Data breach statistics come from three kinds of source, and they measure different things: cost studies (IBM interviews breached organizations), breach counts (the Identity Theft Resource Center reads every public notice; HHS publishes every healthcare breach over 500 records), and incident analyses (Verizon’s DBIR). This page takes the current edition of each and labels which is which. Every figure is linked to where it came from. We update the page as the annual reports land.
How to cite: link to this page or to the primary source beside each figure. Cost figures are averages across IBM’s 602 studied organizations and do not describe any single incident.
1. What a data breach costs
- $4.99 million: the global average cost of a data breach in 2026, a record, up 12% in a year. (IBM Cost of a Data Breach Report 2026, 602 organizations breached between March 2025 and February 2026)
- $11.5 million: the average cost in the United States, the most expensive country and more than double the global average. A year earlier it was $10.22 million. (IBM 2026)
- By industry: healthcare $6.64 million (down 10.5% from $7.42 million but still the highest), financial services $6.3 million, energy $5.2 million. (IBM 2026)
- By vector: phishing was the initial vector in 17% of breaches at an average cost of $5.9 million. AI-enabled breaches averaged $6 million. (IBM 2026)
- Detection and escalation costs plus lost business from operational disruption and customer churn made up nearly two-thirds of the total. (IBM 2026)
- Organizations that used security AI and automation extensively spent almost $2 million less per breach; one in four still have not adopted these tools. (IBM 2026)
- For small and medium-sized enterprises the insurer data is the better guide: $264,000 average total incident cost, of which $152,000 was crisis services (forensics, legal, notification). (NetDiligence Cyber Claims Study 2025, 10,402 claims)
- 62.5% of breached small businesses put their total financial impact above $250,000, and 38.3% raised prices to cover it. (ITRC 2025 Business Impact Report, 662 owners and executives)
2. How long a breach lasts
- 247 days: the mean time to identify and contain a breach, 183 days to identify and 64 to contain, up 2.5% from the previous year. (IBM 2026)
- Breaches with a lifecycle over 200 days cost $5.65 million; under 200 days, $4.32 million. (IBM 2026)
- Breaches through the supply chain or removable media took the longest: 258 days. (IBM 2026)
- The attacker’s side of the clock is faster: the average time from initial access to lateral movement fell to 29 minutes, and in one intrusion data exfiltration began within four minutes. (CrowdStrike 2026 Global Threat Report)
3. How many breaches there are
- 3,322 publicly reported data compromises in the United States in 2025, a record, up from 3,152 in 2024 and 3,202 in 2023, and up 79% over five years. (ITRC 2025 Annual Data Breach Report)
- 278,827,933 victim notices in 2025, down 79% from 1.37 billion in 2024, because 2025 had no mega-breach on the scale of 2024’s. (ITRC 2025)
- 70% of breach notices (2,324) gave no information about the attack, up from 65%. In 2020 nearly every notice explained how the breach happened. (ITRC 2025)
- By industry: financial services 739 compromises, healthcare 534, professional services 478, manufacturing 299, education 188. (ITRC 2025)
- Verizon analyzed 22,000 confirmed breaches for the 2026 DBIR, from more than 31,000 incidents across 145 countries. (Verizon 2026 Data Breach Investigations Report)
4. How breaches happen
- 31% of breaches started with the exploitation of a vulnerability, the first year it beat stolen credentials as the top entry point. Credential abuse as the initial vector fell to 13% but appeared somewhere in 39% of breaches. (Verizon 2026 DBIR)
- 62% of breaches involved the human element. (Verizon 2026 DBIR)
- Attackers sought to steal data in 80% of the incidents Microsoft’s responders investigated. (Microsoft Digital Defense Report 2025)
- Ransomware was present in 48% of breaches, and 70% of ransomware insurance claims were dual extortion, with data stolen as well as encrypted. Data-theft claims cost more than twice as much as encryption-only claims. (Verizon 2026 DBIR; Coalition 2026 Cyber Claims Report)
- Only 26% of known exploited vulnerabilities were fully remediated during 2025, down from 38%, and the median time to remediate rose from 32 to 43 days. (Verizon 2026 DBIR)
- Human error was cited as the leading cause of breach by 28% of organizations. Only 34% say they know where all their data is stored and 39% can fully classify it; 47% of sensitive data in the cloud is encrypted. (Thales 2026 Data Threat Report, 3,120 respondents)
- More than 20% of organizations reported a breach targeting their AI models or applications, caused by compromised APIs, applications or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%). Shadow AI incidents hit 43% of breached organizations, up from 20%. (IBM 2026)
What this means for testing: the two leading vectors, an exploitable vulnerability on an exposed system and a stolen credential, are exactly what a penetration test is designed to find first. The types of penetration testing guide maps each vector to the test that covers it.
5. Third-party and supply chain breaches
- 48% of breaches involved a third party in some capacity, a 60% increase in one year: vendors, SaaS providers, cloud platforms, contractors and OAuth integrations. (Verizon 2026 DBIR)
- Supply chain attacks affected 1,251 entities in 2025 against 660 in 2024, nearly double, and roughly twice the 2021 level. (ITRC 2025 via HIPAA Journal)
- Supply chain breaches took the longest to resolve, 258 days against 247 across all vectors. (IBM 2026)
- Business associates, the vendors of healthcare organizations, were responsible for 35.8% of large healthcare breaches and the majority of the mega-breaches. The largest breach of 2025, at Conduent Business Services, affected 62.2 million people through a single vendor. (HIPAA Journal)
- 44.2% of vendor email compromise messages that were read were engaged with. (Verizon 2026 DBIR)
Our third-party penetration testing page covers what to require from a vendor and how an independent test of their system is scoped.
6. Healthcare data breaches
- 804 healthcare data breaches of 500 or more records were reported to HHS for 2025, the most ever, against 738 in 2024 and 749 in 2023. (HIPAA Journal, tally of the HHS Office for Civil Rights breach portal)
- More than 138.5 million individuals had protected health information exposed in 2025, 379,306 a day. In 2024 the figure was 792,226 a day, inflated by the Change Healthcare attack’s 192.7 million. (HIPAA Journal)
- Hacking and IT incidents caused more than 80% of large healthcare breaches in 2025, up from 49% in 2019. (HIPAA Journal)
- Where the data was: network servers 61.5% of breaches, compromised email accounts 24.9%. Who was breached: healthcare providers 57.5%, business associates 35.8%, health plans 6.5%. (HIPAA Journal 2025 Healthcare Data Breach Report)
- The largest of 2025: Conduent Business Services 62.2 million, Aflac 13,924,906, Yale New Haven Health System 5,556,702, Episource 5,418,866, Blue Shield of California 4,700,000 (tracking-tool disclosure), DaVita 2,689,826 (ransomware). (HIPAA Journal)
- OCR closed 21 enforcement actions in 2025 and collected $8,330,066 in penalties; 76% of those actions cited a failure to perform a risk analysis. The New York Attorney General separately fined Orthopedics NY $500,000 over a breach affecting 656,086 people. (HIPAA Journal)
- The average healthcare breach cost $6.64 million. (IBM 2026)
- January to April 2026: 252 large healthcare breaches, 9.5% fewer than the same period of 2025. (HIPAA Journal)
The testing side is on our HIPAA penetration testing page and in the medical device penetration testing guide.
7. What the numbers say to do
- Shorten the 247 days. Breaches found in under 200 days cost $1.3 million less. Detection is a control; a red team exercise measures whether yours fires.
- Patch what is exposed, in order. 31% of breaches start with a vulnerability and only 26% of known exploited ones get fully fixed. A vulnerability assessment ranks them by what is reachable.
- Treat vendors as part of the perimeter. Half of breaches involve a third party. Ask for the test report; see how to choose a penetration testing company for what a real one contains.
- Do the risk analysis. 76% of OCR penalties cite its absence. A penetration test report is the evidence that one happened; the sample report shows the format.
Sources
- IBM, Cost of a Data Breach Report 2026
- Identity Theft Resource Center, 2025 Annual Data Breach Report and 2025 Business Impact Report
- Verizon, 2026 Data Breach Investigations Report
- HIPAA Journal, Healthcare Data Breach Statistics and 2025 Healthcare Data Breach Report, from the HHS OCR breach portal
- Thales, 2026 Data Threat Report
- Microsoft, Digital Defense Report 2025
- CrowdStrike, 2026 Global Threat Report
- Coalition, 2026 Cyber Claims Report
- NetDiligence, Cyber Claims Study 2025
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →