Skip to content

Cybersecurity Statistics 2026: Attacks, Breaches, Costs and How Attackers Get In

Cybersecurity statistics for 2026, sourced to Verizon, IBM, the FBI, Microsoft and CrowdStrike: attack volume, breach costs, entry points, ransomware and AI.

Invadel TeamSeptember 14, 20268 min read

Most cybersecurity statistics online are copies of copies. The number gets rounder each time and the source falls off. This page goes back to the reports themselves: the 2026 editions of Verizon’s DBIR and IBM’s Cost of a Data Breach, the FBI’s 2025 Internet Crime Report, Microsoft’s Digital Defense Report, CrowdStrike’s Global Threat Report, Sophos, Chainalysis, the Identity Theft Resource Center and the Anti-Phishing Working Group. Every figure below links to where it came from, with the sample size where it is a survey. We update the page as each annual report lands.

How to cite: link to this page or to the primary source beside each figure. Where two reports disagree, both are shown.

1. How many attacks happen

A note on a number you will see elsewhere: “a cyber attack every 39 seconds” traces to a 2007 University of Maryland honeypot study of brute-force login attempts against four test computers. It is not a measure of attacks on organizations and we do not use it.

2. What a breach costs

  • $4.99 million: the global average cost of a data breach in 2026, a record, up 12% in a year. (IBM Cost of a Data Breach Report 2026, 602 organizations)
  • $11.5 million: the average in the United States, more than double the global figure. (IBM 2026)
  • $6.64 million in healthcare, $6.3 million in financial services, $5.2 million in energy. (IBM 2026)
  • 247 days: the mean time to identify and contain a breach (183 to identify, 64 to contain). Breaches that ran past 200 days cost $5.65 million against $4.32 million for shorter ones. (IBM 2026)
  • AI-enabled breaches averaged $6 million, about $1 million more than the average, and were one in four malicious breaches, up 56%. (IBM 2026)
  • Organizations using security AI and automation extensively cut breach costs by almost $2 million. One in four still have not adopted them. (IBM 2026)
  • Cyber insurance claims averaged $116,000 in 2025, down 19%, while frequency rose 3%. Ransomware claims averaged $269,000. (Coalition 2026 Cyber Claims Report)
  • Small and medium-sized enterprises averaged $264,000 per incident in insurer claims data, up about 30%. (NetDiligence Cyber Claims Study 2025)

Our guide to what a penetration test costs puts those figures next to the price of finding the problem first.

3. How attackers get in

  • 31% of breaches started with the exploitation of a vulnerability in 2025, the first time in the DBIR’s nineteen years that it beat stolen credentials. Credential abuse as the initial vector fell to 13%, though credentials still appeared somewhere in 39% of breaches. (Verizon 2026 DBIR)
  • 62% of breaches involved the human element. Social engineering on mobile devices succeeded 40% more often than email phishing. (Verizon 2026 DBIR)
  • 48% of breaches involved a third party, a 60% increase in one year. (Verizon 2026 DBIR)
  • Phishing was the initial vector in 17% of breaches, at an average cost of $5.9 million. (IBM 2026)
  • Among ransomware victims, the root cause was malicious email 26%, phishing 24%, compromised credentials 23%, exploited vulnerabilities 18%, brute force 6%. The entry point was an exposed application or system in 38% of cases, a user device in 30%, a firewall in 21%, a VPN in 8%. (Sophos State of Ransomware 2026, 2,158 organizations)
  • 42% of vulnerabilities exploited by adversaries in 2025 were exploited before public disclosure. 40% of China-linked exploitation targeted internet-facing edge devices. (CrowdStrike 2026 Global Threat Report)
  • In cloud environments, exploited third-party software vulnerabilities were 44.5% of primary entry vectors in the second half of 2025, up from 2.9% in the first half, while weak or absent credentials fell from 47.1% to 27.2%. (Google Cloud Threat Horizons Report, H1 2026)
  • Only 26% of known exploited vulnerabilities were fully remediated during 2025, down from 38%; the median time to full remediation rose from 32 to 43 days, while organizations had 50% more critical vulnerabilities to patch. (Verizon 2026 DBIR)

What this means for testing: the three vectors that account for most breaches (unpatched exposed software, credentials, people) are exactly what a penetration test is built to find before someone else does.

4. How fast attacks move

  • The average eCrime breakout time, from initial access to lateral movement, fell to 29 minutes in 2025. The fastest observed was 27 seconds. In one intrusion data exfiltration began within four minutes. (CrowdStrike 2026)
  • The gap between a vulnerability’s disclosure and mass exploitation in the cloud collapsed from weeks to days; React2Shell (CVE-2025-55182) was exploited within 48 hours of disclosure. (Google Cloud Threat Horizons, H1 2026)
  • Identity-based attacks rose 32% in the first half of 2025. More than 97% of them are password attacks, and phishing-resistant MFA blocks over 99%. (Microsoft Digital Defense Report 2025)

5. Ransomware and extortion

  • Ransomware was present in 48% of breaches in 2025, up from 44%. 96% of ransomware victims whose size was known were small and medium-sized businesses. (Verizon 2026 DBIR)
  • More than 52% of attacks with a known motive were driven by extortion or ransomware; espionage was 4%. Attackers sought to steal data in 80% of the incidents Microsoft investigated. (Microsoft Digital Defense Report 2025)
  • Ransomware payments fell to about $820 million in 2025, down 8%, as the share of victims paying reached an all-time low of 28%. The median payment still rose to $59,556 from $12,738. (Chainalysis 2026)
  • Verizon’s median ransom payment fell below $140,000 and 31% of victims paid; Sophos found 48% of victims whose data was encrypted paid, with a median payment of $769,000; Coalition’s policyholders refused 86% of the time. The spread reflects who each report counts. (Verizon; SophosCoalition)
  • Recovery cost an average of $1.7 million excluding any ransom, up 11%. (Sophos 2026)

The full set is on our ransomware statistics page.

6. AI on both sides

  • One in four malicious breaches was AI-enabled in 2026, a 56% increase, and shadow AI incidents hit 43% of breached organizations, up from 20%. (IBM 2026)
  • More than 20% of organizations reported a breach targeting their AI models or applications; the causes were compromised APIs, applications or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%). (IBM 2026)
  • Employees using unapproved AI tools tripled from 15% to 45% in a single year. (Verizon 2026 DBIR)
  • AI-enabled adversary operations increased 89% year over year, with malicious prompts injected at more than 90 organizations. (CrowdStrike 2026)
  • The FBI received more than 22,000 complaints referencing AI in 2025, with adjusted losses above $893 million. (FBI IC3 2025)
  • 61% of organizations rank AI as their top data security risk. (Thales 2026 Data Threat Report, 3,120 respondents)

We test AI systems as a service line; the scope is on the AI and LLM penetration testing page.

7. Data breaches by the numbers

  • 3,322 publicly reported data compromises in the United States in 2025, a record, up 79% over five years. Victim notices fell to 278.8 million from 1.37 billion because 2025 had no mega-breaches. (ITRC 2025 Annual Data Breach Report)
  • 70% of breach notices gave no information about how the attack happened, up from 65%. (ITRC 2025)
  • Financial services had the most compromises (739), then healthcare (534), professional services (478), manufacturing (299) and education (188). (ITRC 2025)
  • Only about half of sensitive data stored in the cloud is encrypted: 47%. (Thales 2026)

8. People

  • 33.1% of employees worldwide click on a simulated phishing email before any training; 37.1% in North America. After a year of training the rate falls 86%. (KnowBe4 2025 Phishing by Industry Benchmarking Report, 14.5 million users)
  • 44.2% of vendor email compromise messages that were read were engaged with. (Verizon 2026 DBIR)
  • Business email compromise cost $3.046 billion in reported US losses in 2025; 86% of it moved by wire or ACH. (FBI IC3 2025)

Sources

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation