Security

You Can't Defend What You Can't See: Five Lessons From the 2026 Verizon DBIR

You Can't Defend What You Can't See: Five Lessons From the 2026 Verizon DBIR

For eighteen straight years, Verizon's Data Breach Investigations Report told a consistent story: stolen credentials got attackers in the door more often than anything else. This year, that changed.

The 19th edition of the DBIR — built from more than 22,000 confirmed breaches across 145-plus countries, one of the largest datasets the report has ever drawn on — found that exploiting unpatched software has overtaken stolen credentials as the leading way businesses get breached. It's a small shift in ranking with a large implication: the thing most likely to sink an organization this year isn't a careless click. It's an asset nobody was watching.

That's the thread running through this year's report, and it's worth pulling on directly. Below are five findings from the 2026 DBIR that matter most, and what they actually demand from the businesses reading them.

1. Vulnerability exploitation is now the #1 way in — and remediation is losing ground

Exploited vulnerabilities now account for 31% of breaches, enough to displace credential abuse from the top spot for the first time in the report's 19-year history. Verizon attributes much of the shift to AI-assisted attack tooling, which has compressed the time between a vulnerability's public disclosure and its first real-world exploitation from months down to hours.

Defenders, meanwhile, are losing ground on the metric that matters most: how fast they close the gap. The median organization now carries 16 vulnerabilities from CISA's Known Exploited Vulnerabilities catalog at any given time, up from 11 the year before. Of those, only 26% get fully remediated — down sharply from 38% the previous year — and the median time to close one out has stretched from 32 days to 43. Do the arithmetic and the median organization is sitting on roughly a dozen known-exploited vulnerabilities at all times, not as a worst-case scenario, but as the baseline.

None of that is a patching problem in the traditional sense. It's a visibility problem wearing a patching costume. Teams can't prioritize remediation on assets they don't know are internet-facing, and a CVSS score alone doesn't tell you whether a given flaw is actually reachable, actually exploited in the wild, or actually attached to something the business cares about. That's the gap Cyber Oracle's attack surface monitoring is built to close — a continuously updated map of every domain, subdomain, exposed service, and certificate tied to your organization, so "unpatched" stops being a euphemism for "unknown."

2. The credential story is more precise than "phishing" — and more dangerous

It's tempting to lump every identity-related breach into one bucket, but the DBIR's own categorization is more specific, and more useful, than that. Phishing accounts for roughly 16% of breaches as a primary pattern; credential abuse another 13%; pretexting a further 6%. Combined with everything else touching human trust, some measure of the human element shows up in 62% of all breaches.

The part that should concern security leaders more than the raw percentages is what a stolen credential now carries with it. Session cookies and authentication tokens are increasingly harvested alongside passwords, which means multi-factor authentication — long treated as the fix for credential theft — can be sidestepped entirely if an attacker hijacks a live session instead of logging in fresh. A password rarely travels alone anymore.

Most organizations can tell you whether MFA is enabled. Far fewer can tell you which identities hold standing access they no longer need, which service accounts have never been reviewed, or where a compromised session would actually lead once inside. That's the question Cyber Oracle's identity and privilege graph is built to answer — mapping not just who can authenticate, but what each identity can actually reach.

3. The human element didn't go away. It went to your phone.

Security awareness training has spent a decade optimizing for one channel: email. Attackers have noticed, and moved. As employees have gotten sharper at spotting a phishing email, voice calls and text messages have picked up the slack — vishing and SMS-based social engineering now succeed at a rate roughly 40% higher than traditional email lures, according to Verizon's own analysis.

Pretexting — building a convincing scenario over the phone rather than through a link — has become a favored technique among some of the most disciplined attack groups tracked in this year's report, precisely because it's harder to filter and easier to trust. A voice on the phone doesn't get caught by a spam folder.

This is the one weakness on this list that isn't primarily a tooling problem, and it's why Cyber Oracle Academy exists as more than a compliance checkbox: hands-on labs built around real attack patterns — including voice and SMS-based pretexting — rather than another slideshow about suspicious email links.

4. Third parties are now involved in almost half of all breaches

Third-party involvement — a vendor, contractor, or integration whose weak security becomes your incident — jumped 60% year-over-year and now shows up in roughly 48% of all breaches the DBIR analyzed. For smaller and mid-sized businesses, the number is worse: third parties are implicated in over half of SMB breaches specifically.

The uncomfortable part is how slowly this category gets fixed once it's found. Weak passwords and misconfigured permissions inside vendor environments can take the better part of a year to resolve, largely because the organization that's exposed doesn't control the fix. Most businesses can name their biggest vendors. Far fewer maintain a living inventory of every third-party connection, OAuth grant, and integration with standing access to their systems.

This is, at its core, the same visibility problem as vulnerability management, just extended past your own perimeter: you're only ever as exposed as the assets and connections you've mapped, and third parties are assets too.

5. Shadow AI is the newest weakness, and the fastest-growing

The DBIR's authors have called this the quietest finding in the report and the most consequential one. Regular employee use of generative AI tools at work has roughly tripled in a single year, from about 15% to 45%. Source code, internal documents, and customer records are being pasted into tools that sit entirely outside the organization's security stack, on personal accounts nobody in IT approved or can see.

This isn't a future risk. It's a present one that most security programs have no instrumentation for at all — there's no firewall rule for "an employee pasted a customer record into a chatbot," and no awareness training built five years ago anticipated it.

Discovering shadow IT and shadow AI usage before it becomes a breach footnote is exactly what Cyber Oracle's shadow discovery engine is built to do: surface the unsanctioned tools, unmanaged accounts, and unofficial data flows that never show up in an asset inventory because nobody registered them in the first place.

The common thread

Read all five findings together and the pattern isn't subtle. It's rarely a total absence of controls that turns into a breach. It's something the organization didn't know it had: an internet-facing server nobody flagged, a vendor account nobody reviewed, a chatbot extension nobody approved. Firewalls, endpoint tools, and training all still matter, but every one of them only defends what it can see.

That's the premise Cyber Oracle is built on. Attack surface monitoring, identity and privilege mapping, hands-on security training, and shadow discovery aren't five separate products bolted together — they're five answers to the same question, the one every security program should be asking continuously: what do we actually have, who can reach it, and what is it doing right now?

Sources are drawn from Verizon's 2026 Data Breach Investigations Report (19th edition) and supporting research from contributing partners including Tenable, Qualys, and Veracode.

Learn this topic in depth
Cyber Oracle Academy has full courses on this topic — with interactive labs and real exploit walkthroughs.
Browse Courses

0 Comments

No comments yet. Be the first to share your thoughts.

Leave a Comment