Data Breach Statistics 2026

Nishtha chauhan
Nishtha chauhan
|Published on |12 Mins
Cover Image for Data Breach Statistics 2026

A breach statistic can look definitive until you compare it with the next one. A cost study says $4.99 million. A breach-investigation dataset says 22,000+ confirmed breaches. Two U.S. trackers report 3,322 compromises and 4,080 unique events. None is necessarily wrong, but none is a global total.

The short answer: the average cost of a data breach is at a record high in IBM’s 2026 study, vulnerability exploitation is the leading initial-access vector in Verizon’s 2026 coverage, and disclosed-breach counts depend on what each organization counts. This report puts the primary figures side by side, explains their limits, and identifies what the data means for your mobile app security program.

Data breach statistics at a glance

Measure

Latest figure

What it does and does not measure

Average cost of a data breach

$4.99 million

IBM’s global average breach cost; not total global losses

Confirmed breaches

22,000+

Breaches in Verizon’s incident dataset; not all breaches worldwide

U.S. data compromises

3,322

ITRC’s publicly reported U.S. compromises in 2025

U.S. unique breach events

4,080

PRC’s deduplicated events from notification filings in 2025

UK businesses reporting a breach or attack

43%

Survey prevalence in the prior 12 months, not a breach-event census

IBM reports that the average cost of a data breach reached $4.99 million in 2026, up 12% from the prior year and the highest figure in the study’s history. The estimate covers costs associated with detecting, responding to, investigating, and recovering from a breach. It is not a count of incidents or a prediction of what your organization will pay. (IBM Cost of a Data Breach Report 2026)

The most useful way to read these numbers is as a set of different instruments. Cost, confirmed incidents, publicly disclosed compromises, notification filings, and survey responses answer different questions. Combining them would create a number with no coherent meaning.

Ebook Preview

Get the Mobile Testing Playbook Used by 800+ QA Teams

Discover 50+ battle-tested strategies to catch critical bugs before production and ship 5-star apps faster.

100% Free. No spam. Unsubscribe anytime.

Why breach totals do not match

The reporting windows differ before the methodologies do. IBM’s 2026 study covers March 2025 through February 2026. Verizon’s 2026 DBIR dataset covers October 2024 through November 2025. ITRC and Privacy Rights Clearinghouse report calendar-year 2025 activity, while the UK survey’s fieldwork took place from August through December 2025. (IBM Cost of a Data Breach Report 2026; Verizon 2026 DBIR; GOV.UK Cyber Security Breaches Survey 2025/2026)

Verizon’s dataset contains more than 22,000 confirmed breaches

Verizon’s 2026 DBIR analyzed more than 31,000 security incidents, including more than 22,000 confirmed breaches. SecurityWeek’s report on the DBIR describes that confirmed-breach count as nearly double the prior year’s 12,195, a baseline Verizon also reported for its 2025 DBIR. (SecurityWeek’s Verizon DBIR 2026 coverage; Verizon’s 2025 DBIR announcement)

A DBIR confirmed breach belongs to Verizon’s incident dataset. It is not interchangeable with a regulatory filing, an individual receiving a notice, or every breach that happened during the reporting period.

ITRC and PRC describe different U.S. disclosure datasets

The Identity Theft Resource Center tracked 3,322 U.S. data compromises in 2025, up 5% from 3,152 in 2024. Those compromises generated 278,827,933 victim notices, approximately 79% below the prior year’s 1.37 billion notices. ITRC attributed the lower notice total to the absence of a comparable mega-breach. (ITRC’s 2025 annual-report release)

Privacy Rights Clearinghouse recorded 8,019 notification filings from state and federal agencies for 2025. After deduplication, PRC reported 4,080 unique breach events affecting at least 375 million individuals; its report identifies Change Healthcare as affecting 192.7 million people. (Privacy Rights Clearinghouse’s 2025 Data Breach Report)

Do not add ITRC’s 3,322 to PRC’s 4,080. ITRC aggregates publicly reported compromises, whereas PRC begins with filings and deduplicates filings that point to an underlying event. One compromise can generate many victim notices, and one event can trigger filings in more than one jurisdiction.

Neither public dataset claims to measure every breach that occurred. They describe the disclosed-breach environment, which is valuable for trend tracking but narrower than all compromise activity.

What is causing the breaches

Vulnerability exploitation became the leading access vector

Vulnerability exploitation rose to approximately 31% in Verizon’s 2026 reporting dataset, while credential abuse fell to 13%. Credential abuse had been the leading initial-access vector in the prior year, so the ranking changed. (SecurityWeek’s Verizon DBIR 2026 coverage)

For your security program, identity controls cannot substitute for patching and exposure testing. A mobile app can enforce authentication correctly while a vulnerable API, dependency, backend service, or client-side implementation still exposes sensitive data.

Ransomware and third parties remain material risks

Ransomware appeared in 48% of breaches in the 2026 DBIR, up from 44% in the prior report. The same reporting says 69% of ransomware victims did not pay, meaning 31% paid, and that the median ransom paid was $139,875. Those values describe Verizon’s dataset, not a forecast of your likely loss. (SecurityWeek’s Verizon DBIR 2026 coverage)

Third-party involvement rose 60% year over year to 48% of total breaches in the same reporting. (SecurityWeek’s Verizon DBIR 2026 coverage)

That changes the test boundary for a mobile app. Include the identity provider, analytics SDK, payment service, crash-reporting library, feature-flag service, and API gateway that participate in a sensitive workflow. Testing only code your team authored can leave important user-data paths unexamined.

People and social engineering remain part of the picture

The human element was involved in 62% of breaches, and social engineering accounted for 16%, according to the DBIR coverage. In Verizon’s phishing simulations, the median successful click rate for mobile-centric vectors such as voice and text messaging was 40% higher than for email. (SecurityWeek’s Verizon DBIR 2026 coverage)

That does not mean mobile phishing attacks are universally 40% more successful than email attacks, nor does it mean a mobile app causes phishing. The figure comes from phishing simulations. It does mean your threat model should account for how people encounter links, authentication prompts, approvals, and data requests on a phone.

How AI changes the average cost and the attack surface

IBM reports a 56% year-over-year increase in AI-driven attacks, citing deepfake impersonation and AI-enabled malware among the drivers. It also puts the average cost of an AI model inversion attack at $6 million. Model inversion is an attempt to infer sensitive information from an AI model or its outputs, so this is a scenario-specific average cost rather than the cost of every AI-related breach. (IBM Cost of a Data Breach Report 2026)

IBM’s defensive finding is equally specific: organizations using AI and automation extensively in security saved $1.93 million per breach compared with organizations using none. That association is useful evidence for evaluating security operations, but it is not a guarantee of savings from adopting any particular tool. (IBM Cost of a Data Breach Report 2026)

Verizon’s DBIR coverage also reports that 67% of users accessing AI services from corporate devices used non-corporate accounts and 45% of employees were regular AI users, up from 15% in the prior year. (SecurityWeek’s Verizon DBIR 2026 coverage)

Your mobile app review cannot establish whether employees use unauthorized AI services. It can, however, test where sensitive data is stored, logged, displayed, and transmitted in workflows that might intersect with AI-assisted work. For a broader view of how QA organizations are adopting AI, see Quash’s 2026 AI testing statistics and adoption data.

What the UK data shows

The UK government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses and 28% of charities experienced a cyber breach or attack in the previous 12 months. The survey estimates that this represents approximately 612,000 businesses and 57,000 charities. (GOV.UK Cyber Security Breaches Survey 2025/2026)

Phishing was the most prevalent type, affecting 38% of businesses and 25% of charities. Among organizations that reported experiencing a breach or attack, 69% of businesses and 69% of charities identified phishing as the most disruptive type. (GOV.UK Cyber Security Breaches Survey 2025/2026)

Ransomware affected 1% of UK businesses in the 2025/2026 survey, down from 3% in both 2024/2025 and 2023/2024. This does not conflict with Verizon’s 48% figure: the UK survey measures prevalence among businesses surveyed, while Verizon reports ransomware’s presence among breaches in its own dataset. (GOV.UK Cyber Security Breaches Survey 2025/2026; SecurityWeek’s Verizon DBIR 2026 coverage)

The mobile gap in breach reporting

The mobile-specific figure most worth carrying forward comes from Verizon’s phishing simulations: the median successful click rate for mobile-centric vectors such as voice and text messaging was 40% higher than for email. It concerns how people respond to simulated social-engineering attempts through different channels; it does not demonstrate that a mobile app itself caused a breach or that real-world mobile attacks universally have a 40% higher success rate. (SecurityWeek’s Verizon DBIR 2026 coverage)

Generic breach roundups often leave that distinction unexplored. Your mobile app sits within a wider system of device state, operating system behavior, network traffic, authentication flows, backend APIs, SDKs, and user decisions. A weakness in any layer can change what an attacker can access or what a user can be persuaded to disclose.

No first-party Quash telemetry, customer language, recurring bug dataset, or completed experiment covers this question. This mobile interpretation is an analytical reading of published breach data, not a Quash benchmark or product result.

A useful mobile-app security test plan should include the following:

  • Exercise authentication and recovery flows. Test deep links, expired sessions, device changes, password resets, and multi-factor prompts on supported platforms.

  • Inspect sensitive-data handling. Check local storage, logs, screenshots, clipboard behavior, and network requests.

  • Probe authorization boundaries. Verify that changing identifiers, replaying a request, or switching roles cannot expose another user’s records.

  • Map third-party paths. Identify the SDKs and services handling identity, payments, analytics, messaging, and crash data.

  • Use realistic device states. Run flows through backgrounding, interrupted sessions, changed permissions, network transitions, and supported OS versions.

  • Retest after each fix. A release that changes navigation, an API contract, a dependency, or authentication can reintroduce a security regression.

If your delivery process is changing because more code is generated or assisted by AI, the verification problem becomes more acute. Quash’s analysis of vibe coding security risks and verification practices offers adjacent context; it does not replace a threat model or security review for your app.

Use the numbers to set your security priorities

Use the statistics to prioritize questions, not to manufacture a single risk score.

Reduce exploitable exposure first. Vulnerability exploitation led the DBIR’s initial-access figures. Maintain an inventory of internet-facing services, patch known issues, review dependencies, and test the API interfaces that expose data, not only the screens that render it. (SecurityWeek’s Verizon DBIR 2026 coverage)

Model the whole delivery chain. With third-party involvement at 48% of Verizon’s breaches, define who owns validation when an identity service, SDK, payment provider, or API changes. (SecurityWeek’s Verizon DBIR 2026 coverage)

Validate real mobile behavior. The phishing simulation result is not a universal mobile breach or attack rate, but it is a reason to test how users authenticate, follow links, approve requests, and handle data on phones. A disciplined QA automation strategy for 2026 can make those scenarios repeatable across releases.

Treat the average cost as a planning signal. IBM’s $4.99 million figure helps frame the stakes, but it cannot tell you which control will reduce risk most in your environment. Set priorities using your asset inventory, data classification, exposure findings, incident history, and recovery requirements. (IBM Cost of a Data Breach Report 2026)

Conclusion

The useful lesson in 2026 data breach statistics is context, not a single leaderboard number. $4.99 million is IBM’s average cost; 22,000+ is Verizon’s confirmed-breach count; 3,322 is ITRC’s U.S. compromise count; and 4,080 is PRC’s deduplicated notification-based event count. They cannot be added together.

For your security program, the direction is still actionable. Prioritize exploitable vulnerabilities, include third-party services in testing, and make mobile authentication and data-handling flows part of security validation. That connects the published evidence to the parts of your app that you can actually inspect and improve.