Knowledge

State of (in)security - Week 28, 2025

Take action: Make sure to authenticate and authorize every single request to your APIs. And don't use integer auto-incrementing IDs for users, too easy to guess. Naturally, NEVER use trivial credentials for test systems.


Learn More

In the week between July 7, 2025, midnight and July 14, 2025, midnight we witnessed a total of:

  • 17 advisory/vulnerability events
  • 21 incident/data breach events

We also shared 2 practical knowledge items

Week over Week comparison of week 28 2025 vs week 27 2025:


Total impacted individuals via the events of the week

There were a total of 85,106,788 impacted individuals across 8 incidents, with the largest breach being the McDonald's AI hiring platform found to be vulnerable, risking 64 million job applications incident exposing 64,000,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks7
Software Vulnerability and SDLC Exploits3
Unauthorized access3
System Misconfiguration Exploits2
Third Party Compromise1

Industry breakdown of incidents

IndustryNumber of incidents
Consulting/Professional Services5
Healthcare3
Manufacturing2
IT/Software/Technology2
Retail2
Government1
Education1
Entertainment/Leisure1
Media1
Insurance1
Finance1
Food and Beverage1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 28, 2025