Regional assessment data records 8,856 data breach incidents — 39.9% of the total — alongside 4,068 ransomware incidents, 4,061 phishing incidents and 3,966 attributed to advanced persistent threat activity.
The Three Trailing Numbers Are Suspiciously Close
4,068, 4,061 and 3,966 sitting within 3% of each other across three categories with entirely different underlying dynamics is worth noticing rather than reporting.
It may be real. It may also reflect classification: an incident involving a phishing email, followed by ransomware, attributed to a state-linked group, could be counted in any of the three depending on who filed it. Categories that overlap in reality produce counts that converge in datasets.
The APT Figure Is The One To Hold Loosely
Nearly 4,000 incidents classified as advanced persistent threat activity is a very large number for a category that, in this corpus, denotes state-linked operations of the kind at 25-0304 and 25-0611 — patient, targeted, expensive.
It is more likely that "APT" is being used regionally to mean sophisticated or targeted rather than state-sponsored. That is a legitimate usage and it is not the corpus’s, and any comparison against the nation-state files here would be comparing different things.
What The Composition Does Establish
That data breaches dominate by count in this region as elsewhere, and that ransomware is roughly a fifth of recorded incidents rather than the overwhelming majority its share of coverage would suggest.
This corpus is itself skewed that way — ransomware is one of its four sections and generates a disproportionate share of files, because ransomware incidents are the ones that get publicised. Graded medium: category definitions are not published and this desk cannot reconcile them against its own.
Built on published regional assessment data, listed below. Category definitions are not stated and incidents may be classifiable in more than one. Corrections: corrections@forensicpost.com.