
| Characteristic | At organizations (among employees) | At MSPs (among customers) |
|---|---|---|
| Credentials were compromised through a phishing attack | 32.3% | 23.5% |
| Breach of sensitive employee data | 25.9% | 45.1% |
| Compromised by an attacker using techniques to impersonate a trusted customer or business partner | 22.4% | 11.8% |
| None (No security incident types) | 21.4% | 9.8% |
| Credentials were compromised even though a QR code phishing attack | 20.9% | 21.6% |
| Credentials were compromised even though they were protected by MFA | 18.9% | 17.6% |
| Breach of sensitive customer data | 16.9% | 39.2% |
| Ransomware attack successfully exfiltrated or leaked data | 15.4% | 9.8% |
| Ransomware attack successfully encrypted data | 13.9% | 13.7% |
| Lost money through a business e-mail compromise attack | 12.9% | 21.6% |
| Threat actor bypassed the safety features of AI-powered cyber defenses | 12.4% | 11.8% |
| Compromised through an attack that used deepfake techniques | 10.4% | 11.8% |
| Made a ransom payment after a ransomware attack | 7% | 11.8% |
| Threat actor exploited defensive AI systems for malicious purposes | 6.5% | 9.8% |
The chart is not accessible to screen readers. Please switch to the table view to access the data.
Loading statistic...
Download
Source
Release date
March 2025
Region
Worldwide
Survey time period
February 2024 to February 2025
Supplementary notes
Security incidents over the previous 12 months
Citation formats








