Report: the number of cyber attacks per week on corporate networks globally grew 50% YoY in 2021, peaking towards the end of Q4, largely due to the Log4j flaw
Check Point Research said that among its customers, there was a 50% increase in overall attacks per week on corporate networks compared to 2020. Source: Check Point Software .
Context & Ripple Effects
The year-end surge was already visible in mid-December, when Check Point tracked Log4j exploits jumping from a few thousand to over 800K within 72 hours and touching 40%+ of corporate networks worldwide. Today's full-year figure confirms that burst wasn't a blip: it capped a steady climb that included 740 organizations having data posted to leak sites in Q2 alone, up 47% quarter over quarter.
What makes the 50% YoY number notable is its composition — a single open-source flaw in one logging library moved the global weekly attack rate more than any prior single vector in Check Point's dataset, echoing how Kaspersky found ~70% of detected attacks in Q4 2018 targeting Office vulnerabilities. The pattern is repeated concentration: attackers pile onto whichever widely deployed component is exposed.
First-order effects
- Enterprises running Log4j-bearing Java applications faced immediate patching triage through late Q4 and into January, while Check Point's customer base absorbed the elevated weekly attack volume directly.
Second-order effects
- A rising baseline of attacks strengthens the case for cyber insurance at renewal time — adoption already stood at 47% of enterprises in 2019, up from 34% two years earlier — pushing underwriters toward stricter scrutiny of open-source dependency management before pricing coverage.
Third-order effects
- If single-component flaws keep setting annual attack records, security budgets shift from perimeter defense toward software supply-chain auditing, and regulators treating open-source dependencies as critical infrastructure becomes the likely policy response — a trajectory consistent with national agencies like the UK's NCSC handling a record volume of significant incidents years later.
The trend: Corporate attack surface is consolidating around shared open-source components, so one flaw now moves global attack volumes more than entire attack categories did a few years ago.