Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
breach-disclosure-notificationmass-credential-exposurefinancial-sector-threatcredential-stealer-activity

Record Surge in US Data Breaches and Identity Attacks Driven by Stolen Credentials

Updated 3mo agoFirst seen Oct 18, 20252 sources

Data breaches in the United States have reached alarming levels in 2025, with 835 incidents reported in the third quarter alone, affecting 23 million individuals. Despite a slight downturn in Q3, the total number of breaches for the year has already reached 2,563, impacting nearly 202 million victims, according to the Identity Theft Resource Center. The majority of these compromises—83%—were caused by cyberattacks, while physical attacks have also increased, with 53 incidents reported so far, surpassing the total for the previous year. Major organizations affected include Anne Arundel Dermatology, DaVita, Radiology Associates of Richmond, TransUnion, and Absolute Dental Group, each sending millions of breach notifications to affected individuals. The financial sector has been particularly hard hit, experiencing 188 breaches, making it the most impacted industry. A significant concern highlighted by the ITRC is that 71% of breach notifications lacked details about the attack vectors, which complicates efforts to mitigate identity theft and fraud. Microsoft’s 2025 Digital Defense Report corroborates the trend, noting a 32% surge in identity-based attacks in the first half of the year, with over 97% of these attacks leveraging stolen passwords. Hackers are increasingly using credential leaks, infostealer malware, and social engineering tactics such as help desk scams to obtain access to sensitive accounts. The Scattered Spider group has been linked to several high-profile attacks using these methods. Microsoft has also played a role in disrupting infostealer operations, notably taking down the Lumma Stealer infrastructure, though new variants continue to emerge. The prevalence of password-based attacks underscores the need for stronger authentication measures and better user education. The lack of transparency in breach notifications further exacerbates the risk, as individuals and organizations are left without critical information to protect themselves. The rise in both cyber and physical attacks demonstrates the evolving threat landscape facing US organizations. The healthcare and financial sectors remain prime targets due to the sensitive data they hold. Experts warn that unless organizations improve their security posture and reporting practices, the US is on track for another record-breaking year in data breaches. The combination of sophisticated attack techniques and inadequate breach disclosures increases the risk of widespread identity theft and financial fraud. Security professionals are urged to prioritize credential protection, implement multi-factor authentication, and ensure timely, detailed breach notifications to mitigate the growing threat.

Share:
Record Surge in US Data Breaches and Identity Attacks Driven by Stolen Credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 17, 20258mo ago

U.S. remains on pace for a record breach year in 2025

By the time of the Q3 2025 reporting, the U.S. had logged 2,563 breaches and nearly 202 million victims for the year so far, putting it on track for a record year. Major organizations named as impacted included Anne Arundel Dermatology, DaVita, Radiology Associates of Richmond, TransUnion, and Absolute Dental Group.

Oct 16, 20259mo ago

Microsoft publishes Digital Defense Report 2025 on identity and ransomware trends

Microsoft publicly released its Digital Defense Report 2025, highlighting the surge in identity attacks, the dominance of password-based account takeovers, and ongoing disruption efforts against Lumma Stealer infrastructure. The report also referenced high-profile IT help-desk scam activity associated with English-speaking criminals linked to Scattered Spider.

Sep 30, 20259mo ago

U.S. records 835 data breaches and 23 million victims in Q3 2025

The Identity Theft Resource Center said the United States experienced 835 data breaches in the third quarter of 2025, affecting 23 million victims. Cyberattacks accounted for 83% of compromises, the financial sector saw 188 incidents, and 71% of breach notices did not explain how the attacks occurred.

Jun 30, 20251y ago

Microsoft documents 2024–2025 ransomware and intrusion trends in defense report

In its Digital Defense Report 2025, covering July 2024 through June 2025, Microsoft said IT companies and national and local government bodies were the most targeted sectors. The report also noted exploitation of vulnerabilities including CVE-2024-50623 affecting Cleo, found ransomware objectives in 19% of investigated cases where objectives were known, and described attackers switching ransomware strains and abusing broad antivirus exclusions to evade detection.

Identity attacks rise 32% in the first half of 2025, led by password abuse

Microsoft reported that identity-based attacks increased by 32% in the first half of 2025. More than 97% of observed identity attacks involved passwords, driven largely by large-scale password guessing using leaked credentials, along with infostealer malware and help-desk social engineering.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

34 LINKEDOpen in app
Threat actors
2 linked
Affected products
1 linked
Cobalt Strike
Organizations
20 linked
TransUnionDaVitaAbsolute Dental GroupIdentity Theft Resource CenterRadiology Associates of RichmondAnne Arundel DermatologyBeyondtrustRhysidaRecorded FutureVice SocietyCleoFortinetQuantum LockerIntel 471Microsoft CorporationZeppelinSimpleHelpOcto TempestALPHV/BlackCatScattered Spider
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.