Verizon DBIR 2026: Exploits Overtake Credentials at 31% | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


For nineteen straight editions, credential theft sat at the top of Verizon’s Data Breach Investigations Report as the way attackers got in the door. That streak ended on May 19, 2026. The newly released 2026 DBIR shows software vulnerability exploitation climbing to 31% of breaches, up from 20% a year earlier, while stolen credentials remained a major breach pattern. It is the first time in the report’s 19-year history that exploiting a flaw beats stealing a password as the leading initial access vector.

The shift matters beyond a single statistic. Verizon’s analysts reviewed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries for this edition, covering the twelve months from November 1, 2024 through October 31, 2025. Ransomware climbed to 48% of breaches, third-party involvement was not reported at 48%, and the median time to fully resolve a critical vulnerability was not 43 days. Attackers are moving faster than defenders can patch, and the 2026 cybersecurity threat landscape now has the numbers to prove it.

Google · Preferred Sources

Don’t miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

Verizon’s 2026 DBIR Marks a Turning Point in How Breaches Start

The Data Breach Investigations Report has run since 2008, giving Verizon’s security research team one of the longest continuous breach datasets in the industry. Every year through 2025, some form of credential compromise, whether phished, purchased from an infostealer market, or reused from an old breach, sat at or near the top of how attackers got their first foothold.

The 2026 edition breaks that pattern. According to Verizon, exploitation of vulnerabilities became the most common initial access vector, appearing in 31% of breaches, while credential abuse fell to 13% (Verizon 2026 DBIR Healthcare Snapshot). That is not a marginal shift. It represents a 55% jump in exploitation’s share of breaches in a single year, and it pushes credential theft into second place for the first time since the report began.

Security teams that spent the last decade building password hygiene programs, MFA rollouts, and credential-monitoring tools now face a report telling them the bigger risk sits somewhere else entirely: the widening gap between when a vulnerability becomes public and when it actually gets patched.

Inside the 2026 Data Breach Investigations Report: The Numbers

Verizon published the 19th edition of the DBIR on May 19, 2026, built from incidents between November 1, 2024 and October 31, 2025. The report draws on more than 31,000 security incidents and 22,000-plus confirmed data breaches spanning 145 countries, making it one of the broadest annual snapshots of breach activity available anywhere (Verizon 2026 DBIR).

That scale is part of why the report carries weight with CISOs and boards every year. It is not one vendor’s telemetry or a survey of self-reported incidents. Verizon pulls case data from law enforcement agencies, incident response firms, information sharing groups like MS-ISAC, and its own investigations, then normalizes the findings into the initial-access, action, and asset categories security teams use to build defenses.

The 2026 numbers point to a threat landscape moving faster than the patch cycles most enterprises still run on. Ransomware, third-party exposure, and exploitation all grew year over year, while the report’s own framing ties the acceleration to what Verizon calls AI-driven speed, a new pressure pushing security strategy toward resilience rather than prevention alone.

Vulnerability Exploitation Overtakes Credential Abuse for the First Time in 19 Years

The headline number is straightforward. 31% of breaches in the 2026 DBIR started with an attacker exploiting a software vulnerability, up from 20% in the prior year. Verizon’s own announcement puts it plainly: nearly a third of all breaches, 31%, started with software vulnerability exploitation, overtaking stolen credentials as the top breach entry point for the first time in the report’s history (Verizon, “Breach entry point, 2026 DBIR finds”).

Credential abuse, the vector that topped or ran near the top of nearly every prior DBIR, fell to 13% this year, with no confirmed DBIR figure showing it rising to roughly 16% when pretexting-driven credential theft is folded in. That drop does not mean credential theft stopped happening. Stolen logins and session tokens still circulate by the billions across criminal marketplaces, a problem this site covered in depth when a database of 24 billion leaked credentials surfaced earlier this year. It means exploitation simply grew faster.

Two forces explain the crossover. Passkeys and phishing-resistant MFA have made stolen passwords less useful on their own, cutting into one of the oldest attacker playbooks. At the same time, the volume of newly disclosed CVEs, and the speed at which proof-of-concept exploit code appears after disclosure, has outpaced what most patch management programs can absorb.

Why Attackers Are Pivoting From Stolen Passwords to Unpatched Software

The economics changed. A stolen password used to be nearly turnkey for an attacker: log in, move laterally, escalate privileges. Widespread MFA adoption and passwordless authentication have made that path far less reliable, so attackers went looking for a faster, more scalable way in.

Unpatched software offers exactly that. A single flaw in a widely deployed product can open access to thousands of organizations at once, and 2026 gave attackers no shortage of targets. High-severity bugs disclosed this year included a SonicWall SMA zero-day rated CVSS 10.0 that stayed under active exploitation for 22 days before a fix landed, and an Adobe ColdFusion zero-day, also CVSS 10.0, that attackers weaponized within two hours of public disclosure. Both fit the exact pattern the DBIR describes: exploitation racing ahead of remediation.

Automated scanning and AI-assisted exploit development compressed the old timeline even further this year. Where attackers once needed days or weeks to turn a disclosed CVE into working exploit code, that window has shrunk to hours in some of 2026’s highest-profile cases, a pattern SecurityWeek’s own analysis of the report flagged as the defining shift of this DBIR cycle. Patch cycles built around monthly or quarterly cadences simply were not designed for that kind of speed.

Ransomware Hits a Record 48% of Breaches as Payouts Keep Shrinking

Ransomware keeps setting new highs in the DBIR dataset. It appeared in 48% of all breaches in the 2026 report, up from 44% in the previous year, a climb of 4 percentage points. One independent breakdown of the report put it bluntly: there has never been a DBIR edition where ransomware’s share went down.

The twist is what happens after the breach. Payment behavior is moving in the opposite direction of frequency. The median ransom paid dropped to $139,875, down from roughly $150,000 the year before, and 69% of ransomware victims refused to pay at all, leaving only 31% who did. Organizations are getting hit more often but capitulating less, a sign that backup and recovery maturity has genuinely improved even as initial compromise rates keep climbing.

That combination of more incidents but fewer, smaller payouts is reshaping the economics on the attacker side too. Groups that once relied on a handful of large one-off payments are increasingly running higher-volume, lower-yield operations instead, which helps explain why double and triple extortion, and data-auction tactics like the ones used by the CMD ransomware gang, have become more common through 2026.

The Infostealer-to-Ransomware Pipeline: A 95-Day Warning Window

One of the more actionable findings in the 2026 DBIR ties credential theft directly to ransomware risk, even as credential abuse fell as a standalone initial-access vector. Verizon’s analysis found that 27% of ransomware victims had no associated infostealer or credential leak event in the prior year. But among the 73% that did, half saw a credential or infostealer event within 95 days before the ransomware attack actually hit.

That 95-day window is effectively an early warning signal hiding in plain sight. Infostealer logs, the kind traded on criminal forums and increasingly swept up in mass leaks, are not just a password problem. They are a leading indicator that a ransomware operator may already be sitting inside the reconnaissance phase of an attack.

Security teams that monitor for their own domain’s credentials appearing in infostealer dumps, rather than treating that data as a lagging cleanup task, get a genuine head start. The DBIR data suggests that window closes fast. Ninety-five days from first exposure to full ransomware impact is not a lot of runway once the clock starts.

Third-Party and Supply Chain Risk Jumps to 48% of Breaches

Third-party involvement in breaches reached 48% in the 2026 DBIR, and breaches involving a third party increased by 60% year over year, according to Verizon’s official announcement (Verizon, “Breach entry point, 2026 DBIR finds”). A year earlier, that figure sat at 30%. Two consecutive years of steep increases have made vendor and partner risk one of the fastest-growing categories in the entire report.

2026 supplied plenty of real-world illustrations of the trend. The EY vendor breach exposed tax data and stayed unreported for 81 days before disclosure. The Conduent data breach hit 62.2 million records, becoming one of the largest breaches of the year by record count. Aflac’s Japan unit disclosed a second breach in as many years, and Charter’s Spectrum breach affected millions of confirmed customers with claims running far higher. Each traces back, in some form, to a vendor, partner, or shared-infrastructure relationship rather than a direct attack on the primary organization.

The pattern forces a rethink of what a security perimeter even means in 2026. When nearly half of breaches involve a third party, vetting a vendor’s SOC 2 report once a year no longer covers the actual exposure. Continuous monitoring, not periodic review, is what the data now argues for.

The Human Element Still Touches 62% of Breaches

Even with exploitation now leading initial access, people remain deeply embedded in how breaches unfold. The human element, which the DBIR defines broadly to include error, misuse, and social engineering, touched 62% of breaches in the 2026 report. Social engineering itself accounted for roughly 17% of breaches, the third most common attack pattern behind system intrusion, which sat at 61% in Verizon’s healthcare-sector breakdown.

Those figures do not contradict the exploitation headline. They run alongside it. A phishing email can be the delivery mechanism for a payload that then exploits an unpatched service. A misconfigured cloud bucket, a classic error-category incident, can expose the same kind of vulnerable software that gets picked up by automated scanners within hours of going live.

The practical takeaway for security teams is that the exploitation trend does not make security awareness training obsolete. It means the human element and the exploitation element are increasingly two stages of the same attack chain, rather than competing categories fighting over the same training budget.

The Patch Gap: Why Remediation Can’t Keep Pace With Exploitation

If exploitation is winning, patching is losing, and the DBIR’s remediation numbers explain why. Only 26% of critical vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog were fully remediated by organizations in 2025, down from 38% the year before (Verizon 2026 DBIR Healthcare Snapshot). Fewer critical, actively exploited flaws are getting fixed, not more.

Remediation is also getting slower in absolute terms. The median time for full resolution of a critical vulnerability increased to 43 days in 2025, up from 32 days the prior year, per the same Verizon analysis. That is an 11-day increase at exactly the moment attackers are compressing their own timelines from disclosure to exploit.

Microsoft’s own July 2026 Patch Tuesday, which shipped fixes for a record 570 CVEs including two zero-days already under active attack, illustrates the scale problem underneath the DBIR numbers. Security teams are not necessarily patching worse than before. They are being asked to triage and remediate a volume of disclosed vulnerabilities that keeps growing faster than headcount and automation can absorb.

Historical Context: How Breach Vectors Shifted From 2025 to 2026

Lining up the 2025 and 2026 DBIR editions side by side shows how sharply the last twelve months moved the needle on nearly every major metric Verizon tracks.

Metric2025 DBIR2026 DBIRYear-over-Year Change
Vulnerability exploitation (initial access)20%31%+55%
Credential abuse (initial access)Led all vectors13%Dropped to No. 2
Ransomware presence in breaches44%48%+4 points
Third-party/supply-chain involvement30%48%+60%
Median ransom payment~$150,000$139,875-6.8%
Ransomware victims who refused to payLower share69%Increased
CISA KEV vulnerabilities fully remediated38%26%-12 points
Median days to resolve a critical vulnerability32 days43 days+11 days

Every row points the same direction. Breaches are starting faster, spreading through more third parties, and taking longer to fully close out, even as ransom payments themselves shrink. That is the paradox at the center of the 2026 report: attackers are winning the speed race while losing some of the leverage they once had over payment.

Market Impact: Security Vendors Race to Close the Exploitation Gap

A breach report does not just describe attacker behavior. It also reshapes where security budgets go the following year. The 2026 DBIR’s exploitation findings arrive as enterprise security spending was already shifting from pure detection toward exposure management, patch orchestration, and continuous vendor risk scoring, a move Google Cloud’s own 2026 Cybersecurity Forecast anticipated months before Verizon’s data confirmed it. Expect that shift to accelerate through the rest of 2026.

Vulnerability Management and Patch Orchestration Vendors

The exploitation numbers are a direct tailwind for vulnerability management platforms built to close the gap between disclosure and patch. Tenable, Qualys, and Rapid7 compete most directly in this lane, each offering continuous scanning and risk-based prioritization aimed at cutting the 43-day median remediation window the DBIR flagged. Pricing and platform depth vary widely across the three, spanning roughly $15,000 entry packages up to enterprise deployments north of $500,000, depending on asset count and modules.

Identity, EDR, and Cloud Security Platforms

Further down the stack, endpoint detection and response tools from CrowdStrike, Microsoft Defender, and SentinelOne matter more than ever for catching what exploitation misses on the way in, since all three now claim close to full detection coverage in MITRE ATT&CK technique testing. On the identity side, the DBIR’s credential-abuse decline lines up with faster passkey and FIDO2 rollout, with passwordless methods now showing roughly 93% authentication success rates against a fraction of the phishing exposure of passwords and one-time codes. Cloud-native platforms like Wiz, Orca Security, and Prisma Cloud round out the response, targeting the misconfigurations and exposed services that let a disclosed CVE turn into an actual breach inside cloud environments. Meanwhile SIEM platforms including Microsoft Sentinel, Splunk, and Elastic remain the layer that has to correlate signals across all of the above once exploitation attempts start.

Vendor CategoryRepresentative VendorsCore ApproachDBIR Vector Addressed
Vulnerability & Exposure ManagementTenable, Qualys, Rapid7Continuous scanning, risk-based patch prioritizationExploitation (31%), patch gap
Endpoint Detection & ResponseCrowdStrike, Microsoft Defender, SentinelOneRuntime detection after initial accessPost-exploitation containment
Identity & Passwordless AuthenticationOkta, FIDO2/passkey platformsPhishing-resistant MFA, passwordless loginCredential abuse (13%)
Cloud-Native App ProtectionWiz, Orca Security, Prisma CloudCloud misconfiguration and exposure scanningCloud-hosted exploitation
SIEM & Security AnalyticsMicrosoft Sentinel, Splunk, ElasticLog correlation, breach detectionCross-environment visibility
Third-Party Risk ManagementContinuous vendor risk scoring platformsOngoing, not annual, vendor assessmentThird-party involvement (48%)

What This Means for Small and Mid-Size Businesses

Smaller organizations face a version of this shift that is arguably worse. Verizon’s most recent SMB-specific breakdown found ransomware present in 88% of SMB breaches, compared with 39% for larger enterprises, a gap that reflects how few small businesses run dedicated patch management or 24/7 detection.

Vulnerability exploitation compounds that problem. Large enterprises can often throw dedicated vulnerability management teams at a 43-day remediation window. Most small and mid-size businesses cannot. They tend to run lean IT teams covering patching alongside a dozen other responsibilities, which means the newly dominant attack vector plays directly to their weakest area.

The DBIR’s third-party findings matter here too, in both directions. SMBs are frequently the vendor in someone else’s supply chain, meaning their own patch discipline can now expose a much larger downstream customer. That dynamic gives smaller companies a business reason, not just a compliance one, to close the exploitation gap Verizon just quantified.

5 Predictions for Breach Trends Through 2027

Based on where the 2026 DBIR’s trend lines are heading, here is what the data suggests for the next twelve months:

  1. Vulnerability exploitation keeps climbing. With AI-assisted scanning compressing the disclosure-to-exploit window, expect the 2027 DBIR to show exploitation past 35% of breaches as automated tooling lets smaller attacker groups weaponize CVEs within hours rather than weeks.
  2. Ransomware presence keeps rising while payouts keep falling. Expect ransomware’s share of breaches to push past 50% even as the share of victims who pay drops further below the current 31%, as recovery maturity improves faster than attackers can adapt their pressure tactics.
  3. Third-party involvement becomes the single largest breach category. At 48% and climbing 60% year over year, supply-chain and vendor exposure is on pace to overtake every other category Verizon tracks within the next one to two editions.
  4. Credential abuse keeps sliding, but infostealer activity does not disappear. As passkeys and phishing-resistant MFA spread, stolen passwords will matter less as a direct entry point, while infostealer logs increasingly feed the ransomware pipeline rather than driving account takeovers on their own.
  5. Patch orchestration becomes a board-level metric. As the remediation gap widens, expect more organizations to report vulnerability response times to the board the way they already report uptime, with vendor consolidation favoring platforms that combine scanning, prioritization, and automated patching in one workflow.

Frequently Asked Questions About the 2026 Verizon DBIR

When was the 2026 Verizon DBIR released?
Verizon published the 19th edition of the Data Breach Investigations Report on May 19, 2026, covering incidents from November 1, 2024 through October 31, 2025.

What is the biggest change in the 2026 DBIR compared to prior years?
Vulnerability exploitation overtook credential abuse as the top initial access vector for the first time in the report’s 19-year history, rising to 31% of breaches while credential abuse fell to 13%.

How many breaches does the 2026 DBIR cover?
The report analyzes more than 31,000 security incidents and over 22,000 confirmed data breaches across 145 countries, one of the largest datasets Verizon has published to date.

Is ransomware still a major threat according to the 2026 DBIR?
Yes. Ransomware appeared in 48% of all breaches, up from 44% in 2025 and 32% in 2024, even as the median ransom payment fell to $139,875 and 69% of victims refused to pay.

Why did credential abuse fall in the 2026 DBIR?
Wider adoption of passkeys and phishing-resistant multi-factor authentication has reduced the value of a stolen password on its own, pushing attackers toward exploiting unpatched software instead.

How exposed are organizations to third-party breach risk in 2026?
Third-party involvement reached 48% of breaches, up 60% year over year, with real-world 2026 examples spanning tax services, business process outsourcing, insurance, and telecom vendors.

How long does it take organizations to patch critical vulnerabilities?
The median time to fully resolve a critical vulnerability rose to 43 days in 2025, up from 32 days the year before, while only 26% of CISA Known Exploited Vulnerabilities catalog entries were fully remediated.

Where can I read the full 2026 DBIR report?
The complete report, along with industry-specific snapshots for healthcare and other sectors, is available directly from Verizon’s DBIR resource page.

Related Coverage

For more on the vendors and threats shaping the 2026 breach landscape, see:

Sofia Lindström

Editor-in-Chief

Sofia Lindström is the Editor-in-Chief at Tech Insider, where she leads editorial strategy and oversees coverage across AI, cybersecurity, and enterprise technology. With over a decade in Swedish tech journalism, she previously served as technology editor at Dagens Industri and covered the Nordic startup ecosystem for Breakit. Sofia holds an MSc in Media Technology from KTH Royal Institute of Technology and is a frequent speaker at Web Summit and Slush. She is passionate about making complex technology accessible to business leaders.

View all articles

——————————————————–


Click Here For The Original Source.

.........................

National Cyber Security

FREE
VIEW