Verizon 2025 Report Alarming Rise in Cyberattacks Via Third-Parties

With ransomware and data theft continuing to pose significant threats, the report underscores the importance of comprehensive security programs that include regular vulnerability assessments, prompt patching, employee training, and improved visibility into third-party connections. The comprehensive analysis, which examined over 22,000 security incidents including 12,195 confirmed data breaches, found that exploitation of vulnerabilities as an initial attack vector grew by an alarming 34%, now accounting for 20% of all breaches. The report emphasizes that organizations must implement comprehensive third-party risk management programs, including vendor security assessments, continuous monitoring, and zero-trust security models to mitigate these evolving threats. Verizon Business recently released its 2025 Data Breach Investigations Report (DBIR), revealing a disturbing trend in the cybersecurity landscape: third-party involvement in data breaches has doubled to 30% over the past year, creating unprecedented challenges for organizations worldwide. “The proliferation of third-party integrations in modern business environments has created an expanded attack surface that many organizations fail to properly secure or monitor,” explained Chris Novak, Vice President of Global Cybersecurity Solutions at Verizon Business. With supply chain attacks continuing to rise, the traditional security perimeter has effectively dissolved, requiring a fundamental shift in how organizations approach cybersecurity strategy and implementation. Verizon analysts identified a concerning pattern wherein threat actors are leveraging credential abuse (22%) alongside vulnerability exploitation to create multi-stage attack chains that are increasingly difficult to detect and mitigate. The Verizon 2025 DBIR serves as a critical warning for organizations of all sizes to reevaluate their third-party security postures. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Despite increased awareness and security investments, small and medium-sized businesses (SMBs) remain disproportionately impacted, with ransomware present in 88% of breaches affecting these organizations. This tactical shift demonstrates attackers’ growing sophistication in identifying and leveraging security gaps before organizations can implement patches or mitigations. As threat actors continue to evolve their tactics, focusing increasingly on supply chain vulnerabilities, companies must adopt multi-layered defense strategies that address both technical vulnerabilities and human factors. With the median ransom payment reaching $115,000, these attacks pose an existential threat to many smaller enterprises lacking robust security infrastructure. This significant shift indicates cybercriminals are increasingly targeting supply chain vulnerabilities to compromise multiple victims through a single point of entry, maximizing their impact while minimizing their effort. A typical attack sequence involves initial scanning, vulnerability identification, exploitation, lateral movement, and data exfiltration. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 30 Apr 2025 06:35:05 +0000


Cyber News related to Verizon 2025 Report Alarming Rise in Cyberattacks Via Third-Parties

Verizon insider data breach hits over 63,000 employees - Verizon Communications is warning that an insider data breach impacts almost half its workforce, exposing sensitive employee information. Verizon is an American telecommunications and mass media company providing cable TV, telecommunications, and ...
1 year ago Bleepingcomputer.com
Verizon 2025 Report Alarming Rise in Cyberattacks Via Third-Parties - With ransomware and data theft continuing to pose significant threats, the report underscores the importance of comprehensive security programs that include regular vulnerability assessments, prompt patching, employee training, and improved ...
3 hours ago Cybersecuritynews.com
98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis - The digital supply chain is probably more extensive and more complicated than you realize. Upward of 98% of organizations have a relationship with at least one third party that has experienced a breach in the last two years - and these figures are ...
2 years ago Securityweek.com
Verizon Call Filter API flaw exposed customers' incoming call history - "This endpoint requires a JWT (JSON Web Token) in the Authorization header using the Bearer scheme and uses an X-Ceq-MDN header to specify a cell phone number to retrieve call history logs for," explains Connelly. As a result, any user ...
3 weeks ago Bleepingcomputer.com
ProcessUnity Introduces Industry's All-In-One Third-Party Risk Management Platform - PRESS RELEASE. BOSTON-(BUSINESS WIRE)- ProcessUnity, provider of comprehensive end-to-end third-party risk management and cybersecurity solutions to leading enterprises, today announced the completed integration of the Global Risk Exchange. The newly ...
1 year ago Darkreading.com
Verizon says 63K employee info wrongly accessed by insider The Register - Verizon is notifying more than 63,000 people, mostly current employees, that an insider, accidentally or otherwise, had inappropriate access to their personal data. The Pine Tree state's strict data loss rules require security snafu disclosures, even ...
1 year ago Go.theregister.com
Verizon says 63K employee info wrongly accessed by insider The Register - Verizon is notifying more than 63,000 people, mostly current employees, that an insider, accidentally or otherwise, had inappropriate access to their personal data. The Pine Tree state's strict data loss rules require security snafu disclosures, even ...
1 year ago Go.theregister.com
Verizon DBIR Report - Small Businesses Emerges as Prime Targets for Ransomware Attacks - For small businesses with limited resources, focusing on these fundamental security controls represents the most effective defense against the rising tide of ransomware attacks. The attack methodology reveals a sophisticated understanding of small ...
5 days ago Cybersecuritynews.com
Insider Data Breach at Verizon Affects Over 63,000 Employees - An insider data breach at Verizon has compromised the personal information of more than 63,000 employees, nearly half of the company's global workforce. The telecommunications giant disclosed the incident in a Data Breach Notification with the Office ...
1 year ago Heimdalsecurity.com
Third-party breaches hit 90% of top global energy companies - A new report from SecurityScorecard reveals a startling trend among the world's top energy companies, with 90% suffering from data breaches through third parties over the last year. This sheds light on the need for these energy companies to adopt a ...
1 year ago Securityintelligence.com
Ransomware Attacks Strike South Africa, Decline in UAE - Cybercrime - and especially ransomware - traditionally have had an uneven impact across the Middle East and Africa, yet recent data suggests that ongoing geopolitical conflicts will likely raise the overall level of cyberattacks across the regions. ...
1 year ago Darkreading.com Molerats LockBit
Google Cloud Report Spotlights 2024 Cybersecurity Challenges - As the New Year dawns, a cybersecurity report from Google Cloud suggests that while there are many challenges ahead, it will also become simpler for cybersecurity teams to leverage artificial intelligence to better defend IT environments. John ...
1 year ago Securityboulevard.com
How Main Street Businesses Can Up Their Cybersecurity Game - Small businesses are not only essential in keeping Main Street thriving and bustling, but they are essential to our economy. Unauthorized access to data has the potential for significant financial loss that can be difficult or impossible to recover. ...
10 months ago Cyberdefensemagazine.com
Unraveling the Aftermath of Verizon's Insider Data Breach Impacting 63,000 Employees - In the fast-paced world of digital connectivity, data breaches have become an unfortunate reality that businesses must constantly guard against. Recently, telecommunications giant Verizon found itself in the throes of a security crisis as it grappled ...
1 year ago Cysecurity.news
Ransomware now plays a role in nearly half of all breaches, new research finds | The Record from Recorded Future News - Verizon found that 64% of ransomware victims did not pay the ransoms — which was up from 50% two years ago — and the median amount paid to ransomware groups has decreased to $115,000 (from $150,000 last year). One section of the report focusing ...
5 days ago Therecord.media
What's new in the MSRC Report Abuse Portal and API - The Microsoft Security Response Center has always been at the forefront of addressing cyber threats, privacy issues, and abuse arising from Microsoft Online Services. Building on our commitment, we have introduced several key updates to the Report ...
9 months ago Msrc.microsoft.com
Understanding Each Link of the Cyberattack Impact Chain - It's often difficult to fully appreciate the impact of a successful cyberattack. Other consequences aren't so obvious - from a loss of customer trust and potential business to stolen data that may surface as part of another cyberattack years later. ...
1 year ago Securityboulevard.com
Verizon Employee Data Exposed in Insider Threat Incident - About 63,000 Verizon employees have been affected by a breach that occurred in September 2023 but which wasn't discovered for three months. The exposed information includes names, addresses, Social Security numbers, gender, union affiliations, dates ...
1 year ago Darkreading.com
T-Mobile, Verizon workers get texts offering $300 for SIM swaps - Criminals are now texting T-Mobile and Verizon employees on their personal and work phones, trying to tempt them with cash to perform SIM swaps. The targeted employees have shared screenshots of messages offering $300 to those willing to aid the ...
1 year ago Bleepingcomputer.com
Italian Firm Trains Pakistani Navy Officers in Cybersecurity, Raising Concerns - Recently, it has come to light that individuals responsible for state-sponsored cyberattacks, reportedly backed by Pakistan, underwent advanced training by an Italian security firm. Documents shared with The Sunday Guardian indicate that Pakistani ...
1 year ago Cysecurity.news
Cyber Insights 2023: The Geopolitical Effect - The result is more than a dozen features on subjects ranging from AI, quantum encryption, and attack surface management to venture capital, regulations, and criminal gangs. The Russia/Ukraine war that started in early 2022 has been mirrored by a ...
2 years ago Securityweek.com
Mideast Oil & Gas Facilities Could Face Cyber-Related Energy Disruptions - Middle East oil and gas operators will need to be vigilant about the risk of cyberattacks as the Israel-Gaza conflict continues, security experts warn, or else risk energy supply disruption globally. A recent report by S&P Global Ratings found that ...
1 year ago Darkreading.com
North Korean Hackers Utilizing Credential Stuffing to Launch Cyberattacks - In an alarming new report, researchers found that North Korean-linked hackers have been using stolen passwords during cyberattacks to gain access to various government, military and financial networks. According to security experts, the creative ...
2 years ago Thehackernews.com
Cybersecurity Insiders - As the threat landscape rapidly evolves, VPNs cannot provide the secure, segmented access organizations need. The 2023 VPN Risk Report reveals the complexity of today's VPN management, user experience issues, vulnerabilities to diverse cyberattacks, ...
1 year ago Cybersecurity-insiders.com
Third Of European Businesses Have Adopted AI, AWS - AWS finds AI already adopted at sizeable number of European businesses, resulting in increased revenues, productivity. An insight into the adoption rate of artificial intelligence within the business community has been offered in a new report from ...
1 year ago Silicon.co.uk

Latest Cyber News


Cyber Trends (last 7 days)