Tenable Research reveals over 40 bn records were exposed globally in 2021

This is up nearly 78% over 2020. While healthcare and education are most-targeted industries worldwide, APAC region shows another picture, with tech industry and govts being largest victims

Cybersecurity, hacking, hackers,
Peerzada Abrar Bengaluru
3 min read Last Updated : Jan 20 2022 | 8:22 PM IST
According to research by Tenable, the cyber exposure company, at least 40,417,167,937 records were exposed worldwide in 2021, as calculated by Tenable’s Security Response Team’s analysis of 1,825 breach data incidents publicly disclosed between November 2020 and October 2021.

This is a considerable increase in the same period in 2020, which saw 730 publicly disclosed events with just over 22 billion records exposed. Of the 1,825 breaches analysed, 236 happened in APAC (Asia-Pacific), with at least 3,463,489,341 exposed records, representing 8.6 per cent of the global tally. This analysis is detailed in Tenable’s 2021 Threat Landscape Retrospective (TLR) report, and includes an overview of the attack path and vulnerabilities threat actors favour, and insights that will help organisations prepare to face the oncoming challenges in 2022.

“Throughout 2021, CERT-In issued advisories on how unpatched vulnerabilities in Microsoft Active Directory and web browsers were the major causes for cyberattacks such as ransomware among Indian organizations. Tenable’s research correlates to these trends as ransomware groups in APAC leveraged known unpatched vulnerabilities to perpetrate attacks. The report provides security leaders in India a glimpse into why outdated cybersecurity strategies need to change with the evolving threat landscape,” said Satnam Narang, Staff Research Engineer, Tenable. “In 2022, the intensified reliance on digital systems combined with the use of digital currencies will financially motivate attackers to ply their trade. It is important that security leaders understand how threat actors behaved in 2021, so they can formulate effective, proactive cybersecurity strategies in 2022 to raise the barrier of entry.”

By understanding threat actor behaviour, organisations can effectively prioritise security efforts to disrupt attack paths and protect critical systems and assets. Analysis of the events for this report found that many are readily mitigated by patching legacy vulnerabilities and addressing misconfigurations to help limit attack paths.

Ransomware had a monumental impact on organisations in 2021, responsible for approximately 38 per cent of all breaches, and 31 per cent of breaches in APAC.  In APAC, 10 per cent of breaches were the result of unsecured cloud databases, higher than the global average (6 per cent). Unpatched SSL VPNs continue to provide an ideal entry point for attackers to perform cyberespionage, exfiltrate sensitive and proprietary information as well as encrypt networks. Threat groups, particularly ransomware, have increasingly exploited vulnerabilities and misconfigurations in Active Directory.

The report said software libraries and network stacks used commonly amongst OT devices often introduce additional risk when security controls and code audits are not in place. Ransomware groups favoured physical supply chain disruption as a tactic to extort payment while cyberespionage campaigns exploited the software supply chain to access sensitive data. Whilst healthcare and education remain the most-targeted industries worldwide, APAC shows another picture, with the technology industry and governments being the two largest victims of breaches.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Cyber threatcyber securityTechnology

Next Story