> **来源:[研报客](https://pc.yanbaoke.cn)** # 2026 Data Breach Investigations Report Summary ## Core Content The **2026 Data Breach Investigations Report (DBIR)** by Verizon Business provides an in-depth analysis of over 31,000 real-world security incidents, with more than 22,000 confirmed data breaches across 145 countries. The report emphasizes the importance of maintaining strong cybersecurity fundamentals in the face of a rapidly evolving threat landscape. ## Main Findings ### **Vulnerability Exploitation as the Leading Initial Access Vector** - **Exploitation of vulnerabilities** has become the most common initial access vector for breaches, accounting for **31%** of all breaches in 2026. - **Credential abuse**, previously the leading vector, has dropped to **13%**. - Only **26%** of critical vulnerabilities (from CISA KEV catalog) were fully remediated in 2025, down from **38%** in 2024. - The **median time to fully resolve** a breach increased to **43 days**, up from **32 days** in 2025. - Organizations had **50% more critical vulnerabilities** to patch in 2026 compared to 2025. ### **Ransomware and Third-Party Breaches on the Rise** - **Ransomware** now accounts for **48%** of all breaches, up from **44%** in 2025. - **Ransom payments** have declined, with **69%** of victims not paying. - The **median ransom paid** dropped to **\$139,875** from **\$150,000** in 2025. - **Third-party breaches** increased by **60%**, representing **48%** of total breaches. - Only **23%** of third-party organizations fully remediated missing or improperly secured MFA on their cloud accounts. - **Weak passwords and permission misconfigurations** took **almost eight months** to resolve in 50% of cases. ### **Generative AI (GenAI) in Cyberattacks** - **GenAI** is being used by threat actors to assist in various stages of attacks, including targeting, initial access, and malware/tool development. - The **median number of documented techniques** where AI assistance was used by threat actors is **15**, with some using up to **40 or 50**. - **55% of known malware examples** are associated with well-known and defined attack techniques. - Less than **2.5%** of AI-assisted malware observations involved less common techniques with one or fewer known examples. ### **Mobile-Centric Social Engineering** - **Social Engineering** is the third most common breach pattern, accounting for **16%** of breaches. - **Pretexting** has become a more common initial access vector, reaching **6%** of all breaches, compared to **16%** for Phishing. - **Phishing simulations** show a **40% higher success rate** in mobile-centric vectors (e.g., voice and text) than via email. - Pretexting involves building a **trusted relationship** through fabricated scenarios to trick users into actions that compromise the organization. ### **Shadow AI and Malicious Insiders** - **67%** of users access AI services using non-corporate accounts on corporate devices. - **45%** of employees are now regular users of AI (authorized or not) on corporate devices, up from **15%** in 2025. - **Shadow AI** is the third most common non-malicious insider action in DLP data, with a **fourfold increase** from the previous year. - **3.2%** of DLP policy violations involved uploading **research and technical documentation** to unauthorized AI systems, risking **intellectual property exposure**. ## Key Trends and Patterns ### **Incident Classification Patterns** - The report classifies incidents into categories such as **System Intrusion**, **Social Engineering**, **Basic Web Application Attacks**, **Miscellaneous Errors**, **Privilege Misuse**, and **Denial of Service**. - **Ransomware** remains one of the most disruptive breach types. - **System Intrusion** is a major focus, with detailed analysis on how attackers gain access and escalate privileges. ### **Deep-Dive Analysis** - Highlights **long-form research** on topics like **privilege escalation** and the **North Korean IT worker risk**. - Uses **visual tools** such as **slanted bar charts**, **spaghetti charts**, **dot plots**, and **pictogram plots** to represent **uncertainty** in data, especially in the context of **confidence intervals**. ### **Industry and Regional Analysis** - The report provides **detailed analysis** of various **industry verticals**, including **Educational Services**, **Financial and Insurance**, **Healthcare**, **Manufacturing**, **Public Administration**, and **Retail**. - Includes a **focused analysis** on **Small- and Medium-Sized Businesses (SMBs)**. - Offers **regional analysis** for **Asia and the Pacific (APAC)** and **Europe, Middle East and Africa (EMEA)**. ## Methodology and Framework - The report uses the **VERIS framework** to normalize and analyze data. - **VERIS** includes: - **Threat Actors**: Who is behind the event (e.g., external attackers, employees). - **Threat Actions**: What tactics were used (e.g., malware, hacking, social engineering). - **Varieties**: More specific classifications (e.g., SQL injection, brute force). - **Uncertainty** is represented through **visualizations** like **slanted bar charts**, **spaghetti charts**, and **dot plots**. - The report is **anonymized** and **aggregated** to ensure privacy and reduce bias. ## Data Sources and Use - Data is collected from **over 100 contributors**, including **incident response firms**, **law enforcement**, **cyber insurance brokers**, and **research partners**. - **Data contributors** include: - Tenable (Raymond Carney, Scott Caveza) - Qualys (Saeed Abbasi) - Empirical Security (Jay Jacobs, Michael Roytman) - Tenchi Security (Felipe Esposito, Alexandre Sieira) - Anthropic (Kyla Guru, Jacob Klein) - Fastly (Simran Khalsa, Kelly Shortridge) - DTEX (Kellie Roessler, Michael Barnhart, Rajan Koo) - **Usage** of the report is encouraged, but **pie charts** must not be generated from its data. - Proper **citation** is required: "Verizon 2026 Data Breach Investigations Report" and no modifications allowed. ## Conclusion Despite the **rapid evolution** of the threat landscape, the report reinforces that **fundamentals** in cybersecurity—such as **visibility**, **patch management**, and **response planning**—are still critical. The **report's message** is one of **refinement over revolution**, encouraging **collaboration** and **continuous improvement** to stay ahead of cyber threats. ## Figures and Visuals - **Figure 1**: Spaghetti chart showing connections between data points within confidence intervals. - **Figure 2**: Slanted bar chart representing **95% confidence levels**. - **Figure 3**: Dot plot showing **distribution of events** with color-coded categories. - **Figure 4**: Pictogram plot using **kiwi birds** to represent data points. - **Figure 5**: Known initial access vectors over time. - **Figure 6**: Survival analysis of **third-party MFA exposures**. - **Figure 7**: Distribution of **malware examples** per ATT&CK technique. - **Figure 8**: Success rate of **non-email social attack campaigns**. - **Figure 9**: Data types in **untrusted DLP events** targeting GenAI tools. - **Figure 10**: Initial access vectors in breaches. - **Figure 11**: Initial access vectors over time. ## Final Notes - The report is a **collaborative effort** involving the **Verizon DBIR team** and various **research partners**. - **Feedback** and **contributions** are welcomed through **dbir@verizon.com** or **LinkedIn**. - The **2026 DBIR** aims to provide **actionable insights** and **risk guidance** to help organizations **navigate the changing cybersecurity landscape**.