The most common security issue for businesses probably isn't that big a surprise

phishing
(Image credit: stock.adobe.com © A. Stefanovska))

Cybersecurity researchers from ESET discovered that phishing has been the biggest incident type for companies of all shapes and sizes over the past four years.

Of all the incidents reported to the ICO's Data security incident trends report, phishing was by far the most-reported, with almost 2,700 incidents (2,694), roughly twice as many as second-placed unauthorized access. 

With just above 1,000 incidents, ransomware was the third most reported incident type, followed by verbal disclosure of personal data, and hardware/software misconfiguration.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Media hit hardest

In these past couple of years, the number of reported cybersecurity incidents soared, from 573 reports in Q1 2019, to 714 in Q2 2022. Most incidents reported - 737 - occurred in Q2 2020, which ESET speculates might have been due to Covid-19 restrictions forcing people to work remotely.

All sectors have been hit with cyberattacks, but the media industry seems to have had it worst. It had a relatively low number of data security incidents overall, ESET says, but it also had the highest share of cyber incidents. 

Retail and Manufacture had the highest number of cyber incidents overall at 943, followed by General Business (858) and Finance, Insurance and Credit (788).  

Analyzing cyber-incidents overall, ‘Data emailed to incorrect recipient’ is the most common one (3,719 since Q1 of 2019/20), followed by ‘Data posted or faxed to incorrect recipient’ and ‘Loss/theft of paperwork or data left in insecure location’ (2,806 and 1,931 incidents).

With attackers getting more proficient and using better tactics, it’s never been so important to verify authentic emails, says Jake Moore, Global Cybersecurity Advisor at ESET. 

“Criminals continue to use emails as their number one attack vector of choice in the hope that they can install malware or take over email accounts, masquerading as someone known to the victim to siphon off sensitive information. 

Having safeguards in place, such as a firewall, is a must, he continues.

"Organizations must ensure they are prepared for phishing emails by having robust controls in place such as spam filters and multi-factor authentication, however, user awareness and training remain the best defense against these increasing attacks.” 

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Phishing
Corporate executives are being increasingly targeted by AI phishing scams
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
person at a computer
Many workers are overconfident at spotting phishing attacks
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC