News

  • Report

Share

Facebook Twitter linkedin
2025.03.31

In 2024, a security incident will occur at a company or local government approximately once every three days. The number of personal information leaks will be approximately 21.64 million per year, with the industry with the most incidents being "manufacturing" - "Survey Report on Corporate Security Incidents 2024" announced -

Cyber Cyber Security Cloud, Inc., Inc. (Headquarters: Shinagawa-ku, Tokyo; Representative Director, President and CEO: Toshihiro Koike; hereinafter referred to as "the Company"), a global security manufacturer, is releasing the "2024 Corporate Security Incident Survey Report" based on personal information leak cases by companies and organizations announced between January 1, 2024 and December 31, 2024.

[Survey Summary]

  1. The number of security incidents in 2024 will be 121. An incident will occur in a company or organization approximately once every three days.
  2. The industry with the most security incidents was "manufacturing," accounting for about a quarter of the total.
  3. The number one cause of security incidents was "unauthorized access," followed by "human error" and "ransomware attacks."
  4. The number of personal information leaks per year was approximately 21.64 million. The industry with the most personal information leaks was the "wholesale and retail" industry.

 

[Survey results]
Our "Corporate Security Incident Survey Report 2024" is an annual report that compiles the latest figures and trends regarding security incidents based on incident data on personal information leaks made public by corporations and organizations.

In recent years, many companies in Japan, regardless of their size, have been suffering from increasing damage from cyber attacks, and the overall number of attacks is also on the rise, with the number of cyber attack-related communications (※ 1) confirmed through darknet observations by the National Institute of Information and Communications Technology (NICT), a large-scale cyber attack observation network, reaching an all-time high in 2023.
At the same time, each company needs to operate its business while striking a balance between the usability of its services (i.e. the degree to which the service should be easy to use) and the security level (i.e. how robust the security should be).With the number of attacks expected to continue to increase, the key issue will be where to draw the line of security defense while ensuring that the usability of the service is maintained.
Details of the report are as follows:

 

1. The number of security incidents in 2024 will be 121. An incident will occur at a company or organization approximately once every three days.
The total number of security incidents at companies and organizations from January 1 to December 31, 2024 was 121. This means that a security incident involving the leak of personal information occurs approximately once every three days, even if only the publicly announced incidents are included.

 

2. The industry with the most security incidents was "manufacturing," accounting for about a quarter of the total.
Looking at security incidents in 2024 by industry, manufacturing will rank first, accounting for 24.8%, or about a quarter of the total, followed by wholesale and retail (14.9%), services (11.6%), education and learning support (11.5%), and information and communications (10.8%).
The reason behind the high percentage of "manufacturing" and "wholesale and retail" industries is the increased risk to the entire supply chain due to advances in digitalization. In these industries, it is necessary to strengthen security measures for business systems and IoT devices.

 

3. The number one cause of security incidents was "unauthorized access," followed by "human error" and "ransomware attacks."
Looking at the main causes of security incidents, "unauthorized access" accounted for 61.1% of the total, followed by "human error (27.3%)," "ransomware infection (6.6%)," "support fraud (2.5%)," and "system malfunction (1.7%)."
The result that "unauthorized access" accounted for 61.1% of the causes shows that the number of cyber attacks is increasing and that the methods used are still becoming more sophisticated. Companies in particular are required to take measures not only to prevent intrusions but also to quickly detect and respond to them.

 

4. The number of personal information leaks per year was approximately 21.64 million. The industry with the most personal information leaks was the "wholesale and retail" industry.
Based on publicly available data, the number of personal information leaks and credit card information leaks during the year was 21,646,108, and the number of credit card information leaks was 272,237.
Looking at the cases by industry, the industries with the highest number of personal information leaks were 1st place "Wholesale and Retail (8,480,792 cases)" followed by "Manufacturing (8,403,389 cases)" and "Information and Communications (1,448,957 cases)." The industries with the highest number of credit card information leaks were 1st place "Manufacturing (78,513 cases)" followed by "Wholesale and Retail (75,483 cases)" and "Services (69,640 cases)."
"Wholesale and retail" and "manufacturing" rank high in the number of personal information leaks, showing that the large amounts of personal data they handle are the target of many cyber attacks. In addition, the "Information and communications" industry, which ranked third, shows that there is an urgent need to strengthen the security of online transactions and payment systems.

*1: Ministry of Internal Affairs and Communications "FY2024 Information and Communications White Paper"

■Comment from Cyber Security Cloud Representative Director, CTO Yoji Watanabe
As can be seen from the results of this report, security incidents at companies and local governments are expected to increase in 2024, with "unauthorized access" being the main cause. As industries such as manufacturing, wholesale and retail have suffered many losses, there is a demand to strengthen security measures throughout the supply chain as digitalization advances.
In addition, the figure of approximately 21.64 million personal information leaks per year indicates that it is an urgent issue for companies to reconsider how they manage information. In particular, cyberattack methods are becoming more sophisticated every year, with a notable increase in targeted attacks and ransomware attacks. In response to this situation, companies need to develop security strategies that enable not only "defense" but also "rapid detection and response."
As a company specializing in cybersecurity, we will continue to analyze the latest threat trends and support corporate security measures. We hope that this report will help many companies strengthen their security measures.

[Survey Overview]
- Survey period: January 1, 2024 to December 31, 2024
- Survey subjects: Security incidents at corporations and organizations announced during the above period (121 cases)

 

About Cyber Security Cloud, Inc.
Company name: Cyber Security Cloud, Inc.
Address: 13F JR Tokyu Meguro Building, 3-1-1 Kami-Osaki, Shinagawa-ku, Tokyo 141-0021
Representative: Representative Director, President and CEO Toshihiro Koike
Established: August 2010
URL: https://www.cscloud.co.jp
With the mission of "creating a cyberspace that people all over the world can use safely and securely," we are a Japanese security manufacturer that provides vulnerability information collection and management tools and fully managed security services for cloud environments, centered on web application security services that make full use of the world's leading cyber threat intelligence. As one of the global companies in cybersecurity, we will contribute to solving social issues related to cybersecurity and provide added value to society.