Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

IBM X-Force Report: Fewer Records Breached in 2017

cyber7-900px.jpg
April 4, 2018

The 2018 IBM X-Force Threat Intelligence Index has found the number of records breached dropped nearly 25 percent in 2017, as cybercriminals shifted their focus on launching ransomware and destructive attacks that lock or destruct data unless the victim pays a ransom.

Last year, more than 2.9 billion records were reported breached, down from 4 billion disclosed in 2016. While the number of records breached was still significant, ransomware reigned in 2017 as attacks such as WannaCry, NotPetya, and Bad Rabbit caused chaos across industries without contributing to the total number of compromised records reported.

Other key findings include:

  • A historic 424 percent jump in breaches related to misconfigured cloud infrastructure, largely due to human error;
  • For the second year in a row, the Financial Services industry suffered the most cyberattacks against it, accounting for 27 percent of attacks across all industries.

The IBM X-Force Threat Intelligence Index is comprised of insights and observations from data analyzed via hundreds of millions of protected endpoints and servers across nearly 100 countries. IBM X-Force runs thousands of spam traps around the world and monitors tens of millions of spam and phishing attacks daily while analyzing billions of web pages and images to detect fraudulent activity and brand abuse.

"While breached records are a good indication of cybercriminal activity, it doesn't tell the full story of 2017," said Wendi Whitmore, Global Lead, IBM X-Force Incident Response and Intelligence Services (IRIS). "Last year, there was a clear focus by criminals to lock or delete data, not just steal it, through ransomware attacks. These attacks are not quantified by records breached, but have proven to be just as, if not more, costly to organizations than a traditional data breach. The ability to anticipate these attacks and be prepared will be critical as cybercriminals will continue to evolve their tactics to what proves most lucrative."

Ransomware Attacks Put Pressure on Incident Response
Ransomware and destructive attacks, such as WannaCry, NotPetya, and Bad Rabbit, not only grabbed headlines in 2017, but also brought major organizations to a halt as cybercriminals took over and locked critical infrastructure in healthcare, transportation, and logistics, among others. Overall, ransomware incidents have cost organizations more than $8 billion1 in 2017 as cybercriminals launched debilitating attacks that were focused on locking critical data instead of compromising stored records. 

This trend puts increased pressure on organizations to be properly prepared with incident response strategies to limit the impact of an attack. An IBM Security study last year found that a slow response can impact the cost of an attack as incidents that took longer than 30 days to contain cost $1 million more than those contained within 30 days.

Human Error Remains a Weak Link
In 2017, cybercriminals continued to take advantage of human error and mistakes in infrastructure configurations to launch attacks. In fact, the report shows that inadvertent activity such as misconfigured cloud infrastructure was responsible for the exposure of nearly 70 percent of compromised records tracked by IBM X-Force in 2017. The report shows that there is a growing awareness among cybercriminals of the existence of misconfigured cloud servers. For example, 2017 saw an incredible 424 percent increase in records breached through misconfigurations in cloud servers.

Beyond misconfigured cloud, individuals lured via phishing attacks represented one-third of inadvertent activity that led to a security event in 2017. This includes users clicking on a link or opening an attachment laced with malicious code, usually shared via a spam campaign launched by cybercriminals. The report found that in 2017, cybercriminals relied heavily on the Necurs botnet to distribute millions of spam messages over a span of just a few days in some instances. For example, over a two-day period in August, IBM X-Force research observed four separate Necurs campaigns spamming 22 million emails.

Cybercriminals Find Success Targeting Financial Services Customers
In years past, Financial Services has been the most targeted industry by cybercriminals. In 2017, it fell to the third-most attacked (17 percent) – behind Information & Communications Technology (33 percent) and Manufacturing (18 percent) – yet saw the most security incidents (27 percent) – those requiring further investigation – compared to other industries.

While Financial Services organizations have invested heavily in cybersecurity technologies to protect organizations, cybercriminals focused on leveraging banking Trojans specifically targeting consumers and end users across the industry.

For example, the IBM X-Force Threat Intelligence Index report found that in 2017, the Gozi banking Trojan and its variants were the most prevalently used malware against the Financial Services industry. The Gozi malware specifically targets customers as it takes over initial banking login screens with prompts for consumers to enter other personal information that is then shared directly with the attacker.

The use of Gozi, considered to be run by a skilled cybercrime operation, highlights how organized crime is overtaking all other classes of actors in the financial malware-facilitated fraud scene.

https://www.ibm.com/account/reg/us-en/signup?formid=urx-31271

KEYWORDS: cyber security cybercriminal data ransomware

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

The 2025 Security Benchmark Report

The 2025 Security Benchmark Report

Man in mask by LED light

A Real-Life Horror Story: When AI Ghouls Move Faster Than Defenses Can React

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

University lecture

1.2M Individuals’ Data Stolen In University Hacking

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 19, 2025

From Chaos to Clarity: How Real-Time, Location-Aware Intelligence Strengthens Security Programs

When disruptive events hit, security teams must move fast to protect people, executives, and assets. Every minute of delay can mean operational losses, safety risks, and reputational impact. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • healthcare-cybersecurity-freepik1170x658.jpg

    342m medical records breached since 2009

    See More
  • The Cloud Is NOT a Product

    Data Breach Report: Cloud Backup Provider Exposes More than 135 Million Customer Records

    See More
  • Dispelling the Dangerous Myth of Data Breach Fatigue; cyber security news

    Packet capture and analysis: The force multiplier in the cybersecurity battle

    See More

Related Products

See More Products
  • Hospitality Security: Managing Security in Today's Hotel, Lodging, Entertainment, and Tourism Environment

  • Physical Layer Security in Wireless Communications

See More Products

Events

View AllSubmit An Event
  • October 8, 2025

    How to Support the Security Guard Force in Challenging Environments

    ON DEMAND: In this webinar, Brian Howell, Vice President, Global Head of Security at ADM, shares how his organization fosters trust among their security guard force to improve security posture and the safety of sites, processes and the officers themselves.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing