Workplace cyber threat statistics infographic showing $10.22M average U.S. data breach cost (IBM 2025), 62% human element involvement (Verizon DBIR 2026), 48% ransomware prevalence, $670,000 shadow AI breach cost increase, and vulnerability exploitation overtaking credential abuse as the #1 initial access vector.

Workplace Cyber Threats by the Numbers: 40+ Statistics From IBM 2025 and Verizon DBIR 2026

VelSafe Insights
Workplace Cyber Threats by the Numbers: 40+ Statistics From IBM 2025 and Verizon DBIR 2026
U.S. data breaches now cost an all-time high of $10.22 million on average – more than double the $4.44 million global figure. The human element was present in 62% of breaches in the 2026 Verizon DBIR. Ransomware appeared in 48% of breaches. Third-party compromise jumped 60% year-over-year to appear in 48% of all incidents. Vulnerability exploitation overtook credential abuse as the #1 initial access vector. And shadow AI – employees using unauthorized AI tools at work – now contributes to a documented $670,000 increase in breach costs. This article compiles 40+ statistics from IBM Cost of a Data Breach 2025 (the most recent edition as of July 2026) and the Verizon DBIR 2026.
40+ Statistics
IBM Cost of Breach 2025
Verizon DBIR 2026
Shadow AI and Human Risk
$10.22M
Average cost of a data breach for U.S. organizations in 2025 – an all-time high in IBM’s 20-year report series
IBM Cost of a Data Breach Report 2025
62%
of all data breaches in 2026 involved the human element – up from 60% the prior year, per Verizon DBIR 2026
Verizon DBIR 2026
48%
of all breaches in Verizon DBIR 2026 involved ransomware – and 48% also involved third-party compromise (up 60% YoY)
Verizon DBIR 2026

Two major annual reports define what we know about workplace cyber threats: IBM’s Cost of a Data Breach Report, which measures the financial impact of incidents across surveyed organizations, and the Verizon Data Breach Investigations Report, which analyzes confirmed incident data to identify attack patterns and vectors. In 2025 and 2026, both point in the same direction: threats are human-facing, AI is scaling attacker capability, and vulnerability exploitation has overtaken credential theft as the primary entry point.

The IBM 2025 report – the most recent edition as of July 2026 – surveyed 604 organizations across 17 countries and found U.S. breach costs at a record $10.22 million. The Verizon DBIR 2026, analyzing 22,052 incidents and 12,195 confirmed breaches, found the human element in 62% of breaches, ransomware in 48%, and third-party compromise surging 60% year over year. Shadow AI – unauthorized employee use of AI tools at work – is now a measured cost driver rather than a theoretical risk. Below we compile 40+ statistics on these threats and what the data says about reducing breach costs.

Editor's Choice: Key Workplace Cyber Threat Statistics for 2025-26

$4.44M
Global average cost of a data breach in 2025 – a 9% decline from the $4.88M peak in 2024, attributed partly to faster breach containment lifecycles. The U.S. at $10.22M is 2.3x above this global average. (IBM Cost of Data Breach Report 2025)
31%
of breaches in Verizon DBIR 2026 originated from vulnerability exploitation – overtaking credential abuse (13%) as the #1 initial access vector. Only 26% of critical vulnerabilities were fully remediated in 2025. (Verizon DBIR 2026)
241 days
Mean time to detect and contain a breach in 2025 (IBM). Breaches contained within 200 days cost $3.87M; those taking longer cost $5.01M – a $1.14M penalty for every day of dwell time past the threshold. (IBM 2025; StationX, 2026)
$670K
Average additional breach cost when shadow AI is involved – employees using unauthorized AI tools that create unmonitored data pathways. 20% of breaches in IBM 2025 data involved shadow AI. (IBM Cost of Data Breach Report 2025)
$2.2M
Average breach cost reduction for organizations using security AI and automation – the highest single cost-reduction factor in IBM’s 2025 dataset, exceeding incident response planning and employee training. (IBM Cost of Data Breach Report 2025)
$20.9B
Total cybercrime losses reported to the FBI IC3 for 2025 – up from $16.6B in 2024, with business email compromise alone costing $3.05B across 24,768 complaints. (FBI IC3 Annual Report 2025)

1. U.S. Data Breach Costs: The $10.22 Million Record and Why the U.S. Leads

Average Data Breach Cost by Country/Region (IBM 2025)
United States
$10.22M
Middle East
$7.29M
Benelux
$6.24M
Healthcare (Global)
$7.42M (14th yr #1)
Global Average
$4.44M
Source: IBM Cost of a Data Breach Report 2025 (604 organizations, 17 countries)
  • U.S. organizations faced an average data breach cost of $10.22 million in 2025 – an all-time high in IBM’s 20-year Cost of a Data Breach series and 9% above the 2024 figure. The global average fell 9% to $4.44 million over the same period, widening the U.S. premium to 2.3x. (IBM Cost of a Data Breach Report 2025)
  • Three structural factors drive U.S. breach costs above the global average: litigation and class-action exposure unique to the U.S. legal system, 50 different state breach notification laws, and high concentrations of healthcare and financial sector organizations – the two costliest industries. (StationX / IBM data analysis, 2026)
  • Healthcare remained the most expensive sector globally for the fourteenth consecutive year at $7.42 million per breach – a sector where the combination of sensitive data, legacy systems, and patient care continuity obligations creates maximum breach impact. (IBM Cost of Data Breach 2025)
  • The global average decline from $4.88 million (2024) to $4.44 million (2025) is attributed partly to faster breach containment lifecycles in the dataset. IBM’s mean detection-and-containment time improved, but the U.S. continued its upward trajectory. (IBM 2025; DeepStrike.io, 2026)
  • Breaches contained within 200 days cost $3.87 million on average; those taking longer cost $5.01 million – a $1.14 million penalty for extended dwell time. The mean time to detect and contain across all breaches was 241 days. (IBM 2025; ComplianceDocs, 2026)
  • The FBI’s IC3 reported $20.9 billion in total cybercrime losses for 2025, up from $16.6 billion in 2024 – reflecting that even as individual breach costs moderated globally, total aggregate cybercrime damage continued rising. (FBI IC3 Annual Report 2025; ComplianceDocs, 2026)

2. The Human Element: 62% of Breaches Still Trace to People

62% (2026)
Human element present in breaches – up from 60% in 2025. Covers phishing, credential abuse, pretexting, insider action, and social engineering across all channels. (Verizon DBIR 2026)
16% of breaches
Phishing – the most common social engineering action type, held steady as the top email-based attack vector. AI-assisted phishing now generates content indistinguishable from legitimate communications. (Verizon DBIR 2026; IBM 2025)
41% non-email
of social engineering breaches now involve vectors other than email – voice, SMS, social media, and direct messaging apps. A 40% higher click rate on voice/SMS simulations vs. email. (Verizon DBIR 2026)
  • The Verizon DBIR 2026 – analyzing 22,052 incidents and 12,195 confirmed breaches – found the human element present in 62% of all breaches, up from 60% the prior year. Despite years of security awareness investment, this figure has not materially declined across three consecutive DBIR editions. (Verizon DBIR 2026; Symmetry Systems, May 2026)
  • Social engineering was the third most common breach pattern overall at 16% of all breaches, with 5,302 incidents and 3,814 confirmed data breaches in the DBIR 2026 dataset. Email remained the primary delivery channel, but the proportion of non-email attacks is growing. (Verizon DBIR 2026; Mimecast, June 2026)
  • 41% of social engineering breaches now involve vectors other than email – voice calls, SMS, social media, and collaboration tools. Voice and SMS-based phishing simulations showed a median click rate of roughly 2% versus 1.4% for email, a 40% higher success rate when attackers switch from inbox to phone. (Verizon DBIR 2026; Breacher.ai, May 2026)
  • Pretexting – social engineering campaigns built around impersonation, ongoing conversations, and trust manipulation – was added as its own tracked initial access vector in DBIR 2026, appearing at 6% of breaches. The DBIR team noted this change was driven by high-profile ransomware breaches using pretexting as the first action against victims. (Verizon DBIR 2026; Abnormal AI, June 2026)
  • Threat actors leveraged generative AI assistance across a median of 15 distinct techniques in documented 2026 attack campaigns, with some using it across 40 to 50 techniques. Of the AI-assisted initial access vectors identified, phishing accounted for 44% – the single largest category. (Verizon DBIR 2026; Mimecast, June 2026)
  • In IBM’s 2025 data, AI was used in 16% of breaches studied, primarily to power phishing campaigns. Among organizations experiencing AI-related breaches, 97% lacked proper AI access controls. (IBM Cost of a Data Breach Report 2025)

3. Vulnerability Exploitation: Now the #1 Initial Access Vector

31%
Vulnerability exploitation – now #1 initial access vector (DBIR 2026)
Verizon DBIR 2026
13%
Credential abuse – overtaken by vulnerability exploitation for first time
Verizon DBIR 2026
26%
of critical vulnerabilities fully remediated in 2025 – down from 38% the prior year
Verizon DBIR 2026
43 days
Median time to fix critical vulnerabilities – up from prior year, widening the attack window
Verizon DBIR 2026
  • In a significant structural shift, vulnerability exploitation became the #1 initial access vector in the Verizon DBIR 2026 at 31% of breaches, overtaking credential abuse (13%) for the first time in the report’s history. (Verizon DBIR 2026; Abnormal AI, June 2026)
  • Only 26% of known exploited vulnerabilities were fully remediated in 2025 – down from 38% the prior year – while the median time to fix critical vulnerabilities increased to 43 days. These two trends together mean attackers have an increasingly wide and persistent window. (Verizon DBIR 2026; AllCovered, June 2026)
  • The 2026 DBIR reported a 240% year-over-year surge in attackers using legitimate remote monitoring and management (RMM) software to operate inside victim networks – blending with trusted IT tools to evade detection. This “living off the land” technique bypasses security tooling built around detecting malicious software. (Networks Group, June 2026)
  • For employees, the vulnerability exploitation shift has a direct implication: unpatched software on work devices, unsanctioned browser extensions, and delays in accepting system update prompts are no longer peripheral risks – they are now the primary attack entry point. (Verizon DBIR 2026)
  • Supply chain and third-party breaches via vulnerabilities in vendor software represented 267 days average detection and containment time in IBM 2025 – the longest of any major attack vector, reflecting the difficulty of detecting that a breach originated in a third-party environment. (IBM Cost of Data Breach 2025)

4. Third-Party Compromise: A 60% Surge to 48% of All Breaches

Third-Party Breach Trend: From Peripheral Risk to Primary Attack Surface
IBM 2025
Supply chain breaches average $4.91 million per incident. Detection and containment takes 267 days on average – the longest timeline of any major attack vector. Employees who interact with vendor software, communications, or shared systems are the most exposed group.
DBIR 2026
Third-party compromise appeared in 48% of all breaches – a 60% year-over-year increase. Attackers exploit vendors, SaaS platforms, and OAuth integrations as pathways into target organizations, often through legitimate credentials or access grants.
Why it matters for employees
A compromised third-party vendor can deliver malware through legitimate software updates, use valid access credentials to enter your environment, or send convincing phishing via trusted communication channels – making the breach invisible until downstream damage appears.
Sources: IBM Cost of Data Breach 2025; Verizon DBIR 2026; Abnormal AI (June 2026)
  • Third-party compromise appeared in 48% of all breaches in the Verizon DBIR 2026 – a 60% year-over-year increase, making it one of the most rapidly growing threat categories in the current threat landscape. (Verizon DBIR 2026; Abnormal AI, June 2026)
  • IBM’s 2025 data found supply chain breaches averaging $4.91 million per incident with a 267-day average detection and containment timeline – the longest of any major attack vector, significantly longer than phishing (204 days) or credential compromise (246 days). (IBM Cost of Data Breach 2025)
  • From an employee perspective, third-party attacks are particularly dangerous because they arrive through trusted channels: legitimate software updates, valid vendor access credentials, and communications from real supplier email domains. There is no obvious warning indicator for the recipient. (IBM 2025; industry analysis)
  • Organizations that discover breaches internally – rather than being notified by an external party – have significantly shorter detection timelines and lower breach costs. When a vendor notifies you of a breach rather than you detecting it yourself, cost exposure increases substantially. (IBM Cost of Data Breach 2025)

5. Ransomware in 2026: More Prevalent, Smaller Ransoms, Maximum Disruption

Frequency: Rising
Ransomware appeared in 48% of all breaches in Verizon DBIR 2026 – up from 44% in 2025. IBM 2025 found 63% of ransomware victims refused to pay the ransom.
Ransom Amount: Declining
Median ransom payment fell to $139,875 in 2026 DBIR. 69% of victims paid nothing. Sophos 2025 survey put average ransom payment at $1.0M, average recovery costs excluding ransom at approximately $2M.
Attacker Adaptation: Disruption
As more organizations refuse to pay, attackers have shifted to maximizing operational disruption – prolonged outages, encrypted critical systems, and halted supply chains designed to break the will of firms that might otherwise hold firm.
  • Ransomware appeared in 48% of all breaches in the Verizon DBIR 2026 – up from 44% in the prior year – while the median ransom paid continued declining to $139,875. 69% of victims chose not to pay, and IBM’s 2025 data showed 63% refusal to pay. (Verizon DBIR 2026; ComplianceDocs, 2026)
  • Pretexting – direct attacker contact with victims via phone, chat, or email impersonation – increasingly serves as the initial access step in high-profile ransomware attacks, according to the 2026 DBIR. The shift represents attackers bypassing technical controls in favor of human manipulation to gain initial access before deploying encryption. (Verizon DBIR 2026; Abnormal AI)
  • Business email compromise (BEC) – often a ransomware precursor via credential theft – cost U.S. organizations $3.05 billion across 24,768 complaints in 2025, according to the FBI IC3. BEC exploits the same social engineering pathways that ransomware operators use to establish initial access. (FBI IC3 2025; ComplianceDocs)
  • Ransomware resilience is increasingly framed as a business continuity question rather than a purely technical one: C-suite involvement in tabletop exercises, pre-negotiated incident response retainers, and off-network backup verification are the practical preparation steps that determine whether an organization can refuse to pay. (Networks Group, June 2026)

6. Shadow AI: The $670,000 Cost of Unauthorized AI Tool Use at Work

20%
of breaches in IBM 2025 data involved shadow AI
IBM 2025
97%
of AI-breach organizations lacked proper AI access controls
IBM 2025
67%
of users access AI tools through non-corporate accounts on work devices
Verizon DBIR 2026
45%
of employees are now regular AI users – creating a large unsanctioned use footprint
Verizon DBIR 2026
  • Shadow AI – employees using unauthorized AI tools that create unmonitored pathways for data exposure – added an average of $670,000 to breach costs in affected organizations in IBM’s 2025 data. 20% of breaches in the dataset involved shadow AI. (IBM Cost of Data Breach 2025)
  • Among organizations that experienced AI-related breaches, 97% lacked proper AI access controls – not as a matter of negligence, but because organizational AI governance has not kept pace with the speed at which employees are adopting AI tools. (IBM 2025)
  • The Verizon DBIR 2026 found that 67% of users access AI tools through non-corporate accounts on work devices, and 45% of employees are now regular AI users. When employees upload source code, customer data, internal documents, or financial records to external AI platforms, those data transfers may be irretrievable and unaudited. (Verizon DBIR 2026; AllCovered, June 2026)
  • The shadow AI governance gap is a fundamentally different problem from traditional shadow IT: the risk is not unauthorized software installation but unauthorized data sharing. A browser-based AI tool requires no installation and leaves no software footprint while processing sensitive documents that should never leave the corporate environment. (industry analysis; IBM 2025)
  • Effective AI governance in the workplace requires usage visibility, approved AI tool catalogues, and training that explains why specific data types cannot be processed on external AI platforms – not just a prohibition. Blanket bans without alternatives have historically driven usage underground. (DBIR 2026; IBM 2025 security recommendations)

7. What Actually Reduces Breach Costs: The IBM 2025 Evidence

Security AI and Automation
$2.2M average reduction
Incident Response Preparedness
$232K reduction + 54-day faster containment
SOC / Continuous Monitoring
Detection from 204 days to under 50 days
Employee Security Training
Measurable reduction – below AI/automation
Sources: IBM Cost of Data Breach 2025; Orizon.one (March 2026)
  • Security AI and automation produced the largest single measurable breach cost reduction in IBM’s 2025 dataset: $2.2 million on average for organizations that deployed it compared to those that did not. This is the highest single cost-reduction factor, exceeding incident response planning, employee training, and threat intelligence. (IBM Cost of Data Breach 2025)
  • Incident response planning and testing reduced breach costs by $232,000 per incident and shortened containment time by 54 days. At $15,000 to $30,000 per year, the ROI is 8 to 15 times the investment even if only one incident occurs every three years. (Orizon, March 2026; IBM 2025)
  • Continuous monitoring and SOC services reduced mean time to detect from 204 days to under 50 days, cutting breach costs by approximately $1 million based on IBM’s time-to-containment correlation. Every day of reduced dwell time is a day of reduced breach exposure. (Orizon, March 2026)
  • For the employee dimension: the security controls that most reliably produce measurable breach cost reductions are automated threat detection, IR preparedness, and access controls – not awareness training alone. Training has measurable value but its independent cost reduction is substantially below AI-powered defenses. (IBM Cost of Data Breach 2025)
  • Organizations that self-detect breaches pay substantially less than those notified by external parties. Internal detection is partly a function of employee vigilance – reporting suspicious communications, unusual access prompts, or unexpected system behavior before a breach escalates is a measurable risk reduction behavior. (IBM 2025)

Key Takeaways for Safety Managers, CISOs, and HR Professionals

U.S. organizations face breach costs 2.3x the global average
At $10.22M, U.S. breach costs reflect litigation exposure, 50 state notification laws, and sector concentration in healthcare and finance. Organizations benchmarking against the $4.44M global average are significantly underestimating their actual risk. Industry-specific figures – available in IBM’s 2025 breakdown – are the right planning baseline.
Vulnerability exploitation is now the primary entry point
Vulnerability exploitation overtook credential abuse in DBIR 2026 at 31% of breaches, while only 26% of critical vulnerabilities were remediated in 2025. Patching cadence, prioritization by real-world exploitability rather than severity scores alone, and software update discipline at the employee level are now first-order security controls.
Social engineering has expanded beyond the inbox
41% of social engineering breaches now use non-email vectors. Voice and SMS attacks succeed 40% more often than email in simulations. Awareness programs built exclusively around phishing email recognition are not addressing the majority of the social engineering threat surface that employees actually face.
Shadow AI is a measurable cost driver – govern it now
At $670,000 in average additional breach cost and 20% of breaches involving shadow AI in IBM’s 2025 data, unauthorized employee AI tool use is not a theoretical future risk. 67% of employees access AI through non-corporate accounts on work devices. AI governance – approved tool catalogues, usage training, and data classification that specifies what cannot be processed externally – is now a breach cost reduction measure.
Third-party risk requires employee-level awareness
With third-party compromise in 48% of 2026 breaches (up 60% YoY), employees who interact with vendor-provided software, communications, or shared systems are at the front line of supply chain risk. Recognizing anomalous activity in trusted channels – unexpected update prompts, vendor requests for credentials, unusual access grants – is the practical employee-level defense.
$2.2M reduction from AI-driven defense – the highest ROI security investment
IBM’s 2025 data shows security AI and automation delivers a $2.2M average breach cost reduction – the highest of any single security control. Combined with incident response preparedness ($232K reduction, 54 days faster containment) and continuous monitoring (detection from 204 to under 50 days), these are the investments that demonstrably move the cost curve.

Sources

Primary Reports

Analysis and Commentary Sources

Add a Comment

Your email address will not be published. Required fields are marked *