Verizon's 2026 Data Breach Investigations Report (DBIR) analyzed more than 22,000 confirmed breaches across 145 countries, the largest dataset in the report's 19-year history. Its headline finding: vulnerability exploitation overtook credential abuse as the top initial access vector, while ransomware, third-party risk, and AI-assisted attacks all grew sharply.

This is the 19th edition of the report, and it partnered with Anthropic, Qualys, Tenable, Tenchi Security, Fastly, and DTEX to go beyond counting incidents. The 2026 DBIR measures how fast organizations patch, how long vendors leave multi-factor authentication (MFA) disabled, and how threat actors are operationalizing generative AI (GenAI) in live campaigns.

The ten numbers below are the ones worth building next year's security roadmap around.


Key data points from the 2026 DBIR

  1. Vulnerability exploitation overtook credential abuse as the top initial access vector, rising from 20% to 31% of breaches year over year, a 55% increase.
  2. Credential abuse still appears in 39% of breaches overall, remaining the most common chokepoint across attack patterns even as its role as the first entry point declined.
  3. Ransomware appeared in 48% of all breaches, yet 69% of victims refused to pay, pushing the median payment down to $139,875.
  4. Third-party involvement in breaches jumped 60% in a single year, to 48% of all incidents, after already doubling the year before.
  5. Organizations fully remediated only 26% of known exploited vulnerabilities in 2025, down from 38% the year before.
  6. Even top-performing organizations patch at most 30-40% of known exploited vulnerabilities within the first week, a ceiling that has barely moved in three years.
  7. Threat actors used generative AI across a median of 15 distinct MITRE ATT&CK techniques, with extreme cases spanning 40-50 techniques in a single campaign.
  8. Mobile phishing (voice and SMS) produced click rates roughly 40% higher than email, with pretexting now driving 6% of all breaches.
  9. Shadow AI use among employees tripled to 45% in a year, and 67% still access AI tools through personal, non-corporate accounts.
  10. 89% of organizations had to patch memory safety vulnerabilities in 2025, a bug class first documented three decades ago.

What is Verizon's Data Breach Investigations Report

Verizon's 2026 Data Breach Investigations Report logo

The Verizon Data Breach Investigations Report (DBIR) is an annual analysis of confirmed data breaches and security incidents worldwide, published since 2008. The 2026 edition, its 19th, covers data from October 2024 through November 2025 and draws on more than 31,000 security incidents, including over 22,000 confirmed breaches across 145 countries — the largest dataset in the report's history.

How the data comes together

Verizon compiles the report with contributions from nearly 100 partner organizations, each supplying breach and incident data from its own operations. The DBIR team normalizes this data into a common framework built around threat actors, actions, assets, and attributes, which is what lets a hospital breach in Germany and a ransomware case in Ohio show up as comparable data points.

Unlike vendor threat reports built on a single company's telemetry, the DBIR aggregates data across industries, company sizes, and geographies. That breadth is what makes it a reference point for security budgeting and board-level reporting rather than a single-vendor sales narrative.

What's new in the DBIR 2026 dataset

The partner list determines what the report can actually measure, and 2026 brought an addition that reshapes its scope. Anthropic contributed enforcement data on 793 threat actors flagged by its Safeguards Team between March 2025 and February 2026, mapped to specific MITRE ATT&CK techniques.

It's the first time a frontier AI lab has supplied this kind of dataset to the DBIR, and it lets the report quantify GenAI misuse with actual enforcement numbers instead of estimates.

The full Verizon 2026 Data Breach Investigations Report is available directly from Verizon.


10 stats from the 2026 DBIR that should reshape your priorities

These ten findings mark the clearest shifts in the 2026 DBIR: attackers are exploiting vulnerabilities faster than defenders patch them, third-party risk has become a primary breach vector, and generative AI is scaling known attack techniques rather than inventing new ones. Each one points to a specific gap in most current security programs.

1. Vulnerability exploitation is now the #1 initial access vector

Exploitation of vulnerabilities climbed from 20% of breaches in the 2025 report to 31% in 2026, a 55% increase. Credential abuse, which held the top spot for years, dropped from 22% to 13% over the same period as the first recorded action in a breach.

The median organization had to patch 50% more CISA Known Exploited Vulnerabilities (KEV) than the year before, 16 critical CVEs versus 11, while full remediation rates fell to 26%. More vulnerabilities, slower patching, and attackers automating exploitation with AI assistance is not a combination that favors defenders. If your patching cadence has not changed since 2023, the data says you are statistically behind.

2. Credential abuse still touches 39% of every attack chain

Vulnerability exploitation taking the top initial-access spot doesn't mean stolen credentials stopped mattering. The 13% figure only counts the first recorded step in a breach. When the DBIR tracks credential abuse at any point in an attack, it shows up in 39% of breaches, making it the most common chokepoint across nearly every attack pattern in the report.

Verizon DBIR trend chart, 2022-2026, showing credential abuse holding around 39% of breaches while vulnerability exploitation climbs from 6% to 31%]
Initial access vectors (source: DBIR 2026)

Attackers are also blending in better. Many have abandoned tools like Cobalt Strike in favor of legitimate remote access paths, desktop-sharing software and VPNs, which makes credential-based lateral movement harder to catch with signature-based detection. MFA is table stakes at this point, but it is not sufficient on its own.

The password hygiene numbers explain why credential abuse persists. Credentials themselves show up as a stolen data type in 28% of breaches, and password policy is one of the safeguards the DBIR flags as a mitigating control across attack techniques, alongside privilege management and configuration hardening. Basic hardening checks confirm the gap: 97% of assessed devices failed the check for limiting failed login attempts before lockout, and 90% failed to enforce a 15-character minimum length.

3. Ransomware hits 48% of breaches, but victims are paying less

Ransomware grew from 44% to 48% of breaches this year and remains the single most damaging threat category. The counterintuitive part: 69% of ransomware victims refused to pay, and the median payment fell from $150,000 to $139,875.

That combination suggests backup strategies, incident response maturity, and law enforcement disruption are gaining ground. But the sheer volume of ransomware incidents, fueled by initial access brokers and infostealer markets, means treating it as a problem solved by backups alone is a mistake. The organizations that came out of an attack in the best shape were the ones that never had to negotiate.

4. Third-party breaches now account for 48% of all incidents

Third-party involvement in breaches reached 48%, up from 30% a year earlier, a 60% jump on top of a doubling the year before that. Several of 2025's most disruptive breaches involved multiple compromised vendors at once.

The root causes are ordinary: missing MFA on cloud accounts, excessive permissions, and weak passwords. Only 23% of third-party organizations fully remediated MFA gaps on their cloud accounts, though half of all MFA findings were resolved within a month.

Weak passwords and permission misconfigurations fared far worse: the median time to resolve half of those findings stretched to almost eight months. Annual vendor questionnaires cannot catch a problem that takes eight months to fix on the vendor's side.

An eight-month remediation window is exactly what happens when vendor access lives outside your visibility. Passwork's role-based access control lets you grant, log, and revoke vendor credentials from a central vault, with a full audit trail instead. Explore how it fits your third-party access workflow.

5. Only 26% of critical vulnerabilities were fully remediated

Full remediation of CISA KEV vulnerabilities dropped from 38% to 26%, and the median time to patch stretched from 32 to 43 days. The share of vulnerabilities left completely unremediated grew from 12% to 16%.

The survival curve is worse than the averages suggest. By day 28 after detection, 35% of KEV vulnerabilities remained open, representing 184 million vulnerability instances (up from 31 million three years earlier). Detection volume grew nearly eightfold, from 68.7 million records in 2022 to 527.3 million in 2025, while patching capacity barely moved.

Patching alone will not close that gap. Since fixing everything isn't realistic at current volumes, remediation has to be ranked by exploitation risk rather than CVSS score alone. The report's clearest evidence for this: 80% of persistently exploited vulnerabilities were more than two years old, meaning attackers are largely working through vulnerabilities organizations already knew about and chose not to prioritize.

The 8x growth in detection volume (68.7M → 527.3M records) against flat patching capacity is a volume problem that patching speed alone cannot solve — you'd need roughly 8x more remediation throughput just to stay even, and no organization scaled that fast. So patch faster isn't a realistic fix on its own.

6. Threat actors are using generative AI across a median of 15 ATT&CK techniques

Verizon's collaboration with Anthropic produced one of the report's most substantial contributions: analysis of 793 threat actors who violated Anthropic's acceptable use policy between March 2025 and February 2026. The median actor used AI assistance across 15 distinct MITRE ATT&CK techniques.

The extreme cases are the more telling data point. Some campaigns spanned 40-50 techniques in multi-session, agentic operations where the AI functioned as a co-developer across the full attack chain.

That scale hasn't produced novel threats. Less than 1% of these actors fell into the high or critical risk category, and most AI-assisted malware reused well-documented techniques: the median observation had 55 existing malware examples performing the same function. Only 2.5% involved genuinely rare techniques.

AI is scaling what already works, not generating new attack classes. Detection engineering teams don't need to chase novel AI-generated tactics yet. But the speed and volume at which attackers now operate leaves 2024-era mean time to detect (MTTD) and mean time to respond (MTTR) benchmarks already outdated.

7. Mobile phishing produces 40% higher click rates than email

Phishing simulation data shows email click rates at a median 1.4%, while phone-centric methods (voice and SMS) reach closer to 2%, a 40% higher success rate. Pretexting, live manipulation over phone or text, now accounts for 6% of all breaches and is increasingly the initial access vector for ransomware and extortion attacks.

Countermeasures for phishing and pretexting are not the same thing. Email training teaches people to spot a suspicious link. Pretexting requires business-level rules, training help desk staff not to be helpful when someone is manipulating them into resetting a password or disabling MFA. Security awareness programs built only around email simulations are testing for the wrong threat.

8. Shadow AI use tripled to 45% of employees

In the 2025 DBIR, 15% of employees were regular AI users on corporate devices. That number tripled to 45% in 2026. Meanwhile, 67% of users access AI services through non-corporate accounts, a modest drop from the prior year but still a large unauthorized surface.

Shadow AI is now the third most common non-malicious insider action detected in data loss prevention (DLP) datasets, up fourfold year over year. Source code is the most common data type submitted to unsanctioned GenAI tools, followed by images and structured data. In 3.2% of DLP policy violations, research and technical documentation went to external AI systems, a direct intellectual property exposure.

9. 60-70% of known exploited vulnerabilities remain open at day 7, regardless of maturity

The most sobering number in the report: by day 7 after detection, an aggressive target by any standard, 60% to 70% of CISA KEV vulnerabilities remain unpatched. That figure has barely moved across three years of additional tooling, process investment, and regulatory pressure.

Verizon DBIR vulnerability remediation survival curve, 2022-2025, showing the declining share of unpatched CISA KEV vulnerabilities at day 7, day 28, and day 90 from initial detection
CISA KEV vulnerability survival analysis: four-year comparison (source: DBIR 2026)

Verizon's team calls this a speed of light limit, a practical ceiling on how fast vulnerability remediation can move at current resource levels. Even top-performing organizations fix at most 30-40% of KEV instances in the first week.

Prioritization now decides the outcome: which vulnerability gets patched first matters more than how many get patched. Ranking by actual exploitation activity beats relying on CVSS (Common Vulnerability Scoring System) scores alone. Nearly half of KEV vulnerabilities show persistent exploitation, active on 96% of days on average, according to the report.

10. 89% of organizations still ship memory safety vulnerabilities

The DBIR's Common Weakness Enumeration (CWE) analysis found that 89% of organizations had to patch memory safety issues, buffer overflows, use-after-free bugs, out-of-bounds reads, three decades after Smashing the Stack for Fun and Profit first described the class of bug in Phrack in 1996. The report's own framing: "What are we still doing here?"

The top five CWE categories, memory safety, access control, resource lifecycle management, improper neutralization, and file handling, showed up in more than 75% of organizations. When these flaws surface during development, the median time to fix half of them runs six to seven months.

For teams that build or procure software, that argues for memory-safe languages (Rust, Go, C#) in development standards, an approach the DBIR explicitly ties to CISA's Secure by Design initiative. The cheapest patch is the vulnerability that never ships.


Verizon 2026 DBIR: The numbers at a glance

The tables below summarize the categories not covered in depth above, useful as a quick reference against your own metrics.

Breach patterns, three-year trend

Pattern 2026 2025 2024
System intrusion 61% 53% 36%
Social engineering 17% 17% 22%
Basic web application attacks 10% 18% 9%
Miscellaneous errors 8% 12% 25%
Privilege misuse 3% 7% 8%

Actors, motives, and impact

Metric 2026 value
External actors 88% of breaches
Internal actors 12% (down from 18%)
State-affiliated actors ~15% of breaches
Confirmed data disclosure 82% of incidents
Integrity impact 64% of incidents
Availability impact 53% of incidents

Assets and infrastructure exposure

Servers remain the top target, followed by person as a social engineering target. Network devices rose sharply and are now roughly tied with user devices at around 5% each. Verizon's researchers also identified 45,000-50,000 end-of-life cellular routers with publicly accessible management interfaces in operational technology-adjacent sectors, a finding worth flagging to any team managing remote industrial infrastructure.


Three strategic shifts the 2026 DBIR demands

The 2026 DBIR calls for a faster, better-prioritized version of the security program most organizations already run. Patching, MFA, credential hygiene, vendor oversight, and security awareness all still work. The problem is that threat volume has outgrown most teams' capacity to respond at the same pace.

The 2026 DBIR points to three shifts in priority: speed over completeness, third-party visibility over point-in-time trust, and AI-scaled defense over AI-scaled fear.

Speed matters more than completeness

You cannot patch everything, and the data proves it: even top performers fix at most 40% of critical vulnerabilities in the first week. Prioritization based on real exploitation activity, not CVSS score alone, is the only approach that scales with 527 million annual vulnerability detections.

Third parties are part of your attack surface

When nearly half of all breaches involve a third party, vendor oversight carries the same weight as internal controls. A TPRM (third-party risk management) process built on annual questionnaires cannot catch an eight-month MFA gap on a vendor's cloud console.

AI is scaling known techniques, not inventing new ones

Attackers use GenAI to run existing playbooks faster and at higher volume, according to Anthropic's analysis in the 2026 DBIR. Your existing defenses still apply. They just need to operate at the speed and scale attackers have already reached.

Credential hygiene and vendor access gaps keep showing up as root causes because nobody owns continuous visibility into who has access to what, or for how long. Try Passwork free and see how a structured vault closes that gap in your own environment.

Frequently Asked Questions

Frequently Asked Questions

What is the Verizon 2026 DBIR?

The Verizon 2026 Data Breach Investigations Report is the 19th edition of Verizon's annual analysis of confirmed data breaches and security incidents worldwide. It draws on more than 22,000 confirmed breaches across 145 countries, contributed by nearly 100 partner organizations including incident responders, insurers, and threat intelligence firms.

What is the top initial access vector in the 2026 DBIR?

Vulnerability exploitation is the top initial access vector in the 2026 DBIR, accounting for 31% of breaches, up from 20% the year before. It overtook credential abuse, which fell from 22% to 13% over the same period.

How much do companies pay in ransomware attacks according to the 2026 DBIR?

The median ransomware payment in the 2026 DBIR is $139,875, down from $150,000 the year before. Despite ransomware appearing in 48% of all breaches, 69% of victims refused to pay, suggesting stronger backup and incident response practices.

Why did third-party breaches increase so sharply in 2026?

Third-party breaches rose to 48% of all incidents, a 60% increase in one year, largely because of unresolved MFA gaps, excessive cloud permissions, and weak vendor password practices. Only 23% of third-party organizations fully fixed MFA issues on their cloud accounts.

Are attackers actually using AI to hack organizations?

Yes. Anthropic's contribution to the 2026 DBIR found 793 threat actors using generative AI across a median of 15 MITRE ATT&CK techniques, with some campaigns spanning 40-50 techniques. Most AI-assisted attacks scaled known, well-documented techniques rather than creating novel ones.

How fast should organizations patch critical vulnerabilities?

The 2026 DBIR found that even top-performing organizations only remediate 30-40% of known exploited vulnerabilities within the first week. The recommendation is to prioritize by actual exploitation activity and asset exposure rather than aiming for full remediation, which the data shows is unrealistic at current volumes

Cybersecurity news recap: The month AI agents started attacking on their own
A GPT-5.6 agent escaped its sandbox and breached Hugging Face infrastructure. SonicWall shipped two 0-days that forced a full password and TOTP reset. IBM’s 2026 breach cost report hit a record $4.99 million. Here’s what happened in cybersecurity this July and what your team needs to patch first.
Shadow AI: The hidden threat costing enterprises $670K per breach
Shadow AI costs enterprises $670K extra per breach — and most of it traces back to credentials pasted into public LLMs. Learn what shadow AI actually looks like, why it’s harder to stop than shadow IT, and how to govern it.
Why password complexity rules are dead (and what to use instead)
NIST droped mandatory password complexity rules. Here’s why composition requirements backfired, what SP 800-63B-4 recommends instead, and a 5-step checklist to migrate your Group Policy off the 2010-era checklist.