Knowledge

State of (in)security - Week 29, 2025

Take action: A government can fuck up with data protection just as easily as a private organization. But the shocking part is that a government can make a court order to hide that they have fucked up, while leaving the individuals at risk. Most countries do not have a strict regulation of how political parties handle personal data, and are usually excluded from most requirements of privacy laws. A perfect example of "do as I say, don't do as I do".


Learn More

In the week between July 14, 2025, midnight and July 21, 2025, midnight we witnessed a total of:

  • 10 advisory/vulnerability events
  • 23 incident/data breach events

Week over Week comparison of week 29 2025 vs week 28 2025:

We also shared 4 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 46,972,490 impacted individuals across 7 incidents, with the largest breach being the Indian crypto exchange CoinDCX hit by cyber attack, loses $44.2 million incident exposing 44,200,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks10
Human bad security behaviour2
System Misconfiguration Exploits2
Software Vulnerability and SDLC Exploits1
Third Party Compromise1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
Government4
Healthcare4
Finance4
Consulting/Professional Services3
Retail2
IT/Software/Technology2
Energy1
Construction/Realestate1
Other1
Food and Beverage1

 

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 29, 2025