Desk live·
ForensicPost
Breaches/Analysis/File 25-0808

Retail Recorded 837 Incidents and 419 Confirmed Breaches in a Quarter

Industry figures put retail at 837 incidents and 419 confirmed breaches in one quarter of 2025, with publicly disclosed retail ransomware up 58% quarter on quarter. The gap between the two numbers is the story.

Constructed geometry · not a chart of case data
TargetRetail sector
ActorMultiple
S. Rosler10 min readConfidence: medium3 sources reviewed

Published industry figures record 837 cyber incidents in the retail sector during a single quarter of 2025, of which 419 were confirmed data breaches. Publicly disclosed ransomware attacks against retail rose 58% quarter on quarter, and the average cost of a retail data breach was put at $3.54 million.

Half Of Them Never Became A Disclosure

837 incidents produced 419 confirmed breaches. The other 418 were incidents where data loss was not confirmed — a category that includes intrusions successfully stopped, intrusions where investigation was inconclusive, and intrusions where nothing was taken because the attack was aimed at availability instead.

Only the confirmed half generates a notification, a regulatory filing or a headline. The rest is the sector’s actual attack volume, visible here because a survey counted it and invisible everywhere else.

The 58% Is Measuring Disclosure

Note the wording: publicly disclosed ransomware rose 58%. That is a count of leak-site listings and public statements, and this desk has filed repeatedly on why that is not a count of attacks — see 26-0425 and 26-0512.

A quarter in which a high-profile campaign draws attention to a sector will produce more disclosure at any given level of attack. The 2025 retail campaign was exactly such a quarter. Some of that 58% is more attacks; some of it is the same attacks becoming visible.

On The Average Cost

$3.54 million is an average across a distribution with an enormous tail — a sector containing both a corner shop and a company reporting a nine-figure operational loss, as at 25-0430.

An average over that distribution is not a figure any individual retailer should plan against. It is useful for arguing that the cost is non-trivial and useless for estimating your own.

This is an analysis file

Built on published sector statistics, listed below. Figures are as reported by their publishers; sampling frames and definitions vary between them and are not directly comparable. Corrections: corrections@forensicpost.com.

Sources
  1. Retail cybersecurity statisticsHeimdal Security
  2. Inside the 2025 retail cybersecurity threat landscapeThales
  3. Cyber breaches in retail: the 2025 breakdownSecurity Journal UK
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary