A new report from the Identity Theft Resource Center (ITRC) shows that the third quarter of 2024 saw a huge increase in supply chain attacks, with nearly 242 million breach victims recorded in the US.

The nonprofit organization tracks publicly disclosed U.S. data breaches and accidental leaks, and issues quarterly reports.
See also: Internet Archive: Data breach affects 31 million users
The new report (Q3) revealed a significant decrease in the number of victims of data breaches and leaks, but this is due to the huge number of victims (940 million) that occurred in Q2 due to the breaches at Ticketmaster and Advanced Auto Parts.
However, supply chain attacks increased by 203% in the third quarter. Some 97 entities were affected by 31 breaches and data leaks, putting nearly a million people at risk.
“ While we likely won’t set a new record for the number of data breaches like we did in 2023, there are some interesting trends in the Q3 2024 Data Breach Report ,” said Eva Velasquez , CEO of ITRC. For example, there was an increase in the number of businesses reporting multiple data breaches in the past 12 months. In addition, so-called mega-data breaches , which refer to breaches affecting more than 100 million people, are back
See also: ADT: Second breach in two months
«These trends demonstrate that businesses must continue to prioritize data and identity protection, and consumers must take the necessary steps to make their information less useful to criminals.».
The major breach Velasquez referred to involved AT&T. About 110 million victims were affected when attackers downloaded customer data, including call logs, from Snowflake.

Another major breach in Q3 2024 was a data leak from MC2 Data , where a background check specialist left 2.2TB of sensitive data accessible online without password protection . However, there is no indication that threat actors stole the information before the issue was fixed
See also: MoneyGram: Cyberattack led to data breach
Steps towards data security
To prevent data breaches, organizations must implement strict security measures. These may include:
- Regular security audits to identify vulnerabilities in systems and networks.
- Encryption of sensitive data.
- Multi-factor authentication
- Educate employees on cybersecurity best practices , including password management and phishing awareness.
- Real-time monitoring of network activity to detect suspicious behavior or attempted unauthorized access.
Source: www.infosecurity-magazine.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
