Refinement, not revolution.
The DBIR's own framing this year. The threat landscape changed in speed and scale, not in shape. Patching, identity, response and supplier discipline still decide whether you become a statistic.
This page is the Australian operator's reading of the 2026 report. Six attack patterns, the industry breakdowns that matter here, the APAC regional picture, and the controls that close each gap.
The dataset behind the report
Real incidents analysed
31,000+
Confirmed breaches
22,000+
Countries represented
145
Editions of the report
19
Largest single-edition breach dataset Verizon has ever published. The previous edition (2025) covered 22,052 incidents and 12,195 confirmed breaches.
Year on year
Eight numbers that moved between 2025 and 2026.
Green is good news for defenders. Red is not. The pattern is consistent: the controls people are actually deploying (MFA, conditional access) are working, but patching velocity and supplier discipline are losing ground against the volume.
Vulnerability exploitation as initial access
Now the #1 initial access vector for the first time in DBIR history.
20%
31%
Now the #1 initial access vector for the first time in DBIR history.
Credential abuse as initial access
MFA and conditional access are working where deployed.
22%
13%
MFA and conditional access are working where deployed.
Ransomware involvement in breaches
SMBs make up 96% of victims in the dataset.
44%
48%
SMBs make up 96% of victims in the dataset.
Third-party involvement in breaches
60% jump in twelve months, tripled in two years.
30%
48%
60% jump in twelve months, tripled in two years.
Human element present in breaches
Slight drop, but still the majority of all breaches.
68%
62%
Slight drop, but still the majority of all breaches.
Critical vulnerabilities fully remediated
Patch programmes are losing ground against the volume.
38%
26%
Patch programmes are losing ground against the volume.
Median time to remediate critical CVEs
And edge-device CVEs are now exploited within hours.
32 days
43 days
And edge-device CVEs are now exploited within hours.
GenAI use on corporate devices
67% of that use goes through personal, non-corporate accounts.
15%
45%
67% of that use goes through personal, non-corporate accounts.
The six attack patterns
How every breach in the dataset gets classified.
The DBIR has used the same six-pattern taxonomy for nearly a decade. It is how the industry compares year to year. System Intrusion has now passed 50% for the first time, which tells you where attacker investment is going. The light bars behind each show where each pattern sat two years ago.
System Intrusion
53% of breaches
2024
36%
Multi-step attacks: malware, hacking, ransomware. Now over half of all breaches.
Social Engineering
17% of breaches
2024
17%
Phishing, pretexting, voice scams. Steady share, but tactics are shifting to mobile.
Basic Web Application Attacks
11% of breaches
2024
25%
Stolen credentials against web apps. Down sharply as MFA adoption catches up.
Miscellaneous Errors
8% of breaches
2024
11%
Misdelivery, misconfiguration, lost devices. The 'we did it to ourselves' bucket.
Privilege Misuse
6% of breaches
2024
6%
Insider abuse of legitimate access. Stable, but harder to detect than external.
Denial of Service
5% of breaches
2024
5%
Availability attacks. Disruptive, but rarely a confirmed data breach.
detailed look · How a breach actually unfolds
Five steps from foothold to domain compromise.
The DBIR has run this analysis for three editions now. The shape barely changes. What changes is the speed. In 2026 the median dwell time from first compromise to attacker objective is measured in days, not weeks. Each step in the chain is a chance to break it.
01
Initial foothold
Most commonly an unpatched edge device (firewall, VPN, remote-access appliance) or a phished user. 31% start here in the 2026 data.
Median time to first action: minutes from exploit.
02
Local recon
Attackers enumerate the host, list local admins, dump credentials from memory, and scan the local subnet for next-hop targets.
Living-off-the-land tools (PowerShell, WMI, PsExec) keep this stage invisible to legacy AV.
03
Lateral movement
Pass-the-hash, pass-the-ticket and RDP hops to a server with cached domain credentials. Often the first DC or backup server.
EDR with cross-host correlation is the chokepoint. Without it, this stage runs unopposed.
04
Domain compromise
Kerberoasting, golden ticket, or simple credential reuse on a Tier 0 system gets the attacker domain admin or Global Admin in Entra ID.
Tiered admin, dedicated PAW workstations and Just-in-Time access break the chain here.
05
Objective
Encrypt and demand ransom, exfiltrate data, deploy persistence for espionage, or simply sell the access to another group.
Median dwell time from foothold to objective is now under 5 days in the dataset.
The first DBIR edition where AI shows up on both sides of the line.
The 2026 report devotes more pages to GenAI than any previous edition. Two distinct stories. Attackers are using AI to lower the cost of every step in their workflow. Defenders are losing data through personal AI accounts faster than policy can keep up.
Attacker uses
01
Target selection
GenAI assists with reconnaissance and lead scoring against potential victims.
02
Initial access tooling
Faster development of exploit kits and customised malware loaders.
03
Vulnerability research
LLM-assisted code review of public software for new CVE candidates.
04
Social engineering at scale
Personalised phishing, voice cloning, and conversational pretexting agents.
Defender exposures
01
Shadow AI usage
45% of employees regularly use GenAI on corporate devices, up from 15% in twelve months.
02
Personal account exfiltration
67% of that use is through personal, non-corporate accounts. Data leaves the tenant.
03
Prompt injection on agents
Emerging class of attack where a malicious document instructs the AI to act against the user.
04
Model and data-poisoning risk
Less common, but a growing concern for organisations training their own models.
The Australian read on this section
The Voluntary AI Safety Standard is the policy answer the OAIC and DISR have already published. Data classification, an approved AI tool list, and disabling personal-account AI on managed devices closes most of the defender exposures the DBIR is calling out.
The Asia-Pacific picture looks different to the global one.
The DBIR runs a dedicated regional analysis every year. The APAC chapter consistently shows a higher concentration of malware and ransomware than the global average, driven by aggressive nation-state activity, a maturing criminal-as-a-service market in the region, and the same internet-facing patching gaps the global report calls out.
For Australian operators this matters. APAC numbers are a closer proxy for what hits Australian businesses than the all-region average. The control priorities are the same. The urgency is higher.
How we apply this in the Australian market83%
of APAC breaches involved malware, up from 58% the previous edition
51%
of APAC breaches involved ransomware specifically, well above the global average
80%
of APAC breaches fall under the System Intrusion pattern
1 in 4
APAC breaches now involve a third-party as the entry point
Reference: Verizon 2025 and 2026 DBIR APAC regional chapters. The malware concentration in APAC has now been higher than the global average for three consecutive editions.
OAIC notifiable data breach data tells the Australian story.
The Verizon DBIR is the global benchmark. The Office of the Australian Information Commissioner publishes the canonical Australian view: who is notifying, why, and how often. The figures below are drawn from OAIC's published Notifiable Data Breaches statistics, which are the single most reliable source for breach trends in the Australian market.
1,205
notifiable data breaches received by OAIC in calendar year 2025.
The highest annual total since the NDB scheme commenced in 2018, up 8 per cent on 2024.
716
caused by malicious or criminal activity the majority of all 2025 notifications.
Cyber hacking remains the primary cause of breaches reported to the OAIC.
225
health service provider breaches the most commonly affected sector.
19 per cent of the annual total. Financial services followed on 157 notifications.
82%
of Australians are concerned about data breaches.
The top perceived privacy risk in the 2026 Australian Community Attitudes to Privacy Survey, up from 74 per cent in 2023.
Source: Office of the Australian Information Commissioner, calendar year 2025 Notifiable Data Breaches statistics, published 6 July 2026, and the 2026 Australian Community Attitudes to Privacy Survey. Figures as published by OAIC. Refresh expected when OAIC publishes the next reporting period.
By industry
The report runs a chapter for every major sector. Here is the operator's read.
Sector profiles drift year to year, but the structural pattern is consistent. Heavy-asset industries get ransomware. People-heavy industries get social engineering. Data-rich industries get espionage. Your sector tells you which lever moves first.
Healthcare
Misdelivery and supply-chain breach are the dominant patterns.
70%
of healthcare breaches involve a system intrusion (ransomware-heavy)
39%
involve a third party, supply chain remains the soft underbelly
$10.9M
average healthcare breach cost, the highest of any sector
Healthcare runs old kit on flat networks with a long tail of medical IoT. The DBIR data is unforgiving here.
Healthcare IT and securityFinancial Services
Mature controls, but social engineering keeps landing.
60%
of financial breaches involve system intrusion
23%
involve social engineering, well above the global rate
75%
of finance attacks are financially motivated, not espionage
Best baseline in any sector. APRA CPS 234 makes it that way. The gap is now people, voice scams and pretexting.
Finance sector ITEducation
Espionage actors are increasingly active in the sector.
65%
of education breaches involve system intrusion
30%
involve external espionage actors, double the global rate
44%
involve credentials as part of the attack chain
Universities and large schools hold research, IP and student data. Identity hygiene is the single biggest lever.
Education IT and securityManufacturing
OT and IT are converging, and the breach data shows it.
85%
of manufacturing breaches involve system intrusion or ransomware
97%
are financially motivated, this is a ransomware target sector
55%
involve a third party, typically a vendor or contractor
Production downtime is the leverage. Segmentation between IT and OT is the control that buys time during a hit.
OT and industrial securityPublic Administration
Espionage and ransomware in roughly equal measure.
55%
of public sector breaches are financially motivated
33%
involve external espionage actors
72%
involve credentials as part of the chain
Federal, state and council operations are a mixed picture. Essential Eight ML2 is the realistic target here.
Government and public sectorRetail
Web applications and payment data remain the prize.
62%
of retail breaches target web applications directly
37%
involve payment card data as the stolen asset
Up
ransomware against retail is trending sharply upward
Web app hardening, PCI scope reduction and tested response planning. The fundamentals are still the spend.
Retail sector ITIndustry percentages aggregate Verizon 2025 and 2026 DBIR industry chapters. Cost figures from IBM Cost of a Data Breach 2025 (cross-referenced where the DBIR did not publish a dollar value).
From data to control
Six findings. Six operational controls. No theatre.
The DBIR doesn't tell you what to do. It tells you where the attackers are spending their time. This map turns each major finding into the engineering work that actually closes the gap, and shows you where in our service catalogue that work lives.
Threat theme
What the data says
Control that closes it
Service
Vulnerability exploitation
31% of breaches, now the #1 entry vector
Patch SLA for internet-facing systems, exposure monitoring, edge-device hardening
Ransomware
48% of breaches, 96% of victims are SMBs
Immutable backups, EDR with 24x7 SOC, network segmentation, rehearsed response
Third-party / supply chain
48% of breaches, tripled in two years
Supplier access register, MFA on every supplier account, quarterly access review
Human element / social engineering
62% involve a person, voice and SMS pretexting rising
Phishing-resistant MFA, conditional access, DMARC enforcement, helpdesk verification
Credential abuse
13% of entry, but dominant in privilege escalation chains
Entra ID baseline, PAM for Tier 0, just-in-time admin, tiered administration model
Shadow AI and data leakage
45% of staff use GenAI, 67% via personal accounts
Approved AI tool list, data classification, DLP on managed devices, VAISS alignment
Common questions
Questions Australian leadership teams ask about this report.
Find out where the 2026 threat picture lands on your environment.
A 60-minute scoping call, then a written cybersecurity risk review against the DBIR themes. We map your environment to the six attack patterns, score your control coverage, and give you a sequenced lift plan. No obligation, plain language.
Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.

Remote Support