Cybersecurity Then and Now: What Actually Changed (and What Didn't)
A look at how the threats facing ordinary people and the businesses they deal with have shifted over the decades, and why some of the oldest tricks still work best.

Key points
- Phishing, where criminals send fake emails to trick people into giving up passwords, remains the single most common way attackers break into organisations in 2024.
- Data breaches reported to US regulators have risen sharply over the past decade, with the Identity Theft Resource Center recording 3,205 incidents in the United States in 2023 alone.
- Ransomware, malicious software that locks a company's files until a payment is made, did not exist as a mainstream criminal business model before roughly 2013.
- Regulatory pressure has grown: the FTC (Federal Trade Commission, the main US consumer-protection regulator) now has teeth on breach notification, and the ICO (Information Commissioner's Office, the UK privacy regulator) can fine companies up to four percent of global turnover.
- Despite decades of advances in security tools, stolen passwords and unpatched software remain the two most common entry points criminals use.
What has actually changed since the early internet?
A great deal changed in the tooling. Almost nothing changed in the fundamentals.
Thirty years ago a criminal who wanted to steal customer data had to get physically close to it. Today the same criminal can sit anywhere on the planet, buy a list of stolen passwords for a few dollars on a criminal marketplace, and try them against a company's login page in minutes. The scale is different. The ambition is the same.
What shifted most visibly is the money. Ransomware turned data theft into a repeatable, industrialised business. Criminal groups now run help desks, publish press releases, and offer 'customer service' to victims trying to pay up. That is new. The underlying trick, getting inside a network by fooling one employee or exploiting one unpatched flaw, is as old as email.
Why do old attacks still work?
Because people are busy, and busy people click things.
Phishing works in 2024 for the same reason it worked in 1998: a well-crafted fake email is hard to spot, especially when someone is distracted. Security researchers consistently find that even staff at technology companies fail simulated phishing tests at meaningful rates. Training helps. It is not a cure, but it measurably reduces the number of people who hand over credentials.
Unpatched software is the other persistent problem. When a software maker releases a security fix, criminals read the release notes and immediately start scanning the internet for companies that haven't applied it yet. The window between a patch being published and criminals using the flaw it describes is now measured in hours, not weeks.
What does this mean for ordinary people?
If a company you deal with suffers a breach, the data most likely taken includes your name, email address, password hash (an encoded version of your password), and sometimes payment card details or your home address.
The practical steps haven't changed much either. Use a different password for every site, ideally generated by a password manager (an app that creates and stores complex passwords for you). Turn on two-factor authentication, which means a site sends a second code to your phone before letting anyone log in, so a stolen password alone isn't enough. Check whether your email address appears in known breach databases at sites run by security researchers.
None of that is exciting. It works, though.



