The global average cost of a data breach dropped to USD 4.44 million in 2025, according to IBM's Cost of a Data Breach Report, ending four straight years of rising costs. The decline followed faster detection driven partly by AI-assisted defenses, but the United States, healthcare, and credential-based attacks all still cost far more than the global mean. Below is what IBM, Verizon, and the Identity Theft Resource Center each measured this year, side by side, with every figure traced to its named source and publication date.

What is the average cost of a data breach in 2026?

The most current figure is USD 4.44 million globally, per IBM's Cost of a Data Breach Report 2025, based on research into 600 breached organizations across 17 industries and 16 countries and regions, with breaches investigated between March 2024 and February 2025 and Ponemon Institute researchers interviewing more than 3,470 security and business leaders. That average is down from USD 4.88 million in the 2024 report, a 9 percent decrease and the first year-over-year drop in five years of IBM's tracking.

The decline is not uniform. The United States average climbed to a record USD 10.22 million, driven by heavier regulatory fines and comparatively slow detection times. Healthcare remained the single most expensive sector at USD 7.42 million per breach, even after falling by USD 2.35 million from 2024, a decline IBM attributes largely to fewer catastrophic mega-breaches in the sector this cycle rather than a fundamental cost reduction per incident.

Loading chart...

Figure 1: The global average breach cost rose for four straight years before falling in 2025. Source: IBM Cost of a Data Breach Report, 2020 to 2025 editions.

The takeaway for any organization budgeting for incident response: the global average is falling, but that average hides a widening gap between fast, well-contained breaches and slow, credential-driven ones that still cost far more than USD 4.44 million.

How many data breaches happen each year?

In the United States alone, the Identity Theft Resource Center logged 3,322 data compromises in 2025, according to its Annual Data Breach Report published in January 2026, a new record and a 5 percent rise over the 3,152 compromises recorded in 2024. That figure is 79 percent higher than five years earlier and beats the previous record of 3,202 compromises set in 2023.

Globally, Verizon's 2025 Data Breach Investigations Report analyzed 22,052 security incidents and confirmed 12,195 of them as actual data breaches, drawn from contributors across 139 countries. The two counts are not directly comparable: the ITRC tracks US-reported compromise events with a public notice obligation, while Verizon's dataset spans confirmed breaches worldwide regardless of notification law. Read together, they show enforcement-driven disclosure counts and investigator-confirmed breach counts both climbing.

Loading chart...

Figure 2: US data compromises hit a new record in 2025 after a 2024 dip. Source: Identity Theft Resource Center, Annual Data Breach Report 2026 (covering 2025).

One notable counter-trend: total victim notices fell to 278,827,933 in 2025, down 79 percent from 1,367,117,021 in 2024, per the ITRC, because 2025 lacked the handful of billion-record mega-breaches that inflated the 2024 total. More breaches, far fewer records exposed per breach, is the clearest read of the year.

What causes most data breaches?

A human action, a phishing click, a stolen password, a misconfigured system, or a socially engineered phone call, was present in 60% of confirmed breaches in 2025, according to Verizon's Data Breach Investigations Report, down from 68% in the 2024 edition. Stolen or compromised credentials remained Verizon's single highest-ranked entry vector at 22% of breaches, while IBM's own initial-vector data shows phishing edging ahead at 16% of breaches with an average cost of USD 4.8 million, narrowly above the USD 4.67 million average for credential-based breaches.

Ransomware was present in 44% of breaches Verizon analyzed in 2025, up sharply from 32% the year before, though victims are pushing back harder: 64% of organizations refused to pay, up from roughly half two years earlier, and the median ransom paid fell to USD 115,000 from USD 150,000. Third-party involvement in breaches doubled year over year to 30%, and exploitation of software vulnerabilities as an initial vector rose to 20% of breaches, a 34% increase, concentrated in zero-day exploits against perimeter devices and VPNs.

Loading chart...

Figure 3: Cause categories overlap since a single breach can involve several. Source: Verizon 2025 Data Breach Investigations Report.

The shared conclusion across all three reports: attackers still get in most often by targeting people and passwords rather than breaking cryptography, which is why sites that generate a compliant privacy policy disclosing how login credentials and personal data are protected are addressing one of the more overlooked, low-cost defenses available to a small site.

How long does it take to detect a breach?

Organizations took 241 days on average to identify and contain a breach in 2025, according to IBM's Cost of a Data Breach Report, the fastest figure in nine years of IBM tracking and 17 days quicker than 2024. IBM credits part of the improvement to wider use of AI-assisted detection tools, though it also flags a new risk: 20% of breached organizations had a shadow AI component involved, adding an average USD 670,000 to that incident's total cost.

Detection speed varies enormously by how the attacker got in. Breaches that started with stolen or compromised credentials took roughly 292 days on average to identify and contain, well above the 241-day mean, because a valid login does not immediately look like an intrusion to most monitoring tools. Healthcare breaches also ran long at 279 days on average, consistent with the sector's status as the costliest industry per incident.

Loading chart...

Figure 4: The average breach lifecycle from access to full containment. Source: IBM Cost of a Data Breach Report 2025.

For a full breakdown of how detection speed and breach cost vary by country and industry, see the cost of a data breach by country and sector. Faster detection is the single biggest lever behind 2025's cost decline, and it depends more on monitoring credentialed access than on any single tool.

Which industries are hit hardest?

Healthcare remains the most expensive industry per breach at USD 7.42 million on average, per IBM, even after a USD 2.35 million year-over-year drop attributed to fewer catastrophic mega-breaches rather than stronger defenses across the board. By volume rather than cost, the ITRC's 2025 sector breakdown shows financial services logging the most compromises of any US sector at 739, ahead of healthcare at 534, professional services at 478, manufacturing at 299, and education at 188.

Transparency about what happened is getting worse, not better. The ITRC found that 70% of 2025 breach notices lacked any specific attack information, up from 65% in 2024 and 45% in 2023, meaning fewer disclosures tell affected users or investigators how the breach occurred. A companion ITRC survey of 1,040 US consumers found 88% reported a negative personal consequence after receiving a breach notice, and 60% described immediate anxiety on learning their data was exposed.

Loading chart...

Figure 5: Financial services logged the most tracked compromises of any US sector in 2025. Source: Identity Theft Resource Center, Annual Data Breach Report 2026.

Sector2025 US compromises (ITRC)Global average breach cost (IBM 2025)
Healthcare534USD 7.42 million (costliest sector)
Financial services739USD 4.44 million (global all-sector average)
Professional services478USD 4.44 million (global all-sector average)
Manufacturing299USD 4.44 million (global all-sector average)

Some of the most-cited breaches by scale are cataloged in the biggest data breaches of all time, which ranks incidents by records exposed rather than by cost or count.

The Bottom Line

The headline number for 2026 planning purposes is USD 4.44 million, the global average cost of a data breach in IBM's 2025 report, and the fact that it fell for the first time in five years matters as much as the figure itself. That decline came from faster detection, 241 days on average, not from fewer incidents: the ITRC counted a record 3,322 US compromises in 2025, and Verizon confirmed 12,195 breaches worldwide, both up year over year. Credential theft and phishing remain the two most common ways in, present in a majority of confirmed breaches, and both are slower to detect and more expensive to contain than the average incident. A site that keeps its privacy policy, breach-notification commitments, and access-control disclosures current is addressing exactly the gap regulators and researchers keep flagging: not exotic attacks, but ordinary human and credential failures that take months to notice.

Frequently Asked Questions

What is the average cost of a data breach in 2026? The most recent figure is USD 4.44 million globally, per IBM's Cost of a Data Breach Report 2025, covering breaches investigated between March 2024 and February 2025. That is down from USD 4.88 million the year before, a 9 percent decline and the first drop in five years.

How many data breaches happen each year? The Identity Theft Resource Center recorded 3,322 data compromises in the United States in 2025, a record high and a 5 percent increase over the 3,152 compromises logged in 2024. Verizon's 2025 Data Breach Investigations Report separately analyzed 12,195 confirmed breaches worldwide out of 22,052 total security incidents.

What causes most data breaches? A human action, such as a phishing click, a stolen password, or a misdirected email, was present in 60 percent of confirmed breaches, according to Verizon's 2025 DBIR. Ransomware appeared in 44 percent of breaches, up from 32 percent the year before, and phishing overtook stolen credentials in 2025 as the single most common initial attack vector at 16 percent, per IBM.

How long does it take companies to detect a data breach? 241 days on average to identify and contain a breach globally in 2025, per IBM's Cost of a Data Breach Report, the fastest figure in nine years and 17 days quicker than 2024. Breaches that started with stolen or compromised credentials took far longer to catch, around 292 days on average.

Where the Numbers Come From

  1. IBM. (2025). "Cost of a Data Breach Report 2025." Global average USD 4.44 million, 600 organizations studied across 17 industries and 16 countries and regions, breaches investigated March 2024 to February 2025.
  2. Verizon. (2025). "2025 Data Breach Investigations Report." 22,052 security incidents analyzed, 12,195 confirmed breaches, contributors across 139 countries.
  3. Identity Theft Resource Center. (2026). "2025 Annual Data Breach Report." 3,322 US data compromises, 278,827,933 victim notices, published January 2026.
  4. Verizon. (2025). "2025 DBIR Press Release: Third-Party Involvement and Vulnerability Exploitation." Third-party involvement doubled to 30%, vulnerability exploitation up 34% to 20% of breaches.
  5. Have I Been Pwned. Live breach-notification database, 17,708,582,733 pwned accounts across 1,019 pwned websites, checked July 2026.

Note: All figures verified as of July 2026. IBM and Verizon each publish a new annual edition, typically in the second quarter, so year-over-year figures in this post are refreshed at least twice a year to stay current with the newest report cycle.