logo svg
logo

October 10, 2025

Updated: September 2, 2026

The Most Common Causes of Data Breaches in 2026

An in-depth look at what actually leads to data breaches in 2026, ranked by current Verizon DBIR and IBM data, and how to stop each one at the source.

Khaled Hassan

Khaled Hassan

Featured Image

Organizations of every size face rising breach risk. The IBM Cost of a Data Breach Report 2026 puts the global average breach at a record $4.99 million, up 12% year over year, with the US average at $11.5 million. On the cause side, the Verizon 2026 DBIR found the human element present in 62% of breaches, while exploitation of unpatched vulnerabilities became the single most common way in. DeepStrike is one of the top penetration testing companies helping organizations close exactly these gaps.

If you’re asking “what causes data breaches?” or “how do breaches happen?”, this article gives you a complete, expert-backed breakdown. You’ll learn:

This article is optimized for the keyword “common causes of data breaches” and covers long-tail queries like “how insider threats cause data breaches,” “third-party vendor breach causes,” “vulnerability exploits breach examples,” and “human error in data breaches.”

Updated: September 2026. Figures reflect the Verizon 2026 DBIR (22,000+ confirmed breaches across 145 countries) and the IBM Cost of a Data Breach Report 2026.

The Short Answer: Causes Ranked

The single most common cause shifted in 2026: for the first time in the DBIR's 19-year history, exploitation of unpatched vulnerabilities overtook stolen credentials as the top way attackers get in. Here is the full ranking with the current data behind each.

#CauseShare (2026)Source
1Exploitation of unpatched vulnerabilities31% of breaches (top initial access, up from 20%)Verizon DBIR 2026
2Stolen / compromised credentials13% as first step, 39% across all breach stagesVerizon DBIR 2026
3Phishing & social engineeringHuman element in 62% of breaches; phishing IBM's top vector 4 years runningDBIR / IBM 2026
4Third-party & supply-chain compromise48% of breaches, up 60% year over yearVerizon DBIR 2026
5Ransomware & malware48% of breaches involve ransomwareVerizon DBIR 2026
6Human error & misconfigurationA top-three breach pattern; roughly 23% of breachesIBM / DBIR 2026
7Insider threatsInternal actors in about 22% of breachesVerizon DBIR 2026

Why are there two "top" causes? These vectors overlap, and the two authoritative reports measure differently. Verizon's DBIR is forensic, tracing the first confirmed way in, and now ranks vulnerability exploitation first. IBM surveys breached organizations and ranks phishing first, for the fourth year running. Both are right; they answer slightly different questions. The takeaway is that no single cause dominates, so defending against only one leaves the door open.

The reason exploitation keeps working is a remediation gap. Only 26% of the vulnerabilities in CISA's Known Exploited Vulnerabilities (KEV) catalog were fully remediated in 2025, down from 38% the year before, and the median time to fully resolve one rose from 32 to 43 days. New CVEs are now weaponized within hours of disclosure, so a six-week patch window is an open invitation. Edge devices, VPNs, and file-transfer appliances are repeat offenders, which is why a fast patch management cadence paired with continuous attack surface management is the highest-leverage control against the number-one cause.

Economic and Reputational Impact of Data Breaches

A data breach is not just a technical incident, it is a financial and reputational event that ripples across every layer of a business. The IBM Cost of a Data Breach Report 2026 puts the global average at a record $4.99 million, up 12% year over year, with the US average at $11.5 million, more than twice the global figure.

Direct and Indirect Financial Costs

The total cost of a breach extends far beyond immediate containment:

Industry Breakdown of Breach Costs

IndustryAverage Cost (2025)Common Breach Vectors
Healthcare$10.93 MPhishing, misconfigurations, insider misuse
Financial Services$6.04 MCredential theft, third-party risk
Technology$5.22 MCloud misconfiguration, zero-day exploits
Energy$4.45 MRansomware, OT/ICS attacks
Retail$3.28 MPOS malware, credential reuse

Reputational and Brand Damage

Financial recovery is measurable, but the loss of trust can be devastating:

Example: SolarWinds and MOVEit Fallout

The SolarWinds and MOVEit supply chain breaches remain case studies in both cost and trust erosion. Beyond remediation expenses, they caused long-term brand association with “insecurity,” deterring future clients and triggering years of compliance audits.

The takeaway is simple: the true cost of a breach is not just measured in dollars, but in lost reputation, customer confidence, and future opportunity.

Legal and Regulatory Consequences of Data Breaches

Every region enforces strict data protection laws, and failing to comply after a breach can be as damaging as the breach itself. Regulators have escalated enforcement in recent years, producing record penalties and closer cross-border collaboration among data protection authorities.

Global Regulatory Frameworks

Reporting Timelines and Compliance Obligations

After a breach, companies must:

  1. Notify regulators within the legally mandated period (e.g., 72 hours under GDPR).
  2. Inform affected individuals if personal or financial data was exposed.
  3. Document containment and remediation actions.
  4. Maintain detailed incident logs for potential audits or investigations.

Failure to meet these obligations often results in compounding fines and increased oversight.

Examples of Major Regulatory Penalties

Why Legal Compliance Matters for Prevention

Being compliant doesn’t just reduce fines, it enforces best practices:

Regulators have grown less forgiving, and accountability does not transfer with the work: where a breach originates at a third party, the data controller is generally still answerable to the regulator. With third-party involvement now in 48% of breaches, that makes vendor oversight a compliance obligation, not just a security one.

What Drives Data Breaches in 2026?

Broader cybersecurity statistics show that the most common causes of data breaches stem from human error, compromised credentials, system vulnerabilities, insider threats, third-party weaknesses, and ransomware/malware attacks. Together these form the bulk of breaches organizations suffer.

Human Error & Social Engineering The Top Culprit

2026 update: the human element is present in 62% of breaches, and phishing is IBM's top attack vector for the fourth consecutive year. The channel is shifting, though. Email phishing is better filtered than ever, so attackers have moved to voice and SMS: IBM found vishing and smishing in 17% of the attacks it studied, and those produced the costliest breaches at an average of $5.29 million. Pretexting is now a common on-ramp to ransomware, and generative AI makes the lures cheaper and more convincing. Deeper numbers live in our phishing statistics. The control that matters: phishing-resistant MFA, strong filtering, out-of-band verification for help-desk resets and payment changes, and training that covers voice and SMS, not just email.

Why humans are the weakest link

The Verizon 2026 DBIR found the human element present in 62% of breaches, covering phishing clicks, social engineering, errors, and misuse. People are involved in most breaches, even where the technical entry point is something else.

Main forms of social engineering & error

  1. Phishing / Spear phishing
    • Attackers send convincing emails that lure users into clicking malicious links or entering credentials.

Credential abuse fell to 13% as a first step in the 2026 DBIR, partly because pretexting is now tracked separately, but it still appears somewhere in 39% of breaches, making it the most persistent thread across the whole attack chain.

2.Misdelivery, misconfiguration, or mis-sharing

  1. Poor password hygiene / password reuse
    • Billions of credentials have been exposed, many of which are reused across accounts.
    • A single exposed credential can let attackers gain initial access and pivot laterally.
  2. Shadow IT and unsanctioned tools
    • Employees using unauthorized apps or personal tools that circumvent security oversight.
    • IBM’s report notes that “shadow AI” contributed to 20 % of breaches.
Case example: In May 2025, a phishing campaign led to unauthorized access to emails at Mailchimp and other SaaS platforms.

Prevention tips

Credential Compromise & Identity-based Attacks

Credential breaches as a vector

Once attackers hold valid credentials they bypass many defenses, which is why credential abuse still appears somewhere in 39% of breaches even though it fell to 13% as a first step in the 2026 DBIR. Infostealer malware keeps the supply endless, harvesting session tokens and passwords at scale, and mega-compilations like the 16-billion-credential leak feed credential stuffing, a threat quantified in our compromised credential statistics.

Attack patterns

Prevention

Vulnerability Exploits & Zero-Day Attacks

2026 update: this is the headline change of the year. Attackers increasingly skip tricking a person and simply exploit a known, unpatched flaw in internet-facing software. Exploitation is now the most common initial access vector at 31% of breaches, up from 20% the year before, a 55% year-over-year rise, and the first time in the DBIR's history that it has beaten stolen credentials. Prioritize by exploitability rather than raw CVSS: patch anything in the CISA KEV catalog first, and validate the fixes with real vulnerability management rather than assuming a patch landed.

Why exploits still matter

Security flaws in software or infrastructure give attackers direct routes in. In the 2026 DBIR, 31% of breaches involved exploitation of vulnerabilities, up from 20% the year before, a 55% year-over-year rise that made it the single most common initial access vector for the first time in the report's history.

Third-party involvement in breaches rose 60% year over year to 48% in the 2026 DBIR, after already doubling the year before. Nearly half of all breaches now run through a vendor, supplier, or service provider.

Common exploit paths

Case studies

Mitigation strategies

Insider Threats Intentional & Accidental

2026 update: internal actors are involved in about 22% of breaches, split between the malicious (an employee stealing data) and the accidental. Malicious insider attacks are among the costliest vectors because the person already has trusted access and knows where the valuable data lives, which is why they take so long to detect. IBM separately attributes roughly 23% of breaches to human error, with cloud misconfiguration now a prime cause as estates sprawl across multiple providers.

Two faces of insider risk

Data insights

How insiders exploit access

Controls to reduce risk

Third-Party & Supply Chain Risks

2026 update: your risk is now your vendors' risk. Breaches with third-party involvement jumped 60% in the latest DBIR to reach 48% of all breaches, after already doubling the year before. The root causes are mundane: absent MFA, un-rotated credentials, and excessive privileges in a vendor's cloud. IBM found supply-chain compromise both the second most common vector and the costliest single factor, adding an average of $227,250 per breach and taking the longest to detect and contain. Treat vendor risk as a programme rather than a questionnaire, as covered in our third-party risk management guide.

Why third parties are high risk

Organizations rely heavily on vendors, partners, and SaaS providers. A weakness in their security becomes your liability.


DeepStrike cites that third-party / vendor compromise is the second most prevalent attack vector and also among the most costly, averaging $4.91 million in losses.Verizon DBIR flags supply chain risk as an escalating area.

Real examples

Categories of vendor risk

  1. SaaS vendor misconfigurations
  2. Third-party code dependencies
  3. Remote support weak points
  4. Shared credentials or trust relationships

Mitigation roadmap

Ransomware, Malware & Advanced Attacks

2026 update: ransomware appeared in 48% of breaches, up from 44%, and remains the most financially destructive outcome even as the economics shift for attackers. Notably, 69% of victims did not pay, and the median ransom fell below $140,000, a sign that backups, response readiness, and law-enforcement pressure are working. Ransomware rarely stands alone; it is the payload delivered after an unpatched exploit, a stolen credential, or a phishing click opens the door. Our ransomware statistics track the active groups, and a rehearsed incident response plan is what stops a foothold becoming a full compromise.

How malware contributes

Malicious software (ransomware, trojans, RATs) helps attackers encrypt or exfiltrate data. Infrascale stats show malware accounts for 31.2 % of data loss incidents.

Rise of ransomware and extortion

Attack chain

Defenses

Emerging Causes: AI, Cloud Sprawl and DevOps Exposure

AI and GenAI risk in 2026

IBM found shadow AI incidents affected 43% of breached organizations in 2026, up from 20% a year earlier, and those organizations saw higher breach costs, greater operational disruption, and more data loss.

Multi-cloud / hybrid cloud misconfigurations

Cloud sprawl compounds the problem: a large majority of breached data now sits in cloud environments, and a significant share of incidents span more than one environment, which slows both detection and containment.

Credentials in developer environments & DevOps pipelines

Long dwell time and late detection

On average, organizations took 247 days to identify and contain a breach in 2026, 183 days to detect and a further 64 to contain. That figure rose this year, reversing five consecutive years of improvement, and breaches running longer than 200 days cost materially more than those closed faster.

By surfacing these underdiscussed risk vectors, your content outperforms shallow lists in other posts

Prevention Framework - How to Block Breaches at Source

You do not need a separate programme for each cause; a handful of fundamentals blunts most of them.

CauseHighest-leverage control
Vulnerability exploitationFast, KEV-prioritized patching plus attack surface management
Stolen credentialsPhishing-resistant MFA plus credential monitoring
Phishing / social engineeringMFA, filtering, out-of-band verification, and training that covers vishing and smishing
Third-party / supply chainVendor MFA, least privilege, tight access scoping
Ransomware / malwareOffline backups, segmentation, EDR, tested IR plan
Human error / misconfigurationInfrastructure-as-code guardrails, automated posture checks
Insider threatsLeast privilege, access monitoring, strong offboarding

The through-line: most breaches still exploit known, preventable weaknesses, not exotic zero-days. Patch fast, authenticate strongly, scope access tightly, and validate that it all actually works with a penetration test. Broader guidance lives in our data breach prevention guide, the wider trend lines in our data breach statistics, and the full cost picture in our cost of a data breach guide.

Here’s a layered framework combining people, processes, and technology:

LayerKey ActionTools / Best Practices
People & CultureSecurity training, phishing drillsMonthly simulations + intentional retests
Identity & AccessMFA, least privilege, credential hygienePrivileged Access Management (PAM) tools
Systems & NetworksPatch management, segmentationVulnerability scanning, micro-segmentation
Endpoint & MalwareEDR, signatureless detectionNext-gen antivirus, anomaly detection
Data ProtectionEncryption, DLP, backupsAt-rest & in-transit encryption, immutable storage
Third-party RiskVendor assessments, limited accessSecurity audits, contractual clauses

Bonus tactics:

Real-World Case Studies (2025)

Qantas third-party breach (2025)

A compromised vendor contact center system exposed ~6M customer records. It illustrates how third-party access can cascade into major customer data exposure

Farmers Insurance / Salesforce vector

Attackers compromised a supply chain (Salesforce vendor integration), exposing sensitive personal data of millions

Healthcare industry patterns

These examples reinforce how multi-vector attacks combine phishing, vendor risk, and system exploits.

Sources:

Verizon 2026 Data Breach Investigations Report, covering more than 22,000 confirmed breaches across 145 countries.

IBM Cost of a Data Breach Report 2026, for breach cost, detection time, and the AI-attack cost premium.

Cisco Cybersecurity Readiness Index 2025, on AI incident prevalence and organizational readiness.

Trend Micro State of AI Security Report, 1H 2025, on exposed vector-database servers and AI components.

Conclusion

Understanding the common causes of data breaches is your first line of defense. In 2026 most breaches still trace back to a short list: unpatched vulnerabilities, compromised credentials, phishing and social engineering, third-party weaknesses, ransomware, human error, and insiders. What is striking is how ordinary they are, which is also why they are addressable.

By implementing layered defenses identity security, endpoint protection, vendor vetting, and security-aware culture you can dramatically reduce your breach risk. The sooner you act, the higher the odds your organization avoids the headline.

Frequently Asked Questions (FAQ)

What is the most common cause of data breaches in 2026?

It depends on how you measure. Verizon's 2026 DBIR, which traces the forensic entry point, ranks exploitation of unpatched vulnerabilities first at 31% of breaches, having overtaken stolen credentials for the first time in 19 years. IBM's survey of breached organizations ranks phishing first for the fourth year running. Both are authoritative; they simply measure the first way in differently.

Is human error really the biggest cause of data breaches?

The human element (phishing clicks, social engineering, mistakes, and misuse) is present in about 62% of breaches, so people are involved in most of them. But human error specifically, such as misconfigurations and misdelivery, accounts for roughly 23%. The single largest technical entry point in 2026 is the exploitation of unpatched vulnerabilities.

What is the top attack vector according to the 2026 Verizon DBIR?

Exploitation of vulnerabilities, at 31% of breaches, is the most common initial access vector in the 2026 DBIR, overtaking credential abuse (13% as a first step, 39% across all stages). Ransomware appeared in 48% of breaches, and third-party involvement rose 60% to reach 48% of breaches.

How much does a data breach cost in 2026?

The IBM Cost of a Data Breach Report 2026 puts the global average at a record $4.99 million, up 12% year over year. In the United States the average is far higher at $11.5 million, driven by regulatory penalties and detection costs. Detection, escalation, and lost business make up most of that total, and the mean time to identify and contain a breach rose to 247 days.

Why are third-party breaches increasing so fast?

Organizations rely on more vendors, SaaS platforms, and software suppliers than ever, and each connection expands the attack surface. Breaches with third-party involvement rose 60% in the latest DBIR to 48% of the total. The usual root causes are mundane: missing MFA, un-rotated credentials, and excessive privileges inside a vendor's cloud environment.

How can I prevent the most common data breaches?

Focus on fundamentals that cut across causes: patch known-exploited vulnerabilities fast, enforce phishing-resistant MFA everywhere, tightly scope third-party and internal access, keep tested offline backups, and monitor for exposed credentials. Then validate that these controls actually work with a penetration test, since most breaches exploit known, preventable weaknesses rather than novel zero-days.

How effective is multi-factor authentication against these causes?

Phishing-resistant MFA is one of the highest-leverage single controls, because it cuts across two of the top causes at once: it neutralizes stolen credentials, which still appear in 39% of breaches, and it blunts the phishing and social engineering that reach 62% of them. It is not absolute, since attackers now target help desks, MFA-reset workflows, and session tokens rather than passwords, which is why it works best alongside out-of-band verification for sensitive requests and shorter session lifetimes.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us