A data analysis of what breaches really cost, how attackers get in, how much cybercrime takes from victims, and which controls the evidence says cut risk.
The global average cost of a data breach hit a record $4.99 million in 2026, up 12% in a year, per IBM’s Cost of a Data Breach Report. Victims reported $20.877 billion in cybercrime losses to the FBI for 2025. And for the first time in 19 years of the DBIR, exploited software flaws (31%) beat stolen credentials as the top way in, per Verizon. The data below covers cost, attack vectors, ransomware, AI, and the controls that work. For the identity layer, see our password manager picks.
Key takeaways
- $4.99M is the global average breach cost in 2026, a record and up from $4.44M in 2025; US breaches average $11.5M (IBM, HIPAA Journal)
- 247 days to identify and contain a breach, the first increase after five straight years of decline (Help Net Security, HIPAA Journal)
- 31% of breaches now start with an exploited vulnerability, while credential abuse fell to 13% (Verizon 2026 DBIR, Help Net Security)
- 48% of breaches involve a third party, up 60% in a year, and 48% involve ransomware (Verizon)
- $20.877B in cybercrime losses were reported to the FBI for 2025, up 26%, from 1,008,597 complaints (FBI IC3, ABA Banking Journal)
- The median cyber insurance claim is $83,000, and about $38,000 for small businesses, far below the headline averages (Verizon Breach Impact Study)
- One in four malicious breaches is now AI-enabled, up 56% in a year, at about $6M per breach (IBM)
- Extensive security AI and automation cut the average breach to $4.00M from $5.93M, a $1.93M gap (IBM X-Force, Security Boulevard)
- Phishing-resistant MFA stops over 99% of identity attacks, and more than 97% of identity attacks are password attacks (Microsoft)
How much does a data breach cost in 2026?
The average data breach cost $4.99 million in IBM’s 2026 study, a record and 12% more than a year earlier, per IBM. US organizations paid far more: $11.5 million per breach, more than double the global figure, per HIPAA Journal’s coverage of the report.
- The 2026 global average of $4.99 million is an all-time high, driven by higher detection, escalation, and lost-business costs (IBM). It reverses 2025, when the average fell to $4.44 million in the first decline in five years (IBM, 2025).
- US breaches averaged $11.5 million, up 13% from $10.22 million (Security Boulevard, IBM, 2025). The US carries the highest breach costs of any country in the study.
- Detection and escalation ($1.64 million) plus lost business ($1.54 million) make up 63% of the average bill (Security Boulevard). Post-breach response adds $1.36 million and notification $0.45 million. Most of the bill is investigation, downtime, and lost customers.
- Healthcare is still the costliest industry at $6.64 million per breach, despite a 10.5% drop from $7.42 million in 2025 (HIPAA Journal). Cheaper is relative: it is still a third above the global average.
- Financial services breaches averaged $6.3 million and energy breaches $5.2 million (IBM). These two sectors also took the highest concentration of AI-driven attacks.
- IBM’s 2026 sample covers 602 organizations breached between March 2025 and February 2026 (IBM). That matters when you compare it with other studies: it measures confirmed breaches, not every security incident.
| Metric (IBM Cost of a Data Breach) | 2025 report | 2026 report |
|---|---|---|
| Global average cost per breach | $4.44M | $4.99M |
| US average cost per breach | $10.22M | $11.5M |
| Time to identify and contain | 241 days | 247 days |
| Healthcare average cost | $7.42M | $6.64M |
| Breached orgs reporting ransomware | 34% | 39% |
| Shadow AI share of security incidents | 20% | 43% |
Sources: IBM 2025 press release, IBM 2026 press release, HIPAA Journal, Help Net Security.
The direction is the story. After a year of improvement, nearly every headline metric moved the wrong way in 2026: higher cost, slower containment, more ransomware, and twice the shadow AI exposure.
What does a data breach cost a small business?
Half of the cyber insurance claims in Verizon’s 2026 Breach Impact Study had a financial impact above $83,000, and the small-business median was about $38,000, per Verizon. Headline averages run far higher because a few huge losses pull them up: the top 2.5% of claims exceeded $5 million.
- The median claim impact is $83,000, but the top 10% exceed $920,000 (Verizon BIS). Verizon studied 69,683 cyber insurance claims and reports medians on purpose, saying an average would not come close to describing the real spread of losses.
- Median breach impact rose 80% from 2019 to 2024, against about 23% US inflation (Verizon BIS). Breaches have become more expensive in real terms, not just in nominal dollars.
- In extreme cases, a breach cost a small business more than 7% of its revenue (Verizon SMB infographic). For the top 10% of SMB claims the ratio reached 3%, per the full study. For mid-market and large firms it never went over 2%, even in the top 2.5% of cases.
- The median business email compromise loss is $50,000, a long-running DBIR figure that Verizon says its insurance data now corroborates (Verizon BIS). BEC theft is capped by the size of the invoices attackers can redirect.
| Segment (Verizon BIS 2026) | Annual revenue | Median breach impact |
|---|---|---|
| Small and medium businesses | Under $25M | About $38,000 |
| Mid-market | $25M to $250M | About $96,000 |
| Large enterprise | Over $250M | About $283,000 |
| All claims | All sizes | $83,000 |
Source: Verizon 2026 Breach Impact Study, based on cyber insurance claims. The top 2.5% of large-enterprise claims exceeded $22 million each.
The two views are compatible. IBM’s $4.99 million is an average, and averages get pulled up by the costliest cases: Verizon says its own claims average would land in the seven-figure range, against an $83,000 median. The median shows what most insured firms face. For a small company, $38,000 is survivable; 7% of revenue in a bad year is not. More numbers for owners are in our small business statistics.
How long does it take to find and contain a breach?
Breaches took 247 days on average to identify and contain in IBM’s 2026 study: 183 days to find, 64 to contain, per Security Boulevard’s breakdown. That is up from 241 days in 2025, the first rise after five straight years of decline, per Help Net Security.
- Breaches that ran past 200 days averaged $5.65 million, versus $4.32 million for faster ones (Security Boulevard). Speed is a cost lever a security team controls directly.
- Supply chain and removable-media breaches took 258 days, the longest of any vector (HIPAA Journal). Neither shows up in malware scans or inbound traffic, so they hide longer.
- Internal teams found close to four in ten breaches and closed them about five weeks faster than average (Help Net Security). Attackers disclosed roughly one in six, and those breaches cost the most. In 2025, internal detection saved $900,000 per breach versus attacker disclosure (IBM, 2025).
- About four in ten organizations reported complete recovery, and fewer than one in twenty got there inside seven weeks (Help Net Security). Containment is not the end: for most victims, full recovery takes far longer than seven weeks.
How do attackers get in?
Exploited software vulnerabilities started 31% of breaches in Verizon’s 2026 DBIR, passing stolen credentials as the top entry point for the first time in the report’s 19 years, per Verizon. Credential abuse fell to 13% and phishing held at 16%, per the executive summary.
- Vulnerability exploitation now opens 31% of breaches (Verizon). Verizon says AI is shrinking the window between disclosure and exploitation from months to hours. Its dataset spans more than 22,000 breaches across 145 countries (Verizon SMB infographic).
- Only 26% of critical vulnerabilities in CISA’s KEV catalog were fully remediated in 2025, down from 38% (Verizon). The median time to full resolution rose to 43 days from 32, and organizations had 50% more critical vulnerabilities to patch.
- Credential abuse fell to 13% as an initial vector, from first place the year before (Verizon, Help Net Security). Credentials still drive the damage after entry; our password security statistics cover that side.
- Phishing opened 16% of breaches and pretexting 6% (Verizon). Pretexting is becoming a common route into ransomware and extortion.
- IBM ranks phishing as the top initial vector at 17% of breaches, for a fourth straight year (HIPAA Journal, Help Net Security). The two studies sample differently, so read phishing’s share as 16-17% and its rank as first or second.
How big is third-party and supply chain risk?
- 48% of breaches involved a third party, up 60% in a year (Verizon, Help Net Security). Nearly half of all breaches now have a vendor or partner involved.
- Only 23% of third parties fully fixed missing or weak MFA on their cloud accounts (Verizon). For weak passwords and permission misconfigurations, resolving half the findings took almost eight months.
- Supply chain compromise adds more to a breach bill than any other single factor in IBM’s 2026 analysis (Help Net Security). Every extra vendor with access to your data is another door, and apps adopted without review through shadow IT add doors you cannot see.
How common is ransomware, and do victims still pay?
Ransomware appeared in 48% of breaches in Verizon’s 2026 DBIR, up from 44%, yet 69% of victims refused to pay and the median payment fell to $139,875, per Verizon. Sophos’s survey of mid-size firms puts the median payment much higher, at $769,000, so expect a wide range.
- 48% of breaches involved ransomware, up from 44% a year earlier (Verizon, Help Net Security). Volume keeps rising even as payouts fall.
- 69% of ransomware victims didn’t pay, and the median payment fell to $139,875 from $150,000 (Verizon). Refusing to pay is now the norm, not the exception.
- Sophos puts the median payment at $769,000 and the median demand at $698,000 (Sophos, Sophos press release). Its survey covers 2,158 leaders at organizations with 100 to 5,000 employees across 17 countries, a different sample from Verizon’s breach data, so the two medians are not directly comparable.
- Average recovery cost, excluding any ransom, reached $1.7 million (Sophos). That is roughly a tenth higher than the previous report (Help Net Security).
- 79% of ransomware attacks began with an identity-based technique: malicious email, phishing, compromised credentials, or brute force (Sophos press release). Ransomware is mostly a login problem, not an exotic-malware problem.
- Attackers encrypted data in 56% of attacks, and 66% of victims with encrypted data restored it from backups (Sophos, Sophos press release). Tested backups are why most victims can say no.
- IBM: 39% of breached organizations reported ransomware, up from 34%, and 41% of attacks threatened brand reputation (IBM). Threats to publish stolen data and shame the victim are now the most common form of pressure, ahead of encryption (Help Net Security).
- Leadership teams were replaced after 21% of attacks (Sophos press release). Ransomware is a career event for executives, not just an IT incident.
- The FBI logged 3,611 ransomware complaints in 2025 with $32.3 million in reported losses, and identified 63 new variants (FBI IC3). The FBI notes this excludes lost business, time, and remediation, so it understates the real cost. Akira and Qilin were the most reported variants.
| Ransomware benchmark | Figure | Source |
|---|---|---|
| Median ransom paid, breach data | $139,875 | Verizon DBIR 2026 |
| Median ransom paid, survey of 100-5,000 staff firms | $769,000 | Sophos 2026 |
| Median ransom demand | $698,000 | Sophos 2026 |
| Average recovery cost, excluding ransom | $1.7M | Sophos 2026 |
| Victims who did not pay | 69% | Verizon DBIR 2026 |
| Encrypted victims who restored from backups | 66% | Sophos 2026 |
Sources: Verizon 2026 DBIR executive summary, Sophos State of Ransomware 2026, Sophos press release. The median gap reflects different samples, not an error.
How much money is lost to cybercrime each year?
Victims reported $20.877 billion in cybercrime losses to the FBI’s Internet Crime Complaint Center for 2025, a 26% increase, across 1,008,597 complaints, per the FBI IC3 report. The ABA Banking Journal confirms the nearly $20.9 billion total. Investment fraud alone accounted for $8.65 billion of it.
- Complaints passed one million: 1,008,597 in 2025, almost 3,000 a day (FBI IC3). That is up from roughly 859,000 in 2024 (ABA Banking Journal).
- The average reported loss was $20,699 per complaint (FBI IC3). Like IBM’s breach figure, it is an average, not a typical loss.
- Investment fraud ($8.65 billion), business email compromise ($3.05 billion), and tech support scams ($2.13 billion) led losses (FBI IC3). Cyber-enabled fraud made up 85% of all 2025 losses.
- Phishing and spoofing was the most-reported crime, at 191,561 complaints, yet it carried only $215.8 million in direct losses (FBI IC3). Phishing is the entry point; the money moves later through fraud and BEC.
- People 60 and older filed 201,266 complaints and lost $7.7 billion, the most of any age group (FBI IC3).
- Cryptocurrency-related losses hit $11.37 billion, and AI-related complaints reached 22,364 with $893 million lost (FBI IC3). Losses involving cryptocurrency alone equal more than half of the year’s total.
| Crime type (FBI IC3) | 2024 losses | 2025 losses |
|---|---|---|
| Investment fraud | $6.57B | $8.65B |
| Business email compromise | $2.77B | $3.05B |
| Tech and customer support scams | $1.46B | $2.13B |
| Personal data breach | $1.45B | $1.31B |
| Confidence and romance scams | $672M | $929M |
| Ransomware | $12.5M | $32.3M |
Source: FBI IC3 2025 Internet Crime Report, three-year loss comparison. Figures are self-reported by victims and rounded.
Is phishing still the biggest human risk?
Yes, and it is moving to phones. The human element was present in 62% of breaches in Verizon’s 2026 DBIR, up from 60%, and in phishing simulations mobile lures by text and voice drew 40% more successful clicks than email, per Verizon. IBM still ranks phishing the most common entry point.
- The human element appeared in 62% of breaches (Verizon, Help Net Security). Mistakes, misuse, and manipulation are still the common thread.
- Mobile phishing by text and voice is 40% more successful than email phishing (Verizon). As people get better at spotting email phishing, attackers are pivoting to fake texts and voice calls.
- Social engineering was the third most common breach pattern, at 16% of breaches (Verizon).
- Deepfake impersonation drove 45% of AI-driven attacks, AI malware 19%, and AI-generated phishing 17% (HIPAA Journal). The voice on the phone asking for a password reset may not be human.
- Business email compromise drew 24,768 FBI complaints and $3.05 billion in losses in 2025 (FBI IC3). BEC is the second-costliest crime category the FBI tracks.
- Microsoft screens 5 billion emails a day for malware and phishing (Microsoft). It also found attackers sought to steal data in 80% of the incidents its teams investigated.
How is AI changing cyberattacks and defense?
One in four malicious breaches in IBM’s 2026 study was AI-enabled, a 56% jump in a year, and those breaches cost about $6 million each, per IBM. On defense, organizations using security AI and automation extensively averaged $4.00 million per breach, versus $5.93 million for those using none.
- AI-enabled breaches cost about $6 million, roughly $1 million above the $4.99 million average (IBM). Most were deepfake impersonation and AI-generated malware.
- Security AI and automation saved $1.93 million per breach (IBM X-Force), yet one in four organizations still has not adopted these tools in security operations (IBM).
- 50% of breached organizations use AI agents for threat hunting and response, but only 18% use them for vulnerability management (IBM X-Force). Defenders aim AI at alerts while attackers aim it at unpatched holes.
- Roughly one in five organizations reported a breach of an AI model or application, and 92% of those lacked proper AI access controls (IBM X-Force). Model inversion attacks cost $6.07 million on average and prompt injection $5.89 million.
- Shadow AI figured in 43% of security incidents, up from 20% (HIPAA Journal). Verizon found 45% of employees now regularly use AI on corporate devices, up from 15%, and 67% of users accessing AI on corporate devices do it through non-corporate accounts (Verizon). Our shadow IT statistics track the governance gap.
- The median threat actor used AI help across 15 attack techniques, but under 2.5% of AI-assisted malware was novel (Verizon). AI mostly scales known attacks rather than inventing new ones.
- 86% of business leaders with security duties reported at least one AI-related incident in the past year (Cisco, 2025).
- The market for securing AI will reach almost $4.8 billion in 2027, up 68.7% over 2026, and almost $7.7 billion by 2028 (Gartner).
- 28% of security professionals say their organizations have integrated AI security tools, and 63% of teams using them report a significant productivity boost (ISC2). In total, 69% are on a path to regular AI security tool use. For the agent side of this shift, see our agentic AI statistics.
Do more security tools make companies safer?
Not on their own. In Cisco’s 2025 Cybersecurity Readiness Index, 70% of companies ran more than 10 point solutions in their security stack and 26% ran more than 30, while 77% said too many tools slowed their ability to detect, respond, and recover, per Cisco.
- 77% of security leaders say adopting too many solutions slowed incident detection, response, and recovery (Cisco, 2025). Every extra console is another place an alert can sit unread.
- Only 4% of organizations reached Cisco’s “Mature” readiness stage, up just 1 point from the year before (Cisco, 2025). Meanwhile 49% experienced at least one cyberattack in the past year and 71% expect an incident to disrupt their business within 12 to 24 months (Cisco report).
- Security spending hit $213 billion in 2025, up from $193 billion, and Gartner expects $240 billion in 2026 (Gartner). Security software is the fastest-growing segment, forecast at $121.2 billion in 2026.
- 95% of security professionals report at least one skills need, and 59% call their needs critical or significant, up from 44% (ISC2). AI is the most-cited skills need at 41%, ahead of cloud security at 36%.
- 88% of respondents experienced at least one significant security consequence from a skills shortfall (ISC2). The study surveyed a record 16,029 practitioners and did not publish a workforce-gap estimate this year, arguing that skills needs now outweigh headcount.
- 72% say cutting security staff significantly increases breach risk (ISC2), and 86% view the talent shortage as a challenge (Cisco, 2025).
Spending is up and tools are multiplying, but readiness is flat. The constraint is people who can run the stack, not the number of products in it. A smaller set of integrated tools that a thin team can actually operate beats a sprawling one it cannot. Our guide for CTOs applies that lens to the rest of the stack.
Which security controls does the data say work?
Phishing-resistant MFA is the best-documented control: Microsoft says it stops over 99% of identity-based attacks, and more than 97% of identity attacks are password attacks, per its Digital Defense Report 2025. Fast patching, tested backups, encryption, and security automation each show measurable effects in the breach data.
- Phishing-resistant MFA blocks over 99% of identity-based attacks, even when the attacker has the right password (Microsoft). Identity-based attacks rose 32% in the first half of 2025 alone.
- MFA was in place for nearly every credential-based ransomware attack Sophos studied; coverage gaps and bypass methods let attackers through (Help Net Security). The method matters: CISA calls FIDO/WebAuthn the only widely available phishing-resistant option.
- CISA’s Known Exploited Vulnerabilities catalog lists 1,733 flaws as of October 2, 2026 (CISA KEV feed). Patch these first; with only 26% fully fixed in 2025 (Verizon), most organizations have not.
- Only 37% of breached organizations encrypt sensitive data both at rest and in transit (IBM). Encryption limits what a breach exposes, and most breached organizations did not do both.
- Organizations that detected breaches internally saved $900,000 versus attacker disclosure in IBM’s 2025 study (IBM, 2025). Monitoring you actually watch pays for itself.
The pattern across these reports is consistent. The controls that work are boring and well understood: strong authentication, a password manager so every login is unique, fast patching of known-exploited flaws, offline backups, and encryption. Start with 1Password, Bitwarden, or Dashlane for the credential layer.
What to do with this data
- Fix identity first. With 79% of ransomware starting from identity techniques (Sophos), roll out phishing-resistant MFA and a company-wide password manager before buying anything else. Compare options in our password manager category.
- Patch from the KEV list, not the full CVE firehose. Track the CISA KEV catalog and measure your time to fix against Verizon’s 43-day median.
- Audit vendor access. Third parties are in 48% of breaches (Verizon). Require MFA from every vendor that touches your data, and cut the ones you no longer use.
- Consolidate before you add. 77% of teams say tool overload slowed response (Cisco). Choose fewer tools your team will actually run, and put automation where it saves the most: IBM’s $1.93 million gap.
- Test restores, not just backups. Two-thirds of ransomware victims with encrypted data restored it from backups (Sophos); that is what lets you refuse to pay.
- Budget for the median, insure for the tail. A typical small-business claim is about $38,000, but in the worst 2.5% of cases a breach costs more than 7% of revenue (Verizon). See how we score and pick tools on our about page.
Frequently asked questions
What is the average cost of a data breach in 2026?
The global average is $4.99 million, a record and 12% higher than 2025’s $4.44 million, per IBM’s 2026 Cost of a Data Breach Report. US breaches average $11.5 million. Healthcare remains the costliest industry at $6.64 million per breach, per HIPAA Journal.
How much does a data breach cost a small business?
Far less than headline averages, but more as a share of revenue. The median small-business insurance claim was about $38,000 in Verizon’s 2026 Breach Impact Study, against $83,000 for all claims. In the worst 2.5% of cases, a breach cost a small business more than 7% of revenue.
What percentage of breaches involve ransomware?
48% of breaches involved ransomware in Verizon’s 2026 DBIR, up from 44%. Payments are falling: 69% of victims did not pay, and the median payment dropped to $139,875. Sophos’s survey of mid-size firms puts the median payment higher, at $769,000.
What is the most common cause of data breaches?
Exploited software vulnerabilities, at 31% of breaches in Verizon’s 2026 DBIR, now lead for the first time in 19 years. Phishing follows at 16% and credential abuse at 13%. IBM, using a different sample, ranks phishing first at 17%. The human element is present in 62% of breaches.
How much money is lost to cybercrime each year?
Victims reported $20.877 billion in losses to the FBI’s Internet Crime Complaint Center for 2025, up 26% from $16.6 billion in 2024. Investment fraud led with $8.65 billion, followed by business email compromise at $3.05 billion. The FBI received 1,008,597 complaints, almost 3,000 a day.
Does MFA really stop attacks?
Mostly, if it is the right kind. Microsoft says phishing-resistant MFA blocks over 99% of identity-based attacks, per its Digital Defense Report 2025. But Sophos found MFA in place for nearly every credential-based ransomware attack it studied, with gaps and bypasses letting attackers in, so coverage and method both matter.
How long does it take to detect a data breach?
The average breach took 247 days to identify and contain in IBM’s 2026 study: 183 days to find and 64 to contain, per Security Boulevard. Breaches lasting over 200 days cost $5.65 million on average, versus $4.32 million for faster ones.
How we compiled these statistics
We drew on 25 source documents from 13 publishers, led by primary research from IBM and Ponemon Institute, Verizon, the FBI, CISA, Microsoft, Sophos, Cisco, ISC2, and Gartner, plus trade press that quotes those reports directly. Every figure was retrieved from the publisher’s page or report in October 2026. Gartner’s release was read from its Internet Archive copy because the live page blocked automated access. Figures we could not trace to a source were omitted, and where studies disagree, as on median ransom payments and phishing’s share, we show both numbers and explain why.
For related data, see our password security statistics, shadow IT statistics, and small business statistics.
Sources
- IBM: Cost of a Data Breach Report 2026 (2026)
- IBM: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average (2026)
- IBM X-Force: AI-powered adversaries and the enterprise risk challenge (2026)
- IBM: 13% of Organizations Reported Breaches of AI Models or Applications (2025)
- HIPAA Journal: Global Data Breach Cost Rises 12% to Almost $5 Million (2026)
- Help Net Security: Data breach cost 2026 averaged $4.99 million (2026)
- Security Boulevard: IBM’s 2026 Report Puts the US Average at $11.5 Million (2026)
- Verizon: Vulnerability exploitation top breach entry point, 2026 DBIR finds (2026)
- Verizon: 2026 DBIR Executive Summary (2026)
- Verizon: 2026 Breach Impact Study (2026)
- Verizon: 2026 DBIR and BIS infographic for SMBs (2026)
- Help Net Security: Lessons from the Verizon 2026 DBIR (2026)
- FBI IC3: 2025 Internet Crime Report (2026)
- ABA Banking Journal: FBI says cybercrime losses increased 26% in 2025 (2026)
- Sophos: State of Ransomware 2026 (2026)
- Sophos: Identity-Based Attacks Are Responsible for 85% of Ransomware in Education (2026)
- Help Net Security: Ransom demands are down, email is the top way attackers get in (2026)
- Microsoft: Extortion and ransomware drive over half of cyberattacks, Digital Defense Report 2025 (2025)
- CISA: Known Exploited Vulnerabilities catalog data feed (2026)
- CISA: More than a Password, multifactor authentication guidance (2026)
- Cisco: 2025 Cybersecurity Readiness Index report (2025)
- Cisco: 2025 Cybersecurity Readiness Index overview (2025)
- Gartner: Worldwide End-User Spending on Information Security to Total $213 Billion in 2025, archived copy (2025)
- Gartner: Market for Securing AI Will Reach $4.8 Billion in 2027, archived copy (2026)
- ISC2: 2025 Cybersecurity Workforce Study (2025)