Knowledge

State of (in)security - Week 20, 2025

Take action: We all like to consider our colleagues good people, and we don't want to insult them by assuming they can do something bad. But this week we had two examples why controls against malicious insiders are important. However painful it is to consider that your colleagues may be malicious, you still need controls against it.


Learn More

In the week between May 12, 2025, midnight and May 19, 2025, midnight we witnessed a total of:

  • 12 advisory/vulnerability events
  • 19 incident/data breach events

Week over Week comparison of week 20 2025 vs week 19 2025:

We also shared 8 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 93,848,900 impacted individuals across 11 incidents, with the largest breach being the Hacker offer to sell SMS OTP messages of 89M Steam users, Valve clarifies no account connection incident exposing 89,000,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
System Misconfiguration Exploits5
Human bad security behaviour2
Malware, Ransomware and Related Attacks2
Third Party Compromise2
Software Vulnerability and SDLC Exploits1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
IT/Software/Technology5
Government3
Finance2
Education1
Healthcare1
Manufacturing1
Retail1
Telecommunications1
Aviation1
Utilities1
Construction/Realestate1
Consulting/Professional Services1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 20, 2025