Breach data — what all those vulnerabilities actually turn into
Disclosure counts measure what gets found. Breach data measures what gets through. Three reputable series — ITRC's US compromise counts, Verizon's DBIR breach analysis, and IBM's cost report — each measuring something different, none of them a census. The sharpest vulnerability-relevant signal in any of them: the share of breaches that start with an exploited vulnerability has climbed every DBIR edition since 2023, and in 2026 it overtook stolen credentials for the first time in the report's 19-year history.
US data compromises per year (ITRC), 2016–2025
Publicly reported US data compromises, from the Identity Theft Resource Center's annual reports. 2026 is excluded from the line — only Q1 (780 compromises) is published; see the table.
The vulnerability connection — the one breach trend this site exists for
Breaches that began with vulnerability exploitation
Share of confirmed breaches whose initial access vector was exploiting a vulnerability, per Verizon DBIR edition.
Why this matters here
Everything else on this site counts vulnerability disclosure — which is rising for structural reasons that say little about risk. This is the number that connects disclosure to consequence: attackers are increasingly getting in through unpatched vulnerabilities rather than stolen passwords.
And the patching side is losing ground on speed: DBIR 2026 reports median time-to-patch rose from 32 to 43 days while median time-to-exploit collapsed to ~5 days (the clock story). The gap between those two numbers is the exposure window.
Caveat: DBIR percentages describe DBIR's contributed caseload, not all breaches on Earth. The direction across four editions is the signal; the precise digits are not.
The DBIR series, edition by edition
Verizon's Data Breach Investigations Report analyzes incidents contributed by a changing roster of partners — raw counts swing with the contributor base, so read the vector percentages, not the totals, as trend. Editions before 2021 aren't shown: their counts couldn't be verified against a primary page for this build, and this site doesn't publish unverified numbers.
| Edition | Incidents | Confirmed breaches | Vuln-exploit vector | Note |
|---|---|---|---|---|
| 2021 | 29,207 | 5,258 | — | Secondary-source (2021 DBIR PDF mirror); approximate. |
| 2022 | 23,896 | 5,212 | — | Secondary coverage. 82% of breaches involved the human element. |
| 2023 | 16,312 | 5,199 | ~5% | Incident count dropped vs 2022 — scoping change, not a real decline. Ransomware ~24% of breaches. |
| 2024 | 30,458 | 10,626 | 14% | Vuln exploitation as initial access nearly TRIPLED (+180% YoY) to 14% — the MOVEit/zero-day year. |
| 2025 | 22,052 | 12,195 | 20% | Most confirmed breaches ever analyzed to that point. Vuln exploitation 20% (+34% YoY); third-party involvement doubled 15%→30%; ransomware in 44% of breaches. |
| 2026 | ~31,000 | ~22,000 | ~31% | FIRST TIME in the DBIR's 19-year history that vulnerability exploitation (~31%) overtook stolen credentials as the #1 breach entry point. Counts reported rounded ('~31,000 incidents', 'over 22,000 breaches'). Median time-to-patch rose 32→43 days. Published May 2026. |
Global average cost of a breach (IBM), 2017–2025
IBM / Ponemon Cost of a Data Breach report, global average in USD millions. 2016 omitted (inferred-only); 2026 report not yet published.
The ITRC dataset, year by year
| Year | Compromises | Impact | Note |
|---|---|---|---|
| 2016 | 1,093 | 36.6M records exposed | Then all-time record; +40% over 2015. ITRC+CyberScout era. |
| 2017 | 1,579 | 178M records exposed (approx) | New record; +44.7% over 2016. Later ITRC datasets sometimes restate as 1,506/1,632. |
| 2018 | 1,257 | 471M records exposed | Marriott/Starwood alone = 383M records. ITRC internal inconsistency: 1,244 in key findings vs 1,257 restated in the 2019 report. |
| 2019 | 1,473 | 165M records exposed | +17% breaches over 2018; records exposed −65%. Last full year before the methodology change. |
| 2020 | 1,108 | 301M victim notices | −19% from 2019. Methodology-break year: 'compromises' + 'individuals impacted' begin here. |
| 2021 | 1,862 | 294M victim notices (approx) | Then-record; +68% over 2020; broke the 2017 record. Restated 1,860 in later reports. |
| 2022 | 1,802 | 422M victim notices | 60 short of the 2021 record (restated 1,801). Quiet H1 (Russia/Ukraine war, crypto volatility). Only 34% of notices disclosed an attack vector. |
| 2023 | 3,205 | 353M victim notices | RECORD — +78% over 2022, +72% over the prior record. Restated 3,202 in later reports. Victims DOWN 16% vs 2022. |
| 2024 | 3,158 | 1.35B victim notices | −1% vs 2023, 44 events short of the record (restated 3,152). Victim notices ~1.35B, +211% — five mega-breaches each ≥100M notices. |
| 2025 | 3,322 | 279M victim notices | NEW RECORD — +5% vs 2024, +79% over five years. Victim notices crashed −79% (lowest since 2014; no mega-breaches). 70% of notices lacked attack info. Financial Services overtook Healthcare as #1 industry. |
| 2026* | 780 | 140M victim notices (approx) | Q1 only (Jan–Mar). Full H1 2026 report not yet published as of 2026-07-21. Q1: ~140M victim notices; Under Armour 72.7M, SoundCloud 29.8M. 79% of Q1 notices lacked actionable info. |
What breach data does and doesn't say about the AI question
The breach series shows the same 2023–2026 acceleration the disclosure data shows — compromise counts stepped up 78% in 2023 and kept setting records, and vuln-exploitation's share of breach entry tripled-then-doubled across the same window. What none of these sources establish is AI as the cause: ITRC's 2023 jump predates capable AI vuln-discovery tools, DBIR attributes its vector shift to zero-day supply-chain campaigns (MOVEit) and slowing patch cadence, and 70% of 2025 breach notices didn't disclose an attack vector at all. The correlation is real, documented, and — like everything else here — not yet attribution. The AI Question →