October 10, 2025
Updated: September 2, 2026
An in-depth look at what actually leads to data breaches in 2026, ranked by current Verizon DBIR and IBM data, and how to stop each one at the source.
Khaled Hassan

Organizations of every size face rising breach risk. The IBM Cost of a Data Breach Report 2026 puts the global average breach at a record $4.99 million, up 12% year over year, with the US average at $11.5 million. On the cause side, the Verizon 2026 DBIR found the human element present in 62% of breaches, while exploitation of unpatched vulnerabilities became the single most common way in. DeepStrike is one of the top penetration testing companies helping organizations close exactly these gaps.
If you’re asking “what causes data breaches?” or “how do breaches happen?”, this article gives you a complete, expert-backed breakdown. You’ll learn:
This article is optimized for the keyword “common causes of data breaches” and covers long-tail queries like “how insider threats cause data breaches,” “third-party vendor breach causes,” “vulnerability exploits breach examples,” and “human error in data breaches.”
Updated: September 2026. Figures reflect the Verizon 2026 DBIR (22,000+ confirmed breaches across 145 countries) and the IBM Cost of a Data Breach Report 2026.
The single most common cause shifted in 2026: for the first time in the DBIR's 19-year history, exploitation of unpatched vulnerabilities overtook stolen credentials as the top way attackers get in. Here is the full ranking with the current data behind each.
| # | Cause | Share (2026) | Source |
|---|---|---|---|
| 1 | Exploitation of unpatched vulnerabilities | 31% of breaches (top initial access, up from 20%) | Verizon DBIR 2026 |
| 2 | Stolen / compromised credentials | 13% as first step, 39% across all breach stages | Verizon DBIR 2026 |
| 3 | Phishing & social engineering | Human element in 62% of breaches; phishing IBM's top vector 4 years running | DBIR / IBM 2026 |
| 4 | Third-party & supply-chain compromise | 48% of breaches, up 60% year over year | Verizon DBIR 2026 |
| 5 | Ransomware & malware | 48% of breaches involve ransomware | Verizon DBIR 2026 |
| 6 | Human error & misconfiguration | A top-three breach pattern; roughly 23% of breaches | IBM / DBIR 2026 |
| 7 | Insider threats | Internal actors in about 22% of breaches | Verizon DBIR 2026 |
Why are there two "top" causes? These vectors overlap, and the two authoritative reports measure differently. Verizon's DBIR is forensic, tracing the first confirmed way in, and now ranks vulnerability exploitation first. IBM surveys breached organizations and ranks phishing first, for the fourth year running. Both are right; they answer slightly different questions. The takeaway is that no single cause dominates, so defending against only one leaves the door open.
The reason exploitation keeps working is a remediation gap. Only 26% of the vulnerabilities in CISA's Known Exploited Vulnerabilities (KEV) catalog were fully remediated in 2025, down from 38% the year before, and the median time to fully resolve one rose from 32 to 43 days. New CVEs are now weaponized within hours of disclosure, so a six-week patch window is an open invitation. Edge devices, VPNs, and file-transfer appliances are repeat offenders, which is why a fast patch management cadence paired with continuous attack surface management is the highest-leverage control against the number-one cause.
A data breach is not just a technical incident, it is a financial and reputational event that ripples across every layer of a business. The IBM Cost of a Data Breach Report 2026 puts the global average at a record $4.99 million, up 12% year over year, with the US average at $11.5 million, more than twice the global figure.
The total cost of a breach extends far beyond immediate containment:
| Industry | Average Cost (2025) | Common Breach Vectors |
|---|---|---|
| Healthcare | $10.93 M | Phishing, misconfigurations, insider misuse |
| Financial Services | $6.04 M | Credential theft, third-party risk |
| Technology | $5.22 M | Cloud misconfiguration, zero-day exploits |
| Energy | $4.45 M | Ransomware, OT/ICS attacks |
| Retail | $3.28 M | POS malware, credential reuse |
Financial recovery is measurable, but the loss of trust can be devastating:
The SolarWinds and MOVEit supply chain breaches remain case studies in both cost and trust erosion. Beyond remediation expenses, they caused long-term brand association with “insecurity,” deterring future clients and triggering years of compliance audits.
The takeaway is simple: the true cost of a breach is not just measured in dollars, but in lost reputation, customer confidence, and future opportunity.
Every region enforces strict data protection laws, and failing to comply after a breach can be as damaging as the breach itself. Regulators have escalated enforcement in recent years, producing record penalties and closer cross-border collaboration among data protection authorities.
After a breach, companies must:
Failure to meet these obligations often results in compounding fines and increased oversight.
Being compliant doesn’t just reduce fines, it enforces best practices:
Regulators have grown less forgiving, and accountability does not transfer with the work: where a breach originates at a third party, the data controller is generally still answerable to the regulator. With third-party involvement now in 48% of breaches, that makes vendor oversight a compliance obligation, not just a security one.
Broader cybersecurity statistics show that the most common causes of data breaches stem from human error, compromised credentials, system vulnerabilities, insider threats, third-party weaknesses, and ransomware/malware attacks. Together these form the bulk of breaches organizations suffer.
2026 update: the human element is present in 62% of breaches, and phishing is IBM's top attack vector for the fourth consecutive year. The channel is shifting, though. Email phishing is better filtered than ever, so attackers have moved to voice and SMS: IBM found vishing and smishing in 17% of the attacks it studied, and those produced the costliest breaches at an average of $5.29 million. Pretexting is now a common on-ramp to ransomware, and generative AI makes the lures cheaper and more convincing. Deeper numbers live in our phishing statistics. The control that matters: phishing-resistant MFA, strong filtering, out-of-band verification for help-desk resets and payment changes, and training that covers voice and SMS, not just email.
The Verizon 2026 DBIR found the human element present in 62% of breaches, covering phishing clicks, social engineering, errors, and misuse. People are involved in most breaches, even where the technical entry point is something else.
Credential abuse fell to 13% as a first step in the 2026 DBIR, partly because pretexting is now tracked separately, but it still appears somewhere in 39% of breaches, making it the most persistent thread across the whole attack chain.
2.Misdelivery, misconfiguration, or mis-sharing
Case example: In May 2025, a phishing campaign led to unauthorized access to emails at Mailchimp and other SaaS platforms.
Once attackers hold valid credentials they bypass many defenses, which is why credential abuse still appears somewhere in 39% of breaches even though it fell to 13% as a first step in the 2026 DBIR. Infostealer malware keeps the supply endless, harvesting session tokens and passwords at scale, and mega-compilations like the 16-billion-credential leak feed credential stuffing, a threat quantified in our compromised credential statistics.
2026 update: this is the headline change of the year. Attackers increasingly skip tricking a person and simply exploit a known, unpatched flaw in internet-facing software. Exploitation is now the most common initial access vector at 31% of breaches, up from 20% the year before, a 55% year-over-year rise, and the first time in the DBIR's history that it has beaten stolen credentials. Prioritize by exploitability rather than raw CVSS: patch anything in the CISA KEV catalog first, and validate the fixes with real vulnerability management rather than assuming a patch landed.
Security flaws in software or infrastructure give attackers direct routes in. In the 2026 DBIR, 31% of breaches involved exploitation of vulnerabilities, up from 20% the year before, a 55% year-over-year rise that made it the single most common initial access vector for the first time in the report's history.
Third-party involvement in breaches rose 60% year over year to 48% in the 2026 DBIR, after already doubling the year before. Nearly half of all breaches now run through a vendor, supplier, or service provider.
2026 update: internal actors are involved in about 22% of breaches, split between the malicious (an employee stealing data) and the accidental. Malicious insider attacks are among the costliest vectors because the person already has trusted access and knows where the valuable data lives, which is why they take so long to detect. IBM separately attributes roughly 23% of breaches to human error, with cloud misconfiguration now a prime cause as estates sprawl across multiple providers.
2026 update: your risk is now your vendors' risk. Breaches with third-party involvement jumped 60% in the latest DBIR to reach 48% of all breaches, after already doubling the year before. The root causes are mundane: absent MFA, un-rotated credentials, and excessive privileges in a vendor's cloud. IBM found supply-chain compromise both the second most common vector and the costliest single factor, adding an average of $227,250 per breach and taking the longest to detect and contain. Treat vendor risk as a programme rather than a questionnaire, as covered in our third-party risk management guide.
Organizations rely heavily on vendors, partners, and SaaS providers. A weakness in their security becomes your liability.
DeepStrike cites that third-party / vendor compromise is the second most prevalent attack vector and also among the most costly, averaging $4.91 million in losses.Verizon DBIR flags supply chain risk as an escalating area.
2026 update: ransomware appeared in 48% of breaches, up from 44%, and remains the most financially destructive outcome even as the economics shift for attackers. Notably, 69% of victims did not pay, and the median ransom fell below $140,000, a sign that backups, response readiness, and law-enforcement pressure are working. Ransomware rarely stands alone; it is the payload delivered after an unpatched exploit, a stolen credential, or a phishing click opens the door. Our ransomware statistics track the active groups, and a rehearsed incident response plan is what stops a foothold becoming a full compromise.
Malicious software (ransomware, trojans, RATs) helps attackers encrypt or exfiltrate data. Infrascale stats show malware accounts for 31.2 % of data loss incidents.
IBM found shadow AI incidents affected 43% of breached organizations in 2026, up from 20% a year earlier, and those organizations saw higher breach costs, greater operational disruption, and more data loss.
Cloud sprawl compounds the problem: a large majority of breached data now sits in cloud environments, and a significant share of incidents span more than one environment, which slows both detection and containment.
On average, organizations took 247 days to identify and contain a breach in 2026, 183 days to detect and a further 64 to contain. That figure rose this year, reversing five consecutive years of improvement, and breaches running longer than 200 days cost materially more than those closed faster.
By surfacing these underdiscussed risk vectors, your content outperforms shallow lists in other posts
You do not need a separate programme for each cause; a handful of fundamentals blunts most of them.
| Cause | Highest-leverage control |
|---|---|
| Vulnerability exploitation | Fast, KEV-prioritized patching plus attack surface management |
| Stolen credentials | Phishing-resistant MFA plus credential monitoring |
| Phishing / social engineering | MFA, filtering, out-of-band verification, and training that covers vishing and smishing |
| Third-party / supply chain | Vendor MFA, least privilege, tight access scoping |
| Ransomware / malware | Offline backups, segmentation, EDR, tested IR plan |
| Human error / misconfiguration | Infrastructure-as-code guardrails, automated posture checks |
| Insider threats | Least privilege, access monitoring, strong offboarding |
The through-line: most breaches still exploit known, preventable weaknesses, not exotic zero-days. Patch fast, authenticate strongly, scope access tightly, and validate that it all actually works with a penetration test. Broader guidance lives in our data breach prevention guide, the wider trend lines in our data breach statistics, and the full cost picture in our cost of a data breach guide.
Here’s a layered framework combining people, processes, and technology:
| Layer | Key Action | Tools / Best Practices |
|---|---|---|
| People & Culture | Security training, phishing drills | Monthly simulations + intentional retests |
| Identity & Access | MFA, least privilege, credential hygiene | Privileged Access Management (PAM) tools |
| Systems & Networks | Patch management, segmentation | Vulnerability scanning, micro-segmentation |
| Endpoint & Malware | EDR, signatureless detection | Next-gen antivirus, anomaly detection |
| Data Protection | Encryption, DLP, backups | At-rest & in-transit encryption, immutable storage |
| Third-party Risk | Vendor assessments, limited access | Security audits, contractual clauses |
Bonus tactics:
A compromised vendor contact center system exposed ~6M customer records. It illustrates how third-party access can cascade into major customer data exposure
Attackers compromised a supply chain (Salesforce vendor integration), exposing sensitive personal data of millions
These examples reinforce how multi-vector attacks combine phishing, vendor risk, and system exploits.
Verizon 2026 Data Breach Investigations Report, covering more than 22,000 confirmed breaches across 145 countries.
IBM Cost of a Data Breach Report 2026, for breach cost, detection time, and the AI-attack cost premium.
Cisco Cybersecurity Readiness Index 2025, on AI incident prevalence and organizational readiness.
Trend Micro State of AI Security Report, 1H 2025, on exposed vector-database servers and AI components.
Understanding the common causes of data breaches is your first line of defense. In 2026 most breaches still trace back to a short list: unpatched vulnerabilities, compromised credentials, phishing and social engineering, third-party weaknesses, ransomware, human error, and insiders. What is striking is how ordinary they are, which is also why they are addressable.
By implementing layered defenses identity security, endpoint protection, vendor vetting, and security-aware culture you can dramatically reduce your breach risk. The sooner you act, the higher the odds your organization avoids the headline.
It depends on how you measure. Verizon's 2026 DBIR, which traces the forensic entry point, ranks exploitation of unpatched vulnerabilities first at 31% of breaches, having overtaken stolen credentials for the first time in 19 years. IBM's survey of breached organizations ranks phishing first for the fourth year running. Both are authoritative; they simply measure the first way in differently.
The human element (phishing clicks, social engineering, mistakes, and misuse) is present in about 62% of breaches, so people are involved in most of them. But human error specifically, such as misconfigurations and misdelivery, accounts for roughly 23%. The single largest technical entry point in 2026 is the exploitation of unpatched vulnerabilities.
Exploitation of vulnerabilities, at 31% of breaches, is the most common initial access vector in the 2026 DBIR, overtaking credential abuse (13% as a first step, 39% across all stages). Ransomware appeared in 48% of breaches, and third-party involvement rose 60% to reach 48% of breaches.
The IBM Cost of a Data Breach Report 2026 puts the global average at a record $4.99 million, up 12% year over year. In the United States the average is far higher at $11.5 million, driven by regulatory penalties and detection costs. Detection, escalation, and lost business make up most of that total, and the mean time to identify and contain a breach rose to 247 days.
Organizations rely on more vendors, SaaS platforms, and software suppliers than ever, and each connection expands the attack surface. Breaches with third-party involvement rose 60% in the latest DBIR to 48% of the total. The usual root causes are mundane: missing MFA, un-rotated credentials, and excessive privileges inside a vendor's cloud environment.
Focus on fundamentals that cut across causes: patch known-exploited vulnerabilities fast, enforce phishing-resistant MFA everywhere, tightly scope third-party and internal access, keep tested offline backups, and monitor for exposed credentials. Then validate that these controls actually work with a penetration test, since most breaches exploit known, preventable weaknesses rather than novel zero-days.
Phishing-resistant MFA is one of the highest-leverage single controls, because it cuts across two of the top causes at once: it neutralizes stolen credentials, which still appear in 39% of breaches, and it blunts the phishing and social engineering that reach 62% of them. It is not absolute, since attackers now target help desks, MFA-reset workflows, and session tokens rather than passwords, which is why it works best alongside out-of-band verification for sensitive requests and shorter session lifetimes.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us