Only a few years ago, the cybersecurity conversation was largely about stopping malware from crossing the perimeter. In 2026, we’re defending cloud identities, software supply chains, mobile devices, application programming interface (API) keys, session tokens, autonomous agents, and employees who’ve just received a surprisingly convincing text from “the CEO” complete with deep-faked video.
The attack surface hasn’t just expanded. It's faster, more interconnected, automated, and far more dependent on access nobody actually recalls granting.
The most important development in this year’s data is that exploiting software vulnerabilities has overtaken credential abuse as the leading route into an organization. That doesn’t mean identity is suddenly safe. Attackers still need identities, permissions, and tokens to move from an initial foothold to something worth stealing. Initial access gets them through the door; excessive privilege gives them the full tour.
Following last year's 2025 cybersecurity statistics, this year's collection focuses exclusively on current research published in late 2025 or 2026 (so far). It brings together observed breaches, reported crimes, security surveys, insurance claims, and market forecasts. These are different datasets, so we shouldn’t add them together and automatically announce the internet is 347% doomed.
Used properly, however, they provide a practical picture of the latest 2026 cybersecurity trends, where controls are failing, what we can do about it, and tasty sound bites to add to C-suite slide decks when seeking internal funding or for cybersecurity training.
Ten 2026 cybersecurity statistics to brief the board
If we only have ten minutes before everyone starts discreetly answering email, these are the numbers to use.
- The Verizon 2026 Data Breach Investigations Report analyzed more than 22,000 confirmed data breaches across 145 countries. Its dataset covers incidents occurring between November 2024 and October 2025, making it one of the broadest available views of the current threat landscape.
- Exploitation of software vulnerabilities accounted for 31% of initial breach access, a 55% year-over-year increase. It overtook stolen credentials as the leading route into an organization.
- Third-party involvement increased 60% and was present in 48% of breaches. Nearly half of the problem may now arrive with somebody else’s logo on it.
- Ransomware also appeared in 48% of breaches, up from 44% in the previous Verizon dataset.
- The FBI’s 2025 Internet Crime Report, published in April 2026, recorded 1,008,597 complaints and nearly $21 billion in reported losses.
- In the World Economic Forum’s Global Cybersecurity Outlook 2026, 94% of respondents expected artificial intelligence (AI) to be the most significant driver of cybersecurity change during 2026.
- The proportion of organizations assessing the security of their AI tools increased from 37% to 64%, although roughly one-third still had no AI security validation process before deployment.
- The Identity Theft Resource Center’s H1 2026 report recorded approximately 471.2 million victim notices in the first half of 2026, compared with 297.5 million during the whole of 2025.
- The UK government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses had identified a breach or cyberattack during the preceding 12 months. The rate reached 65% among medium-sized businesses and 69% among large businesses.
- Gartner forecasts that global information-security spending will reach $244 billion in 2026, representing constant-currency growth of 11.6%, according to its 2026 worldwide information-security forecast.
The board-level message isn’t only that spending and attacks are rising together. It is that resources need to follow the paths through which business disruption now spreads: exploitable systems, powerful identities, ungoverned third parties, and incomplete recovery plans.
How attackers are getting in during 2026
Vulnerability exploitation taking the top position is strategically important. It means vulnerability management can’t remain a monthly scan followed by a spreadsheet large enough to be visible from space.
- The National Institute of Standards and Technology (NIST) reported that Common Vulnerabilities and Exposures (CVE) submissions increased 263% between 2020 and 2025, according to its April 2026 National Vulnerability Database update.
- CVE submissions during the first three months of 2026 were nearly one-third higher than during the equivalent period in 2025.
- Verizon found that the median time required to fully resolve a critical vulnerability had reached 43 days, almost two weeks longer than in its previous dataset.
- Only 34% of UK businesses had a policy requiring software security updates to be applied within 14 days.
- Even among large UK businesses, only 73% had a 14-day patching policy. The rate fell to 20% among charities.
- The Anti-Phishing Working Group reported that phishing attacks increased 10.1% during Q2 2026. Its Q2 phishing activity summary recorded 425,808 attacks in June alone, the highest monthly volume since April 2023.
- Verizon’s phishing simulations found that mobile entry points, including telephone calls and text messages, produced 40% higher median click rates than email-based attacks.
We don’t need to decide if it’s vulnerabilities or credentials that deserve this quarter's security budget. We need both. Internet-facing systems require risk-based remediation, while privileged access needs to remain difficult to obtain and easy to remove.
Traditional cybersecurity passwords are only one part of that access problem. Session cookies, API tokens, browser sessions, service accounts, and federated identities can all let an attacker operate without repeatedly presenting a password.
Identity and cloud security statistics for 2026
Cloud access is a particularly attractive basket of goodies because it can lead directly to data, infrastructure, and the control plane that administers both. It also tends to be generously permissioned because nobody wants to interrupt a deployment at 16:55 on a Friday before the holidays.
- In a point-in-time cloud-exposure dataset included in the Verizon report, 37% of organizations had an administrator account without multi-factor authentication (MFA) on an Infrastructure as a Service (IaaS) platform. On Snowflake, the corresponding figure was 14%.
- Only 23% of third-party organizations fully remediated missing or improperly secured cloud MFA findings in Verizon’s dataset.
- Resolving half of the identified weak-password and permission-misconfiguration findings took almost eight months.
- In the UK, only 47% of businesses required two-factor authentication. Adoption reached 90% among large businesses but remained below half across the wider business population.
- The SANS 2026 State of Identity Threat Detection and Response found that 55% of surveyed organizations experienced an identity-related compromise, even though 85% reported using identity threat detection and response tools.
- Although 68% detected identity attacks within 24 hours, only 55% contained them within the same period. Detection without prompt containment is essentially a well-observed fire.
- 75% of SANS respondents reported growth in non-human identities, including service accounts and API keys. Only 8% rotated most of those credentials every 90 days.
- 73% of respondents used agentic AI or automations requiring credentials, but no single governance control—such as approvals, audit trails, or sandboxing—was used by more than 40%.
The identity findings are especially important because preventing initial access and limiting post-compromise movement are separate jobs. A patched server doesn’t repair an excessive cloud role. MFA doesn’t remove an unused administrator. A security information and event management (SIEM) alert doesn’t automatically revoke a stolen token.
Finding compromised credentials is useful, but we also need to know what those credentials can reach. That requires visibility into effective entitlements, not merely a directory of account names.
This is where cloud infrastructure entitlement management earns its keep. We need to understand privileges across Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), Snowflake, and Software as a Service (SaaS) applications as one connected access problem.
Non-human identities deserve the same attention. Effective service account security requires ownership, credential rotation, limited scope, usage monitoring, and a reliable retirement process. “Created by someone who left in 2022” isn’t an ownership model.
Ransomware statistics and the real cost of interruption
Ransomware remains a large part of the breach landscape, but the economics are changing. More victims are refusing to pay, and median payments are declining. Unfortunately, attackers appear to have responded by becoming less sentimental about encryption and more enthusiastic about theft, disruption, and extortion.
- Ransomware’s presence in confirmed breaches increased from 44% to 48% in the 2026 Verizon DBIR.
- 69% of ransomware victims didn’t pay a ransom, continuing an upward trend in nonpayment.
- Among organizations that did pay, the median payment declined from $150,000 to $139,875.
- Verizon’s 2026 Breach Impact Study, based on cyber-insurance claims, attributed 32% of ransomware losses to extortion and 26% to business interruption.
- 48% of ransomware claims recorded neither data-restoration costs nor an extortion payment. This may include unsuccessful encryption, data-only extortion, inconsequential impact, or incidents investigated after a criminal group made an unverified claim.
- Only 49% of UK businesses had a policy against paying ransomware demands. Another 24% didn’t know whether such a policy existed.
The declining payment rate is encouraging, but “we probably won’t pay” isn’t an incident-response strategy. Recovery depends on knowing which services must return first, whether backups genuinely work, who can authorize emergency changes, and how responders will obtain access when the ordinary identity systems are unavailable.
Permanent administrative privilege is often defended as an emergency measure. In practice, zero standing privileges can support emergency response by making elevated access temporary, attributable, and available through a controlled workflow. We want responders to move quickly. We don’t need every account to remain powerful forever just in case Tuesday gets exciting.
Third-party and supply-chain cybersecurity statistics
Modern organizations don’t have a perimeter so much as a large extended family of suppliers, contractors, integrations, repositories, and platforms. Some are well governed. Others still have an administrator account belonging to a consultant called Steve.
- The Identity Theft Resource Center connected 280.6 million H1 2026 victim notices to only 38 initial supply-chain compromises. Those incidents ultimately affected 206 organizations.
- Only 15% of UK businesses formally reviewed cybersecurity risk from their immediate suppliers, while 6% reviewed their wider supply chain.
- Among large UK businesses, the figures improved to 48% for immediate suppliers and 24% for the wider supply chain. Even at this level, most wider ecosystems weren’t formally reviewed.
- In the World Economic Forum survey, 65% of large companies by revenue identified third-party and supply-chain vulnerabilities as their greatest challenge to cyber resilience, up from 54% in 2025.
- 74% of highly resilient organizations assessed supplier security, compared with 48% of organizations reporting insufficient resilience.
Supplier questionnaires have their place, but they don’t tell us whether an external administrator still has production access six months after an engagement ended. Effective secure vendor access should be approved for a purpose, limited to the necessary systems, monitored while active, and removed automatically when the work ends.
Third-party concentration also changes incident planning. If one identity provider, repository, data processor, or managed service provider is unavailable, our response procedures need an alternative route that doesn’t depend on the failed service.
AI cybersecurity statistics for 2026
AI occupies three different roles in the 2026 landscape. Attackers use it to work faster, defenders use it to process more information, and organizations deploy it as a new class of application with its own data, identity, and privilege risks.
Bundling those three subjects together produces excellent conference slides and questionable security architecture.
- 87% of World Economic Forum respondents identified AI-related vulnerabilities as the fastest-growing cyber risk during 2025.
- Data leakage associated with generative AI was the leading AI security concern for 34% of respondents, followed by improved adversarial capabilities at 29%.
- 77% of organizations reported adopting AI for cybersecurity.
- The leading defensive uses were phishing detection at 52%, intrusion and anomaly response at 46%, and user behavior analytics at 40%.
- The most frequently reported obstacles to using AI in security were inadequate knowledge or skills at 54%, the need for human oversight at 41%, and uncertainty about risk at 39%.
- The UK government found that 21% of businesses had adopted AI. Among organizations using, adopting, or considering it, only 24% had security processes in place, while 31% had no plans to introduce them.
- The FBI recorded 22,364 complaints involving AI and almost $893 million in reported losses. This was the first time AI received a dedicated section in the Internet Crime Complaint Center report.
- Verizon found verifiable generative-AI research or use across a median of 15 different attack techniques, from identifying vulnerabilities to developing malicious code.
The biggest AI identity risk isn’t that an agent becomes moody and refuses to open the pod bay doors. It is that an automated system receives broad, durable credentials, operates at machine speed, and lacks a clearly accountable owner.
Practical AI security means treating agents as identities. Each needs an owner, an approved purpose, narrowly scoped permissions, protected credentials, observable activity, and an expiration or retirement condition. The principle of least privilege doesn’t become optional because the account is synthetic.
Phishing, smishing, and fraud statistics
Security awareness training has spent years teaching us to inspect email links. Attackers have noticed. They’re now meeting people through text messages, calls, social media advertisements, collaboration platforms, and convincing impersonations.
- The Anti-Phishing Working Group recorded a 40% increase in smishing, or phishing delivered through Short Message Service (SMS) texts, between Q1 and Q2 2026.
- Wire-transfer business email compromise (BEC) attacks increased 88%, while the amount criminals attempted to steal increased 45% to an average of $61,732 per attempt.
- Phishing was identified by 38% of all UK businesses and by 88% of businesses that detected any breach or attack.
- Americans over the age of 60 reported approximately $7.7 billion in cyber-enabled fraud losses, 37% more than in 2024.
- Cryptocurrency-related complaints produced more than $11 billion in reported losses across 181,565 complaints.
- In the World Economic Forum survey, 73% of respondents said they or someone in their personal network had been affected by cyber-enabled fraud during 2025.
Training now needs to address the transaction, not only the communication channel. We should independently verify changes to bank details, unusual access requests, credential resets, and urgent instructions, regardless of whether they arrive by email, telephone, Slack, Microsoft Teams, or an unusually charismatic video call.
What the 2026 cybersecurity statistics mean in practice
The statistics point toward a security model built around speed, context, and containment.
- Prioritize exploitable risk. CVE volume is too high for flat remediation queues. Known exploitation, internet exposure, asset importance, available privilege, and potential business impact should determine urgency.
- Measure containment, not only detection. Alerting within minutes is less impressive if a compromised identity remains active for a day. Mean time to revoke access, isolate sessions, rotate credentials, and remove privilege belongs beside mean time to detect.
- Treat identity as infrastructure. Human users, service accounts, workloads, contractors, integrations, and AI agents all need ownership and lifecycle controls.
- Reduce privilege before an incident. It is much easier to reduce standing access during ordinary operations than to determine which of 600 administrators is legitimate while ransomware is spreading.
- Bring suppliers into the operating model. Contractual language matters, but so do current access records, notification routes, log availability, and joint exercises.
- Test recovery with the people who’ll perform it. A plan hidden in a policy portal is documentation, not readiness. Test what happens when identity services, cloud consoles, communications channels, or key suppliers are unavailable.
- Govern AI access before scale arrives. Agentic systems can make decisions and invoke tools far faster than human operators. Their permissions should be temporary where possible, constrained by context, and continuously reviewed.
The 2026 cybersecurity landscape rewards those attackers who can exploit small gaps at high speed, notably with an AI at their side. Our advantage is that many of those gaps remain understandable: an unpatched service, an unprotected administrator, a forgotten vendor, an unowned service account, or a token that never expires.
None of that’s particularly futuristic. It’s simply unfinished access management, moving much faster than it used to.
Find the access risks hiding behind the statistics
Vulnerability exploitation may open the door, but excessive permissions, standing administrators, orphaned accounts, and ungoverned service identities determine how far an attacker can go.
Start a Trustle free trial to discover risky cloud access, review unused entitlements, and replace permanent privilege with controlled, just-in-time access.




