AmericasPREMIUM

Data breaches increased by 40% in 2016 — and that’s just the ones we know about

US companies and government agencies suffered a record 1,093 data breaches last year, despite spending on cyber security rising to $73.7bn worldwide

Picture: ISTOCK
Picture: ISTOCK

US companies and government agencies suffered a record 1,093 data breaches last year, a 40% increase from 2015, according to the Identity Theft Resource Centre (ITRC). Headline-grabbing hacks, with victims ranging from Wendy’s [fast food] to the Democratic National Committee, are increasing despite regulatory scrutiny and more aggressive cyber-security spending.

Worldwide spending on security-related hardware, software and services rose to $73.7bn in 2016 from $68.2bn a year earlier, according to researcher International Data Corporation, and that number is expected to approach $90bn in 2018.

"We are extremely confident that breaches are undiscovered and under-reported, and we don’t know the full scope," ITRC CEO Eva Casey Velasquez said. "This isn’t the worst-case scenario we are looking at; this is the best-case scenario."

Data breaches in 2016 exposed everything from social security numbers to user account log-in names and passwords. Attacks known as phishing, in which an employee is tricked into clicking an e-mailed link to give hackers access to a corporate network, accounted for about 56% of all breaches last year, according to the ITRC. That’s up from 38% in 2015. In many cases, employees received an e-mail purporting to be from their company’s CEO or other high-level managers.

"When we look at these massive numbers of records and percentages, it’s very easy to forget that each of these data points is a person, and there’s someone behind this who is being very adversely affected," Velasquez said.

Criminals can use stolen information, such as social security numbers, addresses and names, to file false tax returns, order credit cards and to siphon money out of consumers’ bank accounts. Adam Levin, chairman of the security company CyberScout, which sponsored the report, said training employees about data privacy and security is essential. "A lot of companies don’t do it," he said.

The ITRC, which has been tracking breaches since 2005, compiles its reports using data listed on state regulators’ web sites, as well as by filing Freedom of Information Act requests with various government agencies. Many data breaches still aren’t included in these numbers.

Bloomberg


Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.

Comment icon