Two major annual reports define what we know about workplace cyber threats: IBM’s Cost of a Data Breach Report, which measures the financial impact of incidents across surveyed organizations, and the Verizon Data Breach Investigations Report, which analyzes confirmed incident data to identify attack patterns and vectors. In 2025 and 2026, both point in the same direction: threats are human-facing, AI is scaling attacker capability, and vulnerability exploitation has overtaken credential theft as the primary entry point.
The IBM 2025 report – the most recent edition as of July 2026 – surveyed 604 organizations across 17 countries and found U.S. breach costs at a record $10.22 million. The Verizon DBIR 2026, analyzing 22,052 incidents and 12,195 confirmed breaches, found the human element in 62% of breaches, ransomware in 48%, and third-party compromise surging 60% year over year. Shadow AI – unauthorized employee use of AI tools at work – is now a measured cost driver rather than a theoretical risk. Below we compile 40+ statistics on these threats and what the data says about reducing breach costs.
Editor's Choice: Key Workplace Cyber Threat Statistics for 2025-26
1. U.S. Data Breach Costs: The $10.22 Million Record and Why the U.S. Leads
- U.S. organizations faced an average data breach cost of $10.22 million in 2025 – an all-time high in IBM’s 20-year Cost of a Data Breach series and 9% above the 2024 figure. The global average fell 9% to $4.44 million over the same period, widening the U.S. premium to 2.3x. (IBM Cost of a Data Breach Report 2025)
- Three structural factors drive U.S. breach costs above the global average: litigation and class-action exposure unique to the U.S. legal system, 50 different state breach notification laws, and high concentrations of healthcare and financial sector organizations – the two costliest industries. (StationX / IBM data analysis, 2026)
- Healthcare remained the most expensive sector globally for the fourteenth consecutive year at $7.42 million per breach – a sector where the combination of sensitive data, legacy systems, and patient care continuity obligations creates maximum breach impact. (IBM Cost of Data Breach 2025)
- The global average decline from $4.88 million (2024) to $4.44 million (2025) is attributed partly to faster breach containment lifecycles in the dataset. IBM’s mean detection-and-containment time improved, but the U.S. continued its upward trajectory. (IBM 2025; DeepStrike.io, 2026)
- Breaches contained within 200 days cost $3.87 million on average; those taking longer cost $5.01 million – a $1.14 million penalty for extended dwell time. The mean time to detect and contain across all breaches was 241 days. (IBM 2025; ComplianceDocs, 2026)
- The FBI’s IC3 reported $20.9 billion in total cybercrime losses for 2025, up from $16.6 billion in 2024 – reflecting that even as individual breach costs moderated globally, total aggregate cybercrime damage continued rising. (FBI IC3 Annual Report 2025; ComplianceDocs, 2026)
2. The Human Element: 62% of Breaches Still Trace to People
- The Verizon DBIR 2026 – analyzing 22,052 incidents and 12,195 confirmed breaches – found the human element present in 62% of all breaches, up from 60% the prior year. Despite years of security awareness investment, this figure has not materially declined across three consecutive DBIR editions. (Verizon DBIR 2026; Symmetry Systems, May 2026)
- Social engineering was the third most common breach pattern overall at 16% of all breaches, with 5,302 incidents and 3,814 confirmed data breaches in the DBIR 2026 dataset. Email remained the primary delivery channel, but the proportion of non-email attacks is growing. (Verizon DBIR 2026; Mimecast, June 2026)
- 41% of social engineering breaches now involve vectors other than email – voice calls, SMS, social media, and collaboration tools. Voice and SMS-based phishing simulations showed a median click rate of roughly 2% versus 1.4% for email, a 40% higher success rate when attackers switch from inbox to phone. (Verizon DBIR 2026; Breacher.ai, May 2026)
- Pretexting – social engineering campaigns built around impersonation, ongoing conversations, and trust manipulation – was added as its own tracked initial access vector in DBIR 2026, appearing at 6% of breaches. The DBIR team noted this change was driven by high-profile ransomware breaches using pretexting as the first action against victims. (Verizon DBIR 2026; Abnormal AI, June 2026)
- Threat actors leveraged generative AI assistance across a median of 15 distinct techniques in documented 2026 attack campaigns, with some using it across 40 to 50 techniques. Of the AI-assisted initial access vectors identified, phishing accounted for 44% – the single largest category. (Verizon DBIR 2026; Mimecast, June 2026)
- In IBM’s 2025 data, AI was used in 16% of breaches studied, primarily to power phishing campaigns. Among organizations experiencing AI-related breaches, 97% lacked proper AI access controls. (IBM Cost of a Data Breach Report 2025)
3. Vulnerability Exploitation: Now the #1 Initial Access Vector
- In a significant structural shift, vulnerability exploitation became the #1 initial access vector in the Verizon DBIR 2026 at 31% of breaches, overtaking credential abuse (13%) for the first time in the report’s history. (Verizon DBIR 2026; Abnormal AI, June 2026)
- Only 26% of known exploited vulnerabilities were fully remediated in 2025 – down from 38% the prior year – while the median time to fix critical vulnerabilities increased to 43 days. These two trends together mean attackers have an increasingly wide and persistent window. (Verizon DBIR 2026; AllCovered, June 2026)
- The 2026 DBIR reported a 240% year-over-year surge in attackers using legitimate remote monitoring and management (RMM) software to operate inside victim networks – blending with trusted IT tools to evade detection. This “living off the land” technique bypasses security tooling built around detecting malicious software. (Networks Group, June 2026)
- For employees, the vulnerability exploitation shift has a direct implication: unpatched software on work devices, unsanctioned browser extensions, and delays in accepting system update prompts are no longer peripheral risks – they are now the primary attack entry point. (Verizon DBIR 2026)
- Supply chain and third-party breaches via vulnerabilities in vendor software represented 267 days average detection and containment time in IBM 2025 – the longest of any major attack vector, reflecting the difficulty of detecting that a breach originated in a third-party environment. (IBM Cost of Data Breach 2025)
4. Third-Party Compromise: A 60% Surge to 48% of All Breaches
- Third-party compromise appeared in 48% of all breaches in the Verizon DBIR 2026 – a 60% year-over-year increase, making it one of the most rapidly growing threat categories in the current threat landscape. (Verizon DBIR 2026; Abnormal AI, June 2026)
- IBM’s 2025 data found supply chain breaches averaging $4.91 million per incident with a 267-day average detection and containment timeline – the longest of any major attack vector, significantly longer than phishing (204 days) or credential compromise (246 days). (IBM Cost of Data Breach 2025)
- From an employee perspective, third-party attacks are particularly dangerous because they arrive through trusted channels: legitimate software updates, valid vendor access credentials, and communications from real supplier email domains. There is no obvious warning indicator for the recipient. (IBM 2025; industry analysis)
- Organizations that discover breaches internally – rather than being notified by an external party – have significantly shorter detection timelines and lower breach costs. When a vendor notifies you of a breach rather than you detecting it yourself, cost exposure increases substantially. (IBM Cost of Data Breach 2025)
5. Ransomware in 2026: More Prevalent, Smaller Ransoms, Maximum Disruption
- Ransomware appeared in 48% of all breaches in the Verizon DBIR 2026 – up from 44% in the prior year – while the median ransom paid continued declining to $139,875. 69% of victims chose not to pay, and IBM’s 2025 data showed 63% refusal to pay. (Verizon DBIR 2026; ComplianceDocs, 2026)
- Pretexting – direct attacker contact with victims via phone, chat, or email impersonation – increasingly serves as the initial access step in high-profile ransomware attacks, according to the 2026 DBIR. The shift represents attackers bypassing technical controls in favor of human manipulation to gain initial access before deploying encryption. (Verizon DBIR 2026; Abnormal AI)
- Business email compromise (BEC) – often a ransomware precursor via credential theft – cost U.S. organizations $3.05 billion across 24,768 complaints in 2025, according to the FBI IC3. BEC exploits the same social engineering pathways that ransomware operators use to establish initial access. (FBI IC3 2025; ComplianceDocs)
- Ransomware resilience is increasingly framed as a business continuity question rather than a purely technical one: C-suite involvement in tabletop exercises, pre-negotiated incident response retainers, and off-network backup verification are the practical preparation steps that determine whether an organization can refuse to pay. (Networks Group, June 2026)
6. Shadow AI: The $670,000 Cost of Unauthorized AI Tool Use at Work
- Shadow AI – employees using unauthorized AI tools that create unmonitored pathways for data exposure – added an average of $670,000 to breach costs in affected organizations in IBM’s 2025 data. 20% of breaches in the dataset involved shadow AI. (IBM Cost of Data Breach 2025)
- Among organizations that experienced AI-related breaches, 97% lacked proper AI access controls – not as a matter of negligence, but because organizational AI governance has not kept pace with the speed at which employees are adopting AI tools. (IBM 2025)
- The Verizon DBIR 2026 found that 67% of users access AI tools through non-corporate accounts on work devices, and 45% of employees are now regular AI users. When employees upload source code, customer data, internal documents, or financial records to external AI platforms, those data transfers may be irretrievable and unaudited. (Verizon DBIR 2026; AllCovered, June 2026)
- The shadow AI governance gap is a fundamentally different problem from traditional shadow IT: the risk is not unauthorized software installation but unauthorized data sharing. A browser-based AI tool requires no installation and leaves no software footprint while processing sensitive documents that should never leave the corporate environment. (industry analysis; IBM 2025)
- Effective AI governance in the workplace requires usage visibility, approved AI tool catalogues, and training that explains why specific data types cannot be processed on external AI platforms – not just a prohibition. Blanket bans without alternatives have historically driven usage underground. (DBIR 2026; IBM 2025 security recommendations)
7. What Actually Reduces Breach Costs: The IBM 2025 Evidence
- Security AI and automation produced the largest single measurable breach cost reduction in IBM’s 2025 dataset: $2.2 million on average for organizations that deployed it compared to those that did not. This is the highest single cost-reduction factor, exceeding incident response planning, employee training, and threat intelligence. (IBM Cost of Data Breach 2025)
- Incident response planning and testing reduced breach costs by $232,000 per incident and shortened containment time by 54 days. At $15,000 to $30,000 per year, the ROI is 8 to 15 times the investment even if only one incident occurs every three years. (Orizon, March 2026; IBM 2025)
- Continuous monitoring and SOC services reduced mean time to detect from 204 days to under 50 days, cutting breach costs by approximately $1 million based on IBM’s time-to-containment correlation. Every day of reduced dwell time is a day of reduced breach exposure. (Orizon, March 2026)
- For the employee dimension: the security controls that most reliably produce measurable breach cost reductions are automated threat detection, IR preparedness, and access controls – not awareness training alone. Training has measurable value but its independent cost reduction is substantially below AI-powered defenses. (IBM Cost of Data Breach 2025)
- Organizations that self-detect breaches pay substantially less than those notified by external parties. Internal detection is partly a function of employee vigilance – reporting suspicious communications, unusual access prompts, or unexpected system behavior before a breach escalates is a measurable risk reduction behavior. (IBM 2025)
Key Takeaways for Safety Managers, CISOs, and HR Professionals
Sources
Primary Reports
- IBM Cost of a Data Breach Report 2025 (ibm.com) – The most recent edition as of July 2026. 604 organizations, 17 countries, 17 industries. Primary source for U.S. $10.22M average, shadow AI costs, breach vector costs, and cost-reduction factors.
- Verizon Data Breach Investigations Report 2026 (verizon.com/dbir) – 22,052 incidents, 12,195 confirmed breaches analyzed. Primary source for human element (62%), vulnerability exploitation (#1 vector), third-party compromise (48%), ransomware (48%), shadow AI usage patterns.
- FBI Internet Crime Complaint Center 2025 Annual Report – $20.9B in cybercrime losses, $3.05B BEC, primary cybercrime loss figures by category.
Analysis and Commentary Sources
- Abnormal AI (June 2026) – 62% human element, 31% vulnerability exploitation overtaking 13% credential abuse, 48% third-party compromise (+60% YoY)
- Mimecast (June 2026) – GenAI across 15 median techniques, phishing 44% of AI-assisted vectors, 80% of blocked email attacks plain phishing
- Breacher.ai (May 2026) – 41% non-email social engineering, 40% higher voice/SMS success rates, 1.4% vs 2% click rates
- Networks Group (June 2026) – 240% RMM surge, 48% ransomware prevalence, pretexting as ransomware initial access, $139,875 median ransom
- AllCovered (June 2026) – 31% vulnerability exploitation, 26% remediation rate (down from 38%), 43-day median patch time, 67% shadow AI non-corporate access
- StationX (July 2026) – 140 statistics from 50+ sources: $10.22M U.S., 241-day mean detection, $3.87M vs $5.01M containment cost split, 2.3x U.S. premium
- ComplianceDocs (July 2026) – Verizon DBIR 2026 vs IBM 2025 reconciliation, FBI IC3 2025, $20.9B losses, $139,875 median ransom, 69% refusal to pay
- Orizon (March 2026) – IR planning ROI ($232K reduction, 54 days), SOC detection improvement (204 to under 50 days), $1M cost reduction from monitoring


