Security News > 2023 > January > Supply chain attacks caused more data compromises than malware
Data compromises steadily increased in the second half of 2022.
Data breach notices suddenly lacked details, resulting in increased risk for individuals and businesses, as well as uncertainty about the number of data breaches and victims.
The number of data breaches resulting from supply chain attacks exceeded compromises linked to malware in 2022.
In 2022, supply chain attacks surpassed the number of malware-based attacks by 40%. According to the report, more than 10 million people were impacted by supply chain attacks targeting 1,743 entities.
"While we did not set a record for the number of data compromises in the U.S. last year, we came close," said Eva Velasquez, CEO of the Identity Theft Resource Center.
"These compromises impacted at least 422 million people. These numbers are only estimates because data breach notices are increasingly issued with less information. This has resulted in less reliable data that impairs consumers, businesses and government entities from making informed decisions about the risk of a data compromise and the actions to take if impacted by one. People are largely unable to protect themselves from the harmful effects of data compromises, fueling an epidemic - a"scamdemic" of identity fraud committed with compromised or stolen information," added Velasquez.
News URL
https://www.helpnetsecurity.com/2023/01/26/data-compromises-2022/
Related news
- Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks (source)
- Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems (source)
- Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack (source)
- LottieFiles hit in npm supply chain attack targeting users' crypto (source)
- LottieFiles hacked in supply chain attack to steal users’ crypto (source)
- LottieFiles supply chain attack exposes users to malicious crypto wallet drainer (source)
- Lottie Player supply chain compromise: Sites, apps showing crypto scam pop-ups (source)
- VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware (source)
- Iranian Hackers Use "Dream Job" Lures to Deploy SnailResin Malware in Aerospace Attacks (source)
- Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations (source)