2026年数据泄露调查报告_121页_10mb
报告摘要
2026 Data Breach Investigations Report Summary
Core Content
The 2026 Data Breach Investigations Report (DBIR) by Verizon Business provides an in-depth analysis of over 31,000 real-world security incidents, with more than 22,000 confirmed data breaches across 145 countries. The report emphasizes the importance of maintaining strong cybersecurity fundamentals in the face of a rapidly evolving threat landscape.
Main Findings
Vulnerability Exploitation as the Leading Initial Access Vector
- Exploitation of vulnerabilities has become the most common initial access vector for breaches, accounting for 31% of all breaches in 2026.
- Credential abuse, previously the leading vector, has dropped to 13%.
- Only 26% of critical vulnerabilities (from CISA KEV catalog) were fully remediated in 2025, down from 38% in 2024.
- The median time to fully resolve a breach increased to 43 days, up from 32 days in 2025.
- Organizations had 50% more critical vulnerabilities to patch in 2026 compared to 2025.
Ransomware and Third-Party Breaches on the Rise
- Ransomware now accounts for 48% of all breaches, up from 44% in 2025.
- Ransom payments have declined, with 69% of victims not paying.
- The median ransom paid dropped to $139,875 from $150,000 in 2025.
- Third-party breaches increased by 60%, representing 48% of total breaches.
- Only 23% of third-party organizations fully remediated missing or improperly secured MFA on their cloud accounts.
- Weak passwords and permission misconfigurations took almost eight months to resolve in 50% of cases.
Generative AI (GenAI) in Cyberattacks
- GenAI is being used by threat actors to assist in various stages of attacks, including targeting, initial access, and malware/tool development.
- The median number of documented techniques where AI assistance was used by threat actors is 15, with some using up to 40 or 50.
- 55% of known malware examples are associated with well-known and defined attack techniques.
- Less than 2.5% of AI-assisted malware observations involved less common techniques with one or fewer known examples.
Mobile-Centric Social Engineering
- Social Engineering is the third most common breach pattern, accounting for 16% of breaches.
- Pretexting has become a more common initial access vector, reaching 6% of all breaches, compared to 16% for Phishing.
- Phishing simulations show a 40% higher success rate in mobile-centric vectors (e.g., voice and text) than via email.
- Pretexting involves building a trusted relationship through fabricated scenarios to trick users into actions that compromise the organization.
Shadow AI and Malicious Insiders
- 67% of users access AI services using non-corporate accounts on corporate devices.
- 45% of employees are now regular users of AI (authorized or not) on corporate devices, up from 15% in 2025.
- Shadow AI is the third most common non-malicious insider action in DLP data, with a fourfold increase from the previous year.
- 3.2% of DLP policy violations involved uploading research and technical documentation to unauthorized AI systems, risking intellectual property exposure.
Key Trends and Patterns
Incident Classification Patterns
- The report classifies incidents into categories such as System Intrusion, Social Engineering, Basic Web Application Attacks, Miscellaneous Errors, Privilege Misuse, and Denial of Service.
- Ransomware remains one of the most disruptive breach types.
- System Intrusion is a major focus, with detailed analysis on how attackers gain access and escalate privileges.
Deep-Dive Analysis
- Highlights long-form research on topics like privilege escalation and the North Korean IT worker risk.
- Uses visual tools such as slanted bar charts, spaghetti charts, dot plots, and pictogram plots to represent uncertainty in data, especially in the context of confidence intervals.
Industry and Regional Analysis
- The report provides detailed analysis of various industry verticals, including Educational Services, Financial and Insurance, Healthcare, Manufacturing, Public Administration, and Retail.
- Includes a focused analysis on Small- and Medium-Sized Businesses (SMBs).
- Offers regional analysis for Asia and the Pacific (APAC) and Europe, Middle East and Africa (EMEA).
Methodology and Framework
- The report uses the VERIS framework to normalize and analyze data.
- VERIS includes:
- Threat Actors: Who is behind the event (e.g., external attackers, employees).
- Threat Actions: What tactics were used (e.g., malware, hacking, social engineering).
- Varieties: More specific classifications (e.g., SQL injection, brute force).
- Uncertainty is represented through visualizations like slanted bar charts, spaghetti charts, and dot plots.
- The report is anonymized and aggregated to ensure privacy and reduce bias.
Data Sources and Use
- Data is collected from over 100 contributors, including incident response firms, law enforcement, cyber insurance brokers, and research partners.
- Data contributors include:
- Tenable (Raymond Carney, Scott Caveza)
- Qualys (Saeed Abbasi)
- Empirical Security (Jay Jacobs, Michael Roytman)
- Tenchi Security (Felipe Esposito, Alexandre Sieira)
- Anthropic (Kyla Guru, Jacob Klein)
- Fastly (Simran Khalsa, Kelly Shortridge)
- DTEX (Kellie Roessler, Michael Barnhart, Rajan Koo)
- Usage of the report is encouraged, but pie charts must not be generated from its data.
- Proper citation is required: "Verizon 2026 Data Breach Investigations Report" and no modifications allowed.
Conclusion
Despite the rapid evolution of the threat landscape, the report reinforces that fundamentals in cybersecurity—such as visibility, patch management, and response planning—are still critical. The report's message is one of refinement over revolution, encouraging collaboration and continuous improvement to stay ahead of cyber threats.
Figures and Visuals
- Figure 1: Spaghetti chart showing connections between data points within confidence intervals.
- Figure 2: Slanted bar chart representing 95% confidence levels.
- Figure 3: Dot plot showing distribution of events with color-coded categories.
- Figure 4: Pictogram plot using kiwi birds to represent data points.
- Figure 5: Known initial access vectors over time.
- Figure 6: Survival analysis of third-party MFA exposures.
- Figure 7: Distribution of malware examples per ATT&CK technique.
- Figure 8: Success rate of non-email social attack campaigns.
- Figure 9: Data types in untrusted DLP events targeting GenAI tools.
- Figure 10: Initial access vectors in breaches.
- Figure 11: Initial access vectors over time.
Final Notes
- The report is a collaborative effort involving the Verizon DBIR team and various research partners.
- Feedback and contributions are welcomed through dbir@verizon.com or LinkedIn.
- The 2026 DBIR aims to provide actionable insights and risk guidance to help organizations navigate the changing cybersecurity landscape.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载