From Past to Present: The Evolution of Data Breach Causes (2005–2025)

Amit Singh · LatIA · 2025

This review aims to analyze the changing causes of data breaches overtwo decades by synthesising evidence from various data breachinvestigation reports and regulatory filings. The methodology involvesexamining trends in threat actors, actions, and motives identified inreports such as the Verizon Data Breach Investigations Report (DBIR)series from 2008 to 2024, California Attorney General's reports, and thePrivacy Rights Clearinghouse. (1,2,3) The findings reveal an evolutionthrough distinct phases: an initial period (roughly 2008-2010)dominated by external breaches leveraging hacking and malware, asubsequent era (2011-2019) marked by the rise of sophisticatedcybercrime, including increased phishing and the emergence of definedincident patterns, and a more recent epoch (2020-2024) characterisedby a significant surge in ransomware attacks, exploitation ofsystemic vulnerabilities, and the convergence of financially motivatedand nation-state actors. Throughout these periods, human factors anderrors have consistently contributed to successful breaches. In conclusion, the landscape of databreaches have shifted from simpler external attacks to more complex anddisruptive campaigns, where human vulnerabilities remain a keyenabler, and the emerging landscape includes AI-driven threatsthat are being explored by both attackers and defenders, necessitatingcontinuous adaptation of defence strategies to address both traditionalweaknesses and novel AI-related risks.

Read the paper · More papers on PaperTik