% spike compared to the previous year (which had 5.3 billion records exposed), and also marked a 91% increase compared to 2017 (7.95 billion records).

A total of 7.2 billion records were compromised between October 1 and December 31, 2019, with four events accounting for 93.5% of these records. All four involved open, misconfigured databases that were made publicly accessible.

The number of reported data breaches was of 7,098 last year, representing only a 1% increase compared to the 7,035 breaches reported in 2018.

However, the gap is expected to grow in the next two months, as more 2019 incidents are publicly disclosed, Risk Based Security’s 2019 Year End Data Breach QuickView Report reveals (PDF). Another 250-300 incidents are expected to be added to the list.

Sensitive data was accessible but not confirmed as stolen for 22.6% of the incidents. There were “three breaches that compromised 1 billion records or more exposed transaction logs,” but the number of impacted people is much lower than the 7.6 billion exposed records.

Of the 15.1 billion records exposed last year, 13.5 billion were compromised via the web, specifically inadvertent exposure of data online, the report reveals. Hacking exposed 1.5 billion records, while the other types of incidents combined exposed 120 million records.

Hacking, however, accounted for 5,184 of the reported data breaches, while there were only 343 web incidents reported.

Advertisement. Scroll to continue reading.

“There are plenty of malicious actors ready to take advantage of any and every shortcoming or oversight. Hacking, defined as unauthorized intrusion into systems, has been the top breach type by number of incidents for every year of the past decade except for 2010,” Risk Based Security notes.

The information sector emerged as the leader in the number of data breaches, with 614 incidents, with the healthcare sector following on the second position, at 512, and finance and insurance landing on the third, with 435 incidents.

Most of the data breaches in the information sector (88%) can be attributed to software publishers, data processing and hosting services, and Internet publishing companies.

By November, more than 38 million healthcare records had been exposed in the United States, impacting 11.64% of the population, data from the U.S. Department of Health and Human Services Office for Civil Rights breach portal revealed. However, only breaches impacting more than 500 individuals are added to the portal.

A total of 368 third-party breaches were reported in 2019, exposing over 4.7 billion records, with an average number of exposed records of roughly 13 million per breach.

Related: Equifax Ordered to Spend $1 Billion on Data Security Under Data Breach Settlement

Related: Capital One Discloses Massive Data Breach: 106 Million Impacted

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...