2026-dbir-data-breach-investigations-report
The 2026 Verizon Data Breach Investigations Report (DBIR) analyzes more than 31,000 security incidents (over 22,000 confirmed breaches) that occurred between November 1 2024 and October 31 2025. The report is organized by industry verticals (Education, Financial & Insurance, Healthcare, Manufacturing, Public Administration, Retail, Small‑and‑Medium‑Businesses) and by world regions (APAC, EMEA, LAC, NA). Across all sectors, the dominant breach pattern is System Intrusion, now driven primarily by exploitation of vulnerabilities (31‑34% of initial access) and ransomware, which appears in 55‑65% of malware‑related breaches. Social Engineering and Miscellaneous Errors remain the second and third most common patterns, with human‑element mistakes (misdelivery, misconfiguration, loss) accounting for a large share of errors. Financially motivated external actors dominate the threat landscape (78‑99% of actors), though state‑affiliated actors are rising in APAC and EMEA, bringing an espionage motive that now accounts for up to 36% of APAC breaches. Third‑party exposure and the human element are persistent risk factors (40‑71% of breaches). The report also details regional variations, highlights notable case studies (e.g., Oracle E‑Business Suite exploitation, Qantas breach, Jaguar Land Rover ransomware attack), and provides methodological notes on the VERIS framework, data‑quality filters, and bias considerations. Appendices cover emerging threats such as agentic AI, operational lessons from Singapore’s UNC3886 response, and practical guidance on turning DBIR statistics into risk‑based security decisions.
Topics
Industry Breach Landscape – Sector‑wide Patterns and Variations
Across Education, Healthcare, Manufacturing, Public Administration, Retail, and Small‑and‑Medium‑Businesses, System Intrusion remains the dominant breach pattern, now driven primarily by exploitation of vulnerabilities (31‑34% of initial access) and ransomware (present in 55‑65% of malware‑related breaches). Social Engineering and Miscellaneous Errors (misdelivery, misconfiguration, loss) are the next most common vectors. Third‑party exposure and the human element appear in 40‑71% of incidents, with supply‑chain risk especially pronounced in Manufacturing (61% third‑party involvement). Ransomware prevalence varies by sector—from 54% of malware actions in Retail to 83% in SMBs—while internal errors dominate Public Administration (88% of errors).
Regional Breach Analysis – APAC and EMEA Profiles
APAC exhibits the highest share of state‑affiliated actors (up to 36%) and espionage motives (36% of breaches), with vulnerability exploitation (42% of initial access) and ransomware remaining dominant; third‑party exposure (69%) and human‑element involvement (71%) are pronounced. EMEA shows a mixed threat profile with state‑affiliated actors in 23% of breaches and espionage at 27%; phishing accounts for 84% of social actions and malware share (66%) slightly exceeds the global average.
Emerging Threats – Agentic AI and Autonomous Adversaries
An appendix from the U.S. Secret Service outlines how autonomous AI can automate reconnaissance, phishing, and ransomware deployment, lowering barriers for sophisticated attacks and creating new challenges for law‑enforcement and defensive capabilities.
Operational Lessons – Singapore’s UNC3886 Response and Collective Cyber Resilience
Case study of Singapore’s coordinated national response to the UNC3886 APT campaign, highlighting early detection, inter‑agency coordination, and public‑private partnership as pillars of resilience against advanced persistent threats.