How Many Data Breaches Happen, and What They Cost in 2026

How Many Data Breaches Happen, and What They Cost in 2026

Paylaş
İçindekiler

The United States logged 3,322 data compromises in 2025, the highest count on record, according to the Identity Theft Resource Center. Each one is getting pricier, too: IBM puts the global average cost of a breach at $4.99 million in its 2026 report, up 12% in a year, and the typical breach takes 247 days to find and shut down. Below are the numbers that matter from the main annual studies, what they measure, and what they mean if your own data ends up in one.

Key data breach statistics for 2026

  • 3,322 data compromises were publicly reported in the US in 2025, a record and 5% more than in 2024 (ITRC).

  • $4.99 million is the global average cost of a data breach, a record high (IBM, 2026).

  • $11.5 million is the US average, more than twice the global figure (IBM, 2026).

  • 247 days is the average breach lifecycle: 183 days to identify it and 64 more to contain it (IBM, 2026).

  • 31% of breaches started with an exploited software vulnerability, now the most common way in (Verizon DBIR, 2026).

  • 48% of breaches involved ransomware, and 48% involved a third party such as a vendor or supplier (Verizon DBIR, 2026).

  • 443 personal data breaches a day were reported to European regulators, 22% more than the year before (DLA Piper, 2026).

  • 23.8 billion accounts have been breached worldwide since 2004 (Surfshark).

  • Healthcare breaches cost the most, $6.64 million on average, for the 13th year running (IBM, 2026).

  • 70% of US breach notices in 2025 didn't say how the attack happened (ITRC).

  • Only 24% of breaches from 2024 to 2026 exposed passwords, down from 85% in 2016 to 2018 (Browsec analysis of Have I Been Pwned data).

  • 58% of breaches from 2024 to 2026 exposed phone numbers, up from 21% in 2016 to 2018 (Browsec analysis of Have I Been Pwned data).

What counts as a data breach

A data breach is any incident where information gets seen, copied, or taken by someone who shouldn't have it. That covers a hacker pulling a customer database, but also an employee emailing a spreadsheet to the wrong person, a misconfigured cloud bucket left open to the internet, or a stolen laptop with unencrypted files.

The reports below don't all count the same thing, which is why their totals differ so much:

  • A security incident is anything that threatens a system, whether or not data leaves. Verizon separates incidents from confirmed breaches, where disclosure of data is actually verified.

  • A data compromise, ITRC's term, is a publicly reported event in the US where personal information was exposed. It counts events, not people.

  • A breached account, Surfshark's unit, is one email address found in a leaked database. One person can appear many times.

  • A data leak usually means exposure without an attacker, like that open cloud bucket. Many regulators still count it as a breach.

Keep the unit in mind when you compare numbers. "3,322 breaches" and "279 million victim notices" describe the same year in the same country.

How many data breaches happen each year

It depends on where you look and what you count, but every major tracker shows the same direction: more reported breaches, year after year.

Region

Measure

Latest figure

Change

Source

United States

Publicly reported data compromises, 2025

3,322

+5% vs 2024

ITRC

Europe

Breach notifications to regulators per day, Jan 2025 to Jan 2026

443

+22%

DLA Piper

United Kingdom

Businesses that identified a breach or attack, last 12 months

42% to 69%, by company size

n/a

UK government CSBS

Worldwide

Accounts breached per minute, Q2 2026

787

-51.8% vs Q1 2026

Surfshark

Source: ITRC 2025 Annual Data Breach Report, DLA Piper GDPR Fines and Data Breach Survey 2026, Cyber Security Breaches Survey 2025/2026, Surfshark Data Breach Monitoring.

United States

ITRC counted 3,322 data compromises in 2025, beating the previous record of 3,202 set in 2023. That works out to roughly nine publicly reported breaches every day, and the five-year increase is 79%.

The number of victim notices went the other way. Organizations sent 278.8 million of them in 2025, down 79% from 1.37 billion in 2024. That drop isn't good news in disguise, it's the absence of a few mega-breaches that inflated 2024. More breaches, fewer giant ones.

The more worrying trend is transparency. 70% of 2025 breach notices didn't say how the attack happened, up from 65% in 2024 and 45% in 2023. If you get one of these letters, there's a good chance it won't tell you whether a password, a phishing email, or a vendor was the weak point.

Financial services had the most compromises (739), followed by healthcare (534), professional services (478), manufacturing (299), and education (188).

Europe

Under GDPR, organizations have to report personal data breaches to their national regulator. DLA Piper's annual survey counted an average of 443 notifications a day between January 28, 2025, and January 27, 2026, up from 363 a day the year before.

Regulators issued about €1.2 billion in GDPR fines over the same period. Ireland's Data Protection Commission, which oversees most big tech companies with EU headquarters there, has issued €4.04 billion in total since GDPR took effect in May 2018.

United Kingdom

The UK government's Cyber Security Breaches Survey asks organizations whether they identified a breach or attack in the past 12 months. The 2025/2026 edition, based on fieldwork from August to December 2025, found:

  • 42% of micro businesses

  • 46% of small businesses

  • 65% of medium businesses

  • 69% of large businesses

  • 28% of charities

Phishing was the most common attack, hitting 38% of businesses. The report itself warns these figures are likely an undercount, since they only include attacks organizations noticed and were willing to report.

Breached accounts worldwide

Since 2004, 23.8 billion accounts have been breached, tied to about 7.9 billion unique email addresses. In other words, the average breached email has shown up in about three separate leaks.

The pace swings a lot from quarter to quarter. In the first quarter of 2026, 1,631 accounts were breached every minute. In the second quarter, the rate fell to 787 a minute, a 51.8% drop. The US had the most breached accounts in Q2 2026 (29.8 million), followed by France (19.7 million) and Poland (5.8 million).

The cost of a data breach in 2026

The average cost of a data breach worldwide is $4.99 million, according to IBM's Cost of a Data Breach Report 2026. That's a 12% jump from $4.44 million a year earlier and the highest figure the study has recorded. IBM and the Ponemon Institute based it on breaches at 602 organizations between March 2025 and February 2026.

In the US, the average is $11.5 million, more than double the global figure. Higher legal costs, regulatory penalties, and notification rules that vary state by state all push American breaches up.

Average cost by industry

Industry

Average cost of a breach

Healthcare

$6.64 million

Financial services

$6.29 million

Industrial

$5.50 million

Technology

$5.50 million

Entertainment

$5.40 million

All industries (global)

$4.99 million

Source: IBM Cost of a Data Breach Report 2026.

Healthcare has topped this list for 13 years in a row. Medical records carry more personal detail than almost any other data set, they can't be "reissued" like a credit card, and hospitals face both regulatory penalties and the cost of disrupted care.

Where the money goes

IBM splits the average into four categories:

  • Detection and escalation: $1.64 million. Forensics, investigation, internal crisis management.

  • Lost business: $1.54 million. Downtime, customers who leave, damage to reputation.

  • Post-breach response: $1.36 million. Legal fees, credit monitoring for victims, regulatory fines.

  • Notification: $0.45 million. Telling regulators and affected people.

Notice that the smallest slice is the one the public sees. Most of the cost lands before anyone gets a letter, or long after.

What pushes the cost up or down

Speed is the biggest lever. Breaches contained in under 200 days cost an average of $4.32 million, while those that dragged past 200 days cost $5.65 million, a gap of $1.33 million.

AI cuts both ways. About one in four malicious breaches in IBM's study were AI-driven, a 56% increase over the previous year, and those attacks added roughly $1 million to the average cost. On the defense side, organizations that used security AI and automation extensively saved $1.93 million per breach compared with those that didn't, and closed breaches 65 days faster.

The type of data matters as well. Customer personal information was compromised in 52% of breaches, and it's the category that triggers notification duties, credit monitoring, and lawsuits.

How data breaches start

Exploiting a software vulnerability is now the most common way attackers get in. Verizon's 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches across 145 countries, found these initial access routes:

  • Vulnerability exploitation: 31%

  • Phishing: 16%

  • Credential abuse (stolen or guessed passwords): 13%

  • Pretexting (a convincing fake story, often by phone or email): 6%

Stolen credentials show up far more often than that 13% suggests. Counting every stage of an attack, not only the first step, they appear in 39% of breaches. And half of ransomware victims who'd had a credential leak or infostealer infection experienced it within 95 days before the ransomware hit.

Two other shifts stand out. Ransomware was involved in 48% of breaches, up from 44%, though 69% of ransomware victims refused to pay. Third-party involvement, meaning a vendor, contractor, or software supplier was part of the breach, reached 48%, up from 30%. Your data can leak from a company you've never heard of because it processes payroll or support tickets for one you have.

Slow patching keeps the door open. Only 26% of the vulnerabilities on CISA's "known exploited" list were fully fixed by the organizations Verizon surveyed, down from 38%, and the median time to patch grew to 43 days.

IBM's data adds the cost side. Phishing was the most common initial attack vector in its study for the fourth year running, and phone and text scams, vishing and smishing, produced the most expensive breaches at $5.29 million on average.

What breaches expose now: a Browsec analysis of 960 breaches

Leaked passwords used to be the whole story. Now they're the exception. We analyzed 960 verified breaches of organizations listed in Have I Been Pwned, grouped by the year each breach happened, and checked which types of data they exposed. Passwords showed up in 85% of breaches from 2016 to 2018 and in only 24% of breaches from 2024 to 2026. Over the same period, the share of breaches that exposed phone numbers nearly tripled, and physical addresses tripled.

Breach year

Exposed passwords

Exposed phone numbers

Exposed physical addresses

2016 to 2018

85%

21%

16%

2024 to 2026

24%

58%

49%

2026 (January to August)

12%

70%

63%

Source: Browsec analysis of the Have I Been Pwned breach database, September 2026. Excludes fabricated breaches, spam lists, malware and stealer logs, and credential compilations.

2026 brings two new kinds of data into the picture. 16% of this year's breaches exposed support tickets or customer service records, and 25% exposed job titles or employers. Before 2024, both were close to zero. That's the footprint of attacks on the CRM and helpdesk systems companies use to talk to their customers. These systems often get opened not by breaking code but by talking an employee into granting access.

For you, this changes what a breach is actually used for. A leaked password gets used against one account, and a password manager plus two-factor authentication shuts that down. A leaked name, phone number, home address, and a copy of your last support conversation is raw material for a convincing call or text that appears to come from a company you actually use. That lines up with IBM's finding that phone and text scams are now the most expensive way breaches start.

The data has limits. Have I Been Pwned only includes breaches that contain email addresses, became public, and were loaded into the database, so this is a large sample rather than a complete count. Figures for 2026 cover breaches through August.

How long it takes to find and contain a breach

The average breach lasts 247 days from start to containment, per IBM. It takes 183 days on average just to notice something is wrong, and another 64 days to contain it.

Put another way, a breach that started in January typically isn't discovered until July and isn't closed until September. For all of that time, the stolen data is already out there and can be sold, combined with other leaks, or used for targeted phishing. That's why notification letters so often describe events from many months earlier.

Healthcare data breaches

Healthcare is where breaches are both the most frequent and the most expensive. Organizations covered by HIPAA reported 804 large breaches (500 records or more) to the US Department of Health and Human Services in 2025, affecting about 138.5 million individuals. That averages out to more than 379,000 people's health records exposed every day.

2026 is running slightly lower on count: 395 large breaches through June 30, about 9.5% fewer than the same period in 2025. The largest so far is DentaQuest, at 15 million individuals.

The three largest US healthcare breaches ever recorded:

  1. Change Healthcare (2024): 192.7 million people

  2. Anthem (2015): 78.8 million people

  3. Conduent (2025): 62.2 million people

Hacking and IT incidents drive most of these, and many come through business associates, the billing firms, IT vendors, and data processors that hospitals rely on, rather than the hospitals themselves. It's the same third-party pattern Verizon sees across every industry.

The biggest data breaches of 2025 and 2026

Organization

Year disclosed

People affected

Data exposed

Conduent

2025

62.2 million

Names, Social Security numbers, health insurance and medical information

Qantas

2025

5.7 million

Names, email addresses, phone numbers, birth dates, frequent flyer numbers

TransUnion

2025

About 4.5 million

Names, birth dates, Social Security numbers

Instructure (Canvas)

2026

30 million+ students and staff

Names, email addresses, student ID numbers, platform messages

DentaQuest

2026

15 million

Health and insurance data

Carnival

2026

About 6 million

Names, addresses, birth dates, passport and driver's license numbers

ADT

2026

About 5.5 million

Names, phone numbers, addresses, some birth dates, last four digits of SSN or tax ID

Panera Bread

2026

5.1 million unique email addresses

Names, email addresses, phone numbers, addresses

CareCloud

2026

At least 3.7 million

Medical records

Source: HIPAA Journal (HHS breach portal data), Cybersecurity Dive, Infosecurity Magazine, TechCrunch, TechRepublic. Counts are those confirmed by the organization or regulator; attacker claims, such as the 275 million users claimed in the Instructure case, aren't included.

Look at how many of these came through a third party. Qantas was breached via an offshore call center platform, TransUnion through a third-party application, and Conduent processes data on behalf of health plans and government agencies. Several 2026 incidents, including Instructure and Carnival, started with social engineering: someone talked their way past an employee rather than breaking any code.

What the numbers mean for you

You can't stop a company from being breached, but you can limit what a breach does to you. ITRC's consumer research found that 80% of people surveyed got at least one breach notice in the past 12 months, and 88% of those experienced a negative effect afterward. The most common were more spam and robocalls (49%) and phishing attempts (40%).

A few steps cover most of the risk:

  1. Check whether your email appears in known breaches with a free service like Have I Been Pwned.

  2. Change the password on any breached account, and anywhere else you reused it. Credential abuse only works when one leaked password opens several doors.

  3. Turn on two-factor authentication, preferably an authenticator app rather than SMS.

  4. If your Social Security number was exposed, freeze your credit with Equifax, Experian, and TransUnion. It's free and stops new accounts being opened in your name.

  5. Expect targeted phishing. After a breach, scammers know your name, your provider, and sometimes your account details, which makes their messages far more convincing. If you suspect a device is already compromised, here's how to spot a hacked phone.

Where does a VPN fit? Less centrally than some ads suggest. A VPN doesn't protect data that's already sitting on a company's servers, so it won't stop the next Conduent or Qantas. What it does is encrypt your connection, which matters on public and shared networks where someone nearby can try to intercept logins and session data. It's one layer, alongside a properly secured home Wi-Fi, not a fix for corporate breaches. If you're curious how widespread that layer has become, we looked at who uses VPNs today.

FAQ

How many data breaches happen per day?

In the US, about nine publicly reported data compromises a day, based on ITRC's count of 3,322 for 2025. In Europe, organizations filed an average of 443 breach notifications a day with GDPR regulators. The European figure is higher because it includes small incidents that never make the news.

What is the average cost of a data breach in 2026?

$4.99 million worldwide, according to IBM's Cost of a Data Breach Report 2026. In the US, the average is $11.5 million, and in healthcare, the most expensive industry, it's $6.64 million.

What is the most common cause of data breaches?

Exploited software vulnerabilities are now the most common entry point, at 31% of breaches in Verizon's 2026 report, ahead of phishing (16%) and stolen or guessed credentials (13%). IBM, which looks at a different sample, still ranks phishing first.

Which industry has the most data breaches?

In the US, financial services had the most reported compromises in 2025 (739), followed by healthcare (534), according to ITRC. Healthcare has the most expensive breaches, and it has held that position for 13 years.

How can I check if my data was in a breach?

Enter your email address at Have I Been Pwned, which searches billions of records from known breaches. Also read any breach notice you receive in full, since it should list what data was exposed. If you're wondering what else about your online activity is visible, we covered who can see your searches.

About this data

Every figure on this page comes from a published annual report or tracker, and each uses its own definition and time frame:

  • IBM and Ponemon Institute, Cost of a Data Breach Report 2026: 602 organizations, breaches between March 2025 and February 2026.

  • Verizon, 2026 Data Breach Investigations Report: 22,000+ confirmed breaches across 145 countries.

  • Identity Theft Resource Center, 2025 Annual Data Breach Report: publicly reported US data compromises in calendar year 2025.

  • DLA Piper, GDPR Fines and Data Breach Survey 2026: notifications and fines from January 28, 2025, to January 27, 2026.

  • UK Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025/2026: 2,112 businesses and 1,085 charities, fieldwork August to December 2025.

  • HHS Office for Civil Rights breach portal, via HIPAA Journal: US healthcare breaches affecting 500 or more people.

  • Surfshark Data Breach Monitoring: leaked email addresses in public breach databases since 2004.

  • Browsec analysis of Have I Been Pwned: 960 verified organizational breaches from the public HIBP breach list, downloaded in September 2026 and grouped by breach date. Fabricated breaches, spam lists, malware and stealer logs, unverified entries, and credential compilations were excluded. Each figure is the share of breaches in a period that exposed a given data type.

We'll update this page as new editions of these reports are released.


External sources

Paylaş

Bu makaleye atıf yapın

Browsec. "How Many Data Breaches Happen, and What They Cost in 2026." Browsec Blog, 25 Eylül 2026 Cuma, https://browsec.com/tr/blog/data-breach-statistics.