Dataset · Breaches

Breach data — what all those vulnerabilities actually turn into

Disclosure counts measure what gets found. Breach data measures what gets through. Three reputable series — ITRC's US compromise counts, Verizon's DBIR breach analysis, and IBM's cost report — each measuring something different, none of them a census. The sharpest vulnerability-relevant signal in any of them: the share of breaches that start with an exploited vulnerability has climbed every DBIR edition since 2023, and in 2026 it overtook stolen credentials for the first time in the report's 19-year history.

3,322
US data compromises in 2025
ITRC record; +79% over five years
~31%
of breaches start with a vuln
DBIR 2026 — #1 vector, first time ever
$4.44M
global avg breach cost, 2025
first decline in 5 years; US hit a record $10.22M
1.35B
victim notices in 2024
then −79% in 2025 — mega-breach lumpiness, not safety

US data compromises per year (ITRC), 2016–2025

Publicly reported US data compromises, from the Identity Theft Resource Center's annual reports. 2026 is excluded from the line — only Q1 (780 compromises) is published; see the table.

0 1.25k 2.5k 3.75k 5k 1.1k3.2k3.3k2016201720182019202020212022202320242025
The step-change is 2023: from a 1,100–1,900 band to 3,205, and it held — 3,158 in 2024, a record 3,322 in 2025. Note the same caution as the CVE curve: ITRC counts reported compromises, so disclosure laws and reporting culture inflate the trend alongside actual intrusions. ITRC annual data breach reports, 2016–2025

The vulnerability connection — the one breach trend this site exists for

Breaches that began with vulnerability exploitation

Share of confirmed breaches whose initial access vector was exploiting a vulnerability, per Verizon DBIR edition.

0 12.5 25 37.5 50 DBIR '23 DBIR '24 DBIR '25 DBIR '26
~5% → 14% → 20% → ~31% in four editions. 2024's near-tripling was the MOVEit/zero-day year; 2026 is the first edition where vulns beat credentials as the way in. Verizon DBIR 2023–2026

Why this matters here

Everything else on this site counts vulnerability disclosure — which is rising for structural reasons that say little about risk. This is the number that connects disclosure to consequence: attackers are increasingly getting in through unpatched vulnerabilities rather than stolen passwords.

And the patching side is losing ground on speed: DBIR 2026 reports median time-to-patch rose from 32 to 43 days while median time-to-exploit collapsed to ~5 days (the clock story). The gap between those two numbers is the exposure window.

Caveat: DBIR percentages describe DBIR's contributed caseload, not all breaches on Earth. The direction across four editions is the signal; the precise digits are not.

The DBIR series, edition by edition

Verizon's Data Breach Investigations Report analyzes incidents contributed by a changing roster of partners — raw counts swing with the contributor base, so read the vector percentages, not the totals, as trend. Editions before 2021 aren't shown: their counts couldn't be verified against a primary page for this build, and this site doesn't publish unverified numbers.

EditionIncidentsConfirmed breachesVuln-exploit vectorNote
2021 29,207 5,258 Secondary-source (2021 DBIR PDF mirror); approximate.
2022 23,896 5,212 Secondary coverage. 82% of breaches involved the human element.
2023 16,312 5,199 ~5% Incident count dropped vs 2022 — scoping change, not a real decline. Ransomware ~24% of breaches.
2024 30,458 10,626 14% Vuln exploitation as initial access nearly TRIPLED (+180% YoY) to 14% — the MOVEit/zero-day year.
2025 22,052 12,195 20% Most confirmed breaches ever analyzed to that point. Vuln exploitation 20% (+34% YoY); third-party involvement doubled 15%→30%; ransomware in 44% of breaches.
2026 ~31,000 ~22,000 ~31% FIRST TIME in the DBIR's 19-year history that vulnerability exploitation (~31%) overtook stolen credentials as the #1 breach entry point. Counts reported rounded ('~31,000 incidents', 'over 22,000 breaches'). Median time-to-patch rose 32→43 days. Published May 2026.
Dimmed rows are secondary-sourced (medium confidence). 2026 counts are reported rounded by Verizon. full data: breaches.json

Global average cost of a breach (IBM), 2017–2025

IBM / Ponemon Cost of a Data Breach report, global average in USD millions. 2016 omitted (inferred-only); 2026 report not yet published.

0 1.25 2.5 3.75 5 3.624.884.44201720182019202020212022202320242025
A slow grind up ($3.62M → $4.88M), then 2025's twist: the global average fell 9% — first decline in five years, credited to faster containment — while the US average rose 9% to a record $10.22M. IBM Cost of a Data Breach 2017–2025 · CyberScoop

The ITRC dataset, year by year

YearCompromisesImpactNote
2016 1,093 36.6M records exposed Then all-time record; +40% over 2015. ITRC+CyberScout era.
2017 1,579 178M records exposed (approx) New record; +44.7% over 2016. Later ITRC datasets sometimes restate as 1,506/1,632.
2018 1,257 471M records exposed Marriott/Starwood alone = 383M records. ITRC internal inconsistency: 1,244 in key findings vs 1,257 restated in the 2019 report.
2019 1,473 165M records exposed +17% breaches over 2018; records exposed −65%. Last full year before the methodology change.
2020 1,108 301M victim notices −19% from 2019. Methodology-break year: 'compromises' + 'individuals impacted' begin here.
2021 1,862 294M victim notices (approx) Then-record; +68% over 2020; broke the 2017 record. Restated 1,860 in later reports.
2022 1,802 422M victim notices 60 short of the 2021 record (restated 1,801). Quiet H1 (Russia/Ukraine war, crypto volatility). Only 34% of notices disclosed an attack vector.
2023 3,205 353M victim notices RECORD — +78% over 2022, +72% over the prior record. Restated 3,202 in later reports. Victims DOWN 16% vs 2022.
2024 3,158 1.35B victim notices −1% vs 2023, 44 events short of the record (restated 3,152). Victim notices ~1.35B, +211% — five mega-breaches each ≥100M notices.
2025 3,322 279M victim notices NEW RECORD — +5% vs 2024, +79% over five years. Victim notices crashed −79% (lowest since 2014; no mega-breaches). 70% of notices lacked attack info. Financial Services overtook Healthcare as #1 industry.
2026* 780 140M victim notices (approx) Q1 only (Jan–Mar). Full H1 2026 report not yet published as of 2026-07-21. Q1: ~140M victim notices; Under Armour 72.7M, SoundCloud 29.8M. 79% of Q1 notices lacked actionable info.
* 2026 is Q1 only — the full H1 report wasn't published as of this build. The impact column deliberately switches units at 2020: ITRC changed methodology from "records exposed" to "victim notices," and the two aren't comparable — so this site never draws them as one line. Victim notices count notices, not unique people. ITRC · full data: breaches.json

What breach data does and doesn't say about the AI question

The breach series shows the same 2023–2026 acceleration the disclosure data shows — compromise counts stepped up 78% in 2023 and kept setting records, and vuln-exploitation's share of breach entry tripled-then-doubled across the same window. What none of these sources establish is AI as the cause: ITRC's 2023 jump predates capable AI vuln-discovery tools, DBIR attributes its vector shift to zero-day supply-chain campaigns (MOVEit) and slowing patch cadence, and 70% of 2025 breach notices didn't disclose an attack vector at all. The correlation is real, documented, and — like everything else here — not yet attribution. The AI Question →