During the second quarter of 2025, data breaches exposed more than ** million records worldwide. Since the first quarter of 2020, the highest number of data records were exposed in the third quarter of ****, more than *** billion data sets. Data breaches remain among the biggest concerns of company leaders worldwide. The most common causes of sensitive information loss were operating system vulnerabilities on endpoint devices. Which industries see the most data breaches? Meanwhile, certain conditions make some industry sectors more prone to data breaches than others. According to the latest observations, the public administration experienced the highest number of data breaches between 2021 and 2022. The industry saw *** reported data breach incidents with confirmed data loss. The second were financial institutions, with *** data breach cases, followed by healthcare providers. Data breach cost Data breach incidents have various consequences, the most common impact being financial losses and business disruptions. As of 2023, the average data breach cost across businesses worldwide was **** million U.S. dollars. Meanwhile, a leaked data record cost about *** U.S. dollars. The United States saw the highest average breach cost globally, at **** million U.S. dollars.
The government has surveyed UK businesses, charities and educational institutions to find out how they approach cyber security and gain insight into the cyber security issues they face. The research informs government policy on cyber security and how government works with industry to build a prosperous and resilient digital UK.
19 April 2023
Respondents were asked about their approach to cyber security and any breaches or attacks over the 12 months before the interview. Main survey interviews took place between October 2022 and January 2023. Qualitative follow up interviews took place in December 2022 and January 2023.
UK
The survey is part of the government’s National Cyber Strategy 2002.
There is a wide range of free government cyber security guidance and information for businesses, including details of free online training and support.
The survey was carried out by Ipsos UK. The report has been produced by Ipsos on behalf of the Department for Science, Innovation and Technology.
This release is published in accordance with the Code of Practice for Statistics (2018), as produced by the UK Statistics Authority. The UKSA has the overall objective of promoting and safeguarding the production and publication of official statistics that serve the public good. It monitors and reports on all official statistics, and promotes good practice in this area.
The document above contains a list of ministers and officials who have received privileged early access to this release. In line with best practice, the list has been kept to a minimum and those given access for briefing purposes had a maximum of 24 hours.
The Lead Analyst for this release is Emma Johns. For any queries please contact cybersurveys@dsit.gov.uk.
For media enquiries only, please contact the press office on 020 7215 1000.
The largest reported data leakage as of January 2025 was the Cam4 data breach in March 2020, which exposed more than 10 billion data records. The second-largest data breach in history so far, the Yahoo data breach, occurred in 2013. The company initially reported about one billion exposed data records, but after an investigation, the company updated the number, revealing that three billion accounts were affected. The National Public Data Breach was announced in August 2024. The incident became public when personally identifiable information of individuals became available for sale on the dark web. Overall, the security professionals estimate the leakage of nearly three billion personal records. The next significant data leakage was the March 2018 security breach of India's national ID database, Aadhaar, with over 1.1 billion records exposed. This included biometric information such as identification numbers and fingerprint scans, which could be used to open bank accounts and receive financial aid, among other government services.
Cybercrime - the dark side of digitalization As the world continues its journey into the digital age, corporations and governments across the globe have been increasing their reliance on technology to collect, analyze and store personal data. This, in turn, has led to a rise in the number of cyber crimes, ranging from minor breaches to global-scale attacks impacting billions of users – such as in the case of Yahoo. Within the U.S. alone, 1802 cases of data compromise were reported in 2022. This was a marked increase from the 447 cases reported a decade prior. The high price of data protection As of 2022, the average cost of a single data breach across all industries worldwide stood at around 4.35 million U.S. dollars. This was found to be most costly in the healthcare sector, with each leak reported to have cost the affected party a hefty 10.1 million U.S. dollars. The financial segment followed closely behind. Here, each breach resulted in a loss of approximately 6 million U.S. dollars - 1.5 million more than the global average.
In 2024, the number of data compromises in the United States stood at 3,158 cases. Meanwhile, over 1.35 billion individuals were affected in the same year by data compromises, including data breaches, leakage, and exposure. While these are three different events, they have one thing in common. As a result of all three incidents, the sensitive data is accessed by an unauthorized threat actor. Industries most vulnerable to data breaches Some industry sectors usually see more significant cases of private data violations than others. This is determined by the type and volume of the personal information organizations of these sectors store. In 2024 the financial services, healthcare, and professional services were the three industry sectors that recorded most data breaches. Overall, the number of healthcare data breaches in some industry sectors in the United States has gradually increased within the past few years. However, some sectors saw decrease. Largest data exposures worldwide In 2020, an adult streaming website, CAM4, experienced a leakage of nearly 11 billion records. This, by far, is the most extensive reported data leakage. This case, though, is unique because cyber security researchers found the vulnerability before the cyber criminals. The second-largest data breach is the Yahoo data breach, dating back to 2013. The company first reported about one billion exposed records, then later, in 2017, came up with an updated number of leaked records, which was three billion. In March 2018, the third biggest data breach happened, involving India’s national identification database Aadhaar. As a result of this incident, over 1.1 billion records were exposed.
As of January 2025, the most significant data privacy violation fine worldwide was for social media giant Meta. In May 2023, the Data Protection Commission (DPC) of Ireland decided to fine the company with 1.2 billion euros or 1.3 billion U.S. dollars. The Chinese vehicle-for rent company Didi Global ranked second. In July 2022, China's data privacy regulator fined the company 8.026 billion Chinese yuan, or 1.19 billion U.S. dollars. The 2021 Amazon fine issued by Luxembourg's data privacy regulation authorities was 877 million U.S. dollars and was the third-biggest data breach fine as of the measured month. The 2019 fine of 575 million U.S. dollars to Equifax followed. In this incident, because of unpatched vulnerabilities, nearly 150 million people were affected, which caused the American consumer credit reporting agency to pay at least 575 million U.S. dollars.
In 2023, around 96.75 million e-mail accounts breached originated from the United States, making it the country with the most significant number of user account exposures in the examined year. Russia ranked second, with over 78 million accounts breached, while the France followed, with approximately 10.5 million breached accounts.
Between November 2023 and October 2024, organizations in the manufacturing sector worldwide saw around 818 incidents of data breaches caused by hacking. The healthcare industry ranked second, with 745 data breaches in the measured period. Furthermore, hacking caused 564 data breach incidents in the professional sector.
Between March 2024 and February 2025, the highest average cost of a data breach, nearly **** million U.S. dollars, was detected in the healthcare industry. The financial sector ranked second, with **** million U.S. dollars on average per breach. The global average data breach cost in the measured period was **** million U.S. dollars. Data breaches in the public sector cost relatively lower, an average of **** million U.S. dollars during the measured period.
Attribution 4.0 (CC BY 4.0)https://creativecommons.org/licenses/by/4.0/
License information was derived automatically
The AWSD is a global compilation of reports on major security incidents involving deliberate acts of violence affecting aid workers. This dataset includes all incidents up to 2022, which have gone through a comprehensive verification process.
As of February 2025, the United States ranked first by the average cost of a data breach, ***** million U.S. dollars. The average cost of data breaches in the Middle East was **** million U.S. dollars. Benelux followed in the ranking, with **** million U.S. dollars. In the measured period, the global average data breach cost was **** million U.S. dollars. Phishing scams in the U.S. Breached data often ends up in the hands of threat actors who use it for malicious purposes, including online scams. Phishing continues to be a major threat in North America, particularly on smartphones. In the second quarter of 2023, the region recorded the highest number of phishing and malicious attack attempts globally. The United States was particularly affected, with ** percent of U.S. citizens reporting being targeted by scam texts, e-mails, and calls on a daily basis. Additionally, phishing and spoofing were the most common types of cybercrime, impacting *** thousand individuals in 2023. These attacks led to financial losses, with U.S. victims reporting nearly ** billion U.S. dollars in damages throughout the year. U.S. users and data privacy Despite only ** percent of internet users in the United States being highly knowledgeable about data privacy and cybersecurity, a significant portion of users demonstrated caution and awareness in protecting their information. In fact, over half of surveyed U.S. users reported being somewhat confident in knowing the right steps to take in the event of a cyberattack. Furthermore, ** percent of U.S. users actively decline cookies on websites, reflecting their increasing concern for data protection. Many respondents also take additional steps to safeguard their digital privacy, such as limiting or avoiding clicking on ads as well as not answering phone calls due to cybersecurity risks.
This page lists ad-hoc statistics released during the period January - March. These are additional analyses not included in any of the Department for Culture, Media and Sport’s standard publications.
Responsibility for policy areas including Digital and Tech Policy, Cyber Security, Data, and Digital Infrastructure now (since February 2023) sit with the Department for Science, Innovation and Technology. However, additional analyses for these sectors are also currently included here.
If you would like any further information please contact evidence@dcms.gov.uk
This is an ad-hoc release that provides an estimate of total employment (number of filled jobs) in the DCMS Sectors for each calendar year from 2011 to 2021. The estimates provide the overall level of employment, and breakdowns by the following characteristics:
These employment statistics were produced to meet user demand for total DCMS Sector estimates without the Digital Sector and Telecoms included, as responsibility for these policy areas now sit with the Department for Science, Innovation and Technology (DSIT).
The DCMS Sector total reported here includes Civil Society, Creative industries, Cultural sector, Sport and - where applicable - Tourism. Due to this specification, users should not attempt to make comparisons to previously published DCMS totals.
<p class="gem-c-attachment_metadata"><span class="gem-c-attachment_attribute"><abbr title="OpenDocument Spreadsheet" class="gem-c-attachment_abbr">ODS</abbr></span>, <span class="gem-c-attachment_attribute">57.9 KB</span></p>
<p class="gem-c-attachment_metadata">
This file is in an <a href="https://www.gov.uk/guidance/using-open-document-formats-odf-in-your-organisation" target="_self" class="govuk-link">OpenDocument</a> format
This is an ad-hoc release that provides figures among micro and small businesses in the North West of England, using the Cyber Security Breaches Survey 2022 (CSBS 2022). This is an abridged set of specific findings from the CSBS 2022, a telephone-based quantitative and qualitative study of UK businesses, charities and educational institutions to find out how they approach cyber security and gain insight into the cyber security issues they face.
In 2022, most healthcare data breaches in the United States happened as a result of hacking or IT-related incidents. The number of such cases was 555 in the examined year. The next-most common cause for data breaches was unauthorized access or disclosure, detected in 113 cases. Loss and theft of data were less common causes of data breaches in the U.S. healthcare system in 2022. Overall, in 2022, there were 707 data breaches of over 500 records in the U.S. healthcare industry.
Open Government Licence - Canada 2.0https://open.canada.ca/en/open-government-licence-canada
License information was derived automatically
This dataset provides a breakdown of requests to the Cyber Centre Contact Centre by client type and by contact type.
Open Government Licence - Canada 2.0https://open.canada.ca/en/open-government-licence-canada
License information was derived automatically
This dataset provides an overview of the courses offered by the Canadian Centre for Cyber Security, the duration, course fee, number of sessions offered, and total number of participants for the given fiscal year.
https://www.cognitivemarketresearch.com/privacy-policyhttps://www.cognitivemarketresearch.com/privacy-policy
According to Cognitive Market Research, the global Zero Trust Security market size will be USD 37621.8 million in 2025. It will expand at a compound annual growth rate (CAGR) of 17.20% from 2025 to 2033.
North America held the major market share for more than 40% of the global revenue with a market size of USD 13920.07 million in 2025 and will grow at a compound annual growth rate (CAGR) of 15.0% from 2025 to 2033.
Europe accounted for a market share of over 30% of the global revenue with a market size of USD 10910.32 million.
APAC held a market share of around 23% of the global revenue with a market size of USD 9029.23 million in 2025 and will grow at a compound annual growth rate (CAGR) of 19.2% from 2025 to 2033.
South America has a market share of more than 5% of the global revenue with a market size of USD 1429.63 million in 2025 and will grow at a compound annual growth rate (CAGR) of 16.2% from 2025 to 2033.
Middle East had a market share of around 2% of the global revenue and was estimated at a market size of USD 1504.87 million in 2025 and will grow at a compound annual growth rate (CAGR) of 16.5% from 2025 to 2033.
Africa had a market share of around 1% of the global revenue and was estimated at a market size of USD 827.68 million in 2025 and will grow at a compound annual growth rate (CAGR) of 16.9% from 2025 to 2033.
The network security segment is expected to have the highest CAGR between 2025 and 2033
Market Dynamics of Zero Trust Security Market
Key Drivers for Zero Trust Security Market
Increasing Prevalence Of Cloud Computing
Cloud computing is expected to drive the growth of the zero-trust security market. Cloud computing is a technology paradigm that involves delivering various computing services via the internet (the cloud), such as servers, storage, databases, networking, software, analytics, and intelligence, in order to provide faster innovation, flexible resources, and economies of scale. Cloud computing boosts the zero-trust security market by providing users with a secure, consistent, and seamless experience regardless of where they are or what applications they want to use. For instance, in June 2022, Cloudwards, a Germany-based company that publishes articles on cloud technology, estimated that the total value of the cloud computing market was $371.4 billion in 2020 and will rise to $832.1 billion in 2025. As a result, the 'zero trust' security market will grow as cloud computing becomes more prevalent
https://www.cloudwards.net/cloud-computing-statistics/
Escalating Data Breaches Fueling Zero Trust Adoption
The growing number of data breaches and cyber threats are expected to fuel the growth of the zero-trust security market. Cyber data breaches are identified as gaining unauthorized access to a computer system or network to obtain private, sensitive, or confidential personal and financial information from customers or users. Due to numerous planned breaches, there is a need to implement zero trust security solutions in order to create a flexible and adaptive network security infrastructure that removes trust from network access and requires additional user authentication. For instance, in September 2023, AAG, a provider of IT support services, reported that 39% of UK businesses had experienced a cyber-attack in 2022. Furthermore, in the first half of 2022, cybercrime affected 53.35 million Americans. As a result, the rise in data breaches and cyber threats will fuel the expansion of the 'zero trust' security market.
Restraint Factor for the Zero Trust Security Market
Complex implementation Limit Market Growth
Complex implementation is a major impediment to the expansion of the Zero Trust Security Market. Organizations frequently struggle to transition from traditional security models to Zero Trust models due to the complexity of their architecture. The need for comprehensive identity verification, continuous monitoring, and network segmentation necessitates significant changes to current systems and processes. Such complexity can increase deployment time, cost, and the need for specialized knowledge, discouraging some organizations from fully implementing Zero Trust architecture. As a result, the perceived implementation difficulty slows market adoption and limits overall potential growth. Introduction of the Zero Trust Security Market
Zero trust security (ZTS) is a cybersecurity framework based on the princi...
Open Government Licence - Canada 2.0https://open.canada.ca/en/open-government-licence-canada
License information was derived automatically
This dataset provides a breakdown of requests to the Cyber Centre Contact Centre by client type and by contact type.
Open Government Licence - Canada 2.0https://open.canada.ca/en/open-government-licence-canada
License information was derived automatically
This dataset provides an overview of the courses offered by the Canadian Centre for Cyber Security, the duration, course fee, number of sessions offered, and total number of participants for the given fiscal year.
The global Security as a Service (SECaaS) market was valued approximately 16.9.2 billion U.S. dollars in 2022 and expected to exceed 20 billion U.S. dollars in 2023. The SECaaS market is forecast to continue growing throughout the coming years and projected to reach more than 81 billion U.S. dollars by 2032. As businesses continuously migrate their data to the cloud and improve their information technology infrastructure, the related threats to their data also increase. For this reason, security solutions are high in demand to ensure data security.
Between November 2022 and October 2023, over 10 thousand organizations worldwide experienced data breaches that included confirmed data loss. Among selected industries, firms in the education and healthcare sector saw the highest number of data violations. Regarding organization size, larger ones were victimized by data breaches more than smaller companies.
During the second quarter of 2025, data breaches exposed more than ** million records worldwide. Since the first quarter of 2020, the highest number of data records were exposed in the third quarter of ****, more than *** billion data sets. Data breaches remain among the biggest concerns of company leaders worldwide. The most common causes of sensitive information loss were operating system vulnerabilities on endpoint devices. Which industries see the most data breaches? Meanwhile, certain conditions make some industry sectors more prone to data breaches than others. According to the latest observations, the public administration experienced the highest number of data breaches between 2021 and 2022. The industry saw *** reported data breach incidents with confirmed data loss. The second were financial institutions, with *** data breach cases, followed by healthcare providers. Data breach cost Data breach incidents have various consequences, the most common impact being financial losses and business disruptions. As of 2023, the average data breach cost across businesses worldwide was **** million U.S. dollars. Meanwhile, a leaked data record cost about *** U.S. dollars. The United States saw the highest average breach cost globally, at **** million U.S. dollars.