2026 Verizon Data Breach Investigations Report: Strong foundations in the face of change
Verizon’s 19th edition of their Data Breach Investigations Report (DBIR) covers over 31,000 cyber incidents between October 2024 and November 2025 and represents victims from 145 countries.
Yet again, the number of breaches broke records and is the largest volume Verizon researchers have pored over. Of the over 31,000 incidents, more than 22,000 were confirmed.
If we were to give this report an overarching theme, it would be “keeping a strong foundation in the face of change.” Few people would argue that change, in every aspect of modern life, confronts us at an ever-increasing pace these days….Even as the threat landscape constantly evolves and changes, the 2026 edition of the DBIR invites you to consider the importance of the fundamentals of cybersecurity as the best way to brave all of this change. A little cyber-stoicism, if you will.
Six Cornerstone Findings
With 78% of breaches in the report classified as either system intrusion (61%) or social engineering (17%), the authors note these trends:
1. Increased vulnerability exploitation
31% of the breaches fall into this category, where criminals leverage unpatched software, flaws in hardware, or system misconfigurations to gain network access. It’s the most common initial access vector in the report; last year, credential abuse topped the charts for initial access.
2. Growth in ransomware
Though most victims chose not to pay ransom, with non-payment rates reaching 69%, ransomware comprised 48% of the data breaches in the report. The median ransom payment dropped to $139,875, down from $150,000 in 2025. You can learn more about the interplay between ransomware and phishing in this article.
3. Compounding third-party breaches
Breaches involving third-parties increased 60% from last year to account for 48% of the total. It’s a numbers game: as businesses migrate more services to the cloud, their chance of exposure increases. Verizon considers the following three types of third-party relationships in their breach calculations:
- Vendor in an organization’s software supply chain
- Vendor hosting an organization’s data
- Vendor connected to an organization’s environment
Criminals are leveraging these relationships, and even combinations of them, to produce successful exploits. The DBIR team notes the lack of Multi-factor authentication (MFA), improper credential rotation, and the absence of least privilege enforcement as core problems in these breaches.
4. AI lurking in the shadows
Criminals are using generative and other forms of AI on an average of 15 times at different periods during an attack, including targeting, initial access, and malware development. In some breaches, AI was used up to 50 times in a single attack.
DBIR authors report that shadow AI, services that aren’t on an organization’s approved tech list, remains a concern with 67% of people using non-corporate credentials on company devices to ply it. Shadow AI has grown to be the third most common non-malicious insider action detected, a fourfold percentage increase.
5. Social engineering: always on
Social engineering is an attack method that has caused successful breaches since 2018. It’s the third most common breach, representing 17% of all breaches in the 2026 DBIR. Email continues to be the choice weapon among criminals who are operating in the social engineering realm, especially when it comes to mobile devices. Pretexting and AI-supported phishing are aiding attackers to make social engineering even more believable, successful, and scalable.
Social Engineering, a longtime fan favorite, is evolving, as well, with attackers increasingly using voice and other mobile-centric techniques to catch people off guard in the middle of the workday.
6. Lures and lies: phishing and pretexting
Phishing is a common element for the thousands of data breaches in the DBIR accounting for 16% of initial access vectors. In the category of AI-assisted initial access vectors, phishing rose to 44%.
Pretexting, when a criminal builds a trustworthy relationship as a prelude to deceitful actions, has grown to become a common move for ransomware and extortion attacks; it was involved in 6% of breaches in this year’s report. Bad actors use email, texting, and phone calls in combination to lure victims and set the stage for fraud.
Back to basics with DMARC and dmarcian
As the DBIR team suggests, you can’t overestimate the importance of “getting the basics right” when it comes to stopping attackers from invading a digital environment.
DMARC comes into play by helping to protect internet domains from criminals using social engineering and phishing attacks. It ends up being the glue that lets organizations manage email as a domain-based service.
DMARC’s utility as an anti-spoofing technology stems from a far more significant innovation; instead of attempting to filter out malicious email, why not provide operators with a way to easily identify legitimate email? DMARC’s promise is to augment the “filter out bad” email security model with a “filter in good” model.
dmarcian’s mission is to see universal DMARC adoption. We advocate for the technology and advance it by helping organizations of all shapes and sizes deploy it. A properly structured DMARC deployment can lay the foundation for an organization’s trustworthy online presence.
We’re here to help you assess your domain catalog and implement and manage DMARC for the long haul.
Want to continue the conversation? Head over to the dmarcian Forum.