Verizon 2026 DBIR · 19th edition · Oct 2024 to Nov 2025

Refinement, not revolution.

The DBIR's own framing this year. The threat landscape changed in speed and scale, not in shape. Patching, identity, response and supplier discipline still decide whether you become a statistic.

This page is the Australian operator's reading of the 2026 report. Six attack patterns, the industry breakdowns that matter here, the APAC regional picture, and the controls that close each gap.

The dataset behind the report

Real incidents analysed

31,000+

Confirmed breaches

22,000+

Countries represented

145

Editions of the report

19

Largest single-edition breach dataset Verizon has ever published. The previous edition (2025) covered 22,052 incidents and 12,195 confirmed breaches.

Year on year

Eight numbers that moved between 2025 and 2026.

Green is good news for defenders. Red is not. The pattern is consistent: the controls people are actually deploying (MFA, conditional access) are working, but patching velocity and supplier discipline are losing ground against the volume.

Vulnerability exploitation as initial access

Now the #1 initial access vector for the first time in DBIR history.

20%

31%

Credential abuse as initial access

MFA and conditional access are working where deployed.

22%

13%

Ransomware involvement in breaches

SMBs make up 96% of victims in the dataset.

44%

48%

Third-party involvement in breaches

60% jump in twelve months, tripled in two years.

30%

48%

Human element present in breaches

Slight drop, but still the majority of all breaches.

68%

62%

Critical vulnerabilities fully remediated

Patch programmes are losing ground against the volume.

38%

26%

Median time to remediate critical CVEs

And edge-device CVEs are now exploited within hours.

32 days

43 days

GenAI use on corporate devices

67% of that use goes through personal, non-corporate accounts.

15%

45%

The six attack patterns

How every breach in the dataset gets classified.

The DBIR has used the same six-pattern taxonomy for nearly a decade. It is how the industry compares year to year. System Intrusion has now passed 50% for the first time, which tells you where attacker investment is going. The light bars behind each show where each pattern sat two years ago.

System Intrusion

53% of breaches

53%

2024

36%

Multi-step attacks: malware, hacking, ransomware. Now over half of all breaches.

Social Engineering

17% of breaches

17%

2024

17%

Phishing, pretexting, voice scams. Steady share, but tactics are shifting to mobile.

Basic Web Application Attacks

11% of breaches

11%

2024

25%

Stolen credentials against web apps. Down sharply as MFA adoption catches up.

Miscellaneous Errors

8% of breaches

8%

2024

11%

Misdelivery, misconfiguration, lost devices. The 'we did it to ourselves' bucket.

Privilege Misuse

6% of breaches

6%

2024

6%

Insider abuse of legitimate access. Stable, but harder to detect than external.

Denial of Service

5% of breaches

5%

2024

5%

Availability attacks. Disruptive, but rarely a confirmed data breach.

detailed look · How a breach actually unfolds

Five steps from foothold to domain compromise.

The DBIR has run this analysis for three editions now. The shape barely changes. What changes is the speed. In 2026 the median dwell time from first compromise to attacker objective is measured in days, not weeks. Each step in the chain is a chance to break it.

01

Initial foothold

Most commonly an unpatched edge device (firewall, VPN, remote-access appliance) or a phished user. 31% start here in the 2026 data.

Median time to first action: minutes from exploit.

02

Local recon

Attackers enumerate the host, list local admins, dump credentials from memory, and scan the local subnet for next-hop targets.

Living-off-the-land tools (PowerShell, WMI, PsExec) keep this stage invisible to legacy AV.

03

Lateral movement

Pass-the-hash, pass-the-ticket and RDP hops to a server with cached domain credentials. Often the first DC or backup server.

EDR with cross-host correlation is the chokepoint. Without it, this stage runs unopposed.

04

Domain compromise

Kerberoasting, golden ticket, or simple credential reuse on a Tier 0 system gets the attacker domain admin or Global Admin in Entra ID.

Tiered admin, dedicated PAW workstations and Just-in-Time access break the chain here.

05

Objective

Encrypt and demand ransom, exfiltrate data, deploy persistence for espionage, or simply sell the access to another group.

Median dwell time from foothold to objective is now under 5 days in the dataset.

detailed look · AI in the breach data

The first DBIR edition where AI shows up on both sides of the line.

The 2026 report devotes more pages to GenAI than any previous edition. Two distinct stories. Attackers are using AI to lower the cost of every step in their workflow. Defenders are losing data through personal AI accounts faster than policy can keep up.

Attacker uses

01

Target selection

GenAI assists with reconnaissance and lead scoring against potential victims.

02

Initial access tooling

Faster development of exploit kits and customised malware loaders.

03

Vulnerability research

LLM-assisted code review of public software for new CVE candidates.

04

Social engineering at scale

Personalised phishing, voice cloning, and conversational pretexting agents.

Defender exposures

01

Shadow AI usage

45% of employees regularly use GenAI on corporate devices, up from 15% in twelve months.

02

Personal account exfiltration

67% of that use is through personal, non-corporate accounts. Data leaves the tenant.

03

Prompt injection on agents

Emerging class of attack where a malicious document instructs the AI to act against the user.

04

Model and data-poisoning risk

Less common, but a growing concern for organisations training their own models.

The Australian read on this section

The Voluntary AI Safety Standard is the policy answer the OAIC and DISR have already published. Data classification, an approved AI tool list, and disabling personal-account AI on managed devices closes most of the defender exposures the DBIR is calling out.

VAISS guide
APAC spotlight

The Asia-Pacific picture looks different to the global one.

The DBIR runs a dedicated regional analysis every year. The APAC chapter consistently shows a higher concentration of malware and ransomware than the global average, driven by aggressive nation-state activity, a maturing criminal-as-a-service market in the region, and the same internet-facing patching gaps the global report calls out.

For Australian operators this matters. APAC numbers are a closer proxy for what hits Australian businesses than the all-region average. The control priorities are the same. The urgency is higher.

How we apply this in the Australian market

83%

of APAC breaches involved malware, up from 58% the previous edition

51%

of APAC breaches involved ransomware specifically, well above the global average

80%

of APAC breaches fall under the System Intrusion pattern

1 in 4

APAC breaches now involve a third-party as the entry point

Reference: Verizon 2025 and 2026 DBIR APAC regional chapters. The malware concentration in APAC has now been higher than the global average for three consecutive editions.

The Australian view

OAIC notifiable data breach data tells the Australian story.

The Verizon DBIR is the global benchmark. The Office of the Australian Information Commissioner publishes the canonical Australian view: who is notifying, why, and how often. The figures below are drawn from OAIC's published Notifiable Data Breaches statistics, which are the single most reliable source for breach trends in the Australian market.

1,205

notifiable data breaches received by OAIC in calendar year 2025.

The highest annual total since the NDB scheme commenced in 2018, up 8 per cent on 2024.

716

caused by malicious or criminal activity the majority of all 2025 notifications.

Cyber hacking remains the primary cause of breaches reported to the OAIC.

225

health service provider breaches the most commonly affected sector.

19 per cent of the annual total. Financial services followed on 157 notifications.

82%

of Australians are concerned about data breaches.

The top perceived privacy risk in the 2026 Australian Community Attitudes to Privacy Survey, up from 74 per cent in 2023.

Source: Office of the Australian Information Commissioner, calendar year 2025 Notifiable Data Breaches statistics, published 6 July 2026, and the 2026 Australian Community Attitudes to Privacy Survey. Figures as published by OAIC. Refresh expected when OAIC publishes the next reporting period.

By industry

The report runs a chapter for every major sector. Here is the operator's read.

Sector profiles drift year to year, but the structural pattern is consistent. Heavy-asset industries get ransomware. People-heavy industries get social engineering. Data-rich industries get espionage. Your sector tells you which lever moves first.

Healthcare

Misdelivery and supply-chain breach are the dominant patterns.

70%

of healthcare breaches involve a system intrusion (ransomware-heavy)

39%

involve a third party, supply chain remains the soft underbelly

$10.9M

average healthcare breach cost, the highest of any sector

Healthcare runs old kit on flat networks with a long tail of medical IoT. The DBIR data is unforgiving here.

Healthcare IT and security

Financial Services

Mature controls, but social engineering keeps landing.

60%

of financial breaches involve system intrusion

23%

involve social engineering, well above the global rate

75%

of finance attacks are financially motivated, not espionage

Best baseline in any sector. APRA CPS 234 makes it that way. The gap is now people, voice scams and pretexting.

Finance sector IT

Education

Espionage actors are increasingly active in the sector.

65%

of education breaches involve system intrusion

30%

involve external espionage actors, double the global rate

44%

involve credentials as part of the attack chain

Universities and large schools hold research, IP and student data. Identity hygiene is the single biggest lever.

Education IT and security

Manufacturing

OT and IT are converging, and the breach data shows it.

85%

of manufacturing breaches involve system intrusion or ransomware

97%

are financially motivated, this is a ransomware target sector

55%

involve a third party, typically a vendor or contractor

Production downtime is the leverage. Segmentation between IT and OT is the control that buys time during a hit.

OT and industrial security

Public Administration

Espionage and ransomware in roughly equal measure.

55%

of public sector breaches are financially motivated

33%

involve external espionage actors

72%

involve credentials as part of the chain

Federal, state and council operations are a mixed picture. Essential Eight ML2 is the realistic target here.

Government and public sector

Retail

Web applications and payment data remain the prize.

62%

of retail breaches target web applications directly

37%

involve payment card data as the stolen asset

Up

ransomware against retail is trending sharply upward

Web app hardening, PCI scope reduction and tested response planning. The fundamentals are still the spend.

Retail sector IT

Industry percentages aggregate Verizon 2025 and 2026 DBIR industry chapters. Cost figures from IBM Cost of a Data Breach 2025 (cross-referenced where the DBIR did not publish a dollar value).

From data to control

Six findings. Six operational controls. No theatre.

The DBIR doesn't tell you what to do. It tells you where the attackers are spending their time. This map turns each major finding into the engineering work that actually closes the gap, and shows you where in our service catalogue that work lives.

Vulnerability exploitation

31% of breaches, now the #1 entry vector

Patch SLA for internet-facing systems, exposure monitoring, edge-device hardening

Ransomware

48% of breaches, 96% of victims are SMBs

Immutable backups, EDR with 24x7 SOC, network segmentation, rehearsed response

Third-party / supply chain

48% of breaches, tripled in two years

Supplier access register, MFA on every supplier account, quarterly access review

Human element / social engineering

62% involve a person, voice and SMS pretexting rising

Phishing-resistant MFA, conditional access, DMARC enforcement, helpdesk verification

Credential abuse

13% of entry, but dominant in privilege escalation chains

Entra ID baseline, PAM for Tier 0, just-in-time admin, tiered administration model

Shadow AI and data leakage

45% of staff use GenAI, 67% via personal accounts

Approved AI tool list, data classification, DLP on managed devices, VAISS alignment

Common questions

Questions Australian leadership teams ask about this report.

Find out where the 2026 threat picture lands on your environment.

A 60-minute scoping call, then a written cybersecurity risk review against the DBIR themes. We map your environment to the six attack patterns, score your control coverage, and give you a sequenced lift plan. No obligation, plain language.

Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.