Group Purchasing
Group Purchasing

SANS 2023 Attack and Threat Report

SANS 2023 Attack and Threat Report (PDF, 3.37MB)Published: 26 Jun, 2023
Created by:
John PescatoreTerry Allan Hicks
John Pescatore & Terry Allan Hicks

The SANS 2023 Attack and Threat Report, published by SANS Institute in June 2023, examines the most dangerous emerging cyberattack techniques based on breach data analysis and expert threat intelligence from the SANS panel at RSA Conference 2023. Written by John Pescatore and Terry Allan Hicks, the report combines baseline breach statistics from the Identity Theft Resource Center (ITRC) and Verizon's Data Breach Investigations Report (DBIR) with insights from four SANS threat experts on attack trends including SEO poisoning, developer-targeted attacks, and generative AI-enabled social engineering.

Key findings:

  • 40% of breaches in 2022 involved a supply chain partner, per ITRC data
  • Records exposed jumped from 298,213,506 in 2021 to 422,143,312 in 2022, averaging more than 234,000 records per breach
  • The average cost of a reported 2022 breach exceeded $24 million, based on a $100-per-record estimate
  • Successful phishing attacks were the leading cause of breaches at 53%, up from 36% in 2021
  • Ransomware accounted for 32% of breaches with known root causes, up from 23% in 2021
  • Zero-day attacks represented under 1% of breaches with a known root cause
  • Verizon's DBIR found 62% of intrusions involved a supply chain partner, higher than the ITRC's figure
  • Only 50% of breaches are detected through means other than the attacker disclosing the breach themselves, as is common in ransomware cases
  • 99% of breaches exploit known vulnerabilities with available mitigations rather than zero-days
  • Multifactor authentication (MFA) stops more than 99.9% of credential-based attacks
  • A compromised version of the Prettier code extension, which has over 27 million legitimate downloads, demonstrated how easily malicious packages can impersonate trusted developer tools

Across every attack vector examined, the same pattern emerges: enterprises have gotten better at hardening their own perimeters, so attackers have shifted toward third parties, supply chain partners, and developers as easier points of entry. Generative AI is accelerating this shift on both fronts, making phishing and impersonation attacks more convincing while also lowering the technical bar for writing malware and exploit code. The report draws on breach data from the Identity Theft Resource Center and Verizon's 2022 DBIR, combined with expert analysis from four SANS-affiliated threat panelists presenting at RSA Conference 2023 in April: Katie Nickels, Dr. Johannes Ullrich, Heather Mahalik, and Stephen Sims.

FAQ

Meet the experts