The damage is caused by ransomware, which is malicious software (also known as malware) that encrypts an organization’s data and then extorts large sums of money to restore access, the Basking Ridge, New Jersey-based company said. That conclusion came from Verizon’s 16th annual Data Breach Investigations Report (2023 DBIR), which analyzed 16,312 security incidents and 5,199 breaches.
Ransomware remains one of the top cyberattack methods, representing almost a quarter of all breaches (24%). It has seen a dramatic rise in frequency over the past couple of years when the number of ransomware attacks was greater than the previous five years combined, Verizon said.
Part of the reason that ransomware is so popular with hackers is that it’s effective: The median cost per ransomware incident more than doubled over the past two years to $26,000.
In the overwhelming majority (74%) of incidents, hackers gain access to companies’ files through the human element, even as enterprises continue to safeguard critical infrastructure and increase training on cybersecurity protocols. One of the most common ways to exploit human nature is social engineering, which refers to manipulating an organization's sensitive information through tactics like phishing, in which a hacker convinces the user into clicking on a malicious link or attachment.
Executives are particularly vulnerable. “Senior leadership represents a growing cybersecurity threat for many organizations,” Chris Novak, managing director of Cybersecurity Consulting at Verizon Business, said in a release. “Not only do they possess an organization’s most sensitive information, they are often among the least protected, as many organizations make security protocol exceptions for them. With the growth and increasing sophistication of social engineering, organizations must enhance the protection of their senior leadership now to avoid expensive system intrusions.”
Another lucrative tactic for cybercriminals is social engineering, when attackers impersonate enterprise employees for financial gain, a method known as Business Email Compromise (BEC). The approach is especially effective when applied to businesses with distributed workforces, since they are challenged to create and strictly enforce human-centric security best practices for their remote employees. The median amount stolen in BECs has increased over the last couple of years to $50,000, based on Internet Crime Complaint Center (IC3) data.
And that trend might have contributed to a near doubling this past year of “pretexting,” an invented scenario that tricks someone into giving up information or committing an act that may result in a breach, Verizon said.
In other findings, the report found:
espionage garners substantial media attention, but only 3% of threat actors were motivated by espionage; the other 97% were motivated by financial gain.
hackers tend to use new techniques soon after vulnerabilities are discovered. For example, 32% of yearly Log4j vulnerability scanning occurred in the first 30 days after its release, demonstrating threat actors’ velocity when escalating from a proof of concept to mass exploitation.
hackers use a variety of different techniques to gain entry to an organization, such as using stolen credentials (49%), phishing (12%), and exploiting vulnerabilities (5%).
Finally, the report concluded that enterprises can help safeguard their critical infrastructure by adopting industry leading protocols and practices. For example, Verizon recently became the first nationwide telecom provider to become a participant of Mutually Agreed Norms for Routing Security (MANRS), a global initiative that provides crucial fixes to reduce the most common routing threats that can be exploited by attackers.
The supply chain risk management firm Overhaul has landed $55 million in backing, saying the financing will fuel its advancements in artificial intelligence and support its strategic acquisition roadmap.
The equity funding round comes from the private equity firm Springcoast Partners, with follow-on participation from existing investors Edison Partners and Americo. As part of the investment, Springcoast’s Chris Dederick and Holger Staude will join Overhaul’s board of directors.
According to Austin, Texas-based Overhaul, the money comes as macroeconomic and global trade dynamics are driving consequential transformations in supply chains. That makes cargo visibility and proactive risk management essential tools as shippers manage new routes and suppliers.
“The supply chain technology space will see significant consolidation over the next 12 to 24 months,” Barry Conlon, CEO of Overhaul, said in a release. “Overhaul is well-positioned to establish itself as the ultimate integrated solution, delivering a comprehensive suite of tools for supply chain risk management, efficiency, and visibility under a single trusted platform.”
Artificial intelligence (AI) and data science were hot business topics in 2024 and will remain on the front burner in 2025, according to recent research published in AI in Action, a series of technology-focused columns in the MIT Sloan Management Review.
In Five Trends in AI and Data Science for 2025, researchers Tom Davenport and Randy Bean outline ways in which AI and our data-driven culture will continue to shape the business landscape in the coming year. The information comes from a range of recent AI-focused research projects, including the 2025 AI & Data Leadership Executive Benchmark Survey, an annual survey of data, analytics, and AI executives conducted by Bean’s educational firm, Data & AI Leadership Exchange.
The five trends range from the promise of agentic AI to the struggle over which C-suite role should oversee data and AI responsibilities. At a glance, they reveal that:
Leaders will grapple with both the promise and hype around agentic AI. Agentic AI—which handles tasks independently—is on the rise, in the form of generative AI bots that can perform some content-creation tasks. But the authors say it will be a while before such tools can handle major tasks—like make a travel reservation or conduct a banking transaction.
The time has come to measure results from generative AI experiments. The authors say very few companies are carefully measuring productivity gains from AI projects—particularly when it comes to figuring out what their knowledge-based workers are doing with the freed-up time those projects provide. Doing so is vital to profiting from AI investments.
The reality about data-driven culture sets in. The authors found that 92% of survey respondents feel that cultural and change management challenges are the primary barriers to becoming data- and AI-driven—indicating that the shift to AI is about much more than just the technology.
Unstructured data is important again. The ability to apply Generative AI tools to manage unstructured data—such as text, images, and video—is putting a renewed focus on getting all that data into shape, which takes a whole lot of human effort. As the authors explain “organizations need to pick the best examples of each document type, tag or graph the content, and get it loaded into the system.” And many companies simply aren’t there yet.
Who should run data and AI? Expect continued struggle. Should these roles be concentrated on the business or tech side of the organization? Opinions differ, and as the roles themselves continue to evolve, the authors say companies should expect to continue to wrestle with responsibilities and reporting structures.
Shippers today are praising an 11th-hour contract agreement that has averted the threat of a strike by dockworkers at East and Gulf coast ports that could have frozen container imports and exports as soon as January 16.
The agreement came late last night between the International Longshoremen’s Association (ILA) representing some 45,000 workers and the United States Maritime Alliance (USMX) that includes the operators of port facilities up and down the coast.
Details of the new agreement on those issues have not yet been made public, but in the meantime, retailers and manufacturers are heaving sighs of relief that trade flows will continue.
“Providing certainty with a new contract and avoiding further disruptions is paramount to ensure retail goods arrive in a timely manner for consumers. The agreement will also pave the way for much-needed modernization efforts, which are essential for future growth at these ports and the overall resiliency of our nation’s supply chain,” Gold said.
The next step in the process is for both sides to ratify the tentative agreement, so negotiators have agreed to keep those details private in the meantime, according to identical statements released by the ILA and the USMX. In their joint statement, the groups called the six-year deal a “win-win,” saying: “This agreement protects current ILA jobs and establishes a framework for implementing technologies that will create more jobs while modernizing East and Gulf coasts ports – making them safer and more efficient, and creating the capacity they need to keep our supply chains strong. This is a win-win agreement that creates ILA jobs, supports American consumers and businesses, and keeps the American economy the key hub of the global marketplace.”
The breakthrough hints at broader supply chain trends, which will focus on the tension between operational efficiency and workforce job protection, not just at ports but across other sectors as well, according to a statement from Judah Levine, head of research at Freightos, a freight booking and payment platform. Port automation was the major sticking point leading up to this agreement, as the USMX pushed for technologies to make ports more efficient, while the ILA opposed automation or semi-automation that could threaten jobs.
"This is a six-year détente in the tech-versus-labor tug-of-war at U.S. ports," Levine said. “Automation remains a lightning rod—and likely one we’ll see in other industries—but this deal suggests a cautious path forward."
Editor's note: This story was revised on January 9 to include additional input from the ILA, USMX, and Freightos.
Logistics industry growth slowed in December due to a seasonal wind-down of inventory and following one of the busiest holiday shopping seasons on record, according to the latest Logistics Managers’ Index (LMI) report, released this week.
The monthly LMI was 57.3 in December, down more than a percentage point from November’s reading of 58.4. Despite the slowdown, economic activity across the industry continued to expand, as an LMI reading above 50 indicates growth and a reading below 50 indicates contraction.
The LMI researchers said the monthly conditions were largely due to seasonal drawdowns in inventory levels—and the associated costs of holding them—at the retail level. The LMI’s Inventory Levels index registered 50, falling from 56.1 in November. That reduction also affected warehousing capacity, which slowed but remained in expansion mode: The LMI’s warehousing capacity index fell 7 points to a reading of 61.6.
December’s results reflect a continued trend toward more typical industry growth patterns following recent years of volatility—and they point to a successful peak holiday season as well.
“Retailers were clearly correct in their bet to stock [up] on goods ahead of the holiday season,” the LMI researchers wrote in their monthly report. “Holiday sales from November until Christmas Eve were up 3.8% year-over-year according to Mastercard. This was largely driven by a 6.7% increase in e-commerce sales, although in-person spending was up 2.9% as well.”
And those results came during a compressed peak shopping cycle.
“The increase in spending came despite the shorter holiday season due to the late Thanksgiving,” the researchers also wrote, citing National Retail Federation (NRF) estimates that U.S. shoppers spent just short of a trillion dollars in November and December, making it the busiest holiday season of all time.
The LMI is a monthly survey of logistics managers from across the country. It tracks industry growth overall and across eight areas: inventory levels and costs; warehousing capacity, utilization, and prices; and transportation capacity, utilization, and prices. The report is released monthly by researchers from Arizona State University, Colorado State University, Rochester Institute of Technology, Rutgers University, and the University of Nevada, Reno, in conjunction with the Council of Supply Chain Management Professionals (CSCMP).
The overall national industrial real estate vacancy rate edged higher in the fourth quarter, although it still remains well below pre-pandemic levels, according to an analysis by Cushman & Wakefield.
Vacancy rates shrunk during the pandemic to historically low levels as e-commerce sales—and demand for warehouse space—boomed in response to massive numbers of people working and living from home. That frantic pace is now cooling off but real estate demand remains elevated from a long-term perspective.
“We've witnessed an uptick among firms looking to lease larger buildings to support their omnichannel fulfillment strategies and maintain inventory for their e-commerce, wholesale, and retail stock. This trend is not just about space, but about efficiency and customer satisfaction,” Jason Tolliver, President, Logistics & Industrial Services, said in a release. “Meanwhile, we're also seeing a flurry of activity to support forward-deployed stock models, a strategy that keeps products closer to the market they serve and where customers order them, promising quicker deliveries and happier customers.“
The latest figures show that industrial vacancy is likely nearing its peak for this cooling cycle in the coming quarters, Cushman & Wakefield analysts said.
Compared to the third quarter, the vacancy rate climbed 20 basis points to 6.7%, but that level was still 30 basis points below the 10-year, pre-pandemic average. Likewise, overall net absorption in the fourth quarter—a term for the amount of newly developed property leased by clients—measured 36.8 million square feet, up from the 33.3 million square feet recorded in the third quarter, but down 20% on a year-over-year basis.
In step with those statistics, real estate developers slowed their plans to erect more buildings. New construction deliveries continued to decelerate for the second straight quarter. Just 85.3 million square feet of new industrial product was completed in the fourth quarter, down 8% quarter-over-quarter and 48% versus one year ago.
Likewise, only four geographic markets saw more than 20 million square feet of completions year-to-date, compared to 10 markets in 2023. Meanwhile, as construction starts remained tempered overall, the under-development pipeline has continued to thin out, dropping by 36% annually to its lowest level (290.5 million square feet) since the third quarter of 2018.
Despite the dip in demand last quarter, the market for industrial space remains relatively healthy, Cushman & Wakefield said.
“After a year of hesitancy, logistics is entering a new, sustained growth phase,” Tolliver said. “Corporate capital is being deployed to optimize supply chains, diversify networks, and minimize potential risks. What's particularly encouraging is the proactive approach of retailers, wholesalers, and 3PLs, who are not just reacting to the market, but shaping it. 2025 will be a year characterized by this bias for action.”