May 10, 2018 By Douglas Bonderud 2 min read

Data breaches are down year-over-year. As noted by Infosecurity Magazine, almost 1.4 billion records were exposed in 686 breaches reported between Jan. 1 and March 31 this year.

As eye-popping as those numbers are, they represent a big improvement from 2017, when 1,442 incidents exposed a total of 3.4 billion records. In addition, tax phishing attempts for W-2 data fell from 214 attacks last year to just 31 in 2018.

Despite the downward trends in data breach statistics, however, new research revealed that disclosure remains a trouble spot for organizations, especially in light of upcoming regulations. Despite year-to-year improvement, according to Computer Weekly, the average time between incident and disclosure is still more than five weeks.

Digging Into Data Breach Statistics

As Help Net Security reported, 2018 is off to a relatively secure start, at least in terms of data breach statistics. The recent spike in cryptocurrency value may provide an explanation: Crypto-mining malware, which leverages unused central processing unit (CPU) cycles to dig for digital currency, saw a significant boost at the beginning of this year, which could account for the shift away from traditional breach methods that may attract more attention from IT security professionals.

In general, however, the nature of data breaches has not changed significantly over the past 12 months. According to Risk Based Security’s “Q1 2018 Data Breach QuickView Report,” fraud remains the top breach type compromising the most records (1.27 billion) while unauthorized access held its spot as the most common breach cause. Skimming, inadvertent disclosure, phishing and malware rounded out the top five, just as they did in 2017.

Data Breach Disclosure Times Remain High

According to the Risk Based Security report, the average time between data breach detection and disclosure is decreasing. In 2015, it took companies 82.6 days on average to disclose a breach. By 2017, this figure was cut nearly in half to 42.7 days, and it dropped even further to 37.9 days in the first quarter of 2018, showing a trend of continuous improvement over the last four years.

The challenge is that, as noted by the Computer Weekly piece, upcoming data privacy regulations include disclosure timelines. The General Data Protection Regulation (GDPR), for example, imposes a 72-hour notification rule for data breaches. Despite the encouraging year-to-year progress in the effort to reduce breach disclosure times, organizations still have a long way to go to meet this requirement.

The Risk Based Security report noted that Q1 2018 has been “the quietest first quarter for breach activity since 2012.” While some trends, such as the move to crypto-mining malware and away from W-2 phishing, help account for these numbers, the researchers identified no underlying pattern, suggesting that these data breach statistics are likely to evolve throughout the rest of the year.

More from

CISA Malware Next-Gen Analysis now available to public sector

2 min read - One of the main goals of the Cybersecurity and Infrastructure Security Agency (CISA) is to promote security collaboration across the public and private sectors. CISA firmly believes that partnerships and effective coordination are essential to maintaining critical infrastructure security and cyber resilience.In faithfulness to this mission, CISA is now offering the Malware Next-Generation Analysis program to businesses and other organizations. This service has been available to government and military workers since November 2023 but is now available to the private…

Social engineering in the era of generative AI: Predictions for 2024

5 min read - Breakthroughs in large language models (LLMs) are driving an arms race between cybersecurity and social engineering scammers. Here’s how it’s set to play out in 2024.For businesses, generative AI is both a curse and an opportunity. As enterprises race to adopt the technology, they also take on a whole new layer of cyber risk. The constant fear of missing out isn’t helping either. But it’s not just AI models themselves that cyber criminals are targeting. In a time when fakery…

Change Healthcare attack expected to exceed $1 billion in costs

3 min read - The impact of the recent Change Healthcare cyberattack is unprecedented — and so are the costs. Rick Pollack, President and CEO of the American Hospital Association, stated, “The Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. healthcare system in history.”In a recent earnings call, UnitedHealth Group, the parent company of Change Healthcare, speculated on the overall data breach costs. When all is said and done, the total tally may reach $1 billion…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today