Data Breach Statistics for 2026: Costs, Causes, and Trends
The average cost of a data breach reached a record $4.99 million in 2026, up 12% in a single year, according to IBM's 2026 Cost of a Data Breach Report.
Table of Contents
The average cost of a data breach reached a record $4.99 million in 2026, up 12% in a single year, according to IBM's 2026 Cost of a Data Breach Report. In the United States, the average breach now costs $11.5 million, more than double the global figure. The Identity Theft Resource Center tracked 1,803 publicly reported data compromises in the first half of 2026 alone, generating 471.2 million victim notices, which already exceeds the full-year 2025 total. And for the first time in the history of the Verizon 2026 Data Breach Investigations Report, vulnerability exploitation (31% of breaches) has overtaken stolen credentials (13%) as the leading way attackers get in.
This page collects the most-cited data breach statistics for 2026, re-sourced to the newest editions of the major reports, with 2025 figures used only where a 2026 edition has not yet been published.
Data breach statistics 2026: key numbers at a glance
$4.99 million: global average cost of a data breach in 2026, a 12% increase year over year (IBM, 2026)
$11.5 million: average cost of a data breach in the United States, up 11% (IBM, 2026)
$6.64 million: average cost of a healthcare data breach, the costliest industry for the 13th consecutive year (IBM, 2026)
247 days: mean time to identify and contain a breach (IBM, 2026)
1 in 4: share of malicious breaches that were AI-enabled, up 56% year over year, costing about $6 million each (IBM, 2026)
43%: share of security incidents involving shadow AI, more than double the prior year (IBM, 2026)
31%: share of breaches that began with vulnerability exploitation, now the top initial access vector (Verizon DBIR, 2026)
48%: share of breaches involving a third party, a 60% year-over-year increase (Verizon DBIR, 2026)
48%: share of breaches involving ransomware (Verizon DBIR, 2026)
3,322: publicly reported data compromises in the US in 2025, a record (ITRC, 2025 annual report)
1,803: compromises in the first half of 2026, on pace for roughly 3,600 for the year (ITRC, 2026)
$20.9 billion: reported losses to internet crime in 2025, up 26% (FBI IC3, 2025 report)
189: large healthcare breaches reported to HHS in the first half of 2026, affecting more than 19 million people (HHS OCR, 2026)
The average cost of a data breach in 2026
Breach economics moved sharply in 2026. After a brief dip in the prior cycle, IBM's 2026 Cost of a Data Breach Report, which analyzed 602 organizations breached between March 2025 and February 2026, put the global average cost of a data breach at $4.99 million. That is the highest figure IBM has ever recorded and a 12% jump in one year.
The US remains the most expensive country in which to be breached. The average US data breach cost $11.5 million in 2026, an 11% increase, driven by regulatory exposure, litigation, and notification requirements that vary across all 50 states.
Cost by industry, per IBM's 2026 report:
Healthcare: $6.64 million, the costliest sector for the 13th year in a row
Financial services: $6.29 million
Industrial: $5.5 million
Technology: $5.5 million
Entertainment: $5.4 million
Time matters as much as sector. The mean time to identify and contain a breach rose to 247 days in 2026. Breaches that took longer than 200 days to contain cost $5.65 million on average, versus $4.32 million for those contained faster. Organizations that used AI and automation across prevention, detection, investigation, and response closed breaches roughly two months faster and paid close to $2 million less per incident. Even so, IBM found that one in four organizations had still not adopted those tools.
Two other cost drivers stand out in the 2026 data. Supply chain compromise adds more to the total breach bill than any other single factor. And only 37% of organizations encrypt sensitive data both at rest and in transit, leaving most breached organizations exposed to the full regulatory and notification cost of a plaintext data loss.
How many data breaches happen each year
Counting breaches depends on who is counting, and the two most rigorous US trackers tell a consistent story: incident frequency is at an all-time high, while the number of people affected swings wildly depending on a handful of mega-breaches.
The ITRC 2025 Annual Data Breach Report, published in January 2026, logged 3,322 publicly reported data compromises in 2025, up 5% from 3,152 in 2024 and a new record. Victim notices, however, fell 79% to 278.8 million, down from 1.36 billion in 2024, because 2025 lacked the billion-record events that inflated the prior year. The largest 2025 compromises were PowerSchool (71.9 million notices), an AT&T data repository from 2021 (44 million), Aflac (22.6 million), Prosper Funding (17.6 million), and Conduent Business Services (14.8 million).
Cyberattacks accounted for 2,656 of the 3,322 compromises (80%), with phishing the leading known vector at 466 incidents. By industry, financial services led with 739 compromises, followed by healthcare (534), professional services (478), manufacturing (299), and education (188).
Then 2026 reversed the victim-count trend. In the first half of 2026, ITRC tracked 1,803 compromises and an estimated 471.2 million victim notices, already surpassing all of 2025. Q2 2026 alone produced 1,029 compromises, the second-highest quarterly total on record. A single event, the Instructure Canvas platform breach, generated roughly 275 million notices, or 58% of the half-year total. Publicly traded companies represented only 10.3% of H1 2026 compromises but 83.4% of victim notices.
The bigger structural change is transparency. In 2025, 70% of breach notices contained no information about how the breach happened. By mid-2026 that number was worse: only 24% of notices disclosed an attack vector, the lowest rate ITRC has ever recorded.
What causes data breaches in 2026
The Verizon 2026 Data Breach Investigations Report is the largest dataset in the report's history: more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries. Its headline finding upends a decade of received wisdom.
Vulnerability exploitation caused 31% of breaches, up from 20% the prior year, making it the number one initial access vector for the first time.
Credential abuse fell to 13%, down from 22%.
Phishing accounted for 16% of breaches, and pretexting for 6%.
The human element was involved in 62% of breaches.
System intrusion was the pattern behind 61% of breaches, followed by social engineering (17%) and basic web application attacks (10%).
Patching is losing ground. Organizations fully remediated only 26% of the critical vulnerabilities in CISA's Known Exploited Vulnerabilities catalog during 2025, down from 38%, and the median time to remediate rose to 43 days from 32. The median organization faced 16 KEV-listed vulnerabilities to patch over the year, and 89% of organizations detected memory safety weaknesses in their environments.
Third-party risk is the other defining theme. Breaches involving a third party or supply chain partner rose 60% year over year and now feature in 48% of all breaches. The HHS data below shows the same pattern in healthcare, where seven of the ten largest 2026 breaches originated at vendors and business associates rather than at the providers themselves.
Ransomware statistics 2026
Ransomware appears in nearly half of all breaches. The Verizon 2026 DBIR found ransomware involved in 48% of breaches analyzed, up from 44%, while IBM's 2026 report found 39% of breached organizations experienced ransomware, up from 34% and the fourth consecutive annual increase. Attackers increasingly rely on leverage rather than encryption alone: 41% of ransomware victims in IBM's study said attackers used the threat of brand reputation damage as pressure, 35% cited threats involving employee data, and 31% cited intellectual property.
Payments are falling even as attacks rise. The DBIR's median ransom payment was $139,875, and 69% of victims did not pay at all. The Sophos State of Ransomware 2026 survey of 2,158 IT and security leaders across 17 countries reported that the median ransom demand fell to $698,000 (down 65% over two years) and the median payment dropped to $769,000 from $1 million the prior year. Among organizations whose data was encrypted, 48% paid, and 51% of those who paid negotiated a lower amount than the initial demand.
The costs beyond the ransom keep climbing. Sophos put the average recovery cost, excluding any ransom, at $1.7 million per incident, up 11% year over year. Attackers succeeded in encrypting data in 56% of attacks, up from 50%. The top root causes were malicious email (26%), phishing (24%), compromised credentials (23%), and exploited vulnerabilities (18%), and 79% of attacks started with an identity-based approach.
Size matters for outcomes. Sophos found that organizations with 100 to 250 employees stopped only 34% of ransomware attacks before encryption occurred, a gap that explains why smaller companies are increasingly turning to managed security service providers for round-the-clock detection and response.
Healthcare data breach statistics 2026
Healthcare remains the most-cited vertical in data breach reporting because federal law forces disclosure. Every breach affecting 500 or more people must be posted to the HHS Office for Civil Rights breach portal, which makes it the most complete public breach dataset for any US industry.
Through June 30, 2026, the OCR portal listed 189 large healthcare breaches affecting more than 19 million individuals. Hacking and IT incidents accounted for 173 of the 189, with the remainder split among unauthorized access or disclosure (14), theft (1), and loss (1). The largest 2026 healthcare breaches reported to date include TriZetto Provider Solutions (3.43 million individuals), QualDerm Partners (3.12 million), Nacogdoches Memorial Hospital (2.51 million), Navia Benefit Solutions (2.15 million), and NYC Health + Hospitals (1.8 million). Seven of the ten largest involved business associates or vendor systems rather than the covered entity itself.
The financial stakes are the highest of any sector. IBM's 2026 report put the average healthcare data breach at $6.64 million, the costliest industry for the 13th straight year. ITRC counted 534 healthcare compromises in 2025 and 281 in the first half of 2026, second only to financial services in both periods. Organizations weighing managed IT services for healthcare should note that vendor and business associate oversight, not just internal controls, now drives most large-scale exposure.
The broader cost of cybercrime
Data breaches sit inside a much larger cybercrime economy. The FBI's 2025 Internet Crime Report, released by IC3 in 2026, recorded more than one million complaints and $20.9 billion in reported losses in 2025, a 26% increase over the prior year, with an average loss of $20,700 per complaint.
Phishing and spoofing generated 191,561 complaints, roughly 19% of the total.
Investment fraud losses surpassed $8.6 billion, 43% of all losses.
Business email compromise cost victims $3 billion, 15% of losses.
Cryptocurrency was involved in 181,565 complaints and more than $11 billion in losses (55% of the total).
AI-related crimes drew 22,364 complaints and $893 million in losses, the first year IC3 broke out AI as a category.
Adults aged 60 and older filed more than a fifth of complaints and lost $7.7 billion, 39% of all reported losses.
Those losses are reported by victims, so they capture fraud and extortion rather than the full internal cost of a breach. Read alongside IBM's $11.5 million US average, they show two separate bills: what attackers steal directly, and what organizations spend cleaning up.
Emerging trends and what's new in 2026
AI is now on both sides of the breach. IBM's 2026 report found that one in four malicious breaches were AI-enabled, a 56% increase, and those breaches cost about $6 million on average, roughly $1 million more than the global average. Deepfake impersonation made up 45% of AI-driven attacks, with AI-enabled malware and AI-generated phishing at 19% each. Over 20% of organizations reported breaches targeting their own AI models or applications, most often through compromised APIs and plug-ins (27%) or cloud misconfigurations (27%). Voice and SMS phishing carried the highest average cost of any initial vector, with help desk impersonation next.
Shadow AI has become a measurable breach factor. Incidents involving unapproved AI tools accounted for 43% of security incidents in IBM's 2026 study, up from 20% a year earlier, and cost $5.39 million on average. The Verizon 2026 DBIR corroborates the exposure: 45% of employees are now regular AI users, up from 15%, and 67% of people accessing AI services on corporate devices did so with non-corporate accounts. Shadow AI ranked as the third most common insider action in data loss prevention violations. Meanwhile, 92% of organizations in IBM's study lacked AI access controls and 68% had no AI governance policy.
Boards are responding with budgets. 85% of organizations in IBM's 2026 study said they plan to increase security spending in response to frontier AI model threats, and 64% plan to increase spending after a breach. The World Economic Forum's Global Cybersecurity Outlook 2026 found 94% of leaders named AI as the biggest driver of change in cybersecurity this year. Notably, concern has shifted from adversarial AI attacks (29% of respondents, down from 47% in 2025) toward data leakage through generative AI tools (34%).
Insider threats spiked. ITRC recorded 21 malicious insider events in the first half of 2026, a sevenfold increase from just 3 in all of 2025. Zero-day exploits hit 14 events in six months, nearly matching the 17 recorded for all of 2025.
Supply chain attacks scale faster than anything else. ITRC counted 38 supply chain attacks in H1 2026 that cascaded to 206 downstream organizations and produced 280.6 million victim notices. In 2025, 133 supply chain attacks affected 1,252 entities and generated 98.7 million notices. Verizon's 60% jump in third-party breach involvement and IBM's finding that supply chain compromise is the single largest cost amplifier point in the same direction.
Small organizations face a widening expertise gap. The WEF's 2026 outlook found 46% of small organizations report insufficient in-house cyber expertise, compared with 29% of large organizations. Combined with Sophos's finding that companies with 100 to 250 employees stop only 34% of ransomware attacks before encryption, and the DBIR's 43-day median patch time against a 31% exploitation rate, the data suggests that the organizations least able to staff a security team are the ones most exposed to the fastest-growing attack vector.
How managed IT services can help
The 2026 data points to three controls with measurable payoff: faster patching of known exploited vulnerabilities, AI and automation in detection and response (worth roughly $2 million and two months per breach in IBM's study), and rigorous third-party oversight. Most mid-sized organizations cannot build all three internally.
Looking for a managed security service provider that can help your organization reduce breach risk and shorten response times? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options in your area.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 29, 2026 · 12 min read