Knowledge

State of (in)security - Week 38, 2025

Take action: Never try to gag the responsible disclosure white hat hackers with stupid DMCA lawsuits. You are just making a "Streisand Effect". Everyone will learn about the vulnerability and how poor you handled it.


Learn More

In the week between Sept. 15, 2025, midnight and Sept. 22, 2025, midnight we witnessed a total of:

  • 14 advisory/vulnerability events
  • 19 incident/data breach events

Week over Week comparison of week 38 2025 vs week 37 2025:


Total impacted individuals via the events of the week

There were a total of 9,145,640 impacted individuals across 7 incidents, with the largest breach being the Shiny Hunters ransomware gang claims breach of Kering's Luxury Brands incident exposing 7,400,000 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks5
Unauthorized access3
Third Party Compromise2
Social Engineering and Phishing2
Human bad security behaviour2
Software Vulnerability and SDLC Exploits1
System Misconfiguration Exploits1

Industry breakdown of incidents

IndustryNumber of incidents
Healthcare7
IT/Software/Technology2
Finance2
Food and Beverage1
Government1
Insurance1
Other1
Automotive1
Retail1
Aviation1
Consulting/Professional Services1

Read the Event Details of the Week

Vulnerabilities

Incidents

State of (in)security - Week 38, 2025