TrollEye Security

Cyber News

Apple’s Report Reveals 2.6 Billion Exposed Records Between 2021 and 2022

An Apple-commissioned study led by an MIT professor found a sharp rise in data breaches and compromised records between 2021 and 2022, totaling 2.6 billion exposed records and underscoring the

Details of the Story

A recent Apple-commissioned report, based on an independent study by an MIT professor, sheds light on the escalating threat landscape in data security. The study, analyzing publicly reported breach data, reveals a sharp increase in data breaches and compromised records in recent years, highlighting the critical role of end-to-end encryption in protecting sensitive data.

In 2021 and 2022 alone, a staggering 2.6 billion personal records were exposed, with 2023 trends indicating a further rise. The first nine months of 2023 saw a 20% increase in data breaches compared to the entirety of 2022. These breaches, often involving corporate and institutional records, have affected millions of individuals. IBM’s 2023 Cost of a Data Breach and Forrester research, cited in the Apple report, underline that recurring breaches are common, with 95% of organizations suffering more than one breach.

Ransomware and attacks on technology vendors have been significant contributors to this surge. The first nine months of 2023 witnessed a 70% increase in ransomware attacks compared to 2022, affecting an increasingly larger number of organizations. The study further reveals that 98% of organizations are linked to a technology vendor that has recently experienced a breach, underscoring the widespread impact of vendor-related security incidents.

Apple’s report emphasizes that the rise in data breaches is a direct consequence of the increasing volumes of unencrypted data, particularly in cloud storage. The company advocates for robust encryption of data – in transit, at rest, and in use – as a key defense strategy against unauthorized access and misuse of stolen data. This stance is supported by various regulatory requirements and industry mandates, such as PCI DSS, HIPAA, and GDPR, which either require or recommend data encryption.

However, many organizations hesitate to implement comprehensive encryption strategies due to perceived complexities, costs, performance impacts, and lack of expertise. Encryption, particularly in cloud environments, presents unique challenges as organizations transition to hybrid networks, combining legacy and modern technologies. Experts warn against relying solely on cloud providers for encryption, urging organizations to take a proactive and direct role in securing their data.

The report not only underscores the escalating threat of data breaches but also the crucial need for organizations to strengthen their cybersecurity measures, with a particular emphasis on end-to-end encryption as a fundamental protective measure.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated