Knowledge

State of (in)security - Week 40, 2025

Take action: Mass firing of people after a cybersecurity incident is just the type of culture which will not help long term. The most the organization can expect is everyone to start pushing the problem onto someone else and covering their behinds.


Learn More

In the week between Sept. 29, 2025, midnight and Oct. 6, 2025, midnight we witnessed a total of:

  • 12 advisory/vulnerability events
  • 17 incident/data breach events

Week over Week comparison of week 40 2025 vs week 39 2025:

We also shared 4 practical knowledge items


Total impacted individuals via the events of the week

There were a total of 29,485 impacted individuals across 1 incidents, with the largest breach being the Fort Wayne Medical Education Program hit ransomware attack, affects almost 30,000 people incident exposing 29,485 individuals. Since not all incidents report a number of impacted individuals, the real number is definitely higher than that.

Cause breakdown of incidents

CauseNumber of incidents
Malware, Ransomware and Related Attacks6
Third Party Compromise3
Software Vulnerability and SDLC Exploits2
Social Engineering and Phishing1
Unauthorized access1

Industry breakdown of incidents

IndustryNumber of incidents
IT/Software/Technology5
Healthcare4
Government2
Food and Beverage1
Insurance1
Automotive1
Media1
Consulting/Professional Services1
Finance1

Read the Event Details of the Week

Knowledge

Vulnerabilities

Incidents

State of (in)security - Week 40, 2025