Knowledge

State of (in)security - Week 19, 2025

Take action: Three rules this week: (1) Your company MUST have responsible disclosure channel to be able to quickly react to reported issues. (2) There is no honor among criminals. This is why it's usually pointless to pay a ransom for stolen data. Criminals will most likely retain the data and extort everyone as much as possible. (3) Never try to write your own cryptography, because that usually ends up with a flawed implementation. Use well known deeply tested libraries.


Learn More

In the week between May 5, 2025, midnight and May 12, 2025, midnight we witnessed a total of:

  • 13 advisory/vulnerability events
  • 22 incident/data breach events

Week over Week comparison of week 19 2025 vs week 18 2025:

We also shared 7 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 2,836,638 impacted individuals across 7 incidents, with the largest breach being the Data leak at beWanted exposes 1.1 Million job seekers' personal information incident exposing 1,100,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks6
System Misconfiguration Exploits2
Third Party Compromise2
Software Vulnerability and SDLC Exploits1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
IT/Software/Technology4
Education4
Consulting/Professional Services2
Government2
Media2
Aviation1
Other1
Food and Beverage1
Healthcare1
Insurance1
Manufacturing1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 19, 2025