Data Breach Volumes in the U.S. Grow by 10% in 2021

Stu Sjouwerman | Mar 2, 2022

Data Breach Volumes in the US GrowNew data shows despite decreases in global data breach levels (-5%) in 2021, the U.S. experienced proportionally more data breaches than in the previous year.

10% may not sound like much when you consider some of the headlines about increases in ransomware attacks and other cyberthreats – even right here on my blog. But when you look at the breakdown of who is being targeted, who is responsible, what’s being stolen, and more from The 2021 Year End Report: Data Breach QuickView from Flashpoint, you begin to see some trends and what aspects of your cybersecurity you may want to shore up.

According to the report:

  • 21% of data breaches in 2021 involved ransomware
  • Nearly 23 billion records were exposed
  • 77% of breaches were external attacks, with 15% being internal

A wide range of data types were stolen. According to the report:

2-21-22 Image

 

 

 

 

 

 

 

 

 

 

Source: Flashpoint

The five most targeted industries in 2021 were:

  1. Healthcare
  2. Finance and Insurance
  3. Public Administration
  4. Information
  5. Professional/Scientific

One last interesting bit from the report is that the top two exploits and services mentioned on dark web forums for sale were zero-day and phishing attacks. Thwarting zero-day attacks require significant monitoring of system and user activity, whereas phishing attacks require a layered security approach that includes Security Awareness Training to identify and stop malicious email content along its path – including those emails that get all the way to the Inbox.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.