Managed ITServices
Statistics

Cybersecurity Statistics for 2026: The Numbers Behind This Year's Threat Landscape

The average cost of a data breach reached a record $4.99 million in 2026, a 12% jump in a single year, according to IBM's 2026 Cost of a Data Breach Report.

The average cost of a data breach reached a record $4.99 million in 2026, a 12% jump in a single year, according to IBM's 2026 Cost of a Data Breach Report. In the United States, the figure is $11.5 million, more than double the global average. Americans reported 1,008,597 cybercrime complaints and $20.9 billion in losses to the FBI's Internet Crime Complaint Center in 2025, which works out to one complaint roughly every 31 seconds. And the Verizon 2026 Data Breach Investigations Report found ransomware in 48% of all confirmed breaches, with third parties implicated in another 48%.

This page collects the most-cited cybersecurity statistics for 2026, sourced from the newest editions of the major industry reports: IBM, Verizon, the FBI, Gartner, Sophos, the World Economic Forum, ISC2, and Cybersecurity Ventures. Where a 2026 edition exists, we use it. Where the freshest data is from 2025, the year is stated so you know exactly how old the number is.

Key cybersecurity statistics at a glance

  • $4.99 million: global average cost of a data breach, a record high and up 12% year over year (IBM, 2026)

  • $11.5 million: average cost of a data breach in the United States (IBM, 2026)

  • $20.9 billion: cybercrime losses reported to the FBI in 2025, up 26% from 2024 (FBI IC3, 2025 report)

  • 1,008,597: cybercrime complaints filed with the FBI in 2025, the first year above one million since 2022 (FBI IC3, 2025 report)

  • 48%: share of confirmed breaches that involved ransomware, up from 44% (Verizon DBIR, 2026)

  • 48%: share of breaches that involved a third party, a 60% increase in one year (Verizon DBIR, 2026)

  • 31%: share of breaches that began with an exploited vulnerability, now the top entry point ahead of stolen credentials (Verizon DBIR, 2026)

  • 62%: share of breaches that involved a human element (Verizon DBIR, 2026)

  • 79%: share of ransomware attacks that started with a compromised identity (Sophos, 2026)

  • 43%: share of security incidents that involved shadow AI, double the prior year (IBM, 2026)

  • $240 billion: forecast worldwide end-user spending on information security in 2026, up 12.5% (Gartner)

  • $10.5 trillion: estimated annual global cost of cybercrime in 2025, on track for $12.2 trillion by 2031 (Cybersecurity Ventures, 2025)

Cybersecurity Statistics for 2026: The Numbers Behind This Year's Threat Landscape infographic

The cost of cybercrime in 2026

Cost is the datapoint journalists cite most often, so it is worth being precise about which cost is being measured.

At the macro level, Cybersecurity Ventures' 2025 Official Cybercrime Report estimates global cybercrime damages at $10.5 trillion annually in 2025, growing about 2.5% per year to $12.2 trillion by 2031. That works out to roughly $333,000 of harm every second in 2025, rising to $386,000 per second by 2031. The firm frames the total as the equivalent of the world's third-largest economy, behind only the United States and China.

At the organizational level, IBM's 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million, the highest figure in the report's history and a 12% increase over 2025. The U.S. average is $11.5 million. Breaches involving an AI model inversion attack averaged $6 million, and breaches that started with phishing (including voice and SMS phishing) averaged $5.9 million.

Healthcare, long the most expensive sector, saw its average breach cost fall 10.5% to $6.64 million in 2026 from $7.42 million in 2025, according to IBM. It remains one of the costliest industries, but the gap with other sectors narrowed for the first time in years.

Breach timelines also reversed course. IBM reports the average breach lifecycle (time to identify plus time to contain) rose 2.5% to 247 days in 2026, the first increase in five years. Breaches originating from supply chain compromises or removable media took the longest at 258 days.

The one bright spot in the cost data: organizations that used AI and automation extensively in their security operations saved an average of $1.93 million per breach compared with those that used none, per IBM.

Cybercrime reported to the FBI

The FBI's 2025 Internet Crime Report, published in 2026, is the best single source for U.S. cybercrime volume. The 2025 numbers set new records on both complaints and losses:

  • 1,008,597 complaints were filed in 2025, with reported losses of $20.877 billion, a 26% increase over 2024.

  • The average loss per complaint was $20,699.

  • Investment fraud was the costliest category at $8.65 billion, followed by business email compromise at $3.05 billion, tech and customer support scams at $2.13 billion, and personal data breaches at $1.31 billion.

  • Phishing and spoofing generated the most complaints (191,561), followed by extortion (89,129), investment fraud (72,984), and personal data breaches (67,456).

  • Americans aged 60 and older filed 201,266 complaints (up 37%) and lost $7.748 billion (up 59%), an average of $38,500 per victim.

  • The FBI logged 3,611 ransomware complaints and identified 63 new ransomware variants during the year.

For context, the FBI received 791,790 complaints and $6.9 billion in losses in 2021. Reported losses have tripled in four years.

Data breach statistics for 2026

The Verizon 2026 Data Breach Investigations Report analyzed more than 31,000 security incidents and over 22,000 confirmed data breaches across 145 countries. Its headline findings reshape several long-running assumptions:

Vulnerabilities overtook credentials as the top entry point. Exploitation of vulnerabilities was the initial access vector in 31% of breaches, up from 20% the prior year. Credential abuse fell to 13%. Organizations fully remediated only 26% of the critical vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog in 2025, down from 38%, with a median remediation time of 43 days.

Third-party risk doubled in importance. Third parties were involved in 48% of breaches, a 60% year-over-year increase. Only 23% of third-party organizations fully remediated missing or misconfigured multi-factor authentication when notified.

The human element is still a majority, but shrinking. Humans were involved in 62% of breaches in the 2026 DBIR. Competitor roundups still quote figures of 74% to 95%; those come from older editions and older studies and no longer reflect the current dataset.

Identity hygiene remains poor. The DBIR found that 37% of organizations had an admin account with MFA disabled on an infrastructure-as-a-service platform. Small organizations experienced a median of 7 credential leak events per year, while large organizations saw a median of 20.

Mobile is the new phishing surface. Mobile phishing simulations produced 40% higher engagement rates than email-based ones. Large organizations faced a median of 48 SMS phishing attempts per year.

The System Intrusion pattern, which covers ransomware and sophisticated hands-on-keyboard attacks, accounted for 60% of all breaches in the 2026 report.

Ransomware statistics

Ransomware is present in nearly half of all breaches, but the economics are shifting toward defenders.

The Sophos State of Ransomware 2026 report, a survey of 2,158 IT and security leaders in 17 countries whose organizations were hit in the past year, found:

  • 79% of ransomware attacks began with an identity-based technique such as compromised credentials or phishing.

  • 56% of attacks succeeded in encrypting data, up from 50% the previous year.

  • 48% of organizations whose data was encrypted paid a ransom, and 51% of those negotiated the amount down.

  • The median ransom demand was $698,000, down 65% over two years. The median payment was $769,000, down from $1 million.

  • The average recovery cost, excluding any ransom, rose 11% to $1.7 million per incident.

  • 66% of victims recovered encrypted data from backups, up 12 percentage points.

  • Root causes: malicious email (26%), phishing (24%), compromised credentials (23%), exploited vulnerabilities (18%), and brute force (6%).

Verizon's data points the same direction on payments. In the 2026 DBIR, 69% of ransomware victims did not pay, and the median payment among those who did fell to $139,875 from $150,000. (The Verizon and Sophos medians differ because they measure different populations: Verizon draws on incident data across all organizations, while Sophos surveys organizations that were hit and reports on the subset that paid.)

IBM's 2026 report adds that 39% of organizations experienced at least one ransomware attack in the past year, up from 24% in 2023, a 62.5% increase in four years. Among those attacks, 41% included threats to damage the organization's brand and 35% targeted employee or health data.

Ransomware is also the dominant malware in manufacturing. The 2026 DBIR attributes 61% of manufacturing malware breaches to ransomware.

AI and cybersecurity statistics

The 2026 editions of every major report share one theme: AI is now measurable on both sides of the fight.

On the attacker side, IBM's 2026 report recorded a 56% year-over-year increase in AI-driven attacks. One in four organizations experienced a breach that was AI-driven, and those breaches added roughly $1 million to the average cost. Of AI-driven breaches, 45% involved deepfake impersonation, 19% involved AI-enabled malware, and 17% involved AI-generated phishing. Verizon found generative AI enhancing 15% of attack techniques observed in the 2026 DBIR.

On the defender side, shadow AI has become a top-tier risk. IBM found that 43% of security incidents involved unsanctioned AI tools, double the 20% recorded a year earlier, with an average cost of $5.39 million, and one in five of those incidents resulted in regulatory fines. Verizon reports that 45% of employees are now regular AI tool users (up from 15%) and 67% of users accessing AI services did so with non-corporate accounts.

Executives see it coming. The World Economic Forum's Global Cybersecurity Outlook 2026, based on a survey of 804 leaders across 92 countries, found that 87% of organizations saw rising AI-related vulnerabilities in 2025 and 94% expect AI to be the single biggest force shaping cybersecurity in 2026. The share of organizations assessing the security of AI tools before deployment nearly doubled, from 37% to 64%.

Security practitioners report the same. In the 2025 ISC2 Cybersecurity Workforce Study, 40% of respondents said their organization had already experienced AI-optimized social engineering, 25% had seen AI-related data leakage, and 23% had faced AI-powered cyberattacks.

Small business and supply chain statistics

Smaller organizations are hit differently, and usually harder.

Sophos found that only 34% of small organizations (100 to 250 employees) stopped a ransomware attack before data was encrypted, compared with 46% of organizations with 3,001 to 5,000 employees. The WEF's 2026 Outlook reports that smaller organizations are twice as likely as large enterprises to say their cyber resilience is insufficient.

Supply chain exposure now tops the list of concerns for large companies. In the WEF survey, 65% of large enterprises cited third-party and supply chain risk as their greatest barrier to resilience, up from 54% the prior year. That lines up with Verizon's finding that third-party involvement in breaches rose 60% in a single year. Cyber-enabled fraud has also gone mainstream: 73% of WEF respondents said they were directly affected by fraud in 2025, or knew someone who was.

Businesses without an in-house security team often turn to managed security service providers to close this gap, since MSSPs can provide 24/7 monitoring and vulnerability management at a fraction of the cost of building an internal SOC.

Cybersecurity spending and workforce statistics

Spending keeps rising. Gartner forecasts worldwide end-user spending on information security will reach $240 billion in 2026, a 12.5% increase from $213 billion in 2025. Security software is the largest and fastest-growing segment at $121.2 billion, followed by security services at $92.8 billion and network security equipment at $25.8 billion.

The workforce picture has shifted from a headcount shortage to a skills shortage. The 2025 ISC2 Cybersecurity Workforce Study, drawing on 16,029 respondents, found:

  • 59% of organizations report critical or significant skills gaps, up from 44% a year earlier, and 95% report at least one skills gap.

  • The most-needed skills are AI (41%), cloud security (36%), and risk assessment (29%).

  • 39% of organizations had a hiring freeze in cybersecurity, 36% cut security budgets, and 24% laid off security staff.

  • Only 34% of organizations say they are adequately staffed, and only 55% believe they have adequate resources for the next two to three years.

  • 28% have already integrated AI tools into security operations, and another 41% are testing or evaluating them.

The WEF found the talent shortage is sharpest outside North America and Europe: 65% of organizations in Latin America and the Caribbean and 63% in sub-Saharan Africa lack sufficient cybersecurity talent.

Several 2026 datapoints have not yet made it into most statistics roundups. These are the ones worth watching:

Vulnerability exploitation is the number one breach vector. Verizon's 31% figure (up from 20%) marks the first DBIR in which exploited vulnerabilities outranked credential abuse. Combined with the finding that only 26% of critical known-exploited vulnerabilities were fully patched, patch cadence is now a board-level metric.

Breach timelines got longer for the first time in five years. IBM's 247-day average lifecycle is a 2.5% increase, reversing a multi-year decline. Attackers are getting harder to find, even as automated detection improves.

Ransom payments are falling while recovery costs climb. Sophos shows median demands down 65% over two years and Verizon shows 69% of victims refusing to pay, but Sophos also shows recovery costs up 11% to $1.7 million. The financial center of gravity is shifting from ransom to rebuild.

Shadow AI doubled. IBM's jump from 20% to 43% of incidents involving unsanctioned AI tools is the fastest-growing risk category in any 2026 report.

Healthcare breach costs dropped. After more than a decade of increases, IBM recorded a 10.5% decline in healthcare breach costs. It is too early to call it a trend, but it is the first good news for the sector in years.

Geopolitics is now a line item. The WEF found that 64% of organizations factor geopolitically motivated attacks into their risk strategies, and 91% of the largest enterprises have adjusted their security posture as a result.

The FBI passed one million complaints. 2025 was only the second year on record above one million complaints, and the first with reported losses above $20 billion. Losses have tripled since 2021.

How managed IT services can help

Looking for a managed security service provider that can help your organization reduce breach risk, close the skills gap, and meet compliance requirements? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options and get a free assessment.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 30, 2026 · 12 min read