Endpoints Under Siege: Billions of Records, Millions of Clients

Endpoints Under Siege: Billions of Records, Millions of Clients

The story of 2025 is not just about one app or one leak. It’s about billions of records siphoned from hacked endpoints, compromised servers, and misconfigured databases. Windows laptops, macOS desktops, cloud services, and forgotten APIs all play their part in the largest theft of digital assets in history.

1.4 billions records.

94 millions records.

184 millions keys.

3 millions spyware apps.

Windows OS.

Servers.

MacOS.

Android.

…

Interesting Numbers

Recent breach statistics show the extent:

  • 1.44 billion records breached in May 2025 alone, across 44 incidents.
  • 94 million records leaked in Q2 2025 worldwide.
  • 184 million+ credentials dumped via infostealer malware.
  • 3.2 million spyware/stalkerware apps exposed user data.
  • 31 million AT&T customer records (unconfirmed) compromised.
  • 20 million Co-op UK records claimed by ransomware gangs.
  • 69,461 Coinbase customer records leaked via insider access.
  • 437,000 Ascension Health records exposed via third-party file tool.
  • 1.2 billion Facebook records scraped from public APIs.

Endpoints: Windows, macOS, and Beyond

  • Attackers increasingly target endpoints (Windows PCs, macOS laptops, mobile devices) with phishing and unpatched software exploits.
  • 68% of incidents involve the human element β€” stolen credentials or phishing.
  • Exploits against unpatched software surged 180% year-over-year.
  • Infostealers harvest browser-stored passwords, session tokens, and autofill data, turning endpoints into gateways for mass credential dumps.

Servers and Databases

  • Misconfigured cloud databases remain a top source of leaks.
  • Forgotten servers or exposed APIs (like the Facebook case) can yield hundreds of millions of records in a single scrape.
  • Ransomware gangs increasingly target enterprise servers and ERP/CRM systems, exfiltrating data before encrypting it.

Costs and Consequences

  • The average global breach cost hit $4.88 million in 2025, up 10% year-over-year.
  • Total annual cost of cybercrime is racing toward $10.5 trillion.
  • Organizations using AI/automation in defense cut breach costs by $2.2 million on average.
  • But detection gaps remain: many breaches go unnoticed for months, allowing attackers to quietly drain data.

Monitoring Failures

What was missed:

  • Rate limits on APIs often absent.
  • Patch management lagging, leaving endpoints vulnerable.
  • Credential hygiene poor β€” reused passwords across services.
  • Insider threats underestimated, as seen in Coinbase’s leak.
  • Cloud misconfigurations left databases open to enumeration.

IT Nerdy Takeaway

Endpoints are the soft underbelly: Windows, macOS, iOS, Android all serve as entry points. Servers and databases amplify the damage. The numbers are staggering:

  • 1.44 billion records in one month.
  • 184 million credentials stolen.
  • 3.2 million spyware apps leaking data.
  • 94 million records in a single quarter.

This is not a single breach β€” it’s a systemic failure of monitoring, patching, and data protection.

References

Science With Data //