Research Article

Analyzing Global Cybersecurity Breach Data: A Secondary Data Study of Trends and Patterns

by  Rabia Nazir
journal cover
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 187 - Issue 126
Published: July 2026
Authors: Rabia Nazir
10.5120/ijca11629c179277
PDF

Rabia Nazir . Analyzing Global Cybersecurity Breach Data: A Secondary Data Study of Trends and Patterns. International Journal of Computer Applications. 187, 126 (July 2026), 74-84. DOI=10.5120/ijca11629c179277

                        @article{ 10.5120/ijca11629c179277,
                        author  = { Rabia Nazir },
                        title   = { Analyzing Global Cybersecurity Breach Data: A Secondary Data Study of Trends and Patterns },
                        journal = { International Journal of Computer Applications },
                        year    = { 2026 },
                        volume  = { 187 },
                        number  = { 126 },
                        pages   = { 74-84 },
                        doi     = { 10.5120/ijca11629c179277 },
                        publisher = { Foundation of Computer Science (FCS), NY, USA }
                        }
                        %0 Journal Article
                        %D 2026
                        %A Rabia Nazir
                        %T Analyzing Global Cybersecurity Breach Data: A Secondary Data Study of Trends and Patterns%T 
                        %J International Journal of Computer Applications
                        %V 187
                        %N 126
                        %P 74-84
                        %R 10.5120/ijca11629c179277
                        %I Foundation of Computer Science (FCS), NY, USA
Abstract

The cybersecurity situation in the world is becoming more dangerous, and the number of data breaches grows and grows. The paper is a secondary data analysis research of publicly available breach archives, such as Privacy Rights Clearinghouse, HaveIBeenPwned, and Kaggle datasets. The study was performed using a quantitative, descriptive research design with the help of the R programming language and tidyverse packages to perform data wrangling, statistical analysis, and visualization. Results indicate that breaches reported have doubled during this time, with 2023 showing the highest number of 59 million breached records due to a mega-breach in the technology sector. The most targeted sectors included healthcare and government sectors, with 22.2% of the incidents each, as this data is valuable. Hacking was the most common attack (44.4%), with ransomware and phishing (22.2% each). This study highlights the trends and patterns of global cybersecurity activities between 2021 and 2024. In this paper, the Healthcare and Government Services sectors are overrepresented. It is typical of the high value of the data that they comprise the sensitivity of their operations to interference. The results prove the ongoing incomparability of phishing as an initial access technique related to attack vectors. Moreover, it founded the drastic and recent escalation of ransomware as a major danger.

References
  • D. Molitor, W. Raghupathi, A. Saharia, and V. Raghupathi, "Exploring Key Issues in Cybersecurity Data Breaches: Analyzing Data Breach Litigation with ML-Based Text Analytics," Information, vol. 14, no. 11, p. 600, 2023.
  • SentinelOne, "Cyber Security Statistics for 2025 (and Beyond)," 2025. [Online]. Available: https://www.sentinelone.com/cybersecurity-101/cybersecurity/cyber-security-statistics/
  • AAG IT, "The Latest Cyber Crime Statistics," 2022. [Online]. Available: https://aag-it.com/the-latest-cyber-crime-statistics/
  • IBM, "Cost of a Data Breach 2024: Financial Industry," 2024. [Online]. Available: https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry
  • CyberPilot, "Key Insights from the 2024 Verizon Data Breach Investigations Report," 2024. [Online]. Available: https://www.cyberpilot.io/cyberpilot-blog/key-insights-from-the-2024-verizon-data-breach-investigations-report
  • Secureframe, "45+ Data Breach Statistics for 2026 [Updated]," 2025. [Online]. Available: https://secureframe.com/blog/data-breach-statistics/
  • Federal Trade Commission, "Data Breach Response: A Guide for Business," 2023. [Online]. Available: https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business
  • Council on Economic Advisers, "The Cost of Malicious Cyber Activity to the U.S. Economy," 2018. [Online]. Available: https://trumpwhitehouse.archives.gov/wp-content/uploads/2018/02/The-Cost-of-Malicious-Cyber-Activity-to-the-U.S.-Economy.pdf
  • European Union Agency for Cybersecurity (ENISA), "ENISA Threat Landscape 2024," 2024. [Online]. Available: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024
  • B. Madnick, K. Huang, and S. Madnick, "The Evolution of Global Cybersecurity Norms in the Digital Age: A Longitudinal Study of the Cybersecurity Norm Development Process," Information Security Journal: A Global Perspective, vol. 33, no. 3, pp. 204–225, 2024.
  • L. Hafiz and T. Hidayat, "Unveiling the Cybercrime Ecosystem: Impact of Ransomware-as-a-Service (RaaS) in Indonesia," International Journal of Science Education and Cultural Studies, vol. 4, no. 1, pp. 11–21, 2025.
  • S. Berrios, D. Leiva, B. Olivares, H. Allende-Cid, and P. Hermosilla, "Systematic Review: Malware Detection and Classification in Cybersecurity," Applied Sciences, vol. 15, no. 14, p. 7747, 2025.
  • H. Kryshtal, M. Samofalova, L. Sakhno, V. Fedyna, T. Mokiienko, and M. Yermolaieva, "Cyber Risks in the Financial and Banking System: Analysis of Direct and Systemic Losses," 2025.
  • S. Navani and G. T. Cirella, "Cybercrimes in the Cryptocurrency Domain: Identifying Types, Understanding Motives and Techniques, and Exploring Future Directions for Technology and Regulation," Journal of Geography, Politics and Society, vol. 14, no. 2, pp. 1–22, 2024.
  • S. Gallagher, B. Gelman, S. Taoufiq, T. Vörös, Y. Lee, A. Kyadige, and S. Bergeron, "Phishing and Social Engineering in the Age of LLMs," in Large Language Models in Cybersecurity: Threats, Exposure and Mitigation, Cham, Switzerland: Springer Nature, 2024, pp. 81–86.
  • R. A. Grimes, Fighting Phishing: Everything You Can Do to Fight Social Engineering and Phishing. Hoboken, NJ, USA: John Wiley & Sons, 2024.
  • F. William, Machine Learning, Fuzzy Logic and Zero Trust-Based Quishing Prevention Solution for Android Smartphones. Rochester, NY, USA: Rochester Institute of Technology, 2024.
  • CrowdStrike, "What Is a Phishing Attack?" [Online]. Available: https://www.crowdstrike.com/en-us/cybersecurity-101/social-engineering/phishing-attack/
  • S. N. Vulpe, R. Rughiniș, D. Țurcanu, and D. Rosner, "AI and Cybersecurity: A Risk Society Perspective," Frontiers in Computer Science, vol. 6, Art. no. 1462250, 2024.
  • T. T. T. Horn, "A Study of Cybersecurity Landscape in the United States: Trend, Regional Variations, and Socioeconomic Factors," Ph.D. dissertation, Indiana State University, Terre Haute, IN, USA, 2024.
  • N. Naik, P. Jenkins, P. Grace, D. Naik, S. Prajapat, and J. Song, "An Introduction to Threat Modelling: Modelling Steps, Model Types, Benefits and Challenges," in Proc. International Conference on Computing, Communication, Cybersecurity & AI, Cham, Switzerland: Springer Nature, Jul. 2024, pp. 260–270.
  • A. C. M. Day, AL Report 2023, 2024.
  • J. F. N. González, A. Ortiz, A. C. Cuenca, M. M. Barón, L. Segú, B. Pimentel, et al., "Projection of the Clinical and Economic Burden of Chronic Kidney Disease Between 2022 and 2027 in Spain: Results of the Inside CKD Project," Nefrología (English Edition), vol. 44, no. 6, pp. 807–817, 2024.
  • Identity Theft Resource Center, "2025 H1 Data Breach Report," 2025. [Online]. Available: https://www.idtheftcenter.org/wp-content/uploads/2025/07/ITRC-H1-2025-Data-Breach-Analysis.pdf
  • S. M. Obisesan, "Integrating Artificial Intelligence and Cybersecurity Frameworks: Challenges and Opportunities in E-Commerce Cybersecurity Management," SSRN Electronic Journal, 2024, Art. no. 5070108.
  • S. Metta, I. Chang, J. Parker, M. P. Roman, and A. F. Ehuan, "Generative AI in Cybersecurity," arXiv preprint arXiv:2405.01674, 2024.
  • H. Collier, "AI: The Future of Social Engineering!," in Proc. European Conference on Cyber Warfare and Security, vol. 23, no. 1, Jun. 2024.
  • N. A. H. S. Ikram, "Data Breaches Exit Strategy: A Comparative Analysis of Data Privacy Laws," Malaysian Journal of Syariah and Law, vol. 12, p. 135, 2024.
  • A. Harkai and C. E. Ciurea, "Economic Impact of IoT and Conventional Data Breaches: Cost Analysis and Statistical Trends," Control and Cybernetics, vol. 53, 2024.
  • P. Kumar, D. Y. Gowda, and A. M. Prakash, "Machine Learning in Cybersecurity: A Comprehensive Survey of Data Breach Detection, Cyber-Attack Prevention, and Fraud Detection," in Pioneering Smart Healthcare 5.0 with IoT, Federated Learning, and Cloud Security, pp. 175–197, 2024.
  • E. V. Cobos, S. Cakir, S. Straub, C. Z. Qiang, and C. Torgusson, A Review of the Economic Costs of Cyber Incidents. Washington, DC, USA: World Bank, 2024.
  • P. Mahadevappa, R. Al-Amri, G. Alkawsi, A. A. Alkahtani, M. F. Alghenaim, and M. Alsamman, "Analyzing Threats and Attacks in Edge Data Analytics Within IoT Environments," IoT, vol. 5, no. 1, pp. 123–154, 2024.
  • S. A. Moamin, M. K. Abdulhameed, R. M. Al-Amri, A. D. Radhi, R. K. Naser, and L. G. Pheng, "Artificial Intelligence in Malware and Network Intrusion Detection: A Comprehensive Survey of Techniques, Datasets, Challenges, and Future Directions," Babylonian Journal of Artificial Intelligence, pp. 77–98, 2025.
  • F. Romanosky, "Examining the Costs and Causes of Cyber Incidents," Journal of Cybersecurity, vol. 2, no. 2, pp. 121–135, 2016, doi: 10.1093/cybsec/tyw001.
  • K. Ben Yahia, "The Dark Side of Cryptocurrency Adoption in an Emerging Market: Perspectives of Tunisian Users vs. Professionals," International Journal of Emerging Markets, vol. 21, no. 5, pp. 1479–1502, 2026.
  • U. Ehsan, S. Passi, K. Saha, T. McNutt, M. O. Riedl, and S. Alcorn, "From Future of Work to Future of Workers: Addressing Asymptomatic AI Harms to Foster Dignified Human-AI Interaction," in Proc. CHI Conference on Human Factors in Computing Systems, Apr. 2026, pp. 1–21.
  • H. Wickham et al., "Welcome to the Tidyverse," Journal of Open Source Software, vol. 4, no. 43, p. 1686, 2019, doi: 10.21105/joss.01686.
  • G. Ireri, C. Abungu, J. Cheptumo, S. Dounia, M. Gitau, S. Kasaon, et al., "Assessing the Case for Africa-Centric AI Safety Evaluations," arXiv preprint arXiv:2602.13757, 2026.
  • S. Woods, "Quantifying Under-Reporting in Cyber Incident Data," Journal of Cybersecurity, vol. 8, no. 1, 2022, doi: 10.1093/cybsec/tyac001.
  • S. Harting, D. Gonzales, M. J. Mazarr, and J. Schmid, Comparative Analysis of US and PRC Efforts to Advance Critical Military Technology. Santa Monica, CA, USA: RAND Corporation, 2024.
  • D. DiPersio, "Data Protection, Privacy and US Regulation," in Proc. Workshop on Ethical and Legal Issues in Human Language Technologies and Multilingual De-identification of Sensitive Data in Language Resources within the 13th Language Resources and Evaluation Conference, Jun. 2022, pp. 9–16.
  • A. Hmaidi, "Here to Stay: Chinese State-Affiliated Hacking for Strategic Goals," MERICS Report, 2023.
  • G. Versluis, Xamarin.Forms Essentials: First Steps Toward Cross-Platform Mobile Apps. New York, NY, USA: Apress, 2017.
  • Privacy Rights Clearinghouse, Privacy Rights Clearinghouse, 2019. [Online]. Available: https://privacyrights.org/
  • L. Li, B. Pal, J. Ali, N. Sullivan, R. Chatterjee, and T. Ristenpart, "Protocols for Checking Compromised Credentials," in Proc. ACM SIGSAC Conference on Computer and Communications Security (CCS), Nov. 2019, pp. 1387–1403.
  • The Devastator, "Data Breaches (A Comprehensive List)," Kaggle, 2022. [Online]. Available: https://www.kaggle.com/datasets/thedevastator/data-breaches-a-comprehensive-list
  • G. Kotronoulas, S. Miguel, M. Dowling, P. Fernández-Ortega, S. Colomer-Lahiguera, G. Bağçivan, et al., "An Overview of the Fundamentals of Data Management, Analysis, and Interpretation in Quantitative Research," Seminars in Oncology Nursing, vol. 39, no. 2, Art. no. 151398, Apr. 2023.
  • L. Sardinha, M. Maheu-Giroux, H. Stöckl, S. R. Meyer, and C. García-Moreno, "Global, Regional, and National Prevalence Estimates of Physical or Sexual, or Both, Intimate Partner Violence Against Women in 2018," The Lancet, vol. 399, no. 10327, pp. 803–813, 2022.
  • Bluefin, "2024 ITRC Data Breach Report: Record-Breaking Breaches," 2024. [Online]. Available: https://www.bluefin.com/bluefin-news/2024-itrc-data-breach-report-record-breaking-breaches/
  • Bank of America, "The Costs of a Cyber Incident Can Ripple Through the Economy," 2024. [Online]. Available: https://www.privatebank.bankofamerica.com/articles/cyber-incident-costs.html
  • C. Elendu, E. K. Omeludike, P. O. Oloyede, B. T. Obidigbo, and J. C. Omeludike, "Legal Implications for Clinicians in Cybersecurity Incidents: A Review," Medicine, vol. 103, no. 39, Art. no. e39887, 2024.
  • R. A. Alsharida, B. A. S. Al-Rimy, M. Al-Emran, and A. Zainal, "A Systematic Review of Multi Perspectives on Human Cybersecurity Behavior," Technology in Society, vol. 73, Art. no. 102258, 2023.
  • S. Backman and T. Stevens, "Cyber Risk Logics and Their Implications for Cybersecurity," International Affairs, vol. 100, no. 6, pp. 2441–2460, 2024.
  • A. I. Sani, A. O. Olajide, O. V. Abosede, D. F. Oyebode, R. Vayyala, J. G. Alfred, et al., "Cybersecurity Challenges in Digitizing Government Administration," Proceedings of the International Academy of Sciences, vol. 2, no. 1, pp. 1–13, 2025.
  • W. Tuleun, "Analysis of Cybercrimes, Major Cyber Security Attacks and the Overall Economic Impact on Nigeria," World Journal of Advanced Research and Reviews, vol. 16, no. 1, pp. 1196–1221, 2022.
  • M. Alshaikh, S. Mehmood, R. Amin, and F. S. Alsubaei, "The Impact of Cybersecurity Through Knowledge Sharing Practices: Limitations, Analysis of Current Trends and Future Research Directions," International Journal of Advanced Computer Science and Applications, vol. 16, no. 3, 2025.
  • S. Backman and T. Stevens, "Cyber Risk Logics and Their Implications for Cybersecurity," International Affairs, vol. 100, no. 6, pp. 2441–2460, 2024.
Index Terms
Computer Science
Information Sciences
No index terms available.
Keywords

The cybersecurity situation in the world is becoming more dangerous and the number of data breaches grows and grows. The paper is a secondary data analysis research of publicly available breach archives such as Privacy Rights Clearinghouse HaveIBeenPwned and Kaggle datasets. The study was performed using a quantitative descriptive research design with the help of the R programming language and tidyverse packages to perform data wrangling statistical analysis and visualization. Results indicate that breaches reported have doubled during this time with 2023 showing the highest number of 59 million breached records due to a mega-breach in the technology sector. The most targeted sectors included healthcare and government sectors with 22.2% of the incidents each as this data is valuable. Hacking was the most common attack (44.4%) with ransomware and phishing (22.2% each). This study highlights the trends and patterns of global cybersecurity activities between 2021 and 2024. In this paper the Healthcare and Government Services sectors are overrepresented. It is typical of the high value of the data that they comprise the sensitivity of their operations to interference. The results prove the ongoing incomparability of phishing as an initial access technique related to attack vectors. Moreover it founded the drastic and recent escalation of ransomware as a major danger.

Powered by PhDFocusTM