Cyber Security Facts and Statistics for 2026
The most important cyber security facts of 2026 point in one direction: attacks are getting more expensive, more automated, and harder to keep out of the supply chain.
Table of Contents
The most important cyber security facts of 2026 point in one direction: attacks are getting more expensive, more automated, and harder to keep out of the supply chain. According to IBM's 2026 Cost of a Data Breach Report, the global average cost of a data breach reached a record $4.99 million this year, a 12% jump in a single year. The Verizon 2026 Data Breach Investigations Report found that 62% of breaches involved a human element and that ransomware appeared in 48% of all confirmed breaches. And in its 2025 Internet Crime Report, released in April 2026, the FBI's Internet Crime Complaint Center logged more than one million complaints and $20.9 billion in reported losses, the highest total in its history.
Below are the cybersecurity facts that matter most this year, each backed by the newest edition of its source (2026, or 2025 where the 2026 edition is not yet out).
Key cyber security facts at a glance
The average data breach now costs $4.99 million globally, a record high and up 12% year over year (IBM Cost of a Data Breach Report, 2026).
A US data breach costs $11.5 million on average, more than double the global figure (IBM, 2026).
62% of breaches involved a human element, whether through error, social engineering, or credential misuse (Verizon DBIR, 2026).
31% of breaches began with an exploited software vulnerability, which overtook stolen credentials (13%) as the top initial access vector (Verizon DBIR, 2026).
48% of breaches involved a third party, a 60% increase from the prior year (Verizon DBIR, 2026).
Ransomware was involved in 48% of breaches, yet 69% of victims refused to pay (Verizon DBIR, 2026).
Americans reported $20.9 billion in cybercrime losses to the FBI in 2025, up 26% from 2024 (FBI IC3, 2025 report published 2026).
3,322 data compromises were reported in the US in 2025, a record and a 79% increase over five years (ITRC, 2025 report published January 2026).
81% of small businesses suffered a security breach, a data breach, or both in the past year (ITRC Business Impact Report, 2025).
AI-driven attacks rose 56% in one year and added roughly $1 million to the average breach cost (IBM, 2026).
87% of security leaders say AI-related vulnerabilities are the fastest-growing cyber risk (World Economic Forum Global Cybersecurity Outlook, 2026).
Worldwide information security spending is projected to hit $240 billion in 2026 (Gartner, 2025 forecast).
Fact 1: Data breaches have never been more expensive
IBM's 2026 Cost of a Data Breach Report, which draws on 602 organizations breached between March 2025 and February 2026, puts the global average at $4.99 million. That is a 12% rise over the 2025 edition.
The United States remains the most expensive place in the world to be breached. IBM reports a US average of $11.5 million per incident, more than double the global average, driven by regulatory exposure, litigation, and notification costs.
By industry, IBM found healthcare the costliest sector for the 13th consecutive year at $6.64 million per breach, even though healthcare costs actually fell 10.5% from the $7.42 million recorded in 2025. Financial services followed at $6.3 million, with the industrial sector and technology at $5.5 million each and entertainment at $5.4 million.
Detection is not getting faster. IBM found the average time to identify and contain a breach rose 2.5% in 2026, and breaches involving complex attack vectors took an average of 258 days to identify and resolve. Phishing accounted for 17% of breaches and carried an average cost of $5.9 million, well above the overall mean.
There is a bright spot in the same report. Organizations making extensive use of AI and automation in security saved an average of $1.93 million per breach compared with organizations using none. That gap is one of the most concrete arguments for investing in detection and response capability, whether in-house or through a managed security services provider.
Fact 2: Unpatched software, not stolen passwords, is now the top way in
Stolen credentials were long the most common entry point for attackers. That changed in the Verizon 2026 Data Breach Investigations Report, which analyzed roughly 31,000 security incidents, including more than 22,000 confirmed breaches, nearly double the 12,195 breaches in the prior edition.
Verizon found that approximately 31% of breaches started with exploitation of a software vulnerability, while credential abuse as an initial vector dropped to 13%. Credentials still appeared somewhere in 39% of breaches overall, but the shift toward vulnerability exploitation is the headline change of 2026.
The patching data explains why. According to the DBIR, organizations fully remediated only 26% of the flaws listed in CISA's Known Exploited Vulnerabilities catalog during 2025, down from 38% the year before. The median time to fully patch increased to 43 days, up from 32 days, and critical flaws took 50% longer to fix in the median case than the previous year.
The human element is still central. Verizon reports that 62% of breaches involved a human element, and social engineering accounted for 16% of breaches. Mobile devices are becoming a favored target: engagement rates for mobile-based phishing simulations were 40% higher than for traditional email phishing.
Fact 3: Ransomware is in nearly half of breaches, but victims are paying less
The Verizon 2026 DBIR found ransomware involved in 48% of confirmed breaches, up from 44% in the prior year.
What has changed is the economics. Verizon reports that 69% of ransomware victims did not pay the demand, and the median payment among those who did dropped below $140,000.
The Sophos State of Ransomware 2026 report, based on 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit in the past year, tells a similar story from a different angle. The median ransom demand fell to $698,000, down 65% over two years, and the median payment fell to $769,000 from $1 million the previous year. Among organizations that paid, 51% negotiated a lower amount than the initial demand.
Attackers are compensating by getting better at the technical side. Sophos found 56% of attacks succeeded in encrypting data, up from 50% a year earlier, and the average recovery cost rose 11% to $1.7 million per incident. Backups are doing more of the heavy lifting: 66% of organizations with encrypted data recovered via backup, up 12 points from 2025, while 48% of encrypted victims paid the ransom.
The root causes Sophos identified are familiar. Malicious email (26%), phishing (24%), and compromised credentials (23%) led the list, while exploited vulnerabilities (18%) fell 14 percentage points year over year. In 79% of ransomware attacks the initial approach was identity-based, and multi-factor authentication was missing where it mattered in 59% of cases examined in Sophos's Active Adversary research. Small organizations are the least prepared: only 34% of organizations with 100 to 250 employees stopped the attack before encryption.
Fact 4: Reported cybercrime losses passed $20 billion for the first time
The FBI's Internet Crime Complaint Center is the most authoritative public count of cybercrime reported by Americans, and its 2025 Internet Crime Report is the first to break both the one million complaint mark and the $20 billion loss mark. IC3 received 1,008,597 complaints in 2025 with $20.877 billion in reported losses, a 26% increase in losses over 2024. The average loss per complaint was $20,699.
Investment fraud was the costliest crime category at $8.65 billion, followed by business email compromise at $3.05 billion and tech and customer support scams at $2.13 billion. By complaint volume, phishing and spoofing led with 191,561 reports, followed by extortion (89,129) and investment fraud (72,984).
Cryptocurrency is now the dominant payment rail for cybercrime. IC3 logged 181,565 crypto-related complaints (up 21%) with $11.366 billion in losses (up 22%), meaning more than half of all reported 2025 losses involved cryptocurrency.
Older Americans bore a disproportionate share. People aged 60 and over filed 201,266 complaints and lost $7.748 billion, a 59% increase from 2024, with an average loss of $38,500 per complaint.
Ransomware complaints to IC3 totaled 3,611 with $32.3 million in direct reported losses, including 460 complaints from organizations in critical infrastructure sectors. Those figures capture only losses reported to the FBI, not downtime or recovery.
Fact 5: Data compromises hit a record, but transparency is falling
The Identity Theft Resource Center's 2025 Annual Data Breach Report, published in January 2026, counted 3,322 publicly reported data compromises in the United States in 2025. That is a 5% increase over 2024 (3,152), a 4% increase over the previous record set in 2023 (3,202), and a 79% jump over five years.
The number of victim notices moved in the opposite direction. ITRC recorded 278,827,933 notices in 2025, down 79% from the 1.37 billion sent in 2024 and the lowest total since 2014. The drop reflects the absence of a 2024-scale mega-breach, not fewer attacks.
The more troubling trend is in disclosure quality. ITRC found that 70% of breach notices (2,324) in 2025 did not include any information about the attack vector, up from 65% in 2024 and 45% in 2023.
Financial services was the most breached industry with 739 compromises, followed by healthcare (534), professional services (478), manufacturing (299), and education (188).
Fact 6: Small businesses are the most exposed and the least prepared
The ITRC 2025 Business Impact Report, published in November 2025, shows that 81% of small businesses reported suffering a security breach, a data breach, or both in the past year.
The financial hit is significant relative to company size. Among breached small businesses, 62.5% reported a total financial impact above $250,000 in 2025, and 36.7% faced costs exceeding $500,000, an increase from 2024. AI-powered attacks were identified as a root cause in more than 40% of incidents.
Those costs are being passed downstream. ITRC found 38.3% of small business leaders raised prices to absorb the impact of a cyber incident.
Preparedness is going backward. The share of small business leaders who felt "very prepared" for a cyberattack fell to 38.4% in 2025 from 56.5% in 2024, and implementation of multi-factor authentication declined from 33.6% to 27.2%. For a company with fewer than 50 employees and no in-house security staff, these numbers make a strong case for outsourcing IT and security to a managed provider rather than trying to close the gap alone.
Fact 7: Third parties are now involved in nearly half of all breaches
In 2026, the Verizon 2026 DBIR reports that breaches involving a third party increased 60% year over year and now feature in 48% of all breaches.
Third-party security hygiene is part of the problem. Verizon found that only 23% of third-party organizations fully remediated missing or improperly configured multi-factor authentication when notified.
Large enterprises see the same risk from the top down. In the World Economic Forum's Global Cybersecurity Outlook 2026, 65% of the largest companies by revenue said third-party and supply chain vulnerabilities were their greatest cybersecurity challenge, up from 54% in 2025.
Fact 8: AI is now the biggest driver of change in cybersecurity, on both sides
On the attacker side, IBM's 2026 report found a 56% year-over-year increase in AI-driven attacks, with more than one in four organizations that suffered a malicious attack saying it was AI-driven. Deepfake impersonation and AI-enabled malware were the most common forms, and AI-driven attacks added about $1 million to the average cost of a breach. A new category, AI model inversion attacks, carried a global average breach cost of $6 million.
On the defender side, the Verizon 2026 DBIR found the median malicious actor leveraged AI across 15 different documented attack techniques, while employee AI use is exploding faster than governance can keep up: 45% of employees are now regular AI users at work, up from 15% the previous year, and 67% of users accessing AI services from corporate devices were doing so with non-corporate accounts.
IBM quantified the shadow AI problem directly. Incidents involving shadow AI more than doubled to 43% of security incidents, up from 20%, and only around one third of organizations have a strict approval process for deploying AI tools.
Security leaders see it coming. The WEF Global Cybersecurity Outlook 2026 found 94% of respondents identified AI as the most significant driver of cybersecurity change, 87% named AI-related vulnerabilities as the fastest-growing cyber risk, and the share of organizations assessing the security of AI tools before deployment rose from 37% in 2025 to 64% in 2026. Geopolitics is compounding the pressure: 64% of organizations are now planning for geopolitically motivated cyberattacks, 91% of the largest organizations have changed their strategies because of geopolitical volatility, and 73% of respondents said they or someone in their network had been personally affected by cyber-enabled fraud.
Fact 9: Security spending is growing faster than the economy
Gartner's July 2025 forecast projected worldwide end-user spending on information security to reach $240 billion in 2026, up 12.5% from $213 billion in 2025 and following 10.4% growth the year before.
Security software is the largest segment at a projected $121.2 billion in 2026, followed by security services at $92.8 billion and network security at $25.8 billion. The services line, which includes managed detection and response, grew from $83.8 billion in 2025 as more organizations turn to MSSPs. Gartner analysts cited rising threats and the expanding use of AI and generative AI, by both defenders and attackers, as the key growth drivers.
What's new in 2026: the facts that changed this year
For journalists and IT leaders tracking the trendline, these are the cyber security facts that moved most between the 2025 and 2026 editions of the major reports:
Vulnerability exploitation overtook credential theft as the top initial access vector, at 31% versus 13% (Verizon DBIR 2026). In 2025 credentials still led.
Third-party involvement in breaches rose 60% to 48% of all breaches (Verizon DBIR 2026).
The global average breach cost jumped 12% to $4.99 million, the largest increase in years (IBM 2026).
Shadow AI incidents more than doubled, from 20% to 43% of security incidents (IBM 2026).
Reported cybercrime losses crossed $20 billion and complaints crossed one million for the first time (FBI IC3, 2025 report).
Ransom demands fell 65% over two years to a median of $698,000, while encryption success rose to 56% (Sophos 2026).
Small business preparedness dropped sharply, with "very prepared" falling from 56.5% to 38.4% in a year (ITRC 2025).
Breach disclosure got worse, with 70% of notices omitting the attack vector (ITRC 2025 annual report).
Taken together, the 2026 data describes attackers who exploit unpatched flaws faster than defenders fix them, use AI to scale social engineering, and increasingly reach targets through their vendors.
How managed IT and security providers can help
Most of the gaps the 2026 data exposes, slow patching, missing MFA, untested backups, and no 24/7 monitoring, are exactly the services a managed security provider delivers. Looking for an MSSP that can help your organization reduce breach risk and meet compliance requirements? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options and get a free assessment.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Oct 1, 2026 · 12 min read