Managed ITServices
Statistics

Data Breach Statistics 2025: The Year in Review (Updated 2026)

Data breaches reached a new peak in 2025, affecting hundreds of millions of people and costing organizations billions of dollars worldwide.

Data breaches reached a new peak in 2025, affecting hundreds of millions of people and costing organizations billions of dollars worldwide. As businesses adopted AI tools at breakneck speed and attackers refined their techniques, the cybersecurity landscape shifted in ways that caught many organizations off guard. This article compiles the most important data breach statistics from 2025, drawn from primary research by the Identity Theft Resource Center, IBM, Verizon, and other leading sources, along with early 2026 updates that show where things are headed next.

Key Data Breach Statistics From 2025

  • The United States experienced a record 3,322 data breaches in 2025, a 5% increase over the previous year and a 79% jump over five years, according to the Identity Theft Resource Center's 2025 Annual Data Breach Report.

  • Approximately 279 million individuals received data breach notification letters in 2025, down sharply from 1.4 billion in 2024 due to fewer mega breaches.

  • The global average cost of a data breach fell to $4.44 million in 2025, a 9% decline from the prior year, as reported by IBM's 2025 Cost of a Data Breach Report.

  • Cyberattacks caused 80% of all data breaches in 2025, totaling 2,656 incidents where personal information was stolen.

  • 48% of all breaches now involve ransomware, according to the Verizon 2026 Data Breach Investigations Report, which analyzed incidents occurring between November 2024 and October 2025.

  • Organizations identified and contained breaches in a mean time of 241 days in 2025, the lowest figure in nine years.

  • Two-thirds of breach incidents exposed Social Security numbers, while one-third disclosed bank account details or driver's license numbers.

  • 70% of breach notices in 2025 lacked specific details about the attack method, up from 65% in 2024.

  • 79 supply chain attacks in the first half of 2025 alone impacted 690 entities and led to 78.3 million victim notifications, per the ITRC H1 2025 Data Breach Report.

  • Shadow AI usage added an average of $670,000 to breach costs when unapproved AI tools were involved.

Data Breach Statistics 2025: The Year in Review (Updated 2026) infographic

The Rising Cost of Data Breaches

While the headline cost figure dropped to $4.44 million globally, the story underneath is more nuanced. IBM's research found that 97% of breached organizations that experienced AI-related incidents lacked proper AI access controls, and 63% had no AI governance policies in place. The emergence of shadow AI, where employees use unapproved internet-based AI tools on corporate data, became a significant cost multiplier in 2025.

Organizations that deployed security AI and automation tools continued to see substantially lower breach costs compared to those without such defenses. The gap between prepared and unprepared organizations grew wider in 2025, rewarding those that invested in detection and response capabilities while penalizing those that lagged behind.

The speed of breach containment also improved meaningfully. At 241 days, the mean time to identify and contain a breach hit its lowest point in nearly a decade. Faster detection translated directly into lower costs, reinforcing the business case for continuous monitoring and automated threat response.

Industries Under Siege

Financial services topped the list of most-breached industries in 2025 with 739 reported compromises, according to ITRC data. Healthcare followed with 534 breaches, professional services reported 478, manufacturing logged 299, and education experienced 188.

The concentration in financial services is not surprising given the value of the data these organizations hold. Bank account numbers, credit card details, and Social Security numbers command premium prices on dark web marketplaces. Healthcare organizations remain attractive targets for ransomware operators because system downtime directly threatens patient safety, creating urgency to pay.

The manufacturing sector's presence in the top five reflects a broader trend of attackers targeting operational technology environments. As factory floors become more connected, the attack surface expands into systems that were never designed with cybersecurity in mind.

Professional services firms, including law offices, accounting practices, and consulting agencies, ranked third with 478 breaches. These organizations often hold sensitive client data across multiple industries, making them high-value targets that can yield access to dozens of downstream organizations through a single compromise. The education sector rounded out the top five with 188 breaches, a number that would rise dramatically in early 2026.

Attack Methods and Vectors

The Verizon 2026 DBIR revealed a significant shift in how attackers gain initial access. Software vulnerabilities overtook stolen credentials as the top entry point, accounting for 31% of breaches. This marks a meaningful change from prior years when phishing and credential theft dominated.

Ransomware continued its upward trajectory, appearing in 48% of all breaches. However, the report noted that actual ransom payouts are shrinking, suggesting that more organizations are refusing to pay and instead relying on backups and incident response plans.

Mobile devices emerged as a growing concern, with attackers achieving 40% higher click rates on mobile-targeted phishing campaigns compared to desktop. The smaller screen size, notification-driven interaction patterns, and tendency to abbreviate URLs on mobile all work in the attacker's favor.

Generative AI began reshaping the threat landscape as well. Verizon identified 15 different attack techniques now being enhanced by generative AI, from crafting more convincing phishing emails to automating vulnerability discovery.

The Transparency Problem

One of the most troubling trends in 2025 was the growing lack of transparency in breach disclosures. The ITRC found that 70% of data breach notices filed in 2025 omitted meaningful details about how the breach occurred, up from 65% the year before. In the first half of 2025, 69% of notices lacked root cause information.

This matters because consumers and businesses cannot make informed security decisions without understanding what went wrong. When breach notices simply state that "unauthorized access" occurred without explaining whether it was a phishing attack, an unpatched vulnerability, or a misconfigured cloud server, the entire ecosystem loses an opportunity to learn and improve.

The ITRC's consumer survey painted a vivid picture of breach fatigue: 80% of respondents received at least one breach notice in the past year, 40% received three to five, and 88% reported negative consequences including phishing attempts, spam, and account takeover efforts.

What Changed in 2026

Early data from 2026 suggests a partial cooling after 2025's record highs, but significant risks remain. The Privacy Rights Clearinghouse 2026 Midyear Report documented 1,969 distinct breach events in the first half of 2026, roughly 10% fewer than the same period in 2025. However, 343 million individuals were still affected.

The decline in breach counts may reflect improved defenses at some organizations, but a single massive incident involving the Canvas learning management platform accounted for the vast majority of affected individuals, with one filing alone listing 275 million people.

AI-driven attacks accelerated in 2026. Attackers increasingly used generative AI to craft targeted phishing campaigns, automate reconnaissance, and exploit vulnerabilities faster than defenders could patch them. The line between automated scanning and sophisticated, AI-assisted intrusion continued to blur.

Healthcare breaches remained stubbornly high, with 509 events in H1 2026, while business services led in total events at 763. Hacking accounted for 58% of breach events, and the share of breaches with unknown causes rose to 34%, continuing the transparency problem identified in 2025.

How Managed IT Services Can Help

The statistics paint a clear picture: data breaches are not slowing down, attack methods are growing more sophisticated, and most organizations lack the internal resources to keep pace. This is where partnering with a managed IT services provider becomes a strategic advantage rather than just a cost center.

A qualified managed services partner delivers continuous network monitoring, automated threat detection, and rapid incident response without requiring organizations to build and staff a full security operations center. With the mean time to contain a breach still sitting at 241 days even at its nine-year low, there is significant room for improvement through 24/7 monitoring and proactive threat hunting.

Managed IT providers also address the shadow AI problem by implementing governance frameworks, approved tool lists, and access controls that prevent employees from inadvertently exposing sensitive data through unapproved AI services. As IBM's research showed, this single factor can add $670,000 to breach costs when left unmanaged.

Patch management is another area where managed services deliver outsized value. With software vulnerabilities now the top initial access vector in 31% of breaches, timely patching is no longer optional. Managed IT providers maintain patching schedules, test updates before deployment, and ensure that critical vulnerabilities are remediated within hours rather than weeks.

Supply chain risk management also benefits from professional oversight. With 79 supply chain attacks in just the first half of 2025 affecting 690 downstream entities, organizations need to assess and monitor their third-party vendors continuously. Managed services teams bring the tools and expertise to conduct vendor risk assessments, monitor supply chain indicators of compromise, and respond quickly when a partner is breached.

For small and mid-sized businesses that represent a growing share of breach targets, manageditservices.ai provides resources to evaluate managed IT partners, compare service offerings, and understand what level of protection fits your organization's risk profile and budget. The cost of prevention remains a fraction of the cost of recovery.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Sep 29, 2026 · 7 min read