New Analysis Reveals Number and Severity of Known Data Breaches in 2022 is Nearly Double What’s Been Reported
Sontiq, a TransUnion company, reported a significant rise in compromised entities due to data breaches in 2022, with a total of 3,495 compromised entities, marking a 45% increase from 2,417 in 2021. The jump is largely attributed to third-party breaches, which accounted for 1,745 of the incidents, reflecting a staggering 220% year-over-year increase. The severity of these breaches, measured by Sontiq's BreachIQ AI algorithm, also increased by 10% in 2022. Sontiq emphasizes the importance of consumers taking swift action when breaches score above 4, as they pose higher risks for identity theft.
- Number of compromised entities rose to 3,495 in 2022, a 45% increase from 2021.
- Third-party breaches accounted for 1,745 incidents, a 220% increase year-over-year.
- Breach severity, as per BreachIQ AI algorithm, increased by 10% in 2022.
- None.
New AI-driven analysis by
Sontiq’s analysis shows 3,495 compromised entities in 2022, of which 1,745 originated from a third-party data breach. This is a nearly
Van Dyke, who has served as an expert harms witness in some of the country’s largest data breach litigations, noted that cybercriminals are pursuing supply chain attacks for a higher return on effort.
“By focusing attacks on the accounting, payroll or administrative firms that serve multiple clients, a single breach can give an attacker access to the data of multiple organizations at once, including customer and employee records,” he said.
Third-Party Breaches Getting More Severe
Van Dyke noted that the severity of third-party data breaches, as measured by Sontiq’s BreachIQ AI algorithm, is also trending higher. BreachIQ analyzes more than 1,300 factors to assess the severity of a data breach and assigns a unique Breach Risk Score on a scale of 1 to 10 for each incident. The algorithm also identifies the primary risks associated with a breach, as well as recommended protective action steps specific to that breach.
In examining the average Breach Risk Score year over year, the severity of third-party breaches increased
Higher-Risk Data Breaches Warrant Quicker Action by Consumers
According to Van Dyke, individual data breaches that score higher than 4 warrant stronger action from those affected due to the potential risks. (Consumers can check on the severity of any publicly reported breach on the
“When a data breach reaches a score greater than 4, typically several pieces of sensitive personal information have been compromised,” said Van Dyke. “This greatly increases the odds of serious identity theft and fraud scams, which give criminals direct access to a victim’s workplace or personal financial, medical and social accounts.”
That said, Van Dyke added that even low-scoring breaches can be dangerous because cyber thieves are willing to work harder to access a victim’s financial accounts. When criminals obtain less-sensitive information in a data breach, they often use social engineering techniques to extract more personal information to gain direct account access or commit payments card and peer-to-peer (P2P) payment fraud.
A free online tool is available at www.sontiq.com/breachiq/#search-breached-organizations for anyone who wants a risk score and recommended actions for a particular data breach.
* The ITRC’s figure is based on the number of initially breached organizations, while
About
About
A leading presence in more than 30 countries across five continents,
View source version on businesswire.com: https://www.businesswire.com/news/home/20230208005202/en/
Media:
kelly@kmprcollective.com, nicole@kmprcollective.com
515-720-9670, 314-805-2165
Source:
FAQ
What was the total number of compromised entities reported by Sontiq in 2022?
How much did third-party breaches increase year-over-year according to Sontiq?
What does a Breach Risk Score above 4 signify?
What is the increase in severity of third-party breaches in 2022?