The headline change this year: vulnerability exploitation overtook stolen credentials as the leading way attackers get in. Verizon's 2026 Data Breach Investigations Report put it at around 31% of breaches — the first time in the report's nineteen-year history that exploits led. Mandiant's separate incident-response data agreed, at 32%.
That's the finding. Below is the context, including where the major reports disagree with each other, because they do.
The numbers, with their sources
| What | Figure | Source |
|---|---|---|
| Leading breach vector | Vulnerability exploitation, ~31% | Verizon DBIR 2026 |
| Credentials involved in | ~39% of breaches | Verizon DBIR 2026 |
| Human element involved in | ~62% of breaches | Verizon DBIR 2026 |
| Third party involved in | ~48% of breaches, up 60% year on year | Verizon DBIR 2026 |
| Median attacker dwell time | 14 days, up from 11 | Mandiant M-Trends 2026 |
| Second-biggest intrusion vector | Voice phishing, ~11% | Mandiant M-Trends 2026 |
| Average time from access to lateral movement | ~29 minutes | CrowdStrike 2026 |
| US reported cybercrime losses, 2025 | $20.9 billion | FBI IC3 |
Two caveats worth carrying with you. The IC3 figure covers only losses reported to the FBI by US complainants, and underreporting is severe. And the DBIR is built from incidents contributed by partner organizations, so year-on-year changes can partly reflect who contributed rather than what happened.
Why exploitation overtook credentials
Not because credentials stopped working. They appear in 39% of breaches — they're just no longer the most common front door.
What changed is the speed at which flaws get weaponized. VulnCheck found that 28% of newly catalogued exploited vulnerabilities were being exploited within a day of public disclosure in early 2025. Mandiant measured average time-to-exploit falling from around 32 days in 2021–22 to about five days by 2023, and has kept falling.
Meanwhile defenders got slower. Median time to patch worsened to roughly 43 days, and organizations remediated only about 26% of the vulnerabilities CISA lists as actively exploited — down from 38%. Both figures are from the 2026 DBIR.
Attackers sped up. Defenders slowed down. The gap is the story.
The edge devices are the worst of it. VPN concentrators, firewalls and gateways sit on the internet by definition, can't run endpoint monitoring software, and have been exploited in waves — Ivanti, Fortinet, Citrix, Palo Alto, Cisco — often before patches exist. In one case documented by Mandiant, an implant sat undetected on this class of device for roughly 400 days.
The biggest incidents still start with a phone call
Here's the tension worth understanding: the aggregate statistics say exploitation leads, but the largest incidents of the last three years mostly didn't start that way.
MGM and Caesars, the UK retail wave, and much of the Scattered Spider activity started with someone calling an IT help desk and asking for a password reset. Voice phishing rose to about 11% of intrusions and second place overall, while email phishing fell to 6% as technical controls improved.
Both things are true. Most breaches start with an exploit; many of the worst ones start with a conversation. Your defences need to cover both, and help-desk verification procedure costs nothing but discipline.
Ransomware: more attacks, less money
Claimed attacks rose roughly 50% to record levels in 2025, per Chainalysis. Payments fell 8%, to about $820 million traced on-chain. The share of victims who pay hit an all-time low near 28% — and just 15% for attacks where data was stolen but nothing encrypted.
We've written that up separately in ransomware economics, because the divergence between attack volume and revenue is the most encouraging trend in security right now and deserves more than a paragraph.
The tactical shift to watch: attackers now target recovery capability first — backup infrastructure, identity systems, virtualization management. Protecting those three as crown jewels is the current best practice.
Your suppliers are now half the problem
Third-party involvement in breaches reached roughly 48%, up 60% year on year. That's not a slow trend; it's a step change.
The mechanism has shifted too. It used to mean a compromised software update. Now it increasingly means connected applications — the OAuth integrations quietly granted access to your email, your CRM, your file storage. In August 2025, stolen tokens from a single chatbot integration allowed data export from more than 700 organizations' Salesforce environments.
Most organizations cannot currently produce a list of which third-party applications have access to their data. That inventory is the control.
What the reports disagree about
Presenting this honestly matters more than smoothing it over.
Ransomware's share of breaches: Verizon says 48%; IBM says 39% of incidents. Different datasets, different definitions. Don't blend them.
Breach cost: IBM's 2025 edition reported a global average of $4.44 million, down 9%. The 2026 edition reported $4.99 million, a record, up 12%. Both are real; they're consecutive editions of a survey with a changing sample. And the figure excludes mega-breaches and skews to large enterprises, so it tells a ten-person company nothing useful.
Ransom payment rates range from 15% to 50% depending on who's counting. Coveware sees negotiated cases; Sophos surveys enterprise IT leaders. They're measuring different populations.
AI's role is where the widest gap sits. IBM attributes about a quarter of malicious breaches to AI-enabled activity. Mandiant's assessment is that most 2025 breaches still stem from human and systemic failures rather than AI. Our read is in the AI hype check.
What to actually do about it
The threat data points at five things, in order.
Patch what's being exploited, fast, using CISA's exploited-vulnerabilities catalog as the floor and internet exposure as the tiebreaker. Thirty-day patch windows for internet-facing systems are obsolete.
Make MFA phishing-resistant, starting with administrators. Push notifications and text codes are routinely defeated.
Harden help-desk identity verification. Callback to a number of record; no resets on caller-supplied information alone.
Protect recovery: immutable backups, tested by actual restore, with identity and hypervisor infrastructure treated as your most sensitive systems.
Inventory third-party access, including OAuth-connected apps, before you need the list during an incident.
None of these require a new product. All of them appear in minimum viable security.
What to do next: Check whether your organization can produce a list of every third-party application with access to your email and CRM. If it can't, that's this month's project.
Related: Ransomware: attacks up, payments down · Minimum viable security · Seven years that changed cybersecurity · AI and security: a hype check
Sources: Verizon 2026 DBIR (May 2026) — breach vectors, third-party involvement, patch timelines, KEV remediation. Mandiant M-Trends 2026 (Mar 2026) — initial infection vectors, dwell time, time-to-exploit. CrowdStrike 2026 Global Threat Report (Feb 2026) — breakout time. FBI IC3 2025 Annual Report (Apr 2026) — reported US losses. Chainalysis Crypto Crime Report 2026. VulnCheck — exploitation-within-one-day analysis. IBM Cost of a Data Breach, 2025 and 2026 editions.