The 2024 Verizon Data Breach Investigation Report (DBIR) paints a troubling picture of the current cybersecurity landscape, marked by the increasing exploitation of vulnerabilities as one of the main data breach gateways, the shift to extortion and the median loss associated with ransomware and extortion almost doubled. The report's authors call for a collective response from the whole cybersecurity community to curb the threats.

For this year's report, Verizon researchers analyzed 30,458 real-world security incidents, including a record 10,626 confirmed data breaches across 94 countries.

The report found a “substantial growth” of attacks involving vulnerability exploitation as the critical path to initiate a breach, compared to previous years. “It almost tripled (180% increase) from last year, which will come as no surprise to anyone who has been following the effect of MOVEit and similar zero-day vulnerabilities,” researchers wrote.

Alex Pinto, the report's lead author and associate director of threat intelligence at Verizon Business, highlighted the severity of the situation. “This is really one of our biggest concerns from the results of this report and certainly the one we're trying to underline and bring to people's attention, because they might need to rethink or reprioritize some of their risk-based decisions of their security program.”

Pinto noted that vulnerability exploitation-caused attacks accounted for about 15% of all data breaches, up from about 5% last year.

He added the increase in ransomware and extortion-based attacks is one of the main drivers behind the surge. “There were a few ransomware groups that became very good in obtaining zero-day vulnerabilities and leveraging zero-day vulnerabilities to get into organizations.”

Additionally, the vulnerability in the MOVEit file transfer software discovered last year became “the poster child,” Pinto said.

Verizon researchers identified 1,567 breach notifications that related to MOVEit based on the breach description and the timing of the breach itself. Other reports found the Cl0p ransomware group had compromised more than 8,000 global organizations from a handful of exploited zero-day vulnerabilities.

Verizon researchers call for community and industry-wide action on vulnerability exploitation

Amidst the surge in data breaches involving vulnerability exploitation, Pinto pointed out a significant gap: While it takes companies that are actively fixing the vulnerability problems an average of 55 days to patch 50% of critical vulnerabilities on their estate, the median time for these vulnerabilities to be exploited by cybercriminals is as little as five days.

He emphasized the need for organizations to prioritize which vulnerabilities to patch first and create a good emergency program. Additionally, he suggested a focus on reducing the attack surface, while making sure security is a top-level due diligence requirement in the vendor selection process.

Pinto said the vulnerability exploitation problem is not slowing down and just patching is not enough.

“This is not something that one company is going to solve. This has to be a kind of an industry or community push to make sure that we try to push those numbers of vulnerabilities being created down,” he added. “The volume seems to be outstripping our capacity to keep our environment safe.”

Ransomware remains a top threat

This year's DBIR found that about one-third (32%) of all data breaches involved ransomware or other extortion techniques, with pure extortion increasing to 9% of all breaches.

The shift toward these newer techniques like extortion resulted in a slight decline in ransomware to 23%, but it remains a top threat across 92% of industries, according to the report.

DBIR also quoted the FBI’s Internet Crime Complaint Center (IC3) ransomware complaint data, which showed the median loss associated with the combination of ransomware and other extortion breaches have been $46,000, ranging between $3 and $1,141,467 for 95% of the cases.

Verizon researchers also found from ransomware negotiation data contributors that the median ratio of initially requested ransom and company revenue is 1.34%, fluctuating between 0.13% and 8.30% for 80% of the cases.