Data Breach Statistics (2026): 50+ Data Points on Breach Costs, Attack Vectors, and Detection Times

Data breach statistics 2026: 50+ sourced data points on breach costs, records exposed, attack vectors, and response times, from IBM, ITRC, and Verizon.

The average U.S. data breach reached an all-time high of $10.22 million in 2025, roughly 2.3 times the global average (IBM, Cost of a Data Breach Report 2025). Yet the global average fell 9 percent to $4.44 million, the first decline in five years, as AI-assisted defense cut the mean breach lifecycle to 241 days (IBM, Cost of a Data Breach Report 2025). Volume moved the other way: the Identity Theft Resource Center logged a record 3,322 U.S. data compromises in 2025, up 5 percent (ITRC, 2025 Annual Data Breach Report). Ransomware now touches 44 percent of breaches, and the human element is present in 60 percent (Verizon, 2025 DBIR). This analysis consolidates data from IBM’s Cost of a Data Breach Report, the ITRC Annual Data Breach Report, the Verizon DBIR, and four other primary sources including the FBI IC3, Sophos, and the HHS Office for Civil Rights.

TL;DR

  • Global average breach cost was $4.44 million in 2025, the first decline in five years (IBM, Cost of a Data Breach Report 2025).
  • The U.S. average hit a record $10.22 million, about 2.3x the global figure (IBM, Cost of a Data Breach Report 2025).
  • The U.S. logged a record 3,322 data compromises in 2025, up 5 percent (ITRC, 2025 Annual Data Breach Report).
  • Victim notices fell 79 percent to 278.8 million as mega-breaches faded (ITRC, 2025 Annual Data Breach Report).
  • Ransomware appeared in 44 percent of breaches, up 37 percent year over year (Verizon, 2025 DBIR).
  • Analysts reviewed 12,195 confirmed breaches out of 22,000+ incidents (Verizon, 2025 DBIR).
  • The mean breach lifecycle dropped to 241 days, the lowest in nine years (IBM, Cost of a Data Breach Report 2025).
  • Internet crime losses reached $20.877 billion in 2025, up 26 percent (FBI, IC3 Internet Crime Report 2025).
  • 710 healthcare breaches exposed 61.6 million records in 2025 (HIPAA Journal / HHS OCR, 2025 Healthcare Data Breach Report).
  • A June 2025 credential leak exposed roughly 16 billion login records (Cybernews, 2025).
  • The median ransomware recovery cost fell 44 percent to $1.53 million (Sophos, State of Ransomware 2025).

1. What a Breach Costs

The headline of IBM’s 2025 report is a split screen. The global average cost fell for the first time since 2020, but that decline is almost entirely a detection-speed story, not a sign that attacks got cheaper. In the United States, the average breach cost climbed 9 percent to a record $10.22 million while the global figure dropped to $4.44 million, a gap driven by aggressive class-action litigation, escalating regulatory fines, and 50 states worth of mandatory notification laws. Healthcare stayed the most expensive industry for a 15th straight year, and organizations that used security AI and automation extensively spent about $1.9 million less per incident than those that used neither. Full methodology is in the IBM Cost of a Data Breach Report 2025.

MetricValueSource
Global average breach cost, 2025$4.44M (down 9%, first decline in 5 years)IBM, Cost of a Data Breach Report 2025
U.S. average breach cost$10.22M (record high, ~2.3x global)IBM, Cost of a Data Breach Report 2025
Highest-cost industry (healthcare)$7.42M (15th consecutive year)IBM, Cost of a Data Breach Report 2025
Second-highest industry (financial services)$5.56MIBM, Cost of a Data Breach Report 2025
Highest / lowest regionMiddle East $7.29M / Brazil $1.22MIBM, Cost of a Data Breach Report 2025
Savings from extensive AI + automation~$1.9M lower per incidentIBM, Cost of a Data Breach Report 2025

Context: IBM’s figures draw on 600 organizations breached between March 2024 and February 2025; nearly two-thirds said they were still recovering, typically beyond 100 days.

2. How Many Breaches, How Many Victims

Breach counts and victim counts moved in opposite directions in 2025, and the divergence is the year’s most important nuance. Compromises hit a new record, but the number of people notified collapsed. Victim notices fell 79 percent to 278.8 million, down from 1.37 billion in 2024, purely because 2025 produced no single mega-breach on the scale of the prior year. Financial services was the most-attacked sector for a second consecutive year, a shift the ITRC attributes to criminals prioritizing static identifiers like bank account numbers that enable long-term fraud. See the ITRC 2025 Annual Data Breach Report for the full breakdown.

MetricValueSource
U.S. data compromises, 20253,322 (record, +5% vs 2024)ITRC, 2025 Annual Data Breach Report
Prior all-time high (2023)3,202ITRC, 2025 Annual Data Breach Report
Growth in compromises over five years+79%ITRC, 2025 Annual Data Breach Report
Victim notices, 2025278,827,933 (down 79% vs 2024’s 1,367,117,021)ITRC, 2025 Annual Data Breach Report
Most-breached sector (financial services)739 compromisesITRC, 2025 Annual Data Breach Report
Healthcare / professional services534 / 478 compromisesITRC, 2025 Annual Data Breach Report
Manufacturing / education299 / 188 compromisesITRC, 2025 Annual Data Breach Report
Largest single exposure (credential leak)~16 billion login records, 30 datasetsCybernews, 2025

That 16 billion figure is aggregated infostealer and prior-breach data, not one fresh hack, which is why reused and stolen passwords dominate the risk picture; our password security statistics roundup breaks down credential reuse in depth.

3. Attack Vectors and Root Causes

The way in has shifted. Vulnerability exploitation surged and now rivals stolen credentials as the leading entry point, while phishing, though still common, slipped in relative share. Stolen credentials remained the single most common initial vector at 22 percent of breaches, with the human element present in 60 percent (Verizon, 2025 DBIR). Third-party involvement doubled to 30 percent, a reminder that a vendor’s weak control becomes your breach. A newer risk category emerged in IBM’s data: breaches tied to unsanctioned “shadow AI” tools cost more and almost always involved missing access controls. The full corpus is documented in the Verizon 2025 Data Breach Investigations Report; for the wider threat picture see our cybersecurity statistics overview.

MetricValueSource
Human element in breaches60%Verizon, 2025 DBIR
Credential abuse (top initial vector)22%Verizon, 2025 DBIR
Vulnerability exploitation20% (+34% year over year)Verizon, 2025 DBIR
Phishing15% of breachesVerizon, 2025 DBIR
Third-party involvement30% (doubled)Verizon, 2025 DBIR
Espionage-motivated breaches17% (+163%)Verizon, 2025 DBIR
Breaches involving shadow AI$4.63M average (+$670K premium)IBM, Cost of a Data Breach Report 2025
AI-related incidents lacking access controls97%IBM, Cost of a Data Breach Report 2025

Outlier: espionage attackers exploit vulnerabilities in 70 percent of their intrusions, far above the all-motive average (Verizon, 2025 DBIR).

4. Detection and Response Time

Speed is now the biggest lever on cost. IBM’s data shows containment time correlates almost linearly with dollars, and the industry finally moved the needle. The mean time to identify and contain a breach fell to 241 days, the lowest in nine years, split into 181 days to detect and 60 to contain. Half of breaches were still caught by internal teams, but nearly one in five were disclosed by the attacker, the worst-case discovery path in both cost and reputational terms. Edge devices remain the soft underbelly: attackers weaponize new VPN and firewall flaws almost instantly. The detection figures come from the IBM Cost of a Data Breach Report 2025.

MetricValueSource
Mean breach lifecycle, 2025241 days (lowest in 9 years)IBM, Cost of a Data Breach Report 2025
Detect / contain split181 days / 60 daysIBM, Cost of a Data Breach Report 2025
Cost premium for >200-day containment+$1.14MIBM, Cost of a Data Breach Report 2025
How breaches are foundInternal 50% / third party 31% / attacker 19%IBM, Cost of a Data Breach Report 2025
Edge/VPN flaws: time to mass exploitation0 days (median)Verizon, 2025 DBIR
Edge/VPN flaws patchedOnly 54% (32-day median fix)Verizon, 2025 DBIR

Context: breaches disclosed by the attacker averaged $5.08 million, versus $4.18 million when a company’s own security team found the intrusion (IBM, Cost of a Data Breach Report 2025).

5. Ransomware Economics

Ransomware is both more prevalent and, for many victims, less lucrative to the attacker. It now factors into 44 percent of breaches, yet payouts and recovery costs both dropped sharply as more organizations refused to pay and restored from backups faster. The median ransom payment halved to $1 million and the mean recovery cost (excluding any ransom) fell 44 percent to $1.53 million in Sophos’s survey of 3,400 organizations. The two headline datasets diverge on payout size, an artifact of different populations: Verizon’s breach corpus includes many small victims, while Sophos surveyed firms of 100 to 5,000 employees. Details are in the Sophos State of Ransomware 2025 report; see our ransomware statistics deep dive for attack-group trends.

MetricValueSource
Ransomware present in breaches44% (+37% year over year)Verizon, 2025 DBIR
Ransomware in SMB breaches88% (vs 39% at large enterprises)Verizon, 2025 DBIR
Median ransom payout (breach corpus)$115K; 64% of victims refused to payVerizon, 2025 DBIR
Median ransom payment (survey)$1M (down 50% from $2M)Sophos, State of Ransomware 2025
Mean recovery cost, excl. ransom$1.53M (down 44%)Sophos, State of Ransomware 2025
Ransom paid vs initial demand85% on averageSophos, State of Ransomware 2025
Fully recovered within a week53% (up from 35%)Sophos, State of Ransomware 2025

Divergence note: the $115K (Verizon) versus $1M (Sophos) median gap reflects sample composition, not a contradiction; both are self-reported.

6. Healthcare Under Siege

Healthcare remains the most consequential breach sector, and 2025 set a records-count high even as the raw number of exposed individuals dropped by more than three-quarters. 710 breaches of 500 or more records exposed 61.6 million individuals, down 78.7 percent from 2024’s 289 million, again a mega-breach effect rather than improved security. The sector’s structural exposure endures: medical records fetch far more than payment cards on illicit markets, HIPAA fines are steep, and detection lags run longer than average. Figures are compiled from the HHS Office for Civil Rights portal, reported in the HHS OCR breach portal and HIPAA Journal’s annual analysis.

MetricValueSource
Healthcare breaches (500+ records), 2025710HIPAA Journal / HHS OCR, 2025 Healthcare Data Breach Report
Individuals affected, 202561,556,256 (down 78.7% from 2024)HIPAA Journal / HHS OCR, 2025
Mega breaches (1M+ individuals)9 (vs 18 in 2024)HIPAA Journal / HHS OCR, 2025
Largest 2025 breach (Aflac)13,924,906 individualsHIPAA Journal / HHS OCR, 2025
Average / median breach size86,699 / 4,011 individualsHIPAA Journal / HHS OCR, 2025
Breach location: network servers / email61.5% / 24.9%HIPAA Journal / HHS OCR, 2025
Entity split: providers / associates / plans57.5% / 35.8% / 6.5%HIPAA Journal / HHS OCR, 2025
Largest U.S. healthcare breach on recordChange Healthcare, 192.7MHHS OCR (2024 incident, total finalized)

Note: Change Healthcare is a 2024 attack whose final tally of 192.7 million was confirmed later; it is included as the most recent all-time benchmark, flagged by year.

7. The Human and Financial Fallout

Breaches convert into fraud losses that fall hardest on individuals, and the FBI’s 2025 tally shows the toll accelerating. U.S. internet crime losses hit $20.877 billion in 2025, up 26 percent year over year, across more than a million complaints. Personal data breaches were their own complaint category with 67,456 filings, but the downstream damage shows up in phishing, extortion, and business email compromise. Older Americans absorbed a disproportionate share of the losses. The full dataset is the FBI IC3 2025 Internet Crime Report; breach-driven fraud is covered further in our identity theft statistics roundup.

MetricValueSource
Internet crime complaints, 20251,008,597FBI, IC3 Internet Crime Report 2025
Total reported losses$20.877B (+26% vs 2024)FBI, IC3 Internet Crime Report 2025
Average loss per complaint$20,699FBI, IC3 Internet Crime Report 2025
Personal data breach complaints67,456FBI, IC3 Internet Crime Report 2025
Phishing / spoofing complaints (top type)191,561FBI, IC3 Internet Crime Report 2025
Losses among victims over 60$7.7B (201,266 complaints)FBI, IC3 Internet Crime Report 2025
Business email compromise losses$3.046BFBI, IC3 Internet Crime Report 2025

Outlier: cryptocurrency-related complaints alone accounted for $11.37 billion of the 2025 loss total (FBI, IC3 Internet Crime Report 2025).

Summary: Data Breaches by the Numbers

MetricValueSource
Global average breach cost$4.44MIBM, Cost of a Data Breach Report 2025
U.S. average breach cost$10.22MIBM, Cost of a Data Breach Report 2025
Healthcare average breach cost$7.42MIBM, Cost of a Data Breach Report 2025
Mean breach lifecycle241 daysIBM, Cost of a Data Breach Report 2025
U.S. data compromises, 20253,322 (record)ITRC, 2025 Annual Data Breach Report
Victim notices, 2025278.8M (down 79%)ITRC, 2025 Annual Data Breach Report
Most-breached sector (financial services)739 compromisesITRC, 2025 Annual Data Breach Report
Confirmed breaches analyzed12,195 (of 22,000+ incidents)Verizon, 2025 DBIR
Ransomware share of breaches44%Verizon, 2025 DBIR
Human element in breaches60%Verizon, 2025 DBIR
Credential abuse (top vector)22%Verizon, 2025 DBIR
Median ransomware recovery cost$1.53MSophos, State of Ransomware 2025
Median ransom payment (survey)$1MSophos, State of Ransomware 2025
Healthcare breaches (500+ records)710HIPAA Journal / HHS OCR, 2025
Healthcare records exposed61.6MHIPAA Journal / HHS OCR, 2025
U.S. internet crime losses$20.877BFBI, IC3 Internet Crime Report 2025
Personal data breach complaints67,456FBI, IC3 Internet Crime Report 2025
Largest single exposure (credentials)~16 billion recordsCybernews, 2025

Methodology and Sources

Data was gathered by aggregating figures directly from primary annual reports, government breach portals, and the original research surveys published in H1 2026 covering 2025 activity, cross-referencing cost and volume figures across multiple reports where possible.

  • IBM, Cost of a Data Breach Report 2025 (analysis of 600 breached organizations, March 2024 to February 2025) - ibm.com/reports/data-breach
  • Identity Theft Resource Center, 2025 Annual Data Breach Report (published January 2026) - idtheftcenter.org
  • Verizon, 2025 Data Breach Investigations Report (22,000+ incidents, 12,195 confirmed breaches) - verizon.com/business/resources/reports/dbir
  • Sophos, State of Ransomware 2025 (survey of 3,400 organizations across 17 countries) - sophos.com/state-of-ransomware
  • FBI Internet Crime Complaint Center, 2025 Internet Crime Report - ic3.gov
  • HHS Office for Civil Rights breach portal and HIPAA Journal, 2025 Healthcare Data Breach Report - ocrportal.hhs.gov
  • Cybernews research, 16-billion-credential exposure disclosure (June 2025)

Data watch: several of these are recurring annual publications with new editions due soon. IBM’s Cost of a Data Breach Report typically publishes in late July, so the 2026 edition (2025-2026 data) is imminent. The Verizon DBIR releases each spring; the 2026 DBIR is already out at the time of writing. Sophos updates its State of Ransomware each June, and the FBI IC3 and ITRC annual reports refresh in the first quarter of the following year. We will fold newer figures in as they publish.

Last updated: July 16, 2026.

We review and update this page quarterly as new data is published.

Try VoxBooster — 3-day free trial.

Real-time voice cloning, soundboard, and effects — wherever you already talk.

  • No credit card
  • ~30ms latency
  • Discord · Teams · OBS
Try free for 3 days