Managed ITServices
Statistics

Cybersecurity Statistics 2025: The Year in Review (Updated for 2026)

Cybersecurity threats reached new heights in 2025, with ransomware infiltrating nearly half of all data breaches and AI-powered phishing attacks surging at an unprecedented rate.

Cybersecurity threats reached new heights in 2025, with ransomware infiltrating nearly half of all data breaches and AI-powered phishing attacks surging at an unprecedented rate. Global cybercrime costs are on track to hit $10.5 trillion annually, a figure that would make cybercrime the third-largest economy in the world if it were a country. Organizations responded by pouring $213 billion into security spending, yet the talent gap widened to 4.8 million unfilled positions. This article breaks down the most important cybersecurity statistics from 2025 and highlights what has already shifted in 2026.

Key Cybersecurity Statistics From 2025 at a Glance

  • The average cost of a data breach globally was $4.44 million, the first decline in five years, according to IBM.

  • Ransomware was present in 44% of all confirmed breaches, a 37% jump from the prior year, per Verizon's DBIR.

  • Global information security spending reached $213 billion, a 10.4% increase over 2024, according to Gartner.

  • The cybersecurity workforce gap grew to 4.8 million unfilled roles worldwide, with 59% of teams reporting critical skills shortages.

  • AI-generated phishing attacks increased roughly 14-fold over the course of 2025, jumping from under 5% to 56% of detected malicious emails in some months.

  • Third-party and supply chain breaches doubled to 30% of all incidents analyzed by Verizon.

  • Ransomware was found in 88% of breaches affecting SMBs, disproportionately hitting smaller organizations.

  • The average breach lifecycle shortened to 241 days, the lowest in nine years.

  • Healthcare remained the costliest sector for breaches at $7.42 million on average, marking the 14th consecutive year on top.

  • Global cybercrime damages are projected to reach $10.5 trillion annually by end of 2025, according to Cybersecurity Ventures.

  • The U.S. recorded a record 3,322 data compromises in 2025, a 79% increase over the previous five years, per the Identity Theft Resource Center.

  • Average adversary breakout time fell to just 48 minutes in 2025, with the fastest recorded intrusion taking only 51 seconds, according to CrowdStrike.

Cybersecurity Statistics 2025: The Year in Review (Updated for 2026) infographic

Data Breach Volume Hit Record Highs

The sheer number of reported data compromises continued to climb in 2025. The Identity Theft Resource Center's 2025 Annual Data Breach Report, published in January 2026, recorded 3,322 publicly reported data compromises in the United States alone. That figure represents a 79% jump compared to five years earlier and a continuation of the upward trajectory that began in 2020. Financial services overtook healthcare as the most frequently breached industry by volume, though healthcare breaches remained costlier on a per-incident basis.

Perhaps more concerning than the raw numbers was the declining transparency around these incidents. The ITRC found that roughly 70% of breach notifications in 2025 omitted the root cause entirely, making it harder for affected individuals and peer organizations to learn from the incidents. This lack of disclosure complicates efforts to identify systemic weaknesses and raises questions about whether current breach notification laws are keeping pace with the threat landscape.

Adversaries Moved Faster Than Ever

Speed became the defining characteristic of cyberattacks in 2025. CrowdStrike's 2025 Global Threat Report found that the average breakout time for adversaries dropped to just 48 minutes, meaning attackers could move laterally from an initial compromised host to other systems in under an hour. The fastest observed breakout time was a staggering 51 seconds. These figures underscore the need for automated detection and response capabilities, since human analysts alone cannot consistently react within such narrow windows.

Identity-based attacks also surged. CrowdStrike reported a 150% increase in interactive intrusions targeting identity infrastructure, including attacks against single sign-on platforms, identity providers, and directory services. Vishing, or voice phishing, emerged as a particularly fast-growing vector, with a 442% increase between the first and second halves of 2025 as attackers used AI-generated voice cloning to impersonate IT help desks and executives.

Ransomware Became the Dominant Threat

Ransomware solidified its position as the single most prevalent attack method in 2025. Verizon's analysis of over 22,000 security incidents found ransomware in 44% of confirmed breaches, up from 32% in the previous year. Small and medium-sized businesses bore the brunt: 88% of SMB breaches involved ransomware, compared to a significantly lower share among large enterprises. For many of these smaller organizations, a single ransomware incident proved existential, disrupting operations for weeks and driving some to close their doors entirely.

Despite the increased frequency, there were signs that the economics of ransomware are shifting. The median ransom payment dropped to $115,000, and 64% of victim organizations refused to pay, up from 50% two years earlier. This growing resistance, combined with improved law enforcement coordination and better backup practices, suggests that paying ransoms is becoming less normalized even as attacks become more common. Cyber insurance carriers also played a role by tightening underwriting requirements and encouraging policyholders to invest in prevention over payouts.

Vulnerability exploitation also rose sharply, accounting for 20% of breaches in 2025, a 34% increase year over year. Attackers increasingly targeted unpatched edge devices and VPN appliances, turning known vulnerabilities into mass-exploitation campaigns within days of disclosure. Credential abuse remained the top initial access vector at 22% of breaches, underscoring the continued importance of multi-factor authentication and password hygiene across all organization sizes.

AI Reshaped the Threat Landscape

Artificial intelligence transformed cybersecurity on both sides of the battle in 2025. On the offensive side, AI-generated phishing attacks exploded. Research from Hoxhunt, which analyzed millions of malicious emails across 131 countries, found that AI-crafted phishing jumped approximately 14-fold by the end of the year. Early in 2025, fewer than 5% of phishing emails were AI-generated; by late 2025, that figure climbed to 56% in peak months.

IBM's 2025 Cost of a Data Breach Report revealed that 16% of breaches involved attacker-used AI, while 20% were linked to shadow AI within organizations. A staggering 97% of organizations that suffered AI-related breaches lacked proper access controls for AI tools, and 63% had no AI governance policies in place.

On the defensive side, organizations using AI and automation in their security operations saved an average of $1.93 million per breach compared to those without such tools. The message was clear: AI is not optional for defenders, but deploying it without governance creates new vulnerabilities.

The Talent Crisis Deepened

The cybersecurity workforce shortage worsened in 2025 despite growing awareness of the problem. The ISC2 2025 Cybersecurity Workforce Study, which surveyed over 16,000 professionals globally, found that 59% of organizations reported critical or significant skills needs, up from 44% in 2024. An estimated 4.8 million cybersecurity positions remained unfilled worldwide.

Budget pressures compounded the problem. Over the previous 12 months, 36% of organizations experienced cybersecurity budget cuts, 39% implemented hiring freezes, and 24% conducted cybersecurity layoffs. The consequences were tangible: 88% of respondents reported experiencing at least one negative outcome from skills deficiencies, and 72% agreed that reducing cybersecurity staff significantly increases the risk of a breach.

AI skills topped the wish list, with 41% of teams identifying AI expertise as their greatest gap, followed by cloud security at 36%. Only 55% of professionals believed their organizations had adequate resources to handle security incidents over the next two to three years.

Supply Chain and Third-Party Risk Doubled

One of the most alarming trends in 2025 was the doubling of third-party involvement in data breaches. According to Verizon's DBIR, 30% of breaches involved a third-party vendor or partner, up from 15% in the prior year. Attackers recognized that compromising a single managed service provider, software vendor, or cloud platform could yield access to dozens or hundreds of downstream targets.

This trend hit the healthcare and manufacturing sectors especially hard. Verizon noted an alarming rise in espionage-motivated attacks against manufacturers, while healthcare continued to face the longest breach detection timelines at 279 days on average.

Organizations spent more than ever to defend against these threats. Gartner's forecast showed global security spending hitting $213 billion in 2025, with security software as the fastest-growing segment, driven by cloud security posture management and zero-trust architecture adoption.

What Changed in 2026

Early data from 2026 shows several 2025 trends accelerating. IBM's 2026 Cost of a Data Breach Report recorded a new record average of $4.99 million per breach, a 12% increase that erased the prior year's decline. AI-driven attacks surged by 56%, with deepfake impersonation and AI-enabled malware emerging as top concerns. The average cost of an AI model inversion attack reached $6 million.

Verizon's 2026 DBIR found that ransomware now appears in 48% of breaches, up from 44% in 2025. Software vulnerabilities overtook stolen credentials as the primary initial access method, accounting for 31% of breaches. Mobile devices became a sharper focus for attackers, with 40% higher click rates on mobile phishing compared to desktop.

On the spending side, Gartner projects global security investment will reach $240 billion in 2026, a 12.5% jump. Security software spending alone is forecast to exceed $121 billion as organizations race to close AI governance gaps and secure increasingly complex cloud environments.

How Managed IT Services Can Help

The statistics paint a consistent picture: organizations face more sophisticated threats, tighter budgets, and a severe shortage of skilled defenders. For small and mid-sized businesses, where 88% of breaches involve ransomware and in-house expertise is hardest to maintain, the gap between threat severity and defense capability is especially wide.

Managed IT services offer a practical path forward. By outsourcing security monitoring, vulnerability management, and incident response to a dedicated provider, businesses gain access to the 24/7 coverage, AI-powered detection tools, and experienced analysts that would be prohibitively expensive to build in-house. A managed approach also addresses supply chain risk through continuous vendor assessment and zero-trust network architecture.

Rather than competing for scarce cybersecurity talent in a market with 4.8 million unfilled roles, organizations can leverage managed services to close the gap between their current security posture and the threat landscape these statistics describe.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 30, 2026 · 8 min read