Verizon’s 2025 Data Breach Investigations Report: System Intrusions Behind 80% of APAC Breaches
Verizon Business has released its 2025 Data Breach Investigations Report (DBIR), revealing alarming cybersecurity trends in the Asia-Pacific region. The report analyzed over 22,000 security incidents, including 12,195 confirmed data breaches across 139 countries.
Key findings show that system intrusions caused 80% of APAC breaches, a significant increase from 38% last year. Malware incidents rose from 58% to 83%, with ransomware accounting for 51% of breaches. Globally, vulnerability exploitation increased by 34%, ransomware attacks rose 37%, and third-party involvement in breaches doubled.
The report highlights particular concerns for SMBs, with the median ransom payment reaching US$115,000. While 64% of organizations refused to pay ransoms (up from 50% two years ago), the report notes increased espionage-motivated attacks in Manufacturing and Healthcare sectors, along with persistent threats to Education, Financial, and Retail industries.
Verizon Business ha pubblicato il suo Rapporto sulle Indagini sulle Violazioni dei Dati 2025 (DBIR), rivelando preoccupanti tendenze di cybersecurity nella regione Asia-Pacifico. Il rapporto ha analizzato oltre 22.000 incidenti di sicurezza, inclusi 12.195 casi confermati di violazioni dei dati in 139 paesi.
I risultati principali mostrano che le intrusioni nei sistemi hanno causato l'80% delle violazioni in APAC, un aumento significativo rispetto al 38% dell'anno scorso. Gli incidenti di malware sono saliti dal 58% all'83%, con il ransomware responsabile del 51% delle violazioni. A livello globale, lo sfruttamento delle vulnerabilità è aumentato del 34%, gli attacchi ransomware del 37% e il coinvolgimento di terze parti nelle violazioni è raddoppiato.
Il rapporto evidenzia preoccupazioni particolari per le PMI, con un riscatto mediano che ha raggiunto i 115.000 dollari USA. Sebbene il 64% delle organizzazioni abbia rifiutato di pagare il riscatto (in aumento rispetto al 50% di due anni fa), il rapporto segnala un aumento degli attacchi motivati da spionaggio nei settori Manifatturiero e Sanitario, insieme a minacce persistenti nei settori dell'Istruzione, Finanza e Retail.
Verizon Business ha publicado su Informe de Investigaciones de Brechas de Datos 2025 (DBIR), revelando alarmantes tendencias de ciberseguridad en la región Asia-Pacífico. El informe analizó más de 22,000 incidentes de seguridad, incluyendo 12,195 brechas de datos confirmadas en 139 países.
Los hallazgos clave muestran que las intrusiones en sistemas causaron el 80% de las brechas en APAC, un aumento significativo desde el 38% del año pasado. Los incidentes de malware aumentaron del 58% al 83%, con ransomware representando el 51% de las brechas. A nivel mundial, la explotación de vulnerabilidades creció un 34%, los ataques de ransomware un 37% y la participación de terceros en las brechas se duplicó.
El informe destaca preocupaciones particulares para las PYMEs, con un rescate medio que alcanzó los 115,000 dólares estadounidenses. Aunque el 64% de las organizaciones se negó a pagar rescates (frente al 50% hace dos años), el informe señala un aumento de ataques motivados por espionaje en los sectores de Manufactura y Salud, junto con amenazas persistentes en Educación, Finanzas y Comercio Minorista.
Verizon Business는 2025년 데이터 유출 조사 보고서(DBIR)를 발표하며 아시아 태평양 지역의 심각한 사이버 보안 동향을 공개했습니다. 이 보고서는 139개국에서 22,000건 이상의 보안 사고와 12,195건의 확인된 데이터 유출 사례를 분석했습니다.
주요 결과에 따르면 시스템 침입이 APAC 지역 유출의 80%를 차지했으며, 이는 지난해 38%에서 크게 증가한 수치입니다. 악성코드 사건은 58%에서 83%로 증가했으며, 랜섬웨어가 유출의 51%를 차지했습니다. 전 세계적으로 취약점 악용은 34% 증가했고, 랜섬웨어 공격은 37% 늘었으며, 제3자 관련 유출도 두 배로 증가했습니다.
이 보고서는 중소기업에 대한 특별한 우려를 강조하며, 평균 몸값이 미화 115,000달러에 달한다고 밝혔습니다. 조직의 64%가 몸값 지불을 거부했으며(2년 전 50%에서 증가), 제조업 및 의료 분야에서 스파이 행위 동기 공격이 증가했으며 교육, 금융, 소매업 분야에 지속적인 위협이 있다고 지적합니다.
Verizon Business a publié son Rapport d'Enquête sur les Violations de Données 2025 (DBIR), révélant des tendances inquiétantes en cybersécurité dans la région Asie-Pacifique. Le rapport a analysé plus de 22 000 incidents de sécurité, dont 12 195 violations de données confirmées dans 139 pays.
Les principales conclusions montrent que les intrusions système ont causé 80 % des violations en APAC, une augmentation significative par rapport à 38 % l'année dernière. Les incidents de malware sont passés de 58 % à 83 %, le ransomware représentant 51 % des violations. À l'échelle mondiale, l'exploitation des vulnérabilités a augmenté de 34 %, les attaques par ransomware de 37 %, et l'implication de tiers dans les violations a doublé.
Le rapport souligne des préoccupations particulières pour les PME, avec une rançon médiane atteignant 115 000 dollars US. Alors que 64 % des organisations ont refusé de payer la rançon (contre 50 % il y a deux ans), le rapport note une augmentation des attaques motivées par l'espionnage dans les secteurs de la fabrication et de la santé, ainsi que des menaces persistantes dans l'éducation, la finance et le commerce de détail.
Verizon Business hat seinen Data Breach Investigations Report (DBIR) 2025 veröffentlicht, der alarmierende Cybersicherheits-Trends in der Asien-Pazifik-Region aufzeigt. Der Bericht analysierte über 22.000 Sicherheitsvorfälle, darunter 12.195 bestätigte Datenverstöße in 139 Ländern.
Die wichtigsten Erkenntnisse zeigen, dass Systemeinbrüche 80 % der Verstöße in APAC verursachten, ein erheblicher Anstieg gegenüber 38 % im Vorjahr. Malware-Vorfälle stiegen von 58 % auf 83 %, wobei Ransomware 51 % der Verstöße ausmachte. Weltweit nahm die Ausnutzung von Schwachstellen um 34 % zu, Ransomware-Angriffe stiegen um 37 % und die Beteiligung Dritter an Verstößen verdoppelte sich.
Der Bericht hebt besondere Sorgen für KMU hervor, wobei die mittlere Lösegeldzahlung 115.000 US-Dollar erreichte. Während 64 % der Organisationen sich weigerten, Lösegeld zu zahlen (im Vergleich zu 50 % vor zwei Jahren), verzeichnet der Bericht einen Anstieg spionagemotivierter Angriffe in den Branchen Fertigung und Gesundheitswesen sowie anhaltende Bedrohungen für Bildung, Finanz- und Einzelhandelssektoren.
- Higher percentage of organizations (64% vs 50%) refusing to pay ransoms shows improved cyber resilience
- Comprehensive analysis of 22,000+ security incidents provides valuable threat intelligence
- System intrusions in APAC surged to 80% from 38% year-over-year
- Malware incidents in APAC increased significantly to 83% from 58%
- Global ransomware attacks rose 37% year-over-year
- Third-party breach involvement doubled, increasing supply chain risks
- SMBs disproportionately impacted by ransomware threats
SINGAPORE, April 23, 2025 (GLOBE NEWSWIRE) -- Verizon Business today released its 2025 Data Breach Investigations Report (DBIR), sounding the alarm on a surge of system intrusions across the Asia-Pacific region. The report reveals that 4 out of 5 data breaches in the region stemmed from such attacks - up from
Now in its 18th year, the report analysed more than 22,000 security incidents, including 12,195 confirmed data breaches spanning 139 countries. Malware increased from
"This year’s report reinforces the growing complexity and persistence of cyber threats facing organisations worldwide. In the Asia-Pacific region in particular, external actors are targeting critical infrastructure and exploiting third-party vulnerabilities. The rising incidence of breaches highlights the imperative for businesses to reassess their risk frameworks," said Robert Le Busque, Regional Vice President, Asia Pacific for Verizon Business.
Key APAC Findings:
- Social Engineering: The absolute number of Social Engineering breaches has been on the decline since 2021, it only accounts for
20% of breaches in 2025 due, in part, to the sharp increase of system intrusion - Malware: Malware in data breaches jumped significantly, from
58% last year to83% this year with email being the key vector for distributing various types of malware - Ransomware: Now accounts for
51% of the total breaches in this region and remains highly visible as threat actors often publicize breaches
Key Global Findings:
- Exploitation of Vulnerabilities: This initial attack vector saw a
34% increase, with a significant focus on zero-day exploits targeting perimeter devices and VPNs - Ransomware: Ransomware attacks rose by
37% since last year, and are now present in44% of breaches, despite a noticeable decrease in the median ransom amount paid. - Third-Party Involvement: The percentage of breaches involving third parties doubled, highlighting the risks associated with supply chain and partner ecosystems
- Human Element: Human involvement in breaches remains high, with a significant overlap between social engineering and credential abuse
The 2025 DBIR also shed light on industry-specific trends, revealing an alarming rise in espionage-motivated attacks in the Manufacturing and Healthcare sectors, and persistent threats to the Education, Financial, and Retail industries. The report also highlighted the disproportionate impact of ransomware on small and medium-sized businesses (SMBs).
Verizon Business's 2025 DBIR serves as a wake-up call for businesses to take immediate action to strengthen their cybersecurity posture and mitigate the risks posed by evolving cyber threats. With the median ransom payment to cybercriminals last year being US
“This year’s DBIR findings reflect a mixed bag of results. Glass-half-full types can celebrate the rise in the number of victim organizations that did not pay ransoms with
Visit our Cybersecurity Awareness page to learn more about data privacy and Verizon’s efforts.
About Verizon Business
Verizon Business is a global leader in providing communication and technology solutions to businesses of all sizes. With a comprehensive portfolio of services, including network, cloud, security, and collaboration solutions, Verizon Business helps organizations improve their operations, enhance their customer experiences, and drive innovation.
Verizon Communications Inc. (NYSE, Nasdaq: VZ) powers and empowers how its millions of customers live, work and play, delivering on their demand for mobility, reliable network connectivity and security. Headquartered in New York City, serving countries worldwide and nearly all of the Fortune 500, Verizon generated revenues of
VERIZON’S ONLINE MEDIA CENTER: News releases, stories, media contacts and other resources are available at verizon.com/news. News releases are also available through an RSS feed. To subscribe, visit www.verizon.com/about/rss-feeds/.
Media contact:
Nilesh Pritam
nilesh.pritam@sg.verizon.com
