Summary
The 2026 Verizon Data Breach Investigations Report (DBIR), published today, reveals a watershed moment in cybersecurity: for the first time in the report’s 19-year history, vulnerability exploitation has overtaken stolen credentials as the leading initial access vector for data breaches. One-third of all confirmed breaches now begin with exploiting a known vulnerability, while credential abuse has fallen to just 13%.
The report, based on over 31,000 real-world security incidents across 145 countries from November 2024 through October 2025, also found that ransomware-related actions are now a factor in a staggering 48% of all breaches — up from 44% the prior year. Supply chain breaches surged 60% and now account for nearly half of all incidents. Perhaps most troubling: organizations are patching fewer critical vulnerabilities (just 25%, down from 38%) and taking longer to do so (43 days on average, up from 32).
The report also flags the rise of “shadow AI” — employees using unapproved AI tools at work — which has tripled and is now the third most common non-malicious data leakage activity.
Source
Verizon 2026 DBIR — Official announcement | Coverage via BankInfoSecurity
Commentary
This is a significant inflection point. For years, credential theft was the undisputed king of initial access. The fact that unpatched vulnerabilities have now taken the crown reflects both the explosion in disclosed CVEs (48,000+ last year, up 18%) and the brutal reality that most organizations simply cannot keep up with patching velocity — even the best performers only remediate 30-40% of actively exploited bugs within the first week.
The shadow AI finding deserves attention too. Organizations pouring resources into perimeter defense are watching sensitive data walk out the front door through unsanctioned ChatGPT clones and AI coding assistants. The threat landscape isn’t just evolving — it’s bifurcating between external exploitation and internal carelessness.
