The average U.S. data breach reached an all-time high of $10.22 million in 2025, roughly 2.3 times the global average (IBM, Cost of a Data Breach Report 2025). Yet the global average fell 9 percent to $4.44 million, the first decline in five years, as AI-assisted defense cut the mean breach lifecycle to 241 days (IBM, Cost of a Data Breach Report 2025). Volume moved the other way: the Identity Theft Resource Center logged a record 3,322 U.S. data compromises in 2025, up 5 percent (ITRC, 2025 Annual Data Breach Report). Ransomware now touches 44 percent of breaches, and the human element is present in 60 percent (Verizon, 2025 DBIR). This analysis consolidates data from IBM’s Cost of a Data Breach Report, the ITRC Annual Data Breach Report, the Verizon DBIR, and four other primary sources including the FBI IC3, Sophos, and the HHS Office for Civil Rights.
TL;DR
- Global average breach cost was $4.44 million in 2025, the first decline in five years (IBM, Cost of a Data Breach Report 2025).
- The U.S. average hit a record $10.22 million, about 2.3x the global figure (IBM, Cost of a Data Breach Report 2025).
- The U.S. logged a record 3,322 data compromises in 2025, up 5 percent (ITRC, 2025 Annual Data Breach Report).
- Victim notices fell 79 percent to 278.8 million as mega-breaches faded (ITRC, 2025 Annual Data Breach Report).
- Ransomware appeared in 44 percent of breaches, up 37 percent year over year (Verizon, 2025 DBIR).
- Analysts reviewed 12,195 confirmed breaches out of 22,000+ incidents (Verizon, 2025 DBIR).
- The mean breach lifecycle dropped to 241 days, the lowest in nine years (IBM, Cost of a Data Breach Report 2025).
- Internet crime losses reached $20.877 billion in 2025, up 26 percent (FBI, IC3 Internet Crime Report 2025).
- 710 healthcare breaches exposed 61.6 million records in 2025 (HIPAA Journal / HHS OCR, 2025 Healthcare Data Breach Report).
- A June 2025 credential leak exposed roughly 16 billion login records (Cybernews, 2025).
- The median ransomware recovery cost fell 44 percent to $1.53 million (Sophos, State of Ransomware 2025).
1. What a Breach Costs
The headline of IBM’s 2025 report is a split screen. The global average cost fell for the first time since 2020, but that decline is almost entirely a detection-speed story, not a sign that attacks got cheaper. In the United States, the average breach cost climbed 9 percent to a record $10.22 million while the global figure dropped to $4.44 million, a gap driven by aggressive class-action litigation, escalating regulatory fines, and 50 states worth of mandatory notification laws. Healthcare stayed the most expensive industry for a 15th straight year, and organizations that used security AI and automation extensively spent about $1.9 million less per incident than those that used neither. Full methodology is in the IBM Cost of a Data Breach Report 2025.
| Metric | Value | Source |
|---|---|---|
| Global average breach cost, 2025 | $4.44M (down 9%, first decline in 5 years) | IBM, Cost of a Data Breach Report 2025 |
| U.S. average breach cost | $10.22M (record high, ~2.3x global) | IBM, Cost of a Data Breach Report 2025 |
| Highest-cost industry (healthcare) | $7.42M (15th consecutive year) | IBM, Cost of a Data Breach Report 2025 |
| Second-highest industry (financial services) | $5.56M | IBM, Cost of a Data Breach Report 2025 |
| Highest / lowest region | Middle East $7.29M / Brazil $1.22M | IBM, Cost of a Data Breach Report 2025 |
| Savings from extensive AI + automation | ~$1.9M lower per incident | IBM, Cost of a Data Breach Report 2025 |
Context: IBM’s figures draw on 600 organizations breached between March 2024 and February 2025; nearly two-thirds said they were still recovering, typically beyond 100 days.
2. How Many Breaches, How Many Victims
Breach counts and victim counts moved in opposite directions in 2025, and the divergence is the year’s most important nuance. Compromises hit a new record, but the number of people notified collapsed. Victim notices fell 79 percent to 278.8 million, down from 1.37 billion in 2024, purely because 2025 produced no single mega-breach on the scale of the prior year. Financial services was the most-attacked sector for a second consecutive year, a shift the ITRC attributes to criminals prioritizing static identifiers like bank account numbers that enable long-term fraud. See the ITRC 2025 Annual Data Breach Report for the full breakdown.
| Metric | Value | Source |
|---|---|---|
| U.S. data compromises, 2025 | 3,322 (record, +5% vs 2024) | ITRC, 2025 Annual Data Breach Report |
| Prior all-time high (2023) | 3,202 | ITRC, 2025 Annual Data Breach Report |
| Growth in compromises over five years | +79% | ITRC, 2025 Annual Data Breach Report |
| Victim notices, 2025 | 278,827,933 (down 79% vs 2024’s 1,367,117,021) | ITRC, 2025 Annual Data Breach Report |
| Most-breached sector (financial services) | 739 compromises | ITRC, 2025 Annual Data Breach Report |
| Healthcare / professional services | 534 / 478 compromises | ITRC, 2025 Annual Data Breach Report |
| Manufacturing / education | 299 / 188 compromises | ITRC, 2025 Annual Data Breach Report |
| Largest single exposure (credential leak) | ~16 billion login records, 30 datasets | Cybernews, 2025 |
That 16 billion figure is aggregated infostealer and prior-breach data, not one fresh hack, which is why reused and stolen passwords dominate the risk picture; our password security statistics roundup breaks down credential reuse in depth.
3. Attack Vectors and Root Causes
The way in has shifted. Vulnerability exploitation surged and now rivals stolen credentials as the leading entry point, while phishing, though still common, slipped in relative share. Stolen credentials remained the single most common initial vector at 22 percent of breaches, with the human element present in 60 percent (Verizon, 2025 DBIR). Third-party involvement doubled to 30 percent, a reminder that a vendor’s weak control becomes your breach. A newer risk category emerged in IBM’s data: breaches tied to unsanctioned “shadow AI” tools cost more and almost always involved missing access controls. The full corpus is documented in the Verizon 2025 Data Breach Investigations Report; for the wider threat picture see our cybersecurity statistics overview.
| Metric | Value | Source |
|---|---|---|
| Human element in breaches | 60% | Verizon, 2025 DBIR |
| Credential abuse (top initial vector) | 22% | Verizon, 2025 DBIR |
| Vulnerability exploitation | 20% (+34% year over year) | Verizon, 2025 DBIR |
| Phishing | 15% of breaches | Verizon, 2025 DBIR |
| Third-party involvement | 30% (doubled) | Verizon, 2025 DBIR |
| Espionage-motivated breaches | 17% (+163%) | Verizon, 2025 DBIR |
| Breaches involving shadow AI | $4.63M average (+$670K premium) | IBM, Cost of a Data Breach Report 2025 |
| AI-related incidents lacking access controls | 97% | IBM, Cost of a Data Breach Report 2025 |
Outlier: espionage attackers exploit vulnerabilities in 70 percent of their intrusions, far above the all-motive average (Verizon, 2025 DBIR).
4. Detection and Response Time
Speed is now the biggest lever on cost. IBM’s data shows containment time correlates almost linearly with dollars, and the industry finally moved the needle. The mean time to identify and contain a breach fell to 241 days, the lowest in nine years, split into 181 days to detect and 60 to contain. Half of breaches were still caught by internal teams, but nearly one in five were disclosed by the attacker, the worst-case discovery path in both cost and reputational terms. Edge devices remain the soft underbelly: attackers weaponize new VPN and firewall flaws almost instantly. The detection figures come from the IBM Cost of a Data Breach Report 2025.
| Metric | Value | Source |
|---|---|---|
| Mean breach lifecycle, 2025 | 241 days (lowest in 9 years) | IBM, Cost of a Data Breach Report 2025 |
| Detect / contain split | 181 days / 60 days | IBM, Cost of a Data Breach Report 2025 |
| Cost premium for >200-day containment | +$1.14M | IBM, Cost of a Data Breach Report 2025 |
| How breaches are found | Internal 50% / third party 31% / attacker 19% | IBM, Cost of a Data Breach Report 2025 |
| Edge/VPN flaws: time to mass exploitation | 0 days (median) | Verizon, 2025 DBIR |
| Edge/VPN flaws patched | Only 54% (32-day median fix) | Verizon, 2025 DBIR |
Context: breaches disclosed by the attacker averaged $5.08 million, versus $4.18 million when a company’s own security team found the intrusion (IBM, Cost of a Data Breach Report 2025).
5. Ransomware Economics
Ransomware is both more prevalent and, for many victims, less lucrative to the attacker. It now factors into 44 percent of breaches, yet payouts and recovery costs both dropped sharply as more organizations refused to pay and restored from backups faster. The median ransom payment halved to $1 million and the mean recovery cost (excluding any ransom) fell 44 percent to $1.53 million in Sophos’s survey of 3,400 organizations. The two headline datasets diverge on payout size, an artifact of different populations: Verizon’s breach corpus includes many small victims, while Sophos surveyed firms of 100 to 5,000 employees. Details are in the Sophos State of Ransomware 2025 report; see our ransomware statistics deep dive for attack-group trends.
| Metric | Value | Source |
|---|---|---|
| Ransomware present in breaches | 44% (+37% year over year) | Verizon, 2025 DBIR |
| Ransomware in SMB breaches | 88% (vs 39% at large enterprises) | Verizon, 2025 DBIR |
| Median ransom payout (breach corpus) | $115K; 64% of victims refused to pay | Verizon, 2025 DBIR |
| Median ransom payment (survey) | $1M (down 50% from $2M) | Sophos, State of Ransomware 2025 |
| Mean recovery cost, excl. ransom | $1.53M (down 44%) | Sophos, State of Ransomware 2025 |
| Ransom paid vs initial demand | 85% on average | Sophos, State of Ransomware 2025 |
| Fully recovered within a week | 53% (up from 35%) | Sophos, State of Ransomware 2025 |
Divergence note: the $115K (Verizon) versus $1M (Sophos) median gap reflects sample composition, not a contradiction; both are self-reported.
6. Healthcare Under Siege
Healthcare remains the most consequential breach sector, and 2025 set a records-count high even as the raw number of exposed individuals dropped by more than three-quarters. 710 breaches of 500 or more records exposed 61.6 million individuals, down 78.7 percent from 2024’s 289 million, again a mega-breach effect rather than improved security. The sector’s structural exposure endures: medical records fetch far more than payment cards on illicit markets, HIPAA fines are steep, and detection lags run longer than average. Figures are compiled from the HHS Office for Civil Rights portal, reported in the HHS OCR breach portal and HIPAA Journal’s annual analysis.
| Metric | Value | Source |
|---|---|---|
| Healthcare breaches (500+ records), 2025 | 710 | HIPAA Journal / HHS OCR, 2025 Healthcare Data Breach Report |
| Individuals affected, 2025 | 61,556,256 (down 78.7% from 2024) | HIPAA Journal / HHS OCR, 2025 |
| Mega breaches (1M+ individuals) | 9 (vs 18 in 2024) | HIPAA Journal / HHS OCR, 2025 |
| Largest 2025 breach (Aflac) | 13,924,906 individuals | HIPAA Journal / HHS OCR, 2025 |
| Average / median breach size | 86,699 / 4,011 individuals | HIPAA Journal / HHS OCR, 2025 |
| Breach location: network servers / email | 61.5% / 24.9% | HIPAA Journal / HHS OCR, 2025 |
| Entity split: providers / associates / plans | 57.5% / 35.8% / 6.5% | HIPAA Journal / HHS OCR, 2025 |
| Largest U.S. healthcare breach on record | Change Healthcare, 192.7M | HHS OCR (2024 incident, total finalized) |
Note: Change Healthcare is a 2024 attack whose final tally of 192.7 million was confirmed later; it is included as the most recent all-time benchmark, flagged by year.
7. The Human and Financial Fallout
Breaches convert into fraud losses that fall hardest on individuals, and the FBI’s 2025 tally shows the toll accelerating. U.S. internet crime losses hit $20.877 billion in 2025, up 26 percent year over year, across more than a million complaints. Personal data breaches were their own complaint category with 67,456 filings, but the downstream damage shows up in phishing, extortion, and business email compromise. Older Americans absorbed a disproportionate share of the losses. The full dataset is the FBI IC3 2025 Internet Crime Report; breach-driven fraud is covered further in our identity theft statistics roundup.
| Metric | Value | Source |
|---|---|---|
| Internet crime complaints, 2025 | 1,008,597 | FBI, IC3 Internet Crime Report 2025 |
| Total reported losses | $20.877B (+26% vs 2024) | FBI, IC3 Internet Crime Report 2025 |
| Average loss per complaint | $20,699 | FBI, IC3 Internet Crime Report 2025 |
| Personal data breach complaints | 67,456 | FBI, IC3 Internet Crime Report 2025 |
| Phishing / spoofing complaints (top type) | 191,561 | FBI, IC3 Internet Crime Report 2025 |
| Losses among victims over 60 | $7.7B (201,266 complaints) | FBI, IC3 Internet Crime Report 2025 |
| Business email compromise losses | $3.046B | FBI, IC3 Internet Crime Report 2025 |
Outlier: cryptocurrency-related complaints alone accounted for $11.37 billion of the 2025 loss total (FBI, IC3 Internet Crime Report 2025).
Summary: Data Breaches by the Numbers
| Metric | Value | Source |
|---|---|---|
| Global average breach cost | $4.44M | IBM, Cost of a Data Breach Report 2025 |
| U.S. average breach cost | $10.22M | IBM, Cost of a Data Breach Report 2025 |
| Healthcare average breach cost | $7.42M | IBM, Cost of a Data Breach Report 2025 |
| Mean breach lifecycle | 241 days | IBM, Cost of a Data Breach Report 2025 |
| U.S. data compromises, 2025 | 3,322 (record) | ITRC, 2025 Annual Data Breach Report |
| Victim notices, 2025 | 278.8M (down 79%) | ITRC, 2025 Annual Data Breach Report |
| Most-breached sector (financial services) | 739 compromises | ITRC, 2025 Annual Data Breach Report |
| Confirmed breaches analyzed | 12,195 (of 22,000+ incidents) | Verizon, 2025 DBIR |
| Ransomware share of breaches | 44% | Verizon, 2025 DBIR |
| Human element in breaches | 60% | Verizon, 2025 DBIR |
| Credential abuse (top vector) | 22% | Verizon, 2025 DBIR |
| Median ransomware recovery cost | $1.53M | Sophos, State of Ransomware 2025 |
| Median ransom payment (survey) | $1M | Sophos, State of Ransomware 2025 |
| Healthcare breaches (500+ records) | 710 | HIPAA Journal / HHS OCR, 2025 |
| Healthcare records exposed | 61.6M | HIPAA Journal / HHS OCR, 2025 |
| U.S. internet crime losses | $20.877B | FBI, IC3 Internet Crime Report 2025 |
| Personal data breach complaints | 67,456 | FBI, IC3 Internet Crime Report 2025 |
| Largest single exposure (credentials) | ~16 billion records | Cybernews, 2025 |
Methodology and Sources
Data was gathered by aggregating figures directly from primary annual reports, government breach portals, and the original research surveys published in H1 2026 covering 2025 activity, cross-referencing cost and volume figures across multiple reports where possible.
- IBM, Cost of a Data Breach Report 2025 (analysis of 600 breached organizations, March 2024 to February 2025) - ibm.com/reports/data-breach
- Identity Theft Resource Center, 2025 Annual Data Breach Report (published January 2026) - idtheftcenter.org
- Verizon, 2025 Data Breach Investigations Report (22,000+ incidents, 12,195 confirmed breaches) - verizon.com/business/resources/reports/dbir
- Sophos, State of Ransomware 2025 (survey of 3,400 organizations across 17 countries) - sophos.com/state-of-ransomware
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report - ic3.gov
- HHS Office for Civil Rights breach portal and HIPAA Journal, 2025 Healthcare Data Breach Report - ocrportal.hhs.gov
- Cybernews research, 16-billion-credential exposure disclosure (June 2025)
Data watch: several of these are recurring annual publications with new editions due soon. IBM’s Cost of a Data Breach Report typically publishes in late July, so the 2026 edition (2025-2026 data) is imminent. The Verizon DBIR releases each spring; the 2026 DBIR is already out at the time of writing. Sophos updates its State of Ransomware each June, and the FBI IC3 and ITRC annual reports refresh in the first quarter of the following year. We will fold newer figures in as they publish.
Last updated: July 16, 2026.
We review and update this page quarterly as new data is published.