Cybersecurity Statistics 2026: Breaches, Costs, Phishing
The average data breach now costs $4.99 million, a record (IBM and Ponemon Institute, Cost of a Data Breach Report, 2026). A person was involved in 62% of breaches (Verizon Data Breach Investigations Report, 2026). Americans reported $20.877 billion in cybercrime losses to the FBI in 2025 (FBI Internet Crime Complaint Center, 2025 IC3 Annual Report, 2026).
Every figure below comes from the newest edition of a primary report, with vendor data flagged. Four of the field’s most repeated numbers do not hold up, and they get their own section.
How much does a data breach cost in 2026
$4.99 million is the global average cost of a data breach, up 12% in a year (IBM, 2026). The study covered 602 organizations breached between March 2025 and February 2026.
$11.5 million is the U.S. average, up 11% from $10.22 million and the highest of any country or region studied (IBM, 2026).
$6.64 million is the healthcare average, the costliest industry for the 13th year running, though down 10.5% from $7.42 million (IBM, 2026).
247 days is the mean time to identify and contain a breach, a 2.5% rise that ended a five-year decline (IBM, 2026).
$1.93 million is what organizations using security AI and automation extensively saved per breach, and they closed breaches 65 days faster (IBM, 2026). IBM sells these tools, so read it as such.
$5.29 million was the average cost of breaches that began with voice or SMS phishing, the most expensive entry point, used in 17% of attacks. Phishing was the top attack vector for the fourth straight year (IBM, 2026).
What percentage of data breaches involve human error
62% of breaches involved the human element, up from 60% (Verizon DBIR, 2026). The 19th edition analyzed more than 31,000 incidents and more than 22,000 confirmed breaches in 145 countries.
31% of breaches began with an exploited vulnerability, which passed credential abuse (13%) as the top way in for the first time (Verizon DBIR, 2026).
16% of breaches involved phishing, unchanged from the prior year. Click rates in simulations run over voice and text were 40% higher than over email (Verizon DBIR, 2026).
48% of breaches involved a third party, a 60% jump in a year (Verizon DBIR, 2026).
14 days is the global median dwell time, up from 11. Exploits led initial infection vectors at 32%, voice phishing rose to 11%, and email phishing fell to 6% of intrusions (Mandiant M-Trends 2026, 2026).
How much money is lost to cybercrime each year
$20.877 billion in losses was reported to the FBI in 2025, up 26%, across 1,008,597 complaints. The average loss was $20,699 (FBI IC3, 2026). These are U.S. complaints only.
$8.65 billion went to investment fraud, the largest category by loss, on 72,984 complaints (FBI IC3, 2026).
$3.05 billion was lost to business email compromise across 24,768 complaints, second by loss (FBI IC3, 2026). The phishing complaint count sits in our email statistics.
3,611 ransomware complaints reported about $32 million in losses, a figure the FBI says excludes lost business, time and wages (FBI IC3, 2026).
How many phishing attacks happen per quarter
1,069,681 phishing attacks were recorded in the second quarter of 2026, up 10.1% from the first. June’s 425,808 was the highest monthly total since April 2023 (APWG Phishing Activity Trends Report, Q2 2026, 2026).
$61,732 was the average amount requested in wire-transfer BEC attacks, up 45% from $42,663, while the number of such attacks rose 88% (Fortra data in APWG, 2026).
“Over 99.9 percent” of account compromise attacks can be blocked by multifactor authentication. That line comes from an August 20, 2019 Microsoft Security blog post, so date it 2019.
Ransomware: how many victims pay, and how much
48% of all breaches involved ransomware, up from 44%. 69% of victims did not pay, and the median payment fell to $139,875 from $150,000 (Verizon DBIR, 2026).
79% of ransomware attacks started with compromised identities. Malicious email (26%) and phishing (24%) replaced exploited vulnerabilities as the top root causes (Sophos State of Ransomware 2026, 2026). Sophos sells security software.
48% of organizations whose data was encrypted paid the ransom. Average recovery cost reached $1.7 million, and 55% recovered within a week (Sophos, 2026).
$1,880,612 was the average ransom payment in Q2 2026, up 176%, while the median fell 50% to $150,000. A few very large payments moved the average (Coveware by Veeam, 2026).
How often small businesses get attacked
7,152 confirmed breaches in the 2026 DBIR hit small and medium-sized businesses. Financial motives accounted for 100% of them, and 55% involved a third party (Verizon DBIR, 2026).
43% of UK businesses identified a breach or attack in the past 12 months: 42% of micro businesses, 46% of small, 65% of medium and 69% of large (UK Government Cyber Security Breaches Survey 2025/2026, 2026). Phishing reached 38% of businesses, by far the most common type.
£0 was the median perceived cost of a UK business’s most disruptive breach. The top 5% of cases cost £4,000 or more (UK Government, 2026).
81% of U.S. small businesses reported a cyberattack, a data breach or both in the past year, and more than 38% passed cleanup costs to customers through price increases (Identity Theft Resource Center 2025 Annual Data Breach Report, 2026).
How many cyberattacks use AI
One in four organizations that suffered a malicious attack said it was AI-driven, a 56% increase, led by deepfake impersonation and AI-enabled malware. Those attacks added about $1 million per breach (IBM, 2026).
22,364 complaints to the FBI carried AI-related information in 2025, with losses over $893 million (FBI IC3, 2026).
15 is the number of documented attack techniques the median threat actor researched or used AI help for (Verizon DBIR, 2026). Employee-side AI risk is in AI in the workplace statistics and AI agent statistics.
Four famous cybersecurity statistics that do not check out
“60% of small businesses close within six months of a cyber attack.” Usually credited to the National Cyber Security Alliance, which has disowned it in writing: “This statistic was not generated from NCSA research, and we cannot verify its original source” (NCSA statement). NCSA calls it a “third-party 2011 statistic” and recommends against using it. We found no study behind it.
“Cybercrime will cost $10.5 trillion annually by 2025.” A projection published by Cybersecurity Ventures, a research and publishing firm, in November 2020. It assumed 15% annual growth from a $3 trillion estimate for 2015 and counts lost productivity among the costs. The target year has passed and it remains a forecast. The FBI’s measured figure, $20.877 billion for 2025, covers U.S. complaints only, so the two are not comparable in scope.
“43% of cyber attacks target small businesses.” The source is the 2019 Verizon DBIR, which said “43% of breaches involved small business victims.” That is a share of breach victims in one year’s dataset, not a share of attacks. In the 2026 edition, SMBs account for 7,152 of more than 22,000 breaches, about a third by our arithmetic.
“95% of breaches are caused by human error.” IBM’s 2014 Cyber Security Intelligence Index said “over 95 percent of all incidents investigated recognize ‘human error’ as a contributing factor” (archived copy). That described incidents at IBM’s own clients 12 years ago. Current numbers: 62% of breaches involve the human element (Verizon DBIR, 2026), and IBM attributes 23% of breaches to human error as the root cause (IBM, 2026).
Where the urgent email meets a busy inbox
Much of the fraud above arrives as an ordinary-looking message (an invoice, a changed bank detail, a request marked urgent) handled fast by someone like Claire with a full inbox waiting. Carly takes the routine load off that person, handling email triage, scheduling and follow-up, so the messages that deserve a slow, careful read get one. Carly connects to thousands of apps. For the volume side of the problem, see our email statistics and the best AI email assistants.
FAQ
What is the average cost of a data breach in 2026? $4.99 million globally, a record and up 12% (IBM, 2026). The U.S. average is $11.5 million, and the mean time to identify and contain a breach is 247 days.
What percentage of breaches involve human error? 62% of breaches involve the human element (Verizon DBIR, 2026), and IBM attributes 23% of breaches to human error as the root cause (IBM, 2026). The popular 95% figure traces to a 2014 IBM report on incidents at its own clients.
How much money is lost to cybercrime each year? The FBI received 1,008,597 complaints reporting $20.877 billion in losses in 2025, up 26% (FBI IC3, 2026). That covers U.S. complaints only. Business email compromise accounted for $3.05 billion.
Do 60% of small businesses close within six months of a cyber attack? No source supports it. The National Cyber Security Alliance, usually credited, says the statistic was not generated from its research. A measured alternative: 43% of UK businesses identified a breach or attack in a year (UK Government, 2026).
Related: Email Statistics · Small Business AI Statistics · AI in the Workplace Statistics · AI Agent Statistics · Workplace Automation Statistics
Ready to automate your busywork?
Carly schedules, researches, and briefs you—so you can focus on what matters.
See what people say
"Before Carly, I relied on a Calendly link, but the whole process felt impersonal and not very professional. Carly changed that by handling all the back-and-forth, so I'm no longer stuck in endless email threads trying to line up schedules.
Now Carly reaches out to candidates, shares my real-time availability, lets them pick a slot, then sends a Zoom link and drops it straight into my calendar. She sends reminders to both of us before each call, which has significantly reduced no-shows and last-minute confusion.
On top of scheduling, Carly acts like a full executive assistant, sending me my schedule the night before so I can prepare for each call. It reminds me of the old x.ai assistant, but Carly is noticeably smarter, faster, and better suited to my healthcare recruitment business."


