Patch Gaps, Pretexting, and AI Use for Crimes and Crimefighting: 2026 Verizon DBIR Highlights

Packet Pushers
Packet PushersJun 9, 2026

Why It Matters

The shift toward vulnerability‑driven breaches and AI‑enhanced attacks forces businesses to overhaul patching, training, and detection strategies, directly impacting risk exposure and financial loss.

Key Takeaways

  • Vulnerability exploits now lead initial breach access, up 31%.
  • Only 26% of critical flaws fully patched; median 43 days.
  • Pretexting attacks surge, demanding stronger security awareness programs.
  • Threat actors leverage AI tools, with Mythos set to accelerate.
  • Ransomware remains common, but victim payouts and payments decline.

Summary

The 2026 Verizon Data Breach Investigations Report (DBIR) analyzes 31,000 incidents—including over 22,000 confirmed breaches—across 145 countries from November 2024 to October 2025. As the industry’s most comprehensive annual cyber‑threat barometer, it offers a data‑driven temperature check on evolving attack vectors, remediation practices, and financial impacts.

Key findings show vulnerability exploitation eclipsing credential abuse as the top initial‑access technique, accounting for 31% of incidents—more than double the prior year. Patch management remains a chronic weakness: only 26% of critical, known‑exploited vulnerabilities were fully remediated, with a median resolution time of 43 days, and 58% only partially addressed. Pretexting attacks are on the rise, pressuring organizations to refresh security‑awareness training, while threat actors increasingly embed AI tools into their workflows, a trend expected to accelerate with the upcoming Mythos platform.

Notable data points include ransomware involvement in 48% of breaches, yet 69% of victims chose not to pay, and the median ransom fell to $140,000—a 6.75% decline. The report also highlights that many organizations still rely on partial mitigations, such as compensating controls, rather than full patch closure, underscoring a fragmented defense posture.

The implications are clear: enterprises must accelerate vulnerability remediation cycles, adopt a holistic view that couples patching with credential hygiene, and invest in AI‑driven detection and response capabilities. Strengthening phishing and pretexting defenses through continuous training will be essential as social‑engineering tactics evolve, while ransomware strategies should focus on robust backup and incident‑response plans rather than ransom payments.

Original Description

The Verizon Data Breach Investigations Report (DBIR) is a postmortem of a year's worth of cyber incidents and breaches, and a snapshot of how well organizations are responding to actual threats. Drew and JJ share highlights from the 2026 installment, including:
- For the first time, vulnerability exploits top the list for initial access
- What a drop in victims paying out ransoms might mean for the criminal ransomware industry
- The troubling rise of pretexting and why it's more effective for threat actors than phishing
- How threat actors are using AI
- More
Links:
Packet Protector is part of the Packet Pushers network. Visit our website to find more great networking and technology podcasts, along with tutorial videos, the Human Infrastructure newsletter, and loads more resources for building your IT career. https://packetpushers.net

Comments

Want to join the conversation?

Loading comments...