2023 Data Breach Investigations Report: frequency and cost of social engineering attacks skyrocket | News Release | Verizon
Accessibility Resource CenterSkip to main content
About UsCareers
Support
Our Company
  • Our Company Overview
  • Who We Are Who We Are
    • Overview
    • Diversity and Inclusion
    • History and Timeline
    • The Verizon Story
    • Headquarters & Contact Info
    • Verizon Fact Sheet
    • Leadership
    • Awards
  • What We Do What We Do
    • Overview
    • 5G
    • Innovation Labs
    • 4G LTE
    • Broadband & Fiber
    • Internet of Things
    • Managed Security
    • Verizon Ventures
  • How We Operate How We Operate
    • Overview
    • Code of Conduct
    • Management Governance
    • Open Internet
    • Policies
    • Retiree Information
    • State Government Affairs
    • Supplier Diversity
 
News
  • News Center News Center
    • News Center
    • Networks & Platforms
    • Products & Plans
    • Responsible Business
    • Financial
    • Public Safety
    • Inside Verizon
    • Noticias
  • News Releases News Releases
    • News Releases
    • Media Contacts
    • B-roll and images
    • RSS Feeds
    • Emergency resource center
    • Verizon Fact Sheet
  • Inside Verizon Inside Verizon
    • Inside Verizon
    • Welcome V Team
 
Responsibility
  • Responsibility Overview
  • Digital Inclusion Digital Inclusion
    • Overview
    • Verizon Innovative Learning
    • Verizon Innovative Learning HQ
    • Small Business Program
  • Climate Protection Climate Protection
    • Overview
    • Sustainability
  • Human Prosperity Human Prosperity
    • Overview
    • Reskilling Program
    • Employee Volunteers
  • Sharing our Success Sharing our Success
    • Overview
    • Giving and Grants
    • Employee Giving
  • Product Responsibility Product Responsibility
    • Overview
    • Accessibility
    • Account Security
    • Privacy Policy
  • ESG Resources Hub ESG Resources Hub
    • Overview
  • Parenting in a Digital World Parenting in a Digital World
    • Overview
    • Digital Parenting 101
    • Young children 3-8
    • Preteens 9-12
    • Teenagers 13-18
    • By topic
    • Meet the editorial team
 
Investors
  • Investor Relations overview
  • Financial Reporting Financial Reporting
    • Overview
    • SEC Filings
    • Annual Reports
    • Quarterly Earnings
    • Stock Information
    • Dividend History
    • Tax Information
    • Fixed Income
    • Asset-backed Securitization
  • Corporate Governance Corporate Governance
    • Overview
    • Board of Directors
    • Board Committees
  • Shareowner Services Shareowner Services
    • Overview
    • Cost Basis Calculator
    • Shareowner FAQs
  • ESG Resources Hub ESG Resources Hub
    • Overview
    • Human Rights at Verizon
  • News & Events News & Events
    • Investor Events & Webcasts
    • Investor News
    • Investor Calendar
    • Email Alerts
  • Contact Investor Relations
 
Support
About UsCareers
end of navigation menu
  1. About
  2. News
  3. Networks & Platforms
  4. Networks Solutions for Business
  5. 2023 Data Breach Investigations Report: frequency and cost of social engineering attacks skyrocket
News Center
  1. Menu
    All News
    Networks & Platforms
    Products & Plans
    Responsible Business
    Public Safety
    Inside Verizon
    Financial
    Noticias
    News Releases
    Media Contacts
    B-roll and images
    Verizon Fact Sheet
    RSS Feeds
    Emergency Resources
    Cable Facts

Full Transparency

No Updates

We're committed to building trust.

The Verizon Newsroom greatly values transparency and we’re committed to setting the industry standard for corporate communications. By integrating blockchain technology, we’re able to permanently log all changes made to official releases after publication.

Learn more
06/06/2023|Networks & Platforms|Networks Solutions for Business

2023 Data Breach Investigations Report: frequency and cost of social engineering attacks skyrocket

Media contact
Carlos Arcila
908-202-0479
Carlos.Arcila@verizon.com
Nilesh Pritam
656-248-6599
Nilesh.Pritam@sg.verizon.com
Louisa Rowntree
777-138-8040
Louisa.Rowntree@uk.verizon.com

Human error continues to play a significant role in breaches across all industries

View the 2023 DBIR Report

Full Transparency

No Updates

Learn more
Verizon 2023 Data Breach Investigations Report | Verizon

What you need to know:

  • Cost per ransomware incident doubled over the past two years, with ransomware accounting for one out of every four breaches.

  • Pretexting (Business Email Compromise) has more than doubled since the previous year.

  • The human element is involved in 3 out of 4 breaches.

  • Analysis of the Log4j incident illustrates the scale of the incident and the effectiveness of the coordinated response.

BASKING RIDGE, NJ – Verizon Business today released the results of its 16th annual Data Breach Investigations Report (2023 DBIR), which analyzed 16,312 security incidents and 5,199 breaches. Chief among its findings is the soaring cost of ransomware – malicious software (malware) that encrypts an organization’s data and then extorts large sums of money to restore access.

The median cost per ransomware more than doubled over the past two years to $26,000, with 95% of incidents that experienced a loss costing between $1 and $2.25 million. This rise in cost coincides with a dramatic rise in frequency over the past couple of years when the number of ransomware attacks was greater than the previous five years combined. That prevalence held steady this year: Representing almost a quarter of all breaches (24%), ransomware remains one of the top cyberattack methods.

The human element still makes up the overwhelming majority of incidents, and is a factor in 74% of total breaches, even as enterprises continue to safeguard critical infrastructure and increase training on cybersecurity protocols. One of the most common ways to exploit human nature is social engineering, which refers to manipulating an organization's sensitive information through tactics like phishing, in which a hacker convinces the user into clicking on a malicious link or attachment.

“Senior leadership represents a growing cybersecurity threat for many organizations,” said Chris Novak, Managing Director of Cybersecurity Consulting at Verizon Business. “Not only do they possess an organization’s most sensitive information, they are often among the least protected, as many organizations make security protocol exceptions for them. With the growth and increasing sophistication of social engineering, organizations must enhance the protection of their senior leadership now to avoid expensive system intrusions.”

Like ransomware, social engineering is a lucrative tactic for cybercriminals, especially given the rise of those techniques being used to impersonate enterprise employees for financial gain, an attack known as Business Email Compromise (BEC). The median amount stolen in BECs has increased over the last couple of years to $50,000 USD, based on Internet Crime Complaint Center (IC3) data, which might have contributed to pretexting nearly doubling this past year. With the growth of BEC, enterprises with distributed workforces face a challenge that takes on greater importance: creating and strictly enforcing human-centric security best practices. 

"Globally, cyber threat actors continue their relentless efforts to acquire sensitive consumer and business data. The revenue generated from that information is staggering, and it's not lost on business leaders, as it is front and center at the board level," said Craig Robinson, Research Vice President at IDC. "Verizon's Data Breach Investigations Report provides deep insights into the topics that are critical to the cybersecurity industry and has become a source of truth for the business community."

In addition to the increase in social engineering, other key findings in the 2023 DBIR include: 

  • While espionage garners substantial media attention, owing to the current geopolitical climate, only 3% of threat actors were motivated by espionage. The other 97% were motivated by financial gain. 

  • 32% of yearly Log4j vulnerability scanning occurred in the first 30 days after its release, demonstrating threat actors’ velocity when escalating from a proof of concept to mass exploitation.

  • External actors leveraged a variety of different techniques to gain entry to an organization, such as using stolen credentials (49%), phishing (12%) and exploiting vulnerabilities (5%).

One of the ways that enterprises can help safeguard their critical infrastructure is through the adoption and adherence of industry leading protocols and practices. Verizon recently became the first nationwide telecom provider to become a participant of Mutually Agreed Norms for Routing Security (MANRS): a global initiative that provides crucial fixes to reduce the most common routing threats that can be exploited by attackers. Participation in MANRS demonstrates Verizon’s commitment to implementing industry best fixes to common routing threats and best practices geared at helping to prevent cyber incidents for customers on the network.

View 2023 Data Breach Investigation Report:

https://www.verizon.com/business/resources/reports/dbir/

Tags:
Cybersecurity

Related Articles

Verizon Business to spotlight the fast-changing cybersecurity landscape and how to manage it at RSA Conference™
05/03/2024

Verizon Business will be front and center at RSA 2024 (Booth #5570) to demonstrate the latest cybersecurity strategies and solutions and how businesses can put them to work

Protect your tech! Open enrollment for Verizon’s device protection options starts now
02/14/2024

For a limited time, now through April 13, eligible Verizon customers can enroll in Verizon Mobile Protect or any other device protection option.

Whether you are raising a concern or have only a question, we want you to know it’s important to us. You are about to visit a third-party website, and the information you provide will be submitted directly to Verizon Ethics. If you have any questions about how the information you share will be used, please view our Ethics Privacy Notice.

Proceed
Services & Solutions
  • Verizon.com
  • Mobile Plans
  • Mobile Devices
  • Home Services
  • Small and Medium Business
  • Enterprise Solutions
  • Verizon Connect
  • Public Sector
  • Partner Solutions
Support
  • Mobile Online Support
  • Home Online Support
  • Contact Customer Support
  • Sign in to your Account
  • Store Locator
  • Account Security & Fraud Claims
  • The Relay Blog
  • Accessibility
Innovation
  • Innovation Labs
  • The Verizon Story & Museum
  • Verizon Ventures
Network Technologies
  • 4G LTE
  • 5G
  • Fiber Optics
  • Multi-Access Edge Compute (MEC)
Careers
  • Welcome to the #NetworkLife
  • Life at Verizon
  • Culture & Diversity
  • Search Open Roles
  • Careers Site Map
Follow Verizon News
  • twitter
  • instagram
Follow Inside Verizon
  • twitter
  • instagram
Follow Verizon Careers
  • twitter
  • instagram
  • linkedln
Follow Customer Support
  • facebook-official
  • twitter
Follow VerizonGreen
  • twitter
  • Privacy Policy
  • California Privacy Notice
  • Health Privacy Notice
  • Your Privacy Choices
  • Terms & Conditions
  • Accessibility
  • Open Internet
  • Important Consumer Information
  • About Our Ads
  • Site Map
© 2024 Verizon