Knowledge

State of (in)security - Week 18, 2025

Take action: When installing new code libraries or packages, always verify their legitimacy by checking for active development, multiple contributors, and an active development history of at least 2-3 years. Organizations should maintain approved package lists and educate developers about security risks. Individual developers should research packages on trusted platforms like StackOverflow before implementation.


Learn More

In the week between April 28, 2025, midnight and May 5, 2025, midnight we witnessed a total of:

  • 9 advisory/vulnerability events
  • 16 incident/data breach events

Week over Week comparison of week 18 2025 vs week 17 2025:

We also shared 10 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 20,674,723 impacted individuals across 7 incidents, with the largest breach being the UK retailer Co-op targeted by cyberattack, shuts down IT systems incident exposing 20,000,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks8
Human bad security behaviour1
Software Vulnerability and SDLC Exploits1
System Misconfiguration Exploits1
Third Party Compromise1

Industry breakdown of incidents

IndustryNumber of incidents
IT/Software/Technology4
Healthcare2
Retail2
Government2
Consulting/Professional Services1
Transport/Logistics1
Education1
Insurance1
Media1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 18, 2025