2026 Verizon DBIR Report: Executive Threat Intelligence Briefing

Illustration of a glowing global data sphere wrapped in layered threat-intelligence rings representing vulnerabilities, ransomware, and third-party risk, visualizing key findings from the 2026 Verizon DBIR report.

⚡ TL;DR — Key Takeaways

  • Macro threat flip: The 2026 Verizon DBIR report confirms that exploitation of vulnerabilities has overtaken credential abuse as the leading initial access vector, reaching 31% of breaches (up from 20%, a 55% relative increase), while credential abuse fell to 13% from 22%.
  • Ransomware economics diverging from payment reality: Ransomware appeared in 48% of all breaches (up from 44%), yet 69% of victims refused to pay (up from 65%), and the median ransom payment continued falling to $139,875 from $150,000 the prior year.
  • Third-party exposure surging: Breaches with third-party involvement jumped 60% year-over-year to 48% of all breaches, while cloud-based third-party MFA exposures showed only 23% full remediation and weak password/permission misconfigurations took nearly eight months to half-resolve.
  • Internal Shadow AI crisis: 67% of users are accessing GenAI platforms through non-corporate accounts on corporate devices, and Shadow AI is now the third most common non-malicious insider DLP violation, a fourfold increase year-over-year, with source code the most commonly leaked asset type.

The 2026 Verizon DBIR report is the 19th edition of Verizon’s annual analysis and represents the largest dataset the report has ever examined: more than 31,000 actual real-world security incidents, of which more than 22,000 were confirmed data breaches, spanning organizations in 145 countries. This scale reflects both an expanded contributor base and doubled-down bulk data collection from major public extortion and espionage-motivated campaigns and ransomware actor activity, though the report notes this information overload measurably slowed its own data pipelines this year.

Threat Actor Distribution (macro level, all breaches):

  • External: 88% (up from prior year, though still below historical highs that routinely exceeded 90%)
  • Internal: 12% (down from 18% the prior year)
  • Partner and Multiple actor combinations: relatively uncommon, barely moving the needle against the dominant External vs. Internal split

External Actor Sub-Varieties: Organized criminal groups dominate the External category, driven largely by the continued popularity of ransomware and extortion-centric attacks. State-affiliated actors make up the bulk of the remainder, appearing in close to 15% of breaches.

Internal Actor Sub-Varieties: End-users account for 75% of internal actor cases; System administrators account for 19%.

Actor Motive Distribution:

  • Financial gain remains the dominant driver for cybercriminals, consistent with every prior DBIR edition.
  • Espionage is present to a much smaller degree, primarily associated with state-affiliated actors, though the same motive surfaces among internal actors exfiltrating proprietary data for competitors or personal benefit.

Overall Attribute Impact (across all incidents, n=31,850):

  • Confidentiality (confirmed data disclosure): 82% of incidents
  • Integrity (unauthorized modification): 64% of incidents
  • Availability (systems taken offline/encrypted): 53% of incidents, with a significant year-over-year rise in the Interruption variety specifically, partly a VERIS coding refinement and partly driven by large-scale ransomware outages such as the April 2025 Marks & Spencer incident, which caused an estimated £300 million in losses from prolonged operational disruption.

From a GRC and macro risk perspective, this year’s dramatic 55% surge in perimeter vulnerability exploitation—coupled with the simultaneous drop in direct initial credential abuse—demands an immediate reprioritisation of the corporate security roadmap. For years, executive boards have treated identity access management as the silver bullet for perimeter defense.

While maintaining strict identity hygiene remains non-negotiable, the 2026 dataset proves that automated, stateful asset scanning by external threat actors has officially weaponised unpatched software layers into the primary corporate entry vector. GRC directors must use these metrics to shift capital allocation away from passive employee awareness training and directly toward real-time attack surface management, continuous vulnerability scanning, and hardened external boundary configurations.

SECTION 1: INITIAL ACCESS VECTORS & PATCH VELOCITY

Initial Access Vector Breakdown (non-Error, non-Misuse breaches, n=19,905–20,023)

Vector2026 ValuePrior YearTrend
Exploitation of vulnerabilities31%20%+55% relative increase
Credential abuse13%22% (2025 DBIR)Down; would have been 16% without the new Pretexting split
Phishing16%16%Flat
Pretexting (newly tracked as distinct vector)6%N/A(newly separated)New category
Credential abuse (all instances at any point in breach progression, not just initial vector)39%Still the top chokepoint overall

Methodology note: Pretexting was reintroduced as a distinct vector from Phishing this year because the two have materially different mitigation requirements — Phishing is asynchronous (email/text attempting to alter victim behavior), while Pretexting is synchronous and involves an attacker actively building a trusted relationship in real time (phone, chat, or email thread) to manipulate a target into taking a compromising action.

CISA KEV Remediation Breakdown (n=515,170 CVE resolution records; n=13,773 organizations)

Remediation Status2026 ValuePrior Year
Fully Remediated26%38%
Unremediated16%12%
Partially RemediatedRemainder (~58%)
  • Median time to full resolution: 43 days (up from 32 days the previous year — almost two weeks longer)
  • Median number of KEV vulnerabilities per organization requiring patching: 16 in 2025, up from 11 in 2024 — almost 50% more critical vulnerabilities to patch year-over-year

Survival Analysis — “Speed of Light” Metrics (n covers 2022–2025, over 1 billion anonymized vulnerability detection records)

  • Volume growth: 68.7 million vulnerability instances tracked in the 2022 dataset vs. 527.3 million in 2025 — almost eight times the volume.
  • Day 7: Organizations at their very best only remediate 30%–40% of KEV instances in the first week after detection, a rate that has barely moved despite three years of additional tooling and process investment. Somewhere between 60% and 70% of KEV vulnerabilities remain open at Day 7 regardless of year, volume, or organizational maturity.
  • Day 28: 35% of vulnerabilities remained open (up from 27% in 2024) — equivalent to 184 million open vulnerability instances in absolute terms (up from 31 million in 2022).
  • Long tail: Settles at 9%, representing 47 million vulnerability instances that, based on curve trajectory, are simply not being addressed any time soon.
  • Preemptive remediation (patched before CISA KEV inclusion): Fell to 12% in 2025 from 17% in 2024, despite defenders proactively patching a record 63.7 million vulnerability instances in 2025 — a 30% increase over 2024’s 48.9 million. The 2025 DBIR (based on 2024 data) was the historical high water mark for remediation speed; 2025 performance reverted to roughly 2023 levels.
  • Persistent exploitation: Nearly half of KEV-listed vulnerabilities show “Persistent” exploitation activity, meaning detectable on an average of 96% of days. Only 20% of vulnerabilities in the Persistent category were registered in the CVE database in 2024–2025 — the other 80% were older vulnerabilities organizations had roughly two years’ advance notice to patch.
  • Resurgence/re-exploitation model: Based on 1.4 million observations across ~1,000 vulnerabilities over six years, the probability of re-exploitation drops by roughly half at 30 days, again at 90 days, and again by half around nine months; after roughly a year, resurgence probability approaches baseline (as if never exploited).

Beating the global 2026 DBIR median remediation drag of 43 days requires moving completely away from manual spreadsheet triage and enforcing a highly structured, automated Service Level Agreement (SLA) framework. In our operating environments, we utilize automated vulnerability tracking tools linked directly to cloud compliance dashboards to establish an unyielding patching hierarchy.

We mandate a strict 7-day remediation window for any CVE flagged in the CISA Known Exploited Vulnerabilities (KEV) catalog that sits on an internet-facing asset, utilizing automated patch compliance deployment tools to enforce the perimeter. By matching the automated velocity of threat actor scanning scripts with code-level deployment automation, an organization can successfully cross the ‘Speed of Light’ barrier and drop its window of exposure far below the underperforming industry average.

SECTION 2: COMMON WEAKNESS ENUMERATION (CWE) & ROOT CAUSE CODE ANALYSIS

Top 5 Individual CWE Weaknesses (Table 1, n=12,208 organizations — percentage of organizations with this weakness detected among CISA KEV CVEs)

CWE IDWeakness% of Organizations
CWE-125Out-of-bounds Read79%
CWE-122Heap-based Buffer Overflow77%
CWE-416Use After Free77%
CWE-73External Control of File Name or Path77%
CWE-843Access of Resource Using Incompatible Type (“Type Confusion”)76%

To find a weakness present in fewer than 70% of organizations in the vulnerability management dataset, analysts had to go beyond the top 10 — nearly all top-five weaknesses relate to memory safety.

Top-Level CWE Categories (Table 2, n=12,208)

CWE Category IDCategory% of Organizations
CWE-1399Memory Safety89%
CWE-1396Access Control85%
CWE-1416Resource Lifecycle Management80%
CWE-1407Improper Neutralization77%
CWE-1404File Handling77%

Median Codebase Remediation Timeline (Active SDLC Pipelines)

  • The top three CWE categories have a median 50% survival rate of six to seven months before code flaws are corrected and re-submitted for testing.
  • The worst-performing category is Improper Input Validation, with a median 50% survival time of just over 13 months.

Confronting an unyielding 89% top-level systemic exposure rate for Memory Safety vulnerabilities makes it clear that legacy patching cycles are no longer an acceptable risk mitigation strategy. In alignment with the CISA ‘Secure by Design’ directive, our engineering organization has formally initiated a phased architectural migration away from memory-unsafe legacy languages and toward memory-safe alternatives like Rust for all new core backend microservices.

While altering an established Secure Software Development Lifecycle (SSDLC) introduces near-term velocity trade-offs, reducing the structural footprint of vulnerabilities like Out-of-bounds Reads and Buffer Overflows is the only permanent method to eliminate these root-cause flaws before code ever enters a staging repository.

SECTION 3: THE THREE ARCHETYPES OF THIRD-PARTY & SUPPLY CHAIN BREACHES

Third-party involvement in breaches increased 60% year-over-year, reaching 48% of total breaches (up from 30% the previous year — a doubling the year before that as well). The report defines three distinct relationship archetypes based on where the initial access vector occurred and where the compromised data was stored:

Archetype 1 — Vendor in an Organization’s Software Supply Chain: The data and initial vector remain under the victim organization’s custody and control, but the initial vector was made possible by a vulnerability in a vendor product (the majority of single “Exploit vuln” actions referenced throughout the report), or the compromise of the vendor itself with a backdoor inserted into the software — the pattern behind the SolarWinds incident, per publicly disclosed information.

Archetype 2 — Vendor Hosting an Organization’s Data: The initial access occurs against the vendor itself, and the vendor is the direct custodian of the victim organization’s data. Two major sub-categories: the vendor’s infrastructure is breached directly, or the victim’s account within the vendor’s environment is stolen and used against vendor systems — the pattern behind the prior year’s Snowflake-related campaign.

Archetype 3 — Vendor with Connection to an Organization’s Environment: Initial access occurs at the vendor, and attackers move laterally to reach the victim’s data. This can involve a literal network connection leveraged by attackers (the historical Target breach pattern) or the vendor losing credentials to an organization’s internal systems.

The Escalation of Threat Actor RMM Tool Abuse: Deeper telemetry parameters within the system intrusion datasets reveal a critical infrastructure risk vector: the systematic weaponization of legitimate Remote Monitoring and Management (RMM) software arrays. External cybercrime syndicates are increasingly bypassing traditional malware detection barriers by using stolen access credentials to log directly into commercial RMM consoles (such as AnyDesk, ConnectWise, or ScreenConnect). Once inside, attackers leverage these authentic, pre-installed administrative management layers to execute lateral command execution, disable internal network endpoints, and push extrusion ransomware payloads down to local target databases without triggering standard security interface alerts.

Real-world blended example (publicly disclosed information): The Salesloft Drift campaign involved compromised customer OAuth tokens from the Salesloft Drift application (Archetype 3 — initial access against the vendor), which were then used against the Salesforce platform to exfiltrate customer data (Archetype 2 — data stolen directly from the vendor environment), demonstrating how a single campaign can chain multiple archetypes.

Survival Analysis — Third-Party Cloud Account Exposures

Missing/Improperly Secured MFA (Figure 21, n=7,513):

  • Full remediation rate: 23%
  • 50% of all findings resolved within approximately one month
  • Lingering tail converges to roughly 32% of issues remaining unresolved long-term

Weak Passwords + Excessive Permission Misconfigurations Combined (Figure 20, n=354):

  • Full remediation rate: 31% (comparable to the CISA KEV vulnerability remediation rate)
  • Time to resolve 50% of all findings: nearly eight months

Supplementary Cloud Exposure Snapshot:

  • 37% of organizations had an admin account with MFA disabled on an IaaS offering.
  • Only 14% of organizations had an admin account with MFA disabled on Snowflake specifically, suggesting customers responded to the prior year’s breach campaign.

The staggering 60% year-over-year surge in third-party breaches proves that traditional point-in-time vendor questionnaires are completely obsolete. Our GRC program enforces a continuous, tier-based vendor risk assessment cadence that maps directly onto all three relationship archetypes defined in the report. For any critical sub-service provider categorized under Archetype 3—maintaining direct network connection paths, active API access strings, or federated OAuth configurations into our perimeter—we mandate a rolling quarterly audit.

This review requires the vendor to submit a current SOC 2 Type II report alongside live, verified evidence of hardware-backed multi-factor authentication (MFA) enforcement across all administrative accounts, eliminating the dangerous eight-month remediation lag that underperforming organizations fall victim to.

SECTION 4: THE ECONOMICS OF RANSOMWARE & THE INFOSTEALER PIPELINE

Ransomware Prevalence

  • Ransomware actions appeared in 48% of all breaches analyzed in 2025 (up from 44% the prior year, a smaller relative increase than the previous year’s growth).
  • Within the System Intrusion pattern specifically, Ransomware appears in 77% of breaches.

Market Saturation Data

  • 69% of ransomware victims did not pay in 2025, up from 65% in 2024. Notably, this increase in “Not Paid” outcomes occurred even in cases involving encryption, not just data-exfiltration-only events.
  • Median ransom payment: $139,875 in 2025, down from $150,000 the prior year — a downward trend that has held consistent even after the dataset tripled or quadrupled in size due to new data contributors (FBI IC3 partnership plus new ransom payment/negotiation/crypto-wallet tracking contributors).
  • Median percentage of publicized victims who actually paid, per ransomware group: approximately 9% (Figure 47, n=261 groups analyzed via cross-referencing actor-disclosed attacks against known crypto-wallet payments). This low figure suggests publicized victim lists likely contain a meaningful percentage of fabricated or reposted entries, since ransomware groups have strong incentive to inflate notoriety.
  • Regulatory context: Australia’s mandatory Ransomware and Cyber Extortion Reporting Regime (effective May 30, 2025, under the Cyber Security Act 2024) requires entities with AUD $3 million+ annual turnover, plus critical infrastructure operators, to report ransom payments within 72 hours.

Infostealer-to-Ransomware Pipeline (Figure 48, n=4,395)

  • 27% of ransomware victims had no associated infostealer or credential leak event within the year prior to the attack.
  • Of the 73% that did have a prior credential/infostealer event, 50% experienced that event within 95 days prior to falling victim to ransomware.
  • Credential leak frequency by org size: Small organizations experienced a median of 7 credential leak events per year; larger organizations faced a median of approximately 20 per year.

Initial Access Broker (IAB) Connection Types (Figure 49, n=876)

  • 44% of IAB-offered connection types were VPN access.
  • Remote desktop applications (RDP, RDPweb, VNC) followed closely behind.
  • ProxyShell/ProxyLogon access offerings persisted, with the majority of these credential offers found to occur two to three years after the original vulnerability disclosure — reinforcing the long-tail patching problem documented in Section 1.

The 2026 DBIR metric revealing that 50% of ransomware victims experience a documented credential leak or infostealer event within 95 days prior to an attack provides an absolute defensive chokepoint. To exploit this critical pre-attack window, our organization has established a continuous threat intelligence monitoring capability that checks dark web marketplaces, initial access broker forums, and known infostealer logs in real time.

The moment an employee credential or active session token is identified as compromised, our automated response pipeline forces an immediate password rotation, revokes all active OAuth session tokens across our identity providers, and places the affected endpoint under strict host isolation for forensic auditing. Proactively disrupting this pipeline during the 95-day window is what allows us to catch the compromise and neutralize the lateral execution chain long before a ransomware script can be dropped into our network infrastructure.

SECTION 5: FRONTIER LABS INTEL — GENERATIVE AI & THE SHADOW AI DLP CRISIS

Threat Actor AI Misuse (Anthropic Collaborative Dataset)

Verizon collaborated directly with Anthropic to analyze 793 unique threat actors tracked between March 2025 and February 2026, all of whom received enforcement action from Anthropic’s Safeguards Team for violating acceptable use policy, with sufficient behavioral data for analysis. Their queries spanned malware development, capability building, and tasking, classified against the MITRE ATT&CK framework.

  • Median actor researched or used AI assistance across 15 distinct documented ATT&CK techniques; extreme cases involved as many as 40 to 50 techniques, representing multi-session campaigns where actors treated the AI platform as a co-developer across the full attack chain.
  • Risk classification: Less than 1% of the 793 actors fell into the High or Critical risk category; 99% fell into Medium or Low Risk.

AI-Assisted Initial Access Method Distribution (Figure 27, n=837)

Method% of AI-Assisted Initial Access Techniques
Phishing44%
Exploitation of vulnerabilities32%
(Credential abuse and others)Remainder

Despite AI-assisted Phishing techniques leading this breakdown, Phishing’s share of the DBIR’s own overall incident initial-access-vector dataset has barely moved over the past several years — suggesting AI assistance may not yet be measurably increasing success rates within the organizations captured in the DBIR’s incident dataset, though it could be uplifting less-experienced actors to a higher baseline proficiency, or increasing success against individuals for fraud (a category outside this report’s scope).

Technique Rarity Analysis (Figure 28, n=9,897 observations, based on MITRE ATT&CK’s catalog of known malicious software/tooling)

  • Median: 55 existing known malware examples per AI-assisted technique observed — indicating most AI-assisted techniques already have dozens of known tools implementing them; attackers are largely outsourcing well-trodden tasks (e.g., file obfuscation, forensic cleanup) to AI rather than pioneering novel methods.
  • Less than 2.5% of AI-assisted malware observations involved rare techniques (defined as having one or fewer known existing software examples), such as “Pre-OS Boot: UEFI” or “Process Injection: VDSO Hijacking.”
  • Core conclusion: AI’s primary current impact is operational — automating and scaling techniques defenders already know how to detect — rather than unlocking genuinely novel or rare attack surfaces.

Internal Shadow AI Crisis (DLP Dataset, n=858,440 select data-type events; n=4,280,149 total non-malicious insider DLP events)

  • 67% of users are using non-corporate accounts on corporate devices to access AI services (a slight decrease from the prior year’s 72%).
  • 45% of employees are now considered regular AI users (defined as accessing an AI platform at least once every 15 days) on corporate devices, authorized or not — up sharply from 15% the previous year.
  • Shadow AI is now the third most common non-malicious insider action detected in DLP datasets in 2025 — a fourfold increase in percentage from the previous year.
  • Browser extension exposure: The average company had more than 15% of users with unauthorized AI browser extensions installed, many of which collect and retain browsing context data, including exposure of internal, non-public sites.

DLP Asset Data Types Leaked to Unauthorized/External GenAI Tools

Data TypeRelative Ranking
Source codeMost common, by a large margin
ImagesSecond most common
Other structured dataThird most common
Research and technical documentation3.2% of DLP policy violations — flagged specifically as an intellectual property exposure risk

With the 2026 dataset showing that source code leakage via personal AI accounts has become the third most common non-malicious insider DLP violation, traditional text-filtering guidelines are completely insufficient. Our GRC program enforces a rigid Shadow AI governance policy that blocks unvetted generative AI URLs and browser extensions at the endpoint layer.

We utilize centralized endpoint management tools to inventory and restrict browser extensions across all company workstations, completely removing tools that harvest browsing context or data. Developers are restricted to secure, enterprise-audited API sandboxes that enforce strict data-retention boundaries, ensuring proprietary intellectual property never leaves our controlled perimeters.

SECTION 6: VERTICAL INDUSTRY & SECTOR-SPECIFIC TELEMETRY MATRICES

Educational Services (NAICS 61)

  • Volume: 1,302 incidents, 1,252 confirmed breaches
  • Top patterns: System Intrusion (52% of breaches), Social Engineering (17%), Miscellaneous Errors (16%) — combined 83% of breaches
  • Threat actors: External 78%, Internal 22%
  • Motives: Financial 78%, Espionage 21%, Ideology 2%
  • Initial access vector breakdown: Exploitation of vulnerabilities 34%, Phishing 22%, Credential abuse 8%
  • Other metrics: Human element 68%, Third-party 40%
  • Asset/action detail: Hacking and Malware in near-equal measure (55% of breaches); within Hacking breaches, Exploitation of vulnerabilities appears in 77%, stolen credentials in 65%; Ransomware is the top Malware action, present in 65% of malware-related breaches; Backdoor/C2 functionality in 35%; primary infection vector is Web applications (71%), followed by web application downloads (65%) and email attachments (52%); a notable 2025 campaign involved a zero-day in Oracle’s E-Business Suite affecting 100+ organizations, heavily concentrated in Education.

Financial and Insurance (NAICS 52)

  • Volume: 3,809 incidents, 1,300 confirmed breaches
  • Top patterns: System Intrusion, Social Engineering, and Everything Else — combined 81% of breaches
  • Threat actors: External 88%, Internal 12%
  • Motives: Financial 98%, Espionage 3%
  • Data compromised: Internal 53%, Personal 43%, Other 28%, Credentials 26%
  • Initial access vector breakdown: Exploitation of vulnerabilities 22%, Phishing 20%, Credential abuse 15%
  • Other metrics: Human element 65%, Third-party 34%

Healthcare (NAICS 62)

  • Volume: 1,492 incidents, 1,438 confirmed breaches
  • Top patterns: System Intrusion, Miscellaneous Errors, and Social Engineering — combined 81% of breaches
  • Threat actors: External 81%, Internal 19%
  • Motives: Financial 99%, Espionage 2%
  • Data compromised: Internal 65%, Personal 37%, Credentials 25%, Other 19%
  • Initial access vector breakdown: Exploitation of vulnerabilities 20%, Phishing 14%, Credential abuse 11%
  • Other metrics: Human element 54%, Third-party 32%
  • Notable detail: Miscellaneous Errors has ranked in the top three patterns every year since 2014; top error varieties this year were Misdelivery, Loss, and Misconfiguration; the Oracle E-Business Suite vulnerability (largely attributed to the Cl0p group) contributed to Healthcare’s third-party figure.

Manufacturing (NAICS 31–33)

  • Volume: 3,627 incidents, 2,713 confirmed breaches
  • Top patterns: System Intrusion, Social Engineering, and Basic Web Application Attacks — combined 91% of breaches
  • Threat actors: External 95%, Internal 5%
  • Motives: Financial 87%, Espionage 15%
  • Data compromised: Internal 81%, Credentials 26%, Other 22%, Personal 17%
  • Initial access vector breakdown: Exploitation of vulnerabilities 38%, Phishing 13%, Credential abuse 11%
  • Other metrics: Third-party 61%, Human element 56%
  • Detail: Malware involved in 75% of breaches (Ransomware alone accounting for 61%); a notable late-2025 ransomware attack on Asahi Group Holdings forced a shutdown of domestic manufacturing facilities and suspended shipments; Hacking actions in 71% of breaches, with Use of stolen credentials and Exploit vulnerability each contributing to 41%; Social Engineering only 16% (77% Phishing variety).

Public Administration / Government (NAICS 92)

  • Volume: 3,634 incidents, 2,410 confirmed breaches
  • Top patterns: System Intrusion, Miscellaneous Errors, and Privilege Misuse — combined 80% of breaches (Privilege Misuse edged out Social Engineering by only 0.01%)
  • Threat actors: External 56%, Internal 44%
  • Motives: Financial 69%, Espionage 33%, Ideology 2%
  • Data compromised: Personal 50%, Internal 39%, Other 37%, Secrets 30%
  • Initial access vector breakdown: Exploitation of vulnerabilities 40%, Phishing 20%, Credential abuse 8%
  • Other metrics: Human element 69%, Third-party 36%
  • Detail: Hacking (38%) and Malware (43%) appear in roughly equal proportions; within Hacking breaches, Exploitation of vulnerabilities accounts for 82%, Evade defenses appears in 64%, Use of stolen credentials in 59%; State-affiliated actors appear in 35% of breaches, frequently Espionage-motivated (33%) — exemplified by the Silk Typhoon breach of the U.S. Department of the Treasury via a third-party cloud support vendor vulnerability; Misdelivery accounts for 88% of all Error-pattern breaches; 91% of government errors stem from plain Carelessness rather than inadequate process (1%) or poor technology (9%); Misuse breaches are dominated by Data mishandling (82%) followed by Privilege abuse (18%).

Retail & E-commerce (NAICS 44–45)

  • Volume: 997 incidents, 806 confirmed breaches
  • Top patterns: System Intrusion, Basic Web Application Attacks, and Social Engineering — combined 95% of breaches
  • Threat actors: External 99%, Internal 1%
  • Motives: Financial 85%, Espionage 19% (up sharply from 9% the prior year)
  • Data compromised: Internal 84% (up from 65% the prior year), Credentials 26%, Secrets 20%, Other 14%
  • Initial access vector breakdown: Exploitation of vulnerabilities 42%, Credential abuse 14%, Phishing 9%
  • Other metrics: Third-party 68%, Human element 58%
  • Detail: The number of breaches nearly doubled year-over-year even as incidents rose only slightly; a notable 2025 breach at clothing retailer Hot Topic affected 57 million customers; social attack varieties are led by Phishing at roughly twice the rate of Pretexting; data targeting has diversified beyond payment card data toward any monetizable data type.

Small- and Medium-Sized Businesses (SMBs)

  • Volume: 7,256 incidents, 7,152 confirmed breaches
  • Top patterns: System Intrusion, Basic Web Application Attacks, and Social Engineering — combined 100% of breaches
  • Threat actors: External 100%
  • Motives: Financial 100%
  • Data compromised: Internal 97%, Credentials 31%, System 1%, Other 1%
  • Initial access vector breakdown: Exploitation of vulnerabilities 26%, Credential abuse 13%, Phishing 9%
  • Other metrics: Third-party 55%, Human element 45%
  • Detail: Approximately 96% of all Ransomware victims (where organization size was known) were SMBs. Ransomware campaigns are largely opportunistic — driven by which organizations had compromised credentials (38%) or unpatched edge-device vulnerabilities (29%), rather than targeted selection by industry or revenue.

EXECUTIVE GRC MITIGATION RULES

High-Risk Threat MetricVerified 2026 DBIR Telemetry HookMandatory Executive Control Policy
Vulnerability exploitation as the #1 initial access vector31% of breaches, up 55% relative from 20%; only 26% of CISA KEV CVEs fully remediated; median 43-day resolution timeMandate a sub-14-day SLA for CISA KEV-listed vulnerabilities on internet-facing assets; report Day-7 and Day-28 open-vulnerability counts to the board quarterly
Credential abuse persisting as the top overall attack chokepoint39% of breaches involve credential abuse at some point in the attack chain, despite falling as an initial vectorEnforce mandatory phishing-resistant MFA across all externally exposed applications and remote network access (CIS Controls 6.3, 6.4)
Memory safety vulnerabilities dominating the CWE landscape89% of organizations carry Memory Safety-category weaknesses; top 5 individual CWEs each present in 76%+ of orgsRequire a Secure by Design roadmap with a stated migration path toward memory-safe languages for new and high-risk codebases
Third-party breach involvement up 60% YoY48% of breaches now involve a third party; only 23% full MFA remediation in third-party cloud environmentsMandate annual SOC 2 or equivalent security report collection for all critical vendors; classify vendors against the three third-party archetypes and apply differentiated controls
Ransomware monetization declining but volume rising48% of breaches involve ransomware; 69% of victims refuse payment; median payout down to $139,875Maintain a tested, board-approved ransomware response and negotiation-refusal playbook; validate backup/recovery RTO against real-world Marks & Spencer-scale outage precedent
Infostealer-to-ransomware pipeline compressing to a 95-day window50% of infostealer-preceded ransomware victims were compromised within 95 days priorDeploy continuous credential-leak/infostealer monitoring with automated forced credential rotation upon detection
Shadow AI as a top-3 non-malicious insider DLP risk67% of users use non-corporate AI accounts on corporate devices; source code is the top leaked asset typePublish and enforce a formal Acceptable AI Use Policy; deploy DLP controls specifically tuned to detect source code and structured data egress toward unauthorized AI endpoints
AI-assisted attacker tooling scaling known techniquesMedian actor leverages AI across 15 ATT&CK techniques; 44% of AI-assisted initial access is PhishingTreat AI-enabled phishing as materially more convincing in security awareness training; do not deprioritize existing detection tooling under the assumption that AI enables genuinely novel attack classes
SMBs absorbing the overwhelming majority of ransomware volume96% of ransomware victims with known org size were SMBsFor SMB-tier organizations or business units, prioritize edge-device patching and credential hygiene above advanced detection tooling investment given constrained resources
North Korean IT Worker (ITW) infiltration riskDPRK-linked ITWs achieved multiple concurrent positions across industries via stolen identities and laptop farmsFormalize identity-verification and background-check controls for remote hires, with heightened scrutiny for remote software/data engineering and blockchain/Web3 roles

CONCLUSION

The 2026 Verizon DBIR report documents a threat landscape defined less by novel attack categories than by acceleration and scale within familiar ones. Vulnerability exploitation has decisively overtaken credential abuse as the primary initial access vector, remediation capacity has failed to keep pace with a nearly eightfold increase in tracked vulnerability volume since 2022, and third-party involvement in breaches has surged 60% in a single year. Generative AI’s measurable impact to date is operational rather than transformative — automating known techniques rather than unlocking novel ones — but the internal Shadow AI data-leakage problem has become a top-three insider risk in its own right, with source code now the most commonly exfiltrated asset type to unauthorized AI platforms.

Every metric in this briefing points toward the same governance conclusion the report itself reaches: organizations that stay grounded in cybersecurity fundamentals — clear visibility into assets and third parties, disciplined patch velocity, and enforced identity controls — remain better positioned than those chasing each year’s newest threat category. The gap between top-performing and average organizations in this year’s dataset is not a gap in awareness; it is a gap in remediation execution.

Defending modern corporate networks requires shifting our organizational mindset completely away from manual, reactive boundary patching and towards continuous, automated risk tracking. What specific threat metrics or data indicators from this year’s report present the highest strategic risk to your unique business operations? Do you map your technical infrastructure defenses straight to these annual DBIR findings, deploy advanced cloud-native threat tracking, or focus entirely on human endpoint identity perimeters? Drop a comment below and let me know your thoughts—lets share our threat intelligence roadmaps and build safer systems together!

Related: Passing a SOC 2 Audit Via 5 Rigid Compliance Controls to Avoid Risks – Passing a SOC 2 audit requires more than policies—it demands continuous, provable controls across access, change management, encryption, monitoring, and vendor risk.

Dissecting the Creeper Worm Via 4 Forensic Analysis Steps of the First Cyberattack – Creeper, the experiment that pioneered self-moving code in 1971, offers a fascinating look at how network trust, malware propagation, and the first cybersecurity countermeasure shaped modern cyber defense.

Implementing Rate Limiting for OpenAI API Endpoints Via 7 Rigid Tiers to Stop Billing Attacks – A seven-tier, code-level guide for Node.js developers on implementing rate limiting for OpenAI API endpoints to stop Denial of Wallet attacks, layering in-memory limits, Redis-backed token buckets, cost-based throttling, and edge-layer Cloudflare/Nginx defenses.

 Prevent API Key Leakage When Building Local AI Applications Via 5 Rigid Rules to Eliminate Risk – Protect your local AI applications from accidental API key leaks with simple, practical security controls that keep secrets out of code, logs, and public repositories.

Frequently Asked Questions (FAQ)

Q1. How does Verizon actually source the incident and breach data behind the DBIR, and can smaller organizations trust it reflects their risk profile too?

Verizon aggregates data from its own VTRAC investigations, incident reports and summaries from dozens of data contributors, and publicly disclosed security incidents, with methodology details published separately in Appendix A of the report. Because contributor participation shifts year to year, the report explicitly notes potential bias in geographic and industry representation, which is worth keeping in mind when benchmarking a specific sector like SMBs or Public Administration against the aggregate figures.

Q2. Why did credential abuse’s percentage drop so significantly this year — is credential-based risk actually decreasing?

No — the drop from 22% to 13% is largely a methodology change, not a real-world decline: this year’s report split out Pretexting as its own distinct initial access vector for the first time, which had previously been bundled partly into credential abuse and phishing figures. When measured across the full attack chain rather than just initial access, credential abuse still sits at 39%, making it the single most pervasive attack element in the entire dataset.

Q3. Is the 26% CISA KEV remediation rate specific to large enterprises, or does it reflect organizations of all sizes?

The 26% full-remediation figure is drawn from an aggregated dataset of more than 13,000 organizations of varying sizes, not filtered specifically to enterprise-tier companies. Given that SMBs represented the overwhelming majority of ransomware victims in this year’s report, it’s reasonable to assume smaller organizations pull this remediation average down further, though the report doesn’t break out KEV remediation speed by organization size explicitly.

Q4. The report says AI isn’t creating novel attack techniques yet — does that mean AI-related security investment is currently overhyped?

Not necessarily; the report’s finding is narrower than that. It states AI is accelerating and scaling techniques defenders already know how to detect, particularly phishing and malware development, which still meaningfully increases attack volume and lowers the skill barrier for less-sophisticated actors, even without unlocking genuinely new attack categories. The bigger near-term risk documented in the report isn’t AI-generated attacks — it’s the internal Shadow AI data leakage problem, which is a governance and DLP issue rather than a novel offensive capability.

Q5. If ransomware payment rates are declining, does that mean the ransomware threat itself is fading?

No — the report is explicit that ransomware prevalence is still rising (48% of breaches, up from 44%), even as the percentage of victims who actually pay continues to decline. The interpretation offered is that attackers are compensating for lower payment rates by increasing volume and casting a wider net, meaning organizations should expect ransomware attempts to continue growing even as the “profitability per victim” trend moves in defenders’ favor.

DISCLAIMER

Educational Notice: This article is published on AI Security Watch strictly for technical educational and general cybersecurity awareness purposes. The configurations and research discussed are based on public threat intelligence data. This content does not constitute professional IT architecture, legal, or financial advice. Because network configurations vary, always verify settings in an isolated test environment or consult with a qualified engineer before modifying live hardware or registries. AI Security Watch contains informational links to external resources; we are not responsible for third-party site accuracy or platform content.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top