• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
NewslettersData Sheet

Blame dumb mistakes for more and more of data breaches

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
May 20, 2020, 11:57 AM ET

This is the web version of Data Sheet, Fortune’s daily newsletter on the top tech news. To get it delivered daily to your in-box, sign up here.

In the cybersecurity industry, good data is hard to come by.

My email inbox is littered with exaggerated claims and dubious survey results. They purport to reveal frequency of hacks, the prevalence of unaddressed vulnerabilities, or the amount of money businesses lose to cybercriminals. I treat most of these as I do expired milk: with a wrinkled nose and a visit to the trash bin.

There’s an exception to the rule. I always make time for a briefing that covers one particular report. Each year, Verizon publishes a compendium that is among the industry’s finest. I consider the “data breach investigations report,” or DBIR, as it’s known, to be like an annual visit to the doctor for a physical examination; it sets a baseline and gives an overview of one’s health.

This year’s report, Verizon’s 13th edition, is as colorfully written as always (the introduction quotes Oscar Wilde) and equally rigorous. Sourcing data from 81 government and industry partners, the report reviewed a record total of 157,525 security incidents and confirmed 3,950 data breaches across 16 industries. The eye-popping number of incidents—which includes Denial of Service, ransomware, and phishing—far exceed the number of breaches, because the latter requires confirmed exposure of data.

The finding that caught my eye the most this year was the indomitable rise of human “error” as a cause of breaches. It is the only factor that has consistently increased year-over-year since 2015. Other data breach causes, like hacking and malware, are dropping. “If we said last year that humans are the weakest link in the chain and the easiest way into computer networks these days, that’s more true now than it ever has been before,” Bryan Sartin, Verizon’s executive director of global security services, told me.

But don’t lose faith in humanity. Humans are imperfect—but they may be getting better, not worse, despite what the data shows.

“Misdelivery,” like sending sensitive emails to the wrong people, and “misconfiguration,” like putting improperly secured databases online, are among the top five breach causes this year. But as the report’s authors note, that may be because of stricter privacy laws being adopted around the world. New regulations are forcing people to disclose more often when such mishaps happen; the behavior is getting “normalized.”

Internal threat actors, or a company’s own employees, have climbed over the years as a cause of breaches. But this too could simply be a result of more people reporting their mistakes.

“People can, and frequently do, make mistakes and many of them probably work for you,” the report warns. But a deeper analysis suggests, hopefully, that recent regulatory changes appear to be working, leading to more visibility and better data.

“We are getting better at admitting our mistakes rather than trying to simply sweep them under the rug,” the authors write.

Robert Hackett

Twitter: @rhhackett

Email: robert.hackett@fortune.com

THREATS

Sunless skies. Big companies like Cigna, Raytheon Technologies, and FedEx are pushing for uniform cybersecurity and data handling practices to be adopted by cloud computing providers like Amazon Web Services, Microsoft Azure, and Google Cloud, the Wall Street Journal reports. A lack of standardization means more work and unnecessary complication for businesses, the corporate customers say. 

Heck, no, we won't go. Anti-lockdown protestors flagrantly defying stay-at-home orders may be spreading coronavirus contagions far and wide, the Guardian reports. Location data from cellphones associated with protestors were seen traveling hundreds of miles and crossing between states. Epidemiologists have warned that such behavior could lead to a surge in infections.

Desert dust-up. A traffic-crippling cyberattack on an Iranian shipping port, Shahid Rajaee, is said to have been the work of Israeli spies, the Washington Post reports. The strike may have been retaliation for an earlier attempted hack of an Israeli water utility, according to intelligence officials. Meanwhile, a new report says that while civilian hacking activity has decreased 90% out of Iran since the onset of pandemic, the country's military hacking escapades have abated less, about 30% to 50%. 

Please remain seated until the seat belt light is off. European budget airline EasyJet disclosed a data breach affecting as many as 9 million customers. An unauthorized person or group purloined people's email addresses and travel details. More than 2,200 people also had their credit card information accessed. The airline, which learned of the breach in January, said it plans to notify victims by May 26.

Star-crossed lovers. People are hacking the Nintendo video game Animal Crossing in order to plant trees bearing "star fragments," a hot in-game commodity. The Washington Post warns that engaging in such rogue activity "not only puts you at risk for a potential ban...but could destabilize your game." Meanwhile, someone is hacking supercomputers in Europe to mine virtual currency.

Is the head of U.S. Army Cyber Command trying to flirt with me?

ACCESS GRANTED

Why did Facebook recently buy GIPHY, the ubiquitous search engine for gifs? Owen Williams at tech blog OneZero says the acquisition provides a way for Facebook to peer across the Internet, linking people's devices to the non-Facebook apps they use. Wherever GIPHY has a foothold—from Apple's iOS keyboard to Twitter—Facebook may be able to glean data useful for to its advertising business.

Adam Mosseri, head of Instagram, disputed this idea, saying Facebook is primarily interested in knowing what's trending online—data of another sort. Here's Williams:

Acquiring Giphy is a smart play by Facebook, which has become increasingly unavoidable in life online. While you may successfully block trackers like the Facebook ad pixel following you around online, or even delete your Facebook account, the majority of us wouldn’t suspect we’re being monitored when we’re sending funny images to friends.

FORTUNE RECON

Spotify shares soar on news of Joe Rogan’s exclusive podcast deal by Lucas Shaw

Facebook makes a bigger push into shopping with new online storefronts for businesses by Jeremy Kahn

Walmart’s online sales surge during the pandemic, bolstering its place as a strong No. 2 to Amazon by Phil Wahba

As reopening becomes polarized, businesses need to use common-ground language by Michal Lev-Ram

What will Uber look like after the coronavirus? by Lucinda Shen

How Honeywell’s CEO plans to survive—and thrive—through pandemic by Robert Hackett

ONE MORE THING

A couple years ago, the social fitness app Strava came under fire for exposing the locations of secret U.S. military bases by logging the jogging routes of soldiers. Now Untappd, the social beer-drinking app, is catching heat for enabling military and intelligence personnel to be tracked around the world, a researcher at the investigative site Bellingcat found. 

Great, now everyone is gonna learn about my secret martini haunt.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Newsletters

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Newsletters

The crypto industry is obsessed with conferences. The vibe at them is changing
NewslettersFortune Crypto
The crypto industry is obsessed with conferences. The vibe at them is changing
By Jeff John RobertsMay 4, 2026
24 minutes ago
VC firm Ethereal has avoided the spotlight for 5 years—now it’s telling its story
NewslettersTerm Sheet
VC firm Ethereal has avoided the spotlight for 5 years—now it’s telling its story
By Jeff John RobertsMay 4, 2026
53 minutes ago
Occidental Petroleum’s CEO transition puts a spotlight on the foreign post advantage
C-SuiteNext to Lead
Occidental Petroleum’s CEO transition puts a spotlight on the foreign post advantage
By Ruth UmohMay 4, 2026
1 hour ago
Spirit Airlines’ shutdown is a case study in what happens when a turnaround plan breaks
NewslettersCFO Daily
Spirit Airlines’ shutdown is a case study in what happens when a turnaround plan breaks
By Sheryl EstradaMay 4, 2026
1 hour ago
The eBay logo with a mobile phone in 2025. (Photo: Klaudia Radecka/NurPhoto/Getty Images)
NewslettersFortune Tech
GameStop makes an unsolicited $56 billion offer for eBay
By Andrew NuscaMay 4, 2026
2 hours ago
How Twilio CEO Khozema Shipchandler is turning the company around and beating SaaSpocalypse fears
NewslettersCEO Daily
How Twilio CEO Khozema Shipchandler is turning the company around and beating SaaSpocalypse fears
By Diane BradyMay 4, 2026
3 hours ago

Most Popular

America got rich and got sad. A top economist says 2020 broke something that hasn't healed
Economy
America got rich and got sad. A top economist says 2020 broke something that hasn't healed
By Nick LichtenbergMay 3, 2026
1 day ago
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
Personal Finance
Scott Bessent on financial literacy: 'it drives me crazy' to see young men in blue-collar construction jobs playing the lottery
By Fatima Hussein and The Associated PressMay 1, 2026
3 days ago
Diary of a CEO founder says he hired someone with 'zero' work experience because she 'thanked the security guard by name' before the interview
Success
Diary of a CEO founder says he hired someone with 'zero' work experience because she 'thanked the security guard by name' before the interview
By Emma BurleighMay 3, 2026
24 hours ago
As economic despair mounts, Russian official admits the country has had enough of Putin's war on Ukraine. 'We can’t even take one region'
Economy
As economic despair mounts, Russian official admits the country has had enough of Putin's war on Ukraine. 'We can’t even take one region'
By Jason MaMay 3, 2026
16 hours ago
Sam Altman says the quiet part out loud, confirming some companies are ‘AI washing’ by blaming unrelated layoffs on the technology
AI
Sam Altman says the quiet part out loud, confirming some companies are ‘AI washing’ by blaming unrelated layoffs on the technology
By Sasha RogelbergMay 3, 2026
24 hours ago
I spent a decade selling homes to the ultra-wealthy. What I saw explains the housing market's nepo problem
Commentary
I spent a decade selling homes to the ultra-wealthy. What I saw explains the housing market's nepo problem
By Blake O'ShaughnessyMay 3, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.