97% of Breaches in APAC Fueled by System Intrusion, Social Engineering, and Web App Attacks

The report analysed more than 22,000 security incidents, including 12,195 confirmed data breaches spanning 139 countrie

97% of Breaches in APAC Fueled by System Intrusion, Social Engineering, and Web App Attacks
(Downloaded from Freepik)

Verizon Business has released its 2025 Data Breach Investigations Report (DBIR), sounding the alarm on a surge of system intrusions across the Asia-Pacific region.

The report reveals that 4 out of 5 data breaches in the region stemmed from such attacks - up from 38% the previous year.

Collectively, 97% of APAC breaches were caused by just three tactics; system intrusion, social engineering, and basic web application attacks, highlighting the region's increasingly concentrated cyber threat landscape.

Now in its 18th year, the report analysed more than 22,000 security incidents, including 12,195 confirmed data breaches spanning 139 countries. Malware increased from 58% last year in APAC to 83% this year, with Ransomware accounting for  51% of breaches.

"In the Asia-Pacific region in particular, external actors are targeting critical infrastructure and exploiting third-party vulnerabilities. The rising incidence of breaches highlights the imperative for businesses to reassess their risk frameworks," Robert Le Busque, Regional Vice President, Asia Pacific for Verizon Business, said.

Key APAC Findings:

  • Social Engineering: The absolute number of Social Engineering breaches has been on the decline since 2021, it only accounts for 20% of breaches in 2025 due, in part, to the sharp increase of system intrusion
  • Malware: Malware in data breaches jumped significantly, from 58% last year to 83% this year with email being the key vector for distributing various types of malware
  • Ransomware:  Now accounts for 51% of the total breaches in this region and remains highly visible as threat actors often publicize breaches

Key Global Findings:

  • Exploitation of Vulnerabilities: This initial attack vector saw a 34% increase, with a significant focus on zero-day exploits targeting perimeter devices and VPNs
  • Ransomware: Ransomware attacks rose by 37% since last year, and are now present in 44% of breaches, despite a noticeable decrease in the median ransom amount paid.
  • Third-Party Involvement: The percentage of breaches involving third parties doubled, highlighting the risks associated with supply chain and partner ecosystems
  • Human Element: Human involvement in breaches remains high, with a significant overlap between social engineering and credential abuse

The 2025 DBIR also shed light on industry-specific trends, revealing an alarming rise in espionage-motivated attacks in the Manufacturing and Healthcare sectors, and persistent threats to the Education, Financial, and Retail industries.

The report also highlighted the disproportionate impact of ransomware on small and medium-sized businesses (SMBs).