
What the document says
Verizon's 2026 Data Breach Investigations Report, described on its own landing page as covering the largest number of breaches it has ever examined in a single report, analysed more than 31,000 security incidents and over 22,000 confirmed data breaches across 145 countries, contributed by close to a hundred organisations including incident responders, forensics firms, law enforcement agencies and insurers. The executive summary states that breaches with third-party involvement increased 60 percent from the prior year's dataset, reaching 48 percent of total breaches. The report defines its two core terms precisely: an incident is a security event that compromises the integrity, confidentiality or availability of an information asset, while a breach is an incident that results in the confirmed disclosure, not just potential exposure, of data to an unauthorised party. Contributed cases are classified using VERIS, a shared vocabulary for actors, actions, assets and attributes that lets Verizon aggregate incidents from many different contributing organisations into one comparable dataset.
Confidence and limits
The percentage and its year-over-year framing come directly from Verizon's own executive summary, which is strong evidence of what the current contributed dataset shows. It is not evidence that third-party involvement in breaches generally rose by that amount across every breach everywhere: the DBIR dataset is built from organisations that chose to contribute cases, using VERIS classifications applied by each contributor, not a random sample of every breach that occurred. A single-year jump in a contributed dataset can also reflect a change in which organisations contributed data, or in how consistently they tagged third-party involvement, rather than only a change in the underlying rate.
Why it mattered
Third-party involvement had already been a growing theme in prior editions, and a sharp single-year increase in a widely cited report tends to shape how boards and regulators frame vendor-risk conversations for the following year. Because the report's own definitions distinguish a confirmed breach from a broader incident, a figure quoted without that distinction can overstate how many incidents actually resulted in confirmed data disclosure.
Defensive takeaway
When citing this figure, state that it describes a contributed dataset's confirmed breaches, not a global rate, and check whether your own vendor incidents would count as VERIS-classified breaches or lesser incidents.
- Do we track which of our own incidents involved a third party, using a definition consistent with how we would report it externally?
- Are we distinguishing incident from breach the way this report's own definitions do, or using the terms interchangeably?
- Would our vendor-risk review change if this specific percentage were revised in a later edition?
A contributed dataset's year-over-year swing is a prompt to look at vendor exposure more closely, not a precise national or global rate. Reading the figure alongside the report's own definitions keeps the takeaway proportionate to what was actually measured.
Treat the 48 percent figure as a contributed-dataset statistic with the report's own definitions attached, not a global rate for every breach.
Verizon's own current report pages establish this edition's headline third-party involvement figure and its formal definitions of incident and breach. They do not disclose whether the contributor mix itself changed in a way that would partly explain the year-over-year increase.
Sources & reading trail
States that the 2026 edition analysed the largest number of breaches yet examined, with figures on incidents, breaches, countries and contributors.
vendor-primary · Source published: Not established · Retrieved: 16 September 2026
States that breaches with third-party involvement rose 60 percent year over year to 48 percent of breaches, and defines incident and breach.
vendor-primary · Source published: Not established · Retrieved: 16 September 2026
Describes the VERIS actor, action, asset and attribute schema Verizon uses to classify contributed incident and breach data.
project-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.