Report: 1,500 data breaches worldwide compromised almost 1B data records in 2014, up 78% from 575M in 2013; 54% of the breaches involved identity theft
Amir Mizroch / Wall Street Journal : Tweets: @scottthurm Tweets: Scott Thurm / @scottthurm : It's not your imagination. Gemalto says breaches rose 49% last year http://blogs.wsj.com/... via @amirmizroch
Context & Ripple Effects
Gemalto's 2014 tally was the moment breach reporting became a quantified annual benchmark rather than a string of incidents: nearly 1 billion records lost across 1,500 breaches, a 78% jump over 575M in 2013, with identity theft behind 54% of them. Later coverage turned that count into an economics story — IBM pegged the average global breach cost at $3.86M in its 2018 study and again in 2020, with mega-breaches of tens of millions of records costing up to $392M.
The sector mix shifted too. Health records became a preferred target: more than 32M patient records were stolen in just the first half of 2019, double all of 2018, and HHS reported 40M+ people exposed in 2021 versus 26M in 2020.
First-order effects
- Gemalto's numbers put every company holding consumer records on notice that breach volume is compounding annually, making security spend a board-level line item rather than an IT detail.
- The 54% identity-theft share means the immediate victims are individual consumers whose stolen credentials fuel downstream account takeover and fraud.
Second-order effects
- As breaches normalized, buyers began demanding a price on failure: IBM's recurring cost-of-breach research gave insurers, boards, and regulators a common dollar figure to negotiate security budgets and cyber premiums against.
- Attackers followed the richest per-record value, shifting toward medical data — where each stolen patient record carries longer fraud shelf life than a payment card, as the 2019-2021 health breach escalation shows.
Third-order effects
- If the pattern holds, breach exposure becomes a priced structural cost of doing business — with standardized loss estimates (IBM's $3.86M baseline) feeding regulation, disclosure mandates, and insurance underwriting rather than ad hoc scandal response.
- Data itself stratifies by liability: industries holding high-value personal records like healthcare get treated as critical infrastructure for protection purposes, concentrating security investment where record sensitivity is highest.
The trend: Data breaches are compounding into a permanent, quantified cost of digital business, with annual benchmark reports turning security failures from episodic scandals into a measured industry-wide expense.