• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
NewslettersData Sheet

Blame dumb mistakes for more and more of data breaches

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
May 20, 2020, 11:57 AM ET

This is the web version of Data Sheet, Fortune’s dailynewsletter on the top tech news. To get it delivered daily to your in-box, sign up here.

In the cybersecurity industry, good data is hard to come by.

My email inbox is littered with exaggerated claims and dubious survey results. They purport to reveal frequency of hacks, the prevalence of unaddressed vulnerabilities, or the amount of money businesses lose to cybercriminals. I treat most of these as I do expired milk: with a wrinkled nose and a visit to the trash bin.

There’s an exception to the rule. I always make time for a briefing that covers one particular report. Each year, Verizon publishes a compendium that is among the industry’s finest. I consider the “data breach investigations report,” or DBIR, as it’s known, to be like an annual visit to the doctor for a physical examination; it sets a baseline and gives an overview of one’s health.

This year’s report, Verizon’s 13th edition, is as colorfully written as always (the introduction quotes Oscar Wilde) and equally rigorous. Sourcing data from 81 government and industry partners, the report reviewed a record total of 157,525 security incidents and confirmed 3,950 data breaches across 16 industries. The eye-popping number of incidents—which includes Denial of Service, ransomware, and phishing—far exceed the number of breaches, because the latter requires confirmed exposure of data.

The finding that caught my eye the most this year was the indomitable rise of human “error” as a cause of breaches. It is the only factor that has consistently increased year-over-year since 2015. Other data breach causes, like hacking and malware, are dropping. “If we said last year that humans are the weakest link in the chain and the easiest way into computer networks these days, that’s more true now than it ever has been before,” Bryan Sartin, Verizon’s executive director of global security services, told me.

But don’t lose faith in humanity. Humans are imperfect—but they may be getting better, not worse, despite what the data shows.

“Misdelivery,” like sending sensitive emails to the wrong people, and “misconfiguration,” like putting improperly secured databases online, are among the top five breach causes this year. But as the report’s authors note, that may be because of stricter privacy laws being adopted around the world. New regulations are forcing people to disclose more often when such mishaps happen; the behavior is getting “normalized.”

Internal threat actors, or a company’s own employees, have climbed over the years as a cause of breaches. But this too could simply be a result of more people reporting their mistakes.

“People can, and frequently do, make mistakes and many of them probably work for you,” the report warns. But a deeper analysis suggests, hopefully, that recent regulatory changes appear to be working, leading to more visibility and better data.

“We are getting better at admitting our mistakes rather than trying to simply sweep them under the rug,” the authors write.

Robert Hackett

Twitter: @rhhackett

Email: robert.hackett@fortune.com

THREATS

Sunless skies. Big companies like Cigna, RaytheonTechnologies, and FedEx are pushing for uniform cybersecurity and data handling practices to be adopted by cloud computing providers like Amazon Web Services, Microsoft Azure, and Google Cloud, the Wall Street Journalreports. A lack of standardization means more work and unnecessary complication for businesses, the corporate customers say. 

Heck, no, we won't go. Anti-lockdown protestors flagrantly defying stay-at-home orders may be spreading coronavirus contagions far and wide, the Guardianreports. Location data from cellphones associated with protestors were seen traveling hundreds of miles and crossing between states. Epidemiologists have warned that such behavior could lead to a surge in infections.

Desert dust-up. A traffic-crippling cyberattack on an Iranian shipping port, Shahid Rajaee, is said to have been the work of Israeli spies, the Washington Postreports. The strike may have been retaliation for an earlier attempted hack of an Israeli water utility, according to intelligence officials. Meanwhile, a new report says that while civilian hacking activity has decreased 90% out of Iran since the onset of pandemic, the country's military hacking escapades have abated less, about 30% to 50%. 

Please remain seated until the seat belt light is off. European budget airline EasyJet disclosed a data breach affecting as many as 9 million customers. An unauthorized person or group purloined people's email addresses and travel details. More than 2,200 people also had their credit card information accessed. The airline, which learned of the breach in January, said it plans to notify victims by May 26.

Star-crossed lovers. People are hacking the Nintendo video game Animal Crossing in order to plant trees bearing "star fragments," a hot in-game commodity. The Washington Postwarns that engaging in such rogue activity "not only puts you at risk for a potential ban...but could destabilize your game." Meanwhile, someone is hacking supercomputers in Europe to mine virtual currency.

Is the head of U.S. Army Cyber Command trying to flirt with me?

ACCESS GRANTED

Why did Facebook recently buyGIPHY, the ubiquitous search engine for gifs? Owen Williams at tech blog OneZero says the acquisition provides a way for Facebook to peer across the Internet, linking people's devices to the non-Facebook apps they use. Wherever GIPHY has a foothold—from Apple's iOS keyboard to Twitter—Facebook may be able to glean data useful for to its advertising business.

Adam Mosseri, head of Instagram, disputed this idea, saying Facebook is primarily interested in knowing what's trending online—data of another sort. Here's Williams:

Acquiring Giphy is a smart play by Facebook, which has become increasingly unavoidable in life online. While you may successfully block trackers like the Facebook ad pixel following you around online, or even delete your Facebook account, the majority of us wouldn’t suspect we’re being monitored when we’re sending funny images to friends.

FORTUNE RECON

Spotify shares soar on news of Joe Rogan’s exclusive podcast deal by Lucas Shaw

Facebook makes a bigger push into shopping with new online storefronts for businesses by Jeremy Kahn

Walmart’s online sales surge during the pandemic, bolstering its place as a strong No. 2 to Amazon by Phil Wahba

As reopening becomes polarized, businesses need to use common-ground language by Michal Lev-Ram

What will Uber look like after the coronavirus? by Lucinda Shen

How Honeywell’s CEO plans to survive—and thrive—through pandemic by Robert Hackett

ONE MORE THING

A couple years ago, the social fitness app Strava came under fire for exposing the locations of secret U.S. military bases by logging the jogging routes of soldiers. Now Untappd, the social beer-drinking app, is catching heat for enabling military and intelligence personnel to be tracked around the world, a researcher at the investigative site Bellingcatfound. 

Great, now everyone is gonna learn about my secret martini haunt.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Newsletters

NewslettersMPW Daily
Alexis Ohanian believes in the future of women’s sports: ‘I can market excellence all day long’
By Emma HinchliffeDecember 12, 2025
21 hours ago
NewslettersCFO Daily
SEC chair moves to boost IPO momentum: ‘Make it cool to be a public company’
By Sheryl EstradaDecember 12, 2025
1 day ago
NewslettersTerm Sheet
Disney plus OpenAI: What could possibly go wrong?
By Alexei OreskovicDecember 12, 2025
1 day ago
Disney CEO Bob Iger in Los Angeles, California on November 20, 2025.(Photo: Unique Nicole/AFP/Getty Images)
NewslettersFortune Tech
Disney and OpenAI do a deal
By Andrew NuscaDecember 12, 2025
1 day ago
NewslettersCEO Daily
Honest Company CEO Carla Vernón on being mentored by Walmart’s Doug McMillon
By Diane BradyDecember 12, 2025
1 day ago
Stephanie Zhan, Partner Sequoia Capital speaking on stage at Fortune Brainstorm AI San Francisco 2025.
AIEye on AI
Highlights from Fortune Brainstorm AI San Francisco
By Jeremy KahnDecember 11, 2025
2 days ago

Most Popular

placeholder alt text
Economy
Tariffs are taxes and they were used to finance the federal government until the 1913 income tax. A top economist breaks it down
By Kent JonesDecember 12, 2025
1 day ago
placeholder alt text
Success
Apple cofounder Ronald Wayne sold his 10% stake for $800 in 1976—today it’d be worth up to $400 billion
By Preston ForeDecember 12, 2025
23 hours ago
placeholder alt text
Success
40% of Stanford undergrads receive disability accommodations—but it’s become a college-wide phenomenon as Gen Z try to succeed in the current climate
By Preston ForeDecember 12, 2025
22 hours ago
placeholder alt text
Economy
For the first time since Trump’s tariff rollout, import tax revenue has fallen, threatening his lofty plans to slash the $38 trillion national debt
By Sasha RogelbergDecember 12, 2025
18 hours ago
placeholder alt text
Economy
The Fed just ‘Trump-proofed’ itself with a unanimous move to preempt a potential leadership shake-up
By Jason MaDecember 12, 2025
16 hours ago
placeholder alt text
Success
At 18, doctors gave him three hours to live. He played video games from his hospital bed—and now, he’s built a $10 million-a-year video game studio
By Preston ForeDecember 10, 2025
3 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.