Verizon’s 2026 Data Breach Investigations Report found that vulnerability exploitation became the leading initial access vector for breaches for the first time in the report’s 19-year history, accounting for about 31% of known breach entry points and surpassing phishing and stolen credentials. Based on more than 31,000 security incidents and 22,000 confirmed breaches across 145 countries, the report said ransomware appeared in 48% of breaches, financially motivated actors drove most activity, and defenders are falling behind on remediation: surveyed organizations fully fixed only 26% of critical known exploited vulnerabilities on average, with a median remediation time of 43 days even as attackers increasingly weaponize flaws within hours. Verizon and other reporting also highlighted rising abuse of third parties, remote monitoring and management tools, infostealer-fed credential theft, and AI-assisted attacker workflows, while voice- and text-based social engineering increasingly outperformed traditional email phishing.
The findings were especially stark for healthcare, where Verizon tracked 1,492 incidents and 1,438 confirmed data disclosures, many tied to ransomware intrusions launched through exploited vulnerabilities or social engineering. Separate reporting said small and mid-sized healthcare providers remain disproportionately exposed, with eight recently disclosed breaches affecting nearly 2 million people, including incidents at Coastal Carolina Health Care and Erie Family Health Centers. Analysts cited limited security resources, slow patching, interconnected vendors, and growing use of unapproved shadow AI tools as factors increasing both compromise and data leakage risk in a sector already handling highly sensitive personal and medical information.

Get the actors, campaigns, and ATT&CK mapping behind it.
9 events from the most recent confirmed update back to the earliest known activity.
The same May 20 reporting identified Erie Family Health Centers as having reported a security incident affecting 570,000 patients.
The May 20 healthcare-sector reporting cited Coastal Carolina Health Care in North Carolina as having reported a breach impacting 110,304 individuals.
A May 20, 2026 report said eight recently disclosed breaches at small and mid-sized healthcare providers affected nearly 2 million individuals, illustrating the sector's continued exposure to ransomware and data theft.
Verizon publicly released its 2026 Data Breach Investigations Report, prompting coverage across multiple outlets on the report's findings about vulnerability exploitation, patching failures, ransomware, healthcare targeting, and AI-related risks.
The 2026 DBIR found ransomware present in 48% of breaches, a 60% year-over-year increase in third-party involvement, growing abuse of voice and text pretexting, and rising risks from attacker use of AI and employee use of unapproved 'shadow AI' tools.
In Verizon's 2026 DBIR healthcare analysis, social engineering, system intrusion, and miscellaneous errors accounted for 81% of healthcare breaches in 2025, with pretexting rising to the second most common social action after phishing. The report and cited researchers also linked the trend to more effective AI-assisted impersonation and credential-theft campaigns tailored to healthcare workflows.
Verizon's healthcare-specific findings for the 2026 DBIR showed 1,492 healthcare incidents, including 1,438 confirmed data disclosures, with most tied to ransomware-driven system intrusions often beginning through exploited vulnerabilities or social engineering.
In the completed 2026 DBIR analysis period, exploited vulnerabilities overtook phishing and stolen credentials as the leading initial access vector for the first time in the report's 19-year history, accounting for about 31% of breaches. The report also tied the shift to slower patching, with only about 26% of critical or known exploited vulnerabilities fully remediated and median remediation time rising to 43 days.
Verizon's 2026 Data Breach Investigations Report analyzed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries during the Nov. 1, 2024 to Oct. 31, 2025 reporting period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
17 references tracked. Mallory keeps watching after this page renders.
health-isac.org
Open sourcehelpnetsecurity.com
Open sourcethecyberexpress.com
Open sourcedarkreading.com
Open sourcetheregister.com
Open sourcehipaajournal.com
Open sourceits.ny.gov
Open sourceverizon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.