Data Breach Statistics
Data Breach by Industry
Latest Statistics
About half of organisations have fully implemented data classification policies (49%) and data loss prevention across key egress channels (48%).
Among healthcare organizations that experience an identity-related incident, 33% incur costs above $250,000, compared with 21% in other industries.
At least 21% of users are logging in with a credential that has appeared in a known data breach.
62% of UK organisations experience material data loss, down from 74% in 2025.
Among UK organisations that experienced material data loss, post-attack recovery costs rose to 36% from 26% in 2025.
Among UK organisations that experienced material data loss, compromised insiders were the leading cause at 48%, with malicious or criminal insiders cited by 44% and careless insiders by 37%.
76% of organizations report their largest data loss event exceeded their Recovery Point Objective (RPO) targets.
In the second quarter (Q2) of 2026, analysis of publicly disclosed victim data and ransomware groups’ postings on Data Leak Sites (DLS) identified 1,140 ransomware incidents affecting industrial organizations worldwide, a 12% increase over the 1,020 incidents recorded in Q1.
In the past 12 months, 27% of organizations reported data breaches tied to AI use.
Sensitive information disclosure ranks as the second biggest LLM threat for a second consecutive year.
11% of reported cybercrime cases in Africa in 2025 involved data breaches.
AI-enabled malicious breaches increased by 56% over the previous year.
Financial services breaches cost on average $6.3 million.
73% of organizations have found their workforce’s credentials in breach, Dark Web, or infostealer data in the past year
Nearly 693,000 records are known to have been breached in the confirmed education-sector ransomware attacks in H1 2026.
Only 24% of H1 2026 breach notices contained attack-vector details, the lowest rate ever recorded by the ITRC.
Financial services recorded the highest frequency of compromises by sector at 387.
Q2 2026 tallied 1,029 compromises, the second-highest single-quarter total on record.
77% of enterprises are concerned about data breaches or theft in non-production environments.
68% of enterprises are concerned about data leaks in AI workflows.
Stealer log exposure increased 175% in a before-and-after security posture comparison.
34% of enterprise leaders report their organizations have experienced data breaches or theft.
The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.
Confirmed ransomware attacks on government entities involved 179,000 known breached records in H1 2026.
The City of Middletown, Ohio began notifying 123,791 people of a breach originating in July 2025.
Deadlock was absent from public data-leak sites for 11 months before emerging publicly.
The City of Suffolk, Virginia breach affected 157,725 people in February 2026.
94% of executives have at least one plaintext password exposed in breach data.
100% of executives have breach data linking their name to at least one current email address.
40% of quick service and fast casual restaurant chains had payment card data leaked in the past 12 months.
32% of quick service and fast casual restaurant chains had customer personal information leaked in the past 12 months.
30% of quick service and fast casual restaurant chains had internal system credentials leaked in the past 12 months.
28% of the top 100 vendors most commonly used by universities have experienced a data breach since 2024.
55.2% of IT and security professionals who experienced a security incident or breach in the past 12 months state they were told to keep it confidential despite believing it should have been reported.
The 55.2% of IT and security professionals told to keep breaches confidential is slightly down from 57.6% in 2025 and substantially higher than 42% in 2023.
68.6% of IT and security professionals in the U.S. who experienced a breach report being told to keep it confidential, the highest regional rate.
Cyber is the leading cause of both IT downtime and data loss for the fourth consecutive year.
43% of large organisations reported losing data as a result of a cyber attack.
31% of healthcare practices are still running on legacy systems that cannot contain a breach quickly once it starts.