logo svg
logo

August 17, 2026

Updated: August 17, 2026

150 Cybersecurity Statistics for 2026

A continuously numbered, source-attached guide to the latest breach, ransomware, phishing, AI, cloud, supply-chain, spending, and workforce data.

Mohammed Khalil

Mohammed Khalil

Featured Image

Last Updated: August 2026

Executive Answer

Cybersecurity statistics for 2026 show that vulnerability exploitation has overtaken credential abuse in Verizon's breach dataset, ransomware appears in nearly half of breaches, and reported US internet-crime losses exceeded $20 billion in 2025. IBM puts the global average breach cost at a record $4.99 million, while AI-enabled malicious breaches cost about $6 million. The 150 figures below separate observed incidents, survey findings, and forecasts, and attach a source to every statistic so security leaders can compare the data without treating unlike datasets as interchangeable.

Cybersecurity Statistics at a Glance

TopicHeadline figureEvidence typePeriod or scopeFull entry
Global attack volume1,968 attempts per organization per weekVendor telemetry2025#1
Confirmed breachesMore than 22,000Incident datasetOctober 2024–November 2025#5
US reported loss$20.877 billionReported complaintsCalendar 2025#8
Global average breach cost$4.99 millionCost study2026 report#16
Ransomware prevalence48% of breachesIncident datasetOctober 2024–November 2025#36
BEC reported loss$3.047 billionReported complaintsCalendar 2025#54
Human element62% of breachesIncident datasetOctober 2024–November 2025#66
Vulnerability exploitation31% of breachesIncident datasetOctober 2024–November 2025#96
Third-party involvement48% of breachesIncident datasetOctober 2024–November 2025#116
API-related incidents87% of respondentsSurveyPrevious 12 months#106

The table is a navigation aid, not a separate evidence source. Each numbered entry below provides the full wording, qualifier, and citation.

How to Read These Cybersecurity Statistics

“2026” refers to the publication's research cutoff, not a claim that every source contains a complete calendar year of 2026 events. Labels such as incident dataset, reported complaints, survey, vendor telemetry, and forecast identify what was measured. Before using any figure in a board paper or risk model, apply the DeepStrike five-question evidence check:

How to Read These Cybersecurity Statistics

Evidence Types and Their Limits

Evidence typeWhat it measuresBest useMain limitation
Incident or breach datasetCases contributed to or investigated by a defined research programAttack patterns and breach compositionCoverage depends on contributors, definitions, and visibility
Reported complaintsReports and claimed losses submitted to an authorityComplaint trends and reported financial harmUnreported crime is absent, and reports are not all independently verified
SurveyResponses from a disclosed sampleExperience, priorities, practices, and perceptionSelf-reporting, sample design, and question wording affect results
Vendor telemetryEvents visible to a provider's products or sensorsHigh-volume attack activity and technical changeIt reflects the provider's customer base, detections, and counting rules
Insurance claimsLosses and incidents within a policyholder populationFinancial impact and claim compositionPolicy coverage, deductibles, and insured population shape the dataset
ForecastAn analyst's modeled future estimateMarket planning and directional scenariosIt is not an observed outcome and can change with assumptions

Several entries may come from the same report because one dataset can answer multiple questions. Those entries are not independent corroboration of one another.

Global Cybercrime and Threat Landscape Statistics

1. 1,968 attacks per week — Observed vendor telemetry. Organizations faced an average of 1,968 cyberattack attempts per week during 2025 in Check Point Research's global dataset. Source: Check Point Cyber Security Report 2026.

2. 18% year-over-year growth — Observed vendor telemetry. Check Point measured an 18% increase in cyberattacks in 2025 compared with the previous year. Source: Check Point Cyber Security Report 2026.

3. 70% growth since 2023 — Observed vendor telemetry. Check Point's measured global attack volume in 2025 was 70% higher than in 2023. Source: Check Point Cyber Security Report 2026.

4. More than 31,000 incidents — Global incident dataset. Verizon analyzed over 31,000 real-world security incidents for its 2026 DBIR. Data window: October 2024–November 2025. Data window: November 2024–October 2025. Source: Verizon 2026 DBIR Executive Summary.

5. More than 22,000 confirmed breaches — Global incident dataset. Over 22,000 incidents in Verizon's 2026 dataset involved confirmed data disclosure. Data window: October 2024–November 2025. Data window: November 2024–October 2025. Source: Verizon 2026 DBIR Executive Summary.

6. 145 countries — Global incident dataset. Organizations in 145 countries were represented in Verizon's 2026 breach corpus. Data window: October 2024–November 2025. Data window: November 2024–October 2025. Source: Verizon 2026 DBIR Executive Summary.

7. 1,008,597 complaints — Reported US cyber-enabled crime. The FBI's Internet Crime Complaint Center received 1,008,597 complaints during 2025. Source: FBI IC3 2025 Annual Report.

8. $20.877 billion in reported losses — Reported US cyber-enabled crime. Losses reported to IC3 reached $20.877 billion in 2025. Source: FBI IC3 2025 Annual Report.

9. 26% annual loss increase — Reported US cyber-enabled crime. IC3-reported losses increased 26% from 2024 to 2025. Source: FBI IC3 2025 Annual Report.

10. $20,699 average reported loss — Reported US cyber-enabled crime. The average loss per IC3 complaint in 2025 was $20,699. Source: FBI IC3 2025 Annual Report.

11. Almost 3,000 complaints per day — Reported US cyber-enabled crime. IC3 said its current intake averages nearly 3,000 complaints each day. Source: FBI IC3 2025 Annual Report.

12. 77% saw more fraud and phishing — Global executive survey. Seventy-seven percent of World Economic Forum respondents reported an increase in cyber-enabled fraud and phishing over 2025. Source: WEF Global Cybersecurity Outlook 2026.

13. 73% were personally exposed — Global executive survey. Seventy-three percent of WEF respondents said they or someone in their network had been affected by cyber-enabled fraud. Source: WEF Global Cybersecurity Outlook 2026.

14. 935 DDoS attacks exceeded 1 Tbps — Observed network telemetry. Cloudflare recorded 935 network-layer DDoS attacks larger than 1 terabit per second during the first half of 2026. Source: Cloudflare DDoS Threat Report: H1 2026.

15. 79% exposure in North America — Global executive survey. Seventy-nine percent of North American WEF respondents reported exposure to digital scams. Source: WEF Global Cybersecurity Outlook 2026.

What this means: Global totals are not interchangeable: a blocked attempt, an incident, a confirmed breach, and an IC3 complaint are different units. Use DeepStrike's dedicated cybercrime statistics guide when you need the loss and complaint methodology in greater depth.

Data Breach Cost and Impact Statistics

16. $4.99 million — Global breach-cost study. IBM calculated a record global average data-breach cost of $4.99 million in its 2026 study. Source: IBM Cost of a Data Breach Report 2026.

17. 12% annual cost increase — Global breach-cost study. IBM's 2026 global average breach cost was 12% higher than the prior year's figure. Source: IBM Cost of a Data Breach Report 2026.

18. One in four malicious breaches — Global breach-cost study. IBM found that one in four malicious breaches in its 2026 research was AI-enabled. Breach window: March 2025–February 2026. Source: IBM 2026 breach study announcement.

19. 56% increase in AI-enabled attacks — Global breach-cost study. AI-enabled malicious breaches increased 56% year over year in IBM's research. Source: IBM 2026 breach study announcement.

20. $6 million — Global breach-cost study. AI-enabled malicious breaches cost an average of $6 million in IBM's 2026 dataset. Source: IBM 2026 breach study announcement.

21. 58% of claims involved BEC or funds transfer fraud — Cyber-insurance claims dataset. Business email compromise and funds transfer fraud together accounted for 58% of claims in Coalition's 2026 report, based on real claims across more than 100,000 global policyholders. Source: Coalition 2026 Cyber Claims Report.

22. $1.93 million saved — Global breach-cost study. Organizations with extensive security AI and automation saved an average of $1.93 million compared with organizations using none. Source: IBM Cost of a Data Breach Report 2026.

23. 62% targeted critical infrastructure — Global breach-cost study. IBM reported that 62% of AI-driven attacks in its study targeted critical-infrastructure sectors. Source: IBM 2026 breach study announcement.

24. $6.3 million in financial services — Global breach-cost study. Financial-services breaches cost an average of $6.3 million in IBM's 2026 research. Source: IBM 2026 breach study announcement.

25. $5.2 million in energy — Global breach-cost study. Energy-sector breaches cost an average of $5.2 million in IBM's 2026 research. Source: IBM 2026 breach study announcement.

26. More than 20% targeted AI systems — Global breach-cost study. More than one-fifth of organizations in IBM's research reported a breach targeting AI models or applications. Source: IBM 2026 breach study announcement.

27. $1.315 billion in personal-data-breach losses — Reported US complaints. IC3 complaints categorized as personal data breaches carried $1,314,923,988 in reported 2025 losses. Source: FBI IC3 2025 Annual Report.

28. $435.2 million in data-breach losses — Reported US complaints. IC3's separate data-breach category recorded $435,240,992 in reported 2025 losses. Source: FBI IC3 2025 Annual Report.

29. $185.8 million in identity-theft losses — Reported US complaints. Identity-theft complaints to IC3 accounted for $185,832,657 in reported 2025 losses. Source: FBI IC3 2025 Annual Report.

30. Approximately 70,000 cyber-insurance claims — Claims dataset. Verizon's 2026 Breach Impact Study analyzed roughly 70,000 cyber-insurance claims. Source: Verizon 2026 DBIR and Breach Impact Study infographic.

31. Around $100,000 in insurable loss — Claims dataset. Verizon's cited insurable-loss figure rose to around $100,000 by 2024, from roughly $60,000 in 2019. Source: Verizon 2026 DBIR and Breach Impact Study infographic.

32. More than 7% of SMB revenue — Claims dataset. In the most severe 2.5% of small and midsize business cases, breach-related financial loss exceeded 7% of annual revenue. Source: Verizon 2026 SMB breach-loss infographic.

33. £560 median when a breach had an outcome — Official UK survey. UK businesses that experienced a breach or attack with an outcome reported a median perceived cost of £560. Source: UK Cyber Security Breaches Survey 2025/2026.

34. £10,000 at the 95th percentile — Official UK survey. For medium and large UK businesses, the perceived cost of the most disruptive breach reached £10,000 at the 95th percentile. Source: UK Cyber Security Breaches Survey 2025/2026.

35. £28,200 at the 95th percentile — Official UK survey. Among medium and large UK businesses reporting a non-zero cost for their most disruptive breach or attack, perceived costs reached £28,200 at the 95th percentile. Base: 164 businesses. Source: UK Cyber Security Breaches Survey 2025/2026.

What this means: A global mean, an insurance claim, an IC3-reported loss, and a survey respondent's perceived cost answer different questions. See DeepStrike's data breach statistics for frequency and vector detail.

For scenario planning and cost-component definitions, use the separate cost of a data breach guide rather than applying $4.99 million as a universal budget assumption.

Ransomware and Extortion Statistics

36. 48% of breaches — Global incident dataset. Ransomware appeared in 48% of all breaches in Verizon's 2026 dataset. Data window: October 2024–November 2025. Data window: November 2024–October 2025. Source: Verizon 2026 DBIR Executive Summary.

37. 69% did not pay — Global incident dataset. Sixty-nine percent of ransomware victims in Verizon's payment dataset did not pay a ransom. Source: Verizon 2026 DBIR Executive Summary.

38. $139,875 median payment — Global incident dataset. The median ransom payment in Verizon's 2026 reporting dataset was $139,875. Source: Verizon 2026 DBIR Executive Summary.

39. 39% reported ransomware incidents — Global breach-cost study. IBM's 2026 study found reported ransomware incidents at 39%, compared with 34% in the prior year. Source: IBM 2026 breach study announcement.

40. 56% encrypted data — Global ransomware survey. Fifty-six percent of ransomware attacks in Sophos's 2026 survey succeeded in encrypting data. Experience window: prior 12 months. Source: Sophos State of Ransomware 2026.

41. Only one in three smaller organizations stopped encryption — Global ransomware survey. Among smaller organizations in Sophos's study, only one-third stopped the attack before data was encrypted. Source: Sophos State of Ransomware 2026.

42. $769,000 median ransom payment — Global ransomware survey. Sophos reported a median ransom payment of $769,000 in its 2026 study. Source: Sophos State of Ransomware 2026.

43. $1.7 million average recovery cost — Global ransomware survey. The average ransomware recovery cost in Sophos's 2026 survey was $1.7 million. Source: Sophos State of Ransomware 2026.

44. 3,611 ransomware complaints — Reported US complaints. IC3 received 3,611 ransomware complaints during 2025. Source: FBI IC3 2025 Annual Report.

45. $32.3 million in reported ransomware losses — Reported US complaints. IC3 ransomware complaints carried $32,320,105 in reported 2025 losses, excluding much of the downstream business impact. Source: FBI IC3 2025 Annual Report.

46. 56.8% of reported incidents — Reported US complaints. The FBI's ten most frequently reported ransomware variants accounted for 56.8% of ransomware incidents reported to IC3 in 2025. Source: FBI IC3 2025 Annual Report.

47. 49.8% of reported ransomware loss — Reported US complaints. Those ten variants accounted for 49.8% of IC3-reported ransomware losses in 2025. Source: FBI IC3 2025 Annual Report.

48. 63 new variants — Reported US complaints. IC3 identified 63 new ransomware variants during 2025. Source: FBI IC3 2025 Annual Report.

49. 3,300 industrial organizations affected — OT ransomware intelligence. Dragos tracked 119 ransomware groups affecting 3,300 industrial organizations in 2025; the number of groups was 49% higher than the 80 tracked in 2024. Source: Dragos 2026 OT Cybersecurity Year in Review.

50. 48% more extorted victims — Observed vendor telemetry. Check Point Research measured a 48% year-over-year increase in publicly extorted ransomware victims during 2025. Source: Check Point Cyber Security Report 2026.

What this means: Payment rates and amounts are only part of ransomware impact; recovery, downtime, data theft, notification, and legal work can dominate the loss. DeepStrike's ransomware statistics page goes deeper into demands, payments, and recovery patterns.

Phishing, BEC, Social Engineering, and Malware Statistics

51. 191,561 phishing and spoofing complaints — Reported US complaints. Phishing and spoofing was the largest IC3 complaint category by count in 2025, with 191,561 reports. Source: FBI IC3 2025 Annual Report.

52. $215.8 million in phishing and spoofing losses — Reported US complaints. IC3 phishing and spoofing complaints carried $215,843,126 in reported 2025 losses. Source: FBI IC3 2025 Annual Report.

53. 24,768 BEC complaints — Reported US complaints. IC3 received 24,768 business email compromise complaints in 2025. Source: FBI IC3 2025 Annual Report.

54. $3.047 billion in BEC losses — Reported US complaints. Business email compromise caused $3,046,598,558 in losses reported to IC3 in 2025. Source: FBI IC3 2025 Annual Report.

55. 32,424 government-impersonation complaints — Reported US complaints. IC3 logged 32,424 government-impersonation complaints in 2025. Source: FBI IC3 2025 Annual Report.

56. $797.9 million in government-impersonation losses — Reported US complaints. Government-impersonation complaints carried $797,943,193 in reported 2025 losses. Source: FBI IC3 2025 Annual Report.

57. 46% of attachment-bearing emails were malicious — Observed vendor telemetry. Check Point found that 46% of emails with attachments received by organizations in its 2025 dataset were malicious. Source: Check Point Cyber Security Report 2026.

58. 82% of malicious-file delivery used email — Observed vendor telemetry. Email accounted for 82% of malicious file delivery measured by Check Point. Source: Check Point Cyber Security Report 2026.

59. 79% growth in infostealer-compromised system logs — Observed threat telemetry. Fortinet measured a 79% year-over-year increase in logs from systems compromised by information-stealing malware during 2025. Source: Fortinet 2026 Global Threat Landscape Report announcement.

60. Approximately 500% growth in ClickFix activity — Observed vendor telemetry. Check Point measured an approximately fivefold increase in ClickFix social-engineering activity. Source: Check Point Cyber Security Report 2026.

61. 16% of breaches involved phishing — Global incident dataset. Phishing remained present in 16% of breaches in Verizon's 2026 dataset. Source: Verizon 2026 DBIR Executive Summary.

62. 6% of breaches involved pretexting — Global incident dataset. Pretexting reached 6% of all breaches in Verizon's 2026 dataset. Source: Verizon 2026 DBIR Executive Summary.

63. 40% higher mobile click success — Phishing simulations. Simulated social attacks delivered through voice or text had a 40% higher median success rate than email-based simulations. Source: Verizon 2026 DBIR Executive Summary.

64. 38% of UK businesses experienced phishing — Official UK survey. Thirty-eight percent of UK businesses reported a phishing breach or attack in the previous 12 months. Source: UK Cyber Security Breaches Survey 2025/2026.

65. 69% called phishing the most disruptive attack — Official UK survey. Among affected UK businesses, 69% identified phishing as their most disruptive breach or attack. Source: UK Cyber Security Breaches Survey 2025/2026.

What this means: Email remains a major delivery channel, but mobile messaging, voice, impersonation, and collaboration tools require verification controls beyond the inbox. Compare the channel-level evidence in DeepStrike's phishing statistics guide.

For payment diversion and executive impersonation specifically, the business email compromise statistics page separates complaint count from reported financial loss.

Identity, Credentials, and Human Risk Statistics

66. 62% of breaches involved the human element — Global incident dataset. Verizon identified a human element in 62% of breaches in its 2026 corpus. Source: Verizon 2026 DBIR Executive Summary.

67. 13% began with credential abuse — Global incident dataset. Credential abuse was the known initial-access vector in 13% of non-error, non-misuse breaches in Verizon's 2026 dataset. Source: Verizon 2026 DBIR Executive Summary.

68. 42% reported rising malicious-insider incidents — Global security-leader survey. Forty-two percent of organizations in Mimecast's 2026 study reported an increase in malicious-insider incidents. Source: Mimecast State of Human Risk 2026.

69. 42% reported rising negligent-insider incidents — Global security-leader survey. The same share, 42%, reported an increase in negligent-insider incidents. Source: Mimecast State of Human Risk 2026.

70. Six insider-driven incidents per month — Global security-leader survey. Organizations in Mimecast's study reported an average of six insider-driven incidents each month. Source: Mimecast State of Human Risk 2026.

71. $13.1 million estimated cost per insider incident — Global security-leader survey. Mimecast reported an estimated $13.1 million cost per insider-driven incident in its survey findings. Source: Mimecast State of Human Risk 2026.

72. 66% expect more insider-related data loss — Global security-leader survey. Two-thirds of Mimecast respondents expected insider-related data loss to increase over the next 12 months. Source: Mimecast State of Human Risk 2026.

73. 91% face communications-data governance challenges — Global security-leader survey. Ninety-one percent of Mimecast respondents reported difficulty maintaining governance and compliance over communications data. Source: Mimecast State of Human Risk 2026.

74. 28% combine training with continuous monitoring — Global security-leader survey. Only 28% of Mimecast respondents paired regular awareness training with continuous policy-violation monitoring. Source: Mimecast State of Human Risk 2026.

75. 65% find security-stack integration complicated — Global security-leader survey. Nearly two-thirds of Mimecast respondents said integration across their security stack was complicated. Source: Mimecast State of Human Risk 2026.

76. 40% faster threat remediation — Global security-leader survey. Mimecast reported that organizations with integrated security tools remediated threats 40% faster. Source: Mimecast State of Human Risk in 2026 analysis.

77. 96% reported incomplete protection — Global security-leader survey. Ninety-six percent of organizations in Mimecast's 2026 research described their protection as incomplete. Source: Mimecast security-effectiveness analysis.

78. 37% rated technology effective — Global security-leader survey. The share rating security technology effective fell to 37% in 2026 from 47% in the comparison period. Source: Mimecast security-effectiveness analysis.

79. 97% of identity attacks used password spray — Observed global identity telemetry. Microsoft reported that password spray accounted for 97% of identity attacks in its 2025 Digital Defense Report. Source: Microsoft Digital Defense Report 2025.

80. 99% of highly resilient organizations involved the board — Global executive survey. WEF found board involvement in cybersecurity at 99% of organizations it classified as highly resilient. Source: WEF Global Cybersecurity Outlook 2026.

What this means: “Human element” does not mean employees cause a universal fixed percentage of attacks; it can include social engineering, errors, credential use, and misuse within a defined dataset. Treat identity controls, behavior signals, and process design as one system—not as an annual training checkbox.

AI, Deepfake, and Security Automation Statistics

81. 94% expect AI to drive cybersecurity change — Global executive survey. Ninety-four percent of WEF respondents expected AI to be the most significant driver of cybersecurity change in the year ahead. Source: WEF Global Cybersecurity Outlook 2026.

82. 87% identified AI vulnerabilities as the fastest-growing risk — Global executive survey. WEF respondents overwhelmingly identified AI-related vulnerabilities as the fastest-growing cyber risk during 2025. Source: WEF Global Cybersecurity Outlook 2026.

83. 34% named GenAI data leaks as a leading concern — Global executive survey. Data leakage associated with generative AI was the top 2026 GenAI concern for 34% of WEF respondents. Source: WEF Global Cybersecurity Outlook 2026.

84. 29% prioritized adversarial AI capability — Global executive survey. Twenty-nine percent of WEF respondents selected advancing adversarial capabilities as a leading GenAI concern for 2026. Source: WEF Global Cybersecurity Outlook 2026.

85. 64% assess the security of AI tools — Global executive survey. The share of organizations with processes to assess AI-tool security reached 64% in WEF's 2026 survey. Source: WEF Global Cybersecurity Outlook 2026.

86. One in five biometric fraud attempts was a deepfake — Identity-verification telemetry. Entrust found that deepfakes accounted for one in five biometric fraud attempts in its 2026 identity-fraud research. Source: Entrust 2026 Identity Fraud Report.

87. 40% conduct periodic AI reviews — Global executive survey. Forty percent of organizations said they periodically reviewed AI tools before deployment. Source: WEF Global Cybersecurity Outlook 2026.

88. 24% rely on a one-time AI assessment — Global executive survey. Twenty-four percent of organizations reported assessing AI tools only once before deployment. Source: WEF Global Cybersecurity Outlook 2026.

89. 54% cite limited AI knowledge and skills — Global executive survey. More than half of WEF respondents identified limited knowledge and skills as a barrier to adopting AI-driven cybersecurity solutions. Source: WEF Global Cybersecurity Outlook 2026.

90. More than 50% use agents for detection and containment — Follow-on breach survey. Over half of organizations in IBM's follow-on research used AI agents for threat detection and containment. Source: IBM 2026 breach study announcement.

91. 18% use agents for vulnerability management — Follow-on breach survey. Only 18% of IBM respondents applied AI agents to vulnerability management. Source: IBM 2026 breach study announcement.

92. 85% plan more security spending after frontier-AI awareness — Follow-on breach survey. IBM found 85% planned to increase security spending after learning about advanced frontier-AI cyber capabilities. Source: IBM 2026 breach study announcement.

93. 58% growth in deepfaked selfie attempts — Identity-verification telemetry. Entrust measured a 58% increase in deepfake selfie attempts during 2025 across a dataset spanning more than one billion verifications. Source: Entrust 2026 Identity Fraud Report.

94. 90% encountered risky AI prompts — Observed enterprise-AI data. Check Point reported that 90% of organizations encountered risky prompts during a three-month observation period. Source: Check Point Cyber Security Report 2026.

95. One in 48 enterprise AI prompts was high risk — Observed enterprise-AI data. Check Point classified one in every 48 prompts submitted to enterprise AI tools as high risk. Source: Check Point Cyber Security Report 2026.

What this means: AI is simultaneously an attack accelerator, a new governed asset, and a defensive tool. The key comparison is not “AI versus no AI,” but whether identity, data, model, API, and monitoring controls scale with adoption. See DeepStrike's AI in cybersecurity statistics for the broader attack-and-defense evidence.

Vulnerability, Cloud, API, and Application Security Statistics

96. 31% of breaches began with vulnerability exploitation — Global incident dataset. Vulnerability exploitation became Verizon's leading known initial-access vector in the 2026 DBIR. Source: Verizon 2026 DBIR Executive Summary.

97. 25.49% growth in exploitation attempts — Observed threat telemetry. Fortinet measured a 25.49% year-over-year increase in global exploitation attempts during 2025. Source: Fortinet 2026 Global Threat Landscape Report announcement.

98. 26% of critical KEV findings were fully remediated — Global remediation dataset. Organizations fully remediated only 26% of critical vulnerabilities tied to CISA KEV entries in Verizon's 2025 measurement. Source: Verizon 2026 DBIR Executive Summary.

99. Only 8% encrypted at least 80% of cloud data — Global cloud-security survey. Thales found that just 8% of organizations encrypted 80% or more of their cloud data in its 2025 study. Source: Thales Cloud Security Research.

100. 43 days to full resolution — Global remediation dataset. The median time to fully resolve a critical vulnerability rose to 43 days in Verizon's 2026 reporting. Source: Verizon 2026 DBIR Executive Summary.

101. 50% more critical vulnerabilities to patch — Global remediation dataset. The median organization had 50% more critical vulnerabilities to patch than in Verizon's prior-year dataset. Source: Verizon 2026 DBIR Executive Summary.

102. 27% involved compromised APIs, apps, or plug-ins — Global breach-cost study. Among breaches targeting AI models or applications, IBM tied 27% to weaknesses in surrounding APIs, applications, or plug-ins. Source: IBM 2026 breach study announcement.

103. 27% involved cloud misconfiguration — Global breach-cost study. Cloud misconfigurations affecting AI workloads accounted for another 27% of the AI-targeting breaches IBM examined. Source: IBM 2026 breach study announcement.

104. 37% encrypted sensitive data at rest and in transit — Global breach-cost study. Only 37% of breached organizations said they encrypted sensitive data in both states. Source: IBM 2026 breach study announcement.

105. 34% had visibility into cryptographic assets — Global breach-cost study. Just 34% of breached organizations reported visibility into their cryptographic assets. Source: IBM 2026 breach study announcement.

106. 87% experienced an API-related incident — Global API-security survey. Eighty-seven percent of Akamai respondents reported at least one API-related security incident in the previous 12 months. Source: Akamai API Security Impact Study 2026.

107. 23% knew which APIs returned sensitive data — Global API-security survey. Only 23% of organizations in Akamai's research knew which APIs returned sensitive data. Source: Akamai API Security Impact Study 2026.

108. $700,000 average annual API-incident cost — Global API-security survey. API-related incidents cost respondent organizations an average of $700,000 annually. Source: Akamai API Security Impact Study 2026.

109. 16% fully integrated API-security testing — Global API-security survey. Only 16% of enterprises fully integrated API-security testing into development pipelines. Source: Akamai API Security Impact Study 2026.

110. More than 5,900 APIs at the median enterprise — Global API-security survey. Akamai reported a global median inventory above 5,900 APIs per enterprise. Source: Akamai API Security Impact Study 2026.

111. More than 29,400 APIs in the top quartile — Global API-security survey. The top quartile of enterprises in Akamai's study managed over 29,400 APIs. Source: Akamai API Security Impact Study 2026.

112. 3,000 sensitive-data APIs per customer — Observed platform telemetry. Akamai found an average of 3,000 APIs containing sensitive data per customer in its security telemetry. Source: Akamai Apps, APIs, and DDoS 2026.

113. 12% of those APIs showed weaknesses — Observed platform telemetry. Twelve percent of the sensitive-data APIs Akamai observed had security weaknesses. Source: Akamai Apps, APIs, and DDoS 2026.

114. 24% of API issues involved sensitive-data exposure — Observed platform telemetry. Nearly one-quarter of the API weaknesses Akamai observed related to sensitive-data exposure. Source: Akamai Apps, APIs, and DDoS 2026.

115. 113% year-over-year growth in daily API attacks — Observed platform telemetry. Akamai measured a 113% annual increase in the average number of daily API attacks. Source: Akamai Apps, APIs, and DDoS 2026.

What this means: Patch queues should be prioritized by exploit evidence, exposure, asset value, and compensating controls—not CVSS alone. DeepStrike's vulnerability statistics page provides more context on disclosure and exploitation.

Cloud governance is part of the same attack surface; use the dedicated cloud security statistics guide for identity, configuration, and hybrid-environment evidence.

API inventories are too large for annual spot checks. The API security statistics page goes deeper into authorization, discovery, testing, and runtime risks.

Third-Party and Software Supply Chain Statistics

116. 48% of breaches involved a third party — Global incident dataset. Third-party involvement appeared in 48% of all breaches in Verizon's 2026 corpus. Source: Verizon 2026 DBIR Executive Summary.

117. 60% year-over-year growth in third-party involvement — Global incident dataset. Verizon measured a 60% annual increase in breaches involving third parties. Source: Verizon 2026 DBIR Executive Summary.

118. 23% fully remediated third-party cloud MFA findings — Global remediation dataset. Only 23% of third-party organizations fully fixed missing or improperly secured MFA on cloud accounts. Source: Verizon 2026 DBIR Executive Summary.

119. One month to resolve half of third-party MFA findings — Global remediation dataset. Verizon found that 50% of third-party cloud MFA findings were resolved within one month. Source: Verizon 2026 DBIR Executive Summary.

120. Nearly eight months to resolve half of password and permission findings — Global remediation dataset. Half of third-party weak-password and permission-misconfiguration findings took almost eight months to resolve. Source: Verizon 2026 DBIR Executive Summary.

121. 65% of large companies named supply-chain risk their greatest challenge — Global executive survey. WEF found third-party and supply-chain vulnerabilities were the top resilience challenge for 65% of large-company respondents. Source: WEF Global Cybersecurity Outlook 2026.

122. 75% growth in open-source malware — Supply-chain telemetry. Sonatype reported a 75% year-over-year increase in newly identified malicious open-source packages during 2025. Source: Sonatype 2026 State of the Software Supply Chain announcement.

123. More than 454,600 new malicious packages — Supply-chain telemetry. Sonatype identified over 454,600 new malicious open-source packages during 2025. Source: Sonatype 2026 Software Supply Chain Report.

124. More than 1.233 million malicious packages cumulatively — Supply-chain telemetry. Sonatype's known and blocked open-source malware corpus exceeded 1.233 million packages. Source: Sonatype 2026 Software Supply Chain Report.

125. 9.8 trillion open-source downloads — Registry telemetry. Downloads across Maven Central, PyPI, npm, and NuGet reached 9.8 trillion in 2025. Source: Sonatype 2026 State of the Software Supply Chain announcement.

What this means: Third-party risk is both a vendor-access problem and a software-provenance problem. Segment access, inventory dependencies, verify update paths, and test shared incident procedures. DeepStrike's supply chain attack statistics page provides the deeper threat and control context.

Industry-Specific Cybersecurity Statistics

Industry Snapshot

IndustryConfirmed breachesMain risk signalQualifier
Education1,25268% involved the human elementBreach composition within Verizon's Educational Services subset
Finance and insurance1,30098% were financially motivatedPercentage applies where motive was known
Healthcare1,43854% involved the human elementBreach composition within Verizon's Healthcare subset
Manufacturing2,71361% involved a third partyBreach composition within Verizon's Manufacturing subset
Public administration2,41044% involved internal actorsPercentage applies where actor type was known
Retail80668% involved a third partyBreach composition within Verizon's Retail subset
Small and midsize businesses7,15231% involved compromised credentialsSMB subset, not a single industry
UtilitiesNot stated in the cited summary71% involved espionagePercentage applies where motive was known

These figures describe the composition of Verizon's contributed dataset. They are not sector breach rates, population-adjusted rankings, or proof that one industry is less secure than another.

126. 1,252 confirmed education breaches — Global incident dataset. Verizon recorded 1,252 confirmed data breaches in Educational Services. Source: Verizon 2026 DBIR Executive Summary.

127. 68% human element in education — Global incident dataset. A human element was present in 68% of Educational Services breaches in Verizon's dataset. Source: Verizon 2026 DBIR Executive Summary.

128. 1,300 confirmed financial and insurance breaches — Global incident dataset. Verizon analyzed 1,300 confirmed breaches in Financial and Insurance organizations. Source: Verizon 2026 DBIR Executive Summary.

129. 98% financially motivated in finance — Global incident dataset. Financial motives were present in 98% of Financial and Insurance breaches with known motive. Source: Verizon 2026 DBIR Executive Summary.

130. 1,438 confirmed healthcare breaches — Global incident dataset. Verizon analyzed 1,438 confirmed Healthcare breaches. Source: Verizon 2026 DBIR Executive Summary.

131. 54% human element in healthcare — Global incident dataset. A human element appeared in 54% of Healthcare breaches in Verizon's dataset. Source: Verizon 2026 DBIR Executive Summary.

132. 2,713 confirmed manufacturing breaches — Global incident dataset. Verizon analyzed 2,713 confirmed Manufacturing breaches. Source: Verizon 2026 DBIR Executive Summary.

133. 61% third-party involvement in manufacturing — Global incident dataset. Third parties were involved in 61% of Manufacturing breaches in Verizon's corpus. Source: Verizon 2026 DBIR Executive Summary.

134. 2,410 confirmed public-administration breaches — Global incident dataset. Verizon analyzed 2,410 confirmed Public Administration breaches. Source: Verizon 2026 DBIR Executive Summary.

135. 44% internal actors in public administration — Global incident dataset. Internal actors were involved in 44% of Public Administration breaches with known actor type. Source: Verizon 2026 DBIR Executive Summary.

136. 806 confirmed retail breaches — Global incident dataset. Verizon analyzed 806 confirmed Retail breaches. Source: Verizon 2026 DBIR Executive Summary.

137. 68% third-party involvement in retail — Global incident dataset. Third parties were involved in 68% of Retail breaches in Verizon's corpus. Source: Verizon 2026 DBIR Executive Summary.

138. 7,152 confirmed SMB breaches — Global incident dataset. Verizon's small- and medium-sized business subset contained 7,152 confirmed breaches. Source: Verizon 2026 DBIR Executive Summary.

139. 31% credential data in SMB breaches — Global incident dataset. Credentials were compromised in 31% of SMB breaches in Verizon's dataset. Source: Verizon 2026 DBIR Executive Summary.

140. 71% espionage motive in utilities — Global incident dataset. Espionage appeared in 71% of Utilities breaches with known motive in Verizon's industry snapshot. Source: Verizon 2026 DBIR Executive Summary.

What this means: Sector figures are best used against the matching industry baseline, not as a league table of who is “least secure.” Start with DeepStrike's healthcare cybersecurity statistics for healthcare-specific risk.

Financial institutions can compare the broader DBIR view with DeepStrike's financial services cybersecurity statistics guide.

Cybersecurity Market and Spending Statistics

141. $239.759 billion in 2026 — Market forecast. Gartner forecast worldwide end-user information-security spending of $239.759 billion for 2026. Source: Gartner Information Security Spending Forecast.

142. 12.5% annual spending growth — Market forecast. Gartner projected worldwide information-security spending to increase 12.5% in 2026. Source: Gartner Information Security Spending Forecast.

143. $121.154 billion for security software — Market forecast. Gartner's 2026 forecast allocated $121.154 billion to security software. Source: Gartner Information Security Spending Forecast.

144. $92.780 billion for security services — Market forecast. Gartner's 2026 forecast allocated $92.780 billion to security services. Source: Gartner Information Security Spending Forecast.

145. $25.825 billion for network security — Market forecast. Gartner's 2026 forecast allocated $25.825 billion to network-security spending. Source: Gartner Information Security Spending Forecast.

What this means: Market growth does not prove that an individual program is effective. Tie spending to risk ownership, control coverage, validation findings, recovery objectives, and measurable reduction in exposure.

Cybersecurity Workforce and Compliance Statistics

146. 29% employment growth — US government projection. US employment for information-security analysts is projected to grow 29% from 2024 to 2034. Source: US Bureau of Labor Statistics.

147. 16,000 openings per year — US government projection. BLS projects about 16,000 information-security analyst openings annually over the 2024–2034 decade. Source: US Bureau of Labor Statistics.

148. $124,910 median annual pay — US government wage data. The US median annual wage for information-security analysts was $124,910 in May 2024. Source: US Bureau of Labor Statistics.

149. 36% reported cybersecurity budget cuts — Global workforce survey. Thirty-six percent of ISC2 respondents said their organizations experienced cybersecurity budget cuts in 2025. Source: ISC2 2025 Cybersecurity Workforce Study.

150. 59% lacked confidence in rapid compliance discovery — Global security-leader survey. Fifty-nine percent of Mimecast respondents lacked confidence that they could quickly locate communications data for legal or regulatory requirements. Source: Mimecast State of Human Risk 2026.

What this means: Hiring demand can grow while individual teams still face budget pressure and evidence-retrieval gaps. DeepStrike's cybersecurity skills gap analysis covers the staffing problem in more depth.

For governance and audit-readiness benchmarks, use the dedicated cybersecurity compliance statistics guide.

From Statistics to Security Validation

From Statistics to Security Validation
Risk signalQuestion to askWhat to validatePrimary owner
Vulnerability exploitationCan an internet-facing weakness reach a critical asset before remediation?External attack surface, exploitability, segmentation, compensating controls, and detectionVulnerability management and application owners
Identity and human riskCan one phished, sprayed, or misused identity produce excessive access?Phishing-resistant MFA, conditional access, privilege boundaries, session controls, and alertingIdentity and security operations
Ransomware and extortionCan an attacker move, steal data, and disrupt recovery?Lateral-movement paths, egress detection, backup isolation, restoration, and crisis proceduresSecurity operations, infrastructure, and resilience
API and cloud exposureWhich unknown or weakly authorized services expose sensitive data?API inventory, object authorization, secrets, cloud configuration, logging, and rate controlsApplication, cloud, and platform engineering
Third-party and supply-chain riskWhat trust path could a supplier, package, or update mechanism create?Vendor access, dependency provenance, build integrity, update channels, and joint responseProcurement, engineering, and third-party risk
DDoS and operational disruptionDo capacity and response controls work under a realistic traffic surge?Upstream mitigation, origin protection, failover, alert thresholds, and runbooksNetwork, infrastructure, and incident response

Statistics can prioritize testing, but they cannot prove that a control works in DeepStrike's or any reader's environment. Convert the most relevant signal into an asset-specific attack path, named control owner, observable success criteria, and safe validation plan.

Frequently Asked Questions

Are all cybersecurity statistics in this 2026 guide from calendar year 2026?

No. The guide uses the newest defensible evidence available through August 17, 2026. Some reports published in 2026 analyze incidents or responses from 2025, and each statistic states its source type or period where that distinction matters.

How many cyberattacks happen each day?

There is no reliable universal attacks-per-day total. Vendors can count events visible in their own telemetry, and the FBI can count submitted complaints, but neither represents every attack worldwide. Use source-specific rates only within the scope the source defines.

What percentage of cyberattacks are caused by human error?

There is no universal percentage. Verizon's “human element” measure includes more than accidental error; it can include social engineering, credential use, and misuse. A statistic about human involvement should not be rewritten as “human error causes that share of all attacks.”

What is the number-one cybersecurity threat in 2026?

It depends on the question and dataset. Vulnerability exploitation was Verizon's leading known initial-access vector, ransomware remained a leading operational concern, and fraud and phishing ranked highly in executive surveys. A single universal “number one” claim would erase those different units and contexts.

What is the average cost of a data breach in 2026?

IBM's 2026 global study reported a $4.99 million mean, but that is not a price tag for every organization. Geography, industry, data type, attack path, business interruption, response maturity, and study methodology can move an individual loss far above or below the global mean.

How should a security team use these statistics?

Use them to form hypotheses and benchmark priorities, then validate your own environment. Map each relevant statistic to an asset, threat scenario, control owner, detection signal, recovery objective, and test plan. Statistics can inform prioritization; they cannot prove that a specific control works.

Key Takeaways

The strongest 2026 signal is convergence. Vulnerability exploitation, identity abuse, social engineering, AI-enabled workflows, API sprawl, ransomware, and third-party dependency increasingly combine within the same attack paths. Security leaders should therefore avoid buying controls from isolated headline numbers. Start with the source scope, identify the business asset and likely path, then validate whether prevention, detection, containment, and recovery work together.

Early-stage companies can translate the same evidence into a narrower risk model with DeepStrike's cybersecurity statistics for startups.

If your risk review identifies important exposure that has not been independently tested, DeepStrike can help scope a defensive penetration test around the assets and attack paths that matter most to your business.

About The Author

Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us