Key Data Breach Statistics at a Glance
The figures above come from different studies with different populations, definitions, and time periods. IBM surveys 600 organizations globally about breach costs. Verizon analyzes confirmed security incidents reported by contributors. The ITRC tracks publicly disclosed U.S. data compromises. These numbers cannot be combined or ranked against each other without explaining the methodological differences.
| Statistic | Figure | Type | Year | Scope | Source |
|---|---|---|---|---|---|
| Global average breach cost | $4.44 million | Mean | 2025 | Global, 600 orgs | IBM / Ponemon Institute |
| U.S. average breach cost (record high) | $10.22 million | Mean | 2025 | United States | IBM / Ponemon Institute |
| Average cost per compromised record | $160 | Mean | 2025 | Global | IBM / Ponemon Institute |
| Mean time to identify a breach | 181 days | Mean | 2025 | Global | IBM / Ponemon Institute |
| Mean time to contain a breach | 60 days | Mean | 2025 | Global | IBM / Ponemon Institute |
| Total breach lifecycle | 241 days | Mean | 2025 | Global | IBM / Ponemon Institute |
| Confirmed data breaches analyzed | 12,195 | Count | 2025 DBIR | Global, 22,052 incidents | Verizon DBIR 2025 |
| Third-party involvement in breaches | 30% | Percentage | 2025 DBIR | Global | Verizon DBIR 2025 |
| Ransomware present in breaches | 44% | Percentage | 2025 DBIR | Global | Verizon DBIR 2025 |
| U.S. data compromises tracked | 3,158 | Count | 2024 | United States (public disclosures) | ITRC 2024 Annual Report |
| U.S. breach victim notices issued | 1.35 billion | Count | 2024 | United States | ITRC 2024 Annual Report |
| Most common initial attack vector | Phishing (16%) | Percentage | 2025 | Global | IBM / Ponemon Institute |
| Healthcare avg. breach cost (highest industry) | $7.42 million | Mean | 2025 | Global | IBM / Ponemon Institute |
| Healthcare large breaches reported to HHS | 663 notifications | Count | 2024 | United States (HIPAA, 500+ individuals) | HHS OCR Report to Congress 2024 |
What Is a Data Breach?
A breach can involve customer records, employee data, financial information, healthcare data, login credentials, intellectual property, or government records. Common types include network intrusions, phishing attacks that capture credentials, ransomware incidents involving data exfiltration, and accidental exposure due to misconfigured databases or cloud storage.
A cyberattack is any unauthorized attempt to access or damage systems. Not every cyberattack produces a data breach. A data leak or exposure typically refers to data made publicly accessible due to misconfiguration rather than active exploitation. A security incident is a broader category that includes any event potentially threatening information security. These terms are not interchangeable, and mixing statistics that use different definitions produces misleading comparisons.
Latest Data Breach Statistics (2025)
The most current primary source for breach cost data is the IBM Cost of a Data Breach Report 2025, conducted by the Ponemon Institute based on data from 600 organizations across 16 countries and 17 industries. The data collection period was March 2024 through February 2025.
Breach volume and records affected
The Verizon 2025 Data Breach Investigations Report analyzed 22,052 security incidents, of which 12,195 were confirmed data breaches with verified data disclosure. The report notes this represents the highest number of breaches ever analyzed in a single DBIR edition. The study covers incidents that occurred between November 1, 2023 and October 31, 2024, contributed by Verizon's global partner network from 139 countries.
Separately, the Identity Theft Resource Center tracked 3,158 data compromises publicly disclosed in the United States in 2024 -- a count that is 44 events below the 2023 all-time high. These are not the same as the Verizon figures: the ITRC tracks U.S. public disclosures, while Verizon analyzes confirmed incidents globally from contributing organizations.
Data Breach Statistics by Year
The table below draws exclusively from the ITRC's annual U.S. data compromise tracking, which uses a consistent methodology for counting publicly reported U.S. events. IBM breach cost figures are included separately because they use a fundamentally different methodology (survey-based cost estimation, global scope). These two datasets should not be merged into a single trend line.
| Year | U.S. Data Compromises | Victim Notices (Rounded) | Key Context |
|---|---|---|---|
| 2024 | 3,158 | 1.35 billion | Near-record count; 5 mega-breaches drove 83% of notices. Financial services led compromises (737). ITRC 2024 Report. |
| 2023 | 3,202 | ~419 million | All-time high count (since revised slightly). 78% increase over 2022. ITRC 2023 Report. |
| 2022 | 1,801 | ~425 million | Significant increase from 2021. ITRC 2022 Report. |
| 2021 | 1,860 | ~301 million | Previous all-time high at that point. ITRC 2021 Report. |
| 2020 | 1,108 | ~310 million | Decline from 2019 partly attributed to pandemic-related operational changes. ITRC 2020 Report. |
| 2019 | 1,279 | ~884 million | High victim count driven by large-scale incidents. ITRC 2019 Report. |
| Year | Global Avg. Breach Cost | U.S. Avg. Breach Cost | Notes |
|---|---|---|---|
| 2025 | $4.44 million | $10.22 million (record high) | First decline in 5 years. Data period: March 2024 - Feb 2025. |
| 2024 | $4.88 million | $9.36 million | Previous global and U.S. record highs. |
| 2023 | $4.45 million | $9.48 million | Increase continued from 2022. |
| 2022 | $4.35 million | $9.44 million | Record at time of publication. |
| 2021 | $4.24 million | $9.05 million | Largest single-year increase at time of publication. |
| 2020 | $3.86 million | $8.64 million | IBM 2020 report. |
Data Breach Cost Trend
IBM Global Average Data Breach Cost, 2020 to 2025
Source: IBM Cost of a Data Breach Reports (Ponemon Institute). Scope: Global survey of ~600 organizations. Measure: Mean total cost per breach incident in USD millions. Hover over bars for exact values.
Data Breaches vs Records Exposed: Why Both Matter
Breach statistics are reported in two distinct ways: the number of incidents and the number of records (or individuals) affected. These measure different dimensions of the problem and must be read separately.
In 2024, the ITRC tracked 3,158 U.S. data compromises -- nearly the same number as 2023. But victim notices jumped 211% to 1.35 billion. The reason: five mega-breaches (each affecting over 100 million individuals) accounted for 83% of all notices. The Change Healthcare breach alone ultimately affected approximately 190 million individuals. One incident can shift annual totals more than hundreds of smaller events combined.
This is why journalists and researchers need to report both figures. Saying "data breaches are getting worse" based on victim notice counts ignores whether the underlying incident count changed. Saying "breach counts are flat" ignores that scale per event can increase dramatically. A complete picture requires both dimensions.
How Much Does a Data Breach Cost?
The IBM Cost of a Data Breach Report is the most widely cited source for breach cost data. It uses a cost accounting approach developed by the Ponemon Institute, which tracks direct and indirect costs across several categories.
| Cost Component | Average Cost | What It Includes |
|---|---|---|
| Detection and escalation | $1.47 million | Forensic investigation, assessment, crisis management, communications |
| Lost business | $1.38 million | Business disruption, revenue loss, customer turnover, reputation-related effects |
| Post-breach response | $1.20 million | Help desk, credit monitoring, legal and regulatory costs, fines |
| Notification | $0.39 million | Notifying affected individuals, regulators, and other required parties |
| Total (global average) | $4.44 million | Sum of above components, global mean across 600 organizations |
IBM surveys ~600 organizations that experienced a breach. The sample is not random -- organizations willing to participate in the study may differ from the broader population. The figures represent means, which can be skewed by a few very expensive breaches. The IBM report does not represent the cost an average small business would experience. It is most useful for benchmarking large organization security investment decisions and identifying which cost drivers (such as detection time) are most significant.
Data Breach Costs by Industry (2025)
IBM breaks down average breach costs by industry. Healthcare has held the top position for 15 consecutive years. The following figures are mean costs per breach incident from the IBM Cost of a Data Breach Report 2025, covering March 2024 through February 2025. Industry rankings reflect IBM's surveyed sample and may not represent the full population of organizations in each sector.
Healthcare
Highest for 15 years. Down from $9.77M in 2024. Breaches take 279 days to identify and contain, 38 days longer than global average. IBM 2025.
Financial Services
Second-highest average. High regulatory scrutiny and complex investigations contribute to cost. IBM 2025.
Industrial
Third-highest in 2025. Operational technology (OT) environments add complexity. IBM 2025.
Energy
Critical infrastructure sector. High impact from operational disruption. IBM 2025.
Technology
Near global average. High IP exposure in breaches. IBM 2025.
Healthcare Data Breach Statistics
Healthcare breach data exists from two distinct sources that measure different things: the IBM cost report (global, survey-based, cost per incident) and the HHS Office for Civil Rights breach portal (U.S.-only, mandatory HIPAA reporting, count of breaches affecting 500 or more individuals). These cannot be directly compared.
HHS OCR data (United States, HIPAA-regulated entities)
Under HIPAA, covered entities and business associates are legally required to report breaches affecting 500 or more individuals to the HHS Secretary. The HHS OCR published its 2024 Annual Report to Congress in 2025, covering breaches reported in calendar year 2024.
The 2024 HHS OCR figure of approximately 243 million affected individuals is dominated by the Change Healthcare breach (approximately 192 million individuals). Excluding that single breach, approximately 51 million individuals were affected by all other large reported healthcare breaches in 2024. The choice to include or exclude mega-breaches substantially changes the picture. Always check whether a reported figure includes or excludes specific outliers.
What Causes Data Breaches?
Different reports categorize breach causes differently. IBM identifies the "initial attack vector" -- how attackers first gained access. Verizon's DBIR categorizes breaches by incident classification pattern and contributing actor. These categorizations overlap but are not identical. The figures below specify which report produced each figure.
Initial attack vectors (IBM Cost of a Data Breach Report 2025)
Leading attack vectors (Verizon DBIR 2025)
Verizon's DBIR uses a different categorization. Among the 12,195 confirmed breaches in the 2025 report, credential abuse was involved in 22% and exploitation of vulnerabilities in 20% of breaches. Credential abuse surged substantially compared to prior years, while vulnerability exploitation rose 34% year over year.
Ransomware and Data Breach Statistics
Ransomware attacks and data breaches are related but distinct. A ransomware attack is a type of malware incident that encrypts data and demands payment. Many modern ransomware attacks also exfiltrate data before encryption -- a tactic called "double extortion" -- which does constitute a data breach. However, not every ransomware attack results in a confirmed data breach, and not every data breach involves ransomware.
When ransomware encrypts files without exfiltrating them, it may or may not constitute a reportable data breach depending on applicable regulations. When attackers also steal the data (double extortion), it typically does qualify as a breach requiring notification. Reports that count all ransomware incidents as data breaches will produce higher breach totals than reports that verify actual data disclosure.
Third-Party and Supply-Chain Breach Statistics
A third-party breach occurs when an organization's data is compromised through a vendor, supplier, cloud provider, SaaS application, or other partner rather than through the organization's own systems directly. These breaches are particularly significant because the primary organization may have limited visibility into or control over the third party's security practices.
The Verizon 2025 DBIR found that third-party involvement in breaches doubled from 15% to 30% year over year. IBM found that breaches caused by third-party vendor and supply-chain compromise took the longest to resolve on average at 267 days, compared to the 241-day global average across all breach types.
How Long Does It Take to Detect a Data Breach?
The IBM Cost of a Data Breach Report tracks two time metrics: the mean time to identify (MTTI) a breach and the mean time to contain (MTTC) it. These are measured from the initial compromise through breach identification and then through full containment. The total is called the breach lifecycle.
| Scenario | Avg. Lifecycle | Avg. Cost |
|---|---|---|
| Global average (all breaches) | 241 days | $4.44 million |
| Healthcare sector | 279 days | $7.42 million |
| Vendor/supply-chain compromise | 267 days | Not separately disclosed |
| Malicious insider | 260 days | $4.92 million |
| Breach contained under 200 days | <200 days | $3.87 million |
| Breach contained over 200 days | >200 days | $5.01 million |
| On-premises only breach | 217 days | $4.01 million |
The relationship between breach lifecycle and cost is an observed correlation in IBM's survey sample. Longer breaches cost more on average, but this does not prove that reducing detection time mechanically reduces cost. Organizations with better security capabilities may both detect breaches faster and spend less on recovery, making security maturity a confounding factor in both measures.
Global Data Breach Statistics
Direct country-to-country comparisons of breach statistics are difficult because reporting requirements, definitions, regulatory environments, and detection capabilities differ substantially across jurisdictions. Differences in reported breach counts between countries often reflect differences in reporting systems as much as differences in actual breach frequency.
United States
The U.S. has the highest average breach cost of any country in IBM's study ($10.22 million in 2025, a record). The ITRC tracked 3,158 U.S. data compromises in 2024. The U.S. has 50+ state-level breach notification laws plus sector-specific federal requirements (HIPAA for healthcare, SEC rules for public companies), making U.S. breach reporting among the most comprehensive globally.
Middle East
IBM's 2025 report placed the Middle East second in average breach cost at $7.29 million. The region's high cost reflects the significant representation of energy and financial sector organizations in IBM's sample from that region.
European Union
The EU's General Data Protection Regulation (GDPR) requires data breach notification to supervisory authorities within 72 hours of awareness when the breach is likely to result in a risk to individuals' rights and freedoms. GDPR fines can reach 4% of global annual turnover for serious violations. This mandatory reporting framework means EU breach statistics tend to capture incidents that might go unreported in jurisdictions with less stringent requirements.
Global incident scope
Verizon's 2025 DBIR covered incidents from 139 countries. The report notes that Asia-Pacific saw system intrusion breaches increase substantially, and EMEA experienced a near-doubling of system intrusion breaches to 53% of regional breaches. These are not directly comparable to U.S. or EU country-specific statistics because methodology, contributing organizations, and reporting thresholds differ.
Why Data Breach Statistics Differ Between Sources
Understanding why published data breach statistics can differ by factors of 10 or more requires examining how each source defines and counts breaches.
| Source | What It Measures | Geography | Unit | Key Limitation |
|---|---|---|---|---|
| IBM / Ponemon Cost of a Data Breach Report 2025 |
Average total cost of a breach incident across 17 cost categories | Global (~600 orgs, 16 countries) | Mean cost in USD per breach | Non-random sample; participants must have experienced a breach; mean can be skewed by large incidents; no median reported |
| Verizon Business Data Breach Investigations Report 2025 |
Security incidents and confirmed data breaches analyzed by Verizon and partner contributors | Global (139 countries, 22,052 incidents) | Count of confirmed breaches and incidents; percentage breakdowns by category | Relies on contributed data from partner organizations; coverage varies by region; not a probability sample of all organizations |
| Identity Theft Resource Center Annual Data Breach Report 2024 |
Publicly reported U.S. data compromises (breaches, exposures, leaks) | United States only | Count of data compromise events; victim notice counts | Captures only publicly disclosed events; does not include unreported incidents; one individual may appear in multiple victim notice counts |
| HHS Office for Civil Rights Breach Portal and Annual Report to Congress |
HIPAA breach notifications (500+ individuals) from covered entities and business associates | United States, healthcare sector only | Count of breach notifications; individuals affected | Mandatory reporting only for HIPAA-covered entities; count of notifications, not unique individuals; one individual may be counted across multiple breaches |
Additional reasons breach statistics vary: mandatory vs. voluntary reporting, whether suspected incidents count alongside confirmed ones, whether ransomware without data exfiltration is counted, and whether the unit is events or affected individuals. For a statistics-based introduction to how different measurement choices affect observed distributions, see the site's descriptive statistics section, or the specific articles on mean and median.
Mean vs. Median in Breach Cost Statistics
The IBM Cost of a Data Breach Report uses mean (average) costs. This matters because a small number of extremely expensive breaches can substantially increase the mean without affecting typical experience. IBM does not publish median breach costs in public summaries, which makes it difficult to assess how skewed the distribution is.
For a rigorous statistical treatment of why choosing mean vs. median matters for skewed distributions, see the mean vs. median vs. mode article and the site's outlier analysis page. The role of a single mega-breach in annual victim counts illustrates exactly why outliers matter -- the outliers in statistics article covers this in depth.
Notable Documented Data Breaches
The following are among the most significant documented data breaches based on confirmed public disclosures and regulatory filings. Figures come from official company filings or regulatory reports.
The Change Healthcare ransomware attack (ALPHV/BlackCat group) disrupted healthcare payment processing across the U.S. The HHS OCR 2024 congressional report recorded this as a breach affecting approximately 192 million individuals, representing the largest healthcare data breach by individual count on record. The breach affected HIPAA-covered information including health insurance information, medical records, and Social Security numbers.
A data broker breach in which personal records including names, addresses, and Social Security numbers were exposed. The "2.9 billion records" figure cited widely in media represents row counts in an aggregated database, not unique individuals. The actual number of distinct individuals is substantially lower. The company filed for bankruptcy following the incident. This case illustrates why database row counts and unique individual counts require separate reporting.
One of several large breaches linked to attackers using stolen credentials to access Snowflake cloud data environments of multiple companies. The Ticketmaster parent company Live Nation disclosed approximately 560 million customer records. The ITRC categorized this as one of five 2024 mega-breaches that collectively drove 83% of that year's U.S. victim notices.
AT&T disclosed two separate 2024 data breaches: one involving records of approximately 73 million customers on a hacker forum, and another affecting call and text metadata for approximately 109 million customers. The company confirmed the metadata breach resulted from unauthorized access to a third-party cloud platform.
Data Breach Statistics Calculator
📊 Data Breach Calculations
Calculate the percentage change in breach count or cost between two periods. Formula: ((Current - Previous) / Previous) × 100. This is a descriptive calculation, not an official industry metric.
Calculate average records affected per reported breach. Formula: Total records / number of breaches. Note: this average is heavily influenced by outliers (mega-breaches).
Calculate cost per affected record. Formula: Total breach cost / records affected. IBM's 2025 global average is $160 per record. This is a descriptive ratio, not a standardized regulatory measure.
How to Interpret Data Breach Statistics
Before accepting any data breach statistic at face value, ask these five questions:
- What is the exact definition? "Breach," "incident," "exposure," and "compromise" are not interchangeable. What did this source actually count?
- What is the population or sample? Is this global or national? All industries or a specific sector? Organizations of what size? A survey of willing participants or mandatory reporting?
- What year and time period? IBM's 2025 report covers March 2024 to February 2025. The ITRC 2024 report covers January to December 2024. These are not the same period.
- Is the figure a mean or a median? Means are sensitive to outliers. A single mega-breach can pull annual averages far from the typical experience. Always check which is being reported.
- What are the limitations? Every primary source contains a methodology section explaining what it cannot measure. Non-reported breaches, companies that declined to participate, and definitional edge cases all affect what any statistic can claim to represent.
The statistical interpretation guide on this site covers these reasoning principles in more depth. The correlation vs. causation article is also relevant when interpreting claims like "organizations with AI save $1.9 million on breaches" -- the relationship is observed in IBM's survey sample, not experimentally proven.
What Data Breach Statistics Mean for Businesses
Aggregate statistics do not translate directly into personalized risk estimates. An organization's actual breach probability and cost depend on its size, industry, security controls, data sensitivity, geographic location, and regulatory environment. That said, published statistics are useful for several practical purposes.
Security investment prioritization: IBM data consistently shows that organizations using AI and automation extensively saved an average of $1.9 million per breach in 2025 and shortened the breach lifecycle by approximately 80 days. This association does not establish causation, but it suggests that investment in detection and response capability is linked to lower costs. Similarly, faster breach detection (under 200 days total lifecycle) correlated with $3.87 million average cost vs. $5.01 million for slower containment.
Third-party risk: Verizon's finding that third-party involvement doubled to 30% of all breaches underscores the importance of vendor security assessments. IBM data shows supply-chain breaches take 267 days to contain on average.
Incident response planning: IBM's data shows that organizations that detect breaches through their own security teams (rather than being notified by an attacker or third party) save approximately $900,000 on average. This supports the case for investment in internal detection capability.
Data Breach Statistics for Students
If you are researching this topic for an academic assignment, three things to establish before citing any statistic: (1) which organization published the data, (2) what definition of "breach" they used, and (3) the geographic and industry scope. These three elements separate a citable, defensible statistic from a generic headline number.
Good research questions for this topic: How does the ITRC define a "data compromise" compared to Verizon's definition of a "confirmed breach"? Why does the IBM Cost of a Data Breach Report use mean rather than median costs? What effect do mandatory breach disclosure laws (HIPAA, GDPR, state laws) have on the number of breaches reported in a given country compared to countries with weaker requirements?
For statistical concepts used in analyzing this kind of data, the site's descriptive statistics section, the AI for business statistics article, and the statistics and probability section cover the foundational methods.
Record: organization name, report title, publication year, specific statistic, the dataset or survey it came from, geographic scope, and the URL. For example: IBM / Ponemon Institute. "Cost of a Data Breach Report 2025." Global average cost of a data breach: $4.44 million (mean). Covers 600 organizations in 16 countries, March 2024 - February 2025. ibm.com/security/data-breach. Published July 30, 2025.
Frequently Asked Questions
As of 2025, IBM reports the global average data breach cost at $4.44 million, a 9% decline from the 2024 record of $4.88 million. The U.S. average reached a record $10.22 million. Verizon's 2025 DBIR analyzed 12,195 confirmed breaches. The ITRC tracked 3,158 U.S. data compromises in 2024. These figures come from different studies with different populations and definitions -- they measure distinct aspects of the breach landscape.
Counts depend on the source and definition. Verizon analyzed 12,195 confirmed data breaches in its 2025 DBIR (November 2023 - October 2024 period, global). The ITRC tracked 3,158 U.S. data compromises in 2024. The difference reflects different geographic scope, contributing data sources, and definitions of what qualifies as a counted breach. Neither figure represents a census of all breaches globally, since many incidents are never discovered or reported.
According to the IBM Cost of a Data Breach Report 2025, the global mean total cost of a data breach was $4.44 million. This is a mean, not a median, so large outliers affect it. The U.S. mean was $10.22 million. Healthcare averaged $7.42 million globally, the highest of any industry. These are IBM's survey-based averages across 600 organizations; individual organization costs vary based on size, industry, controls, and specific incident factors.
IBM's 2025 Cost of a Data Breach Report found the mean time to identify a breach was 181 days and the mean time to contain it was 60 days, for a total mean lifecycle of 241 days. This is the lowest figure since 2016 and continues a downward trend from the 287-day peak in 2021. Note: "identify" means detecting that a breach occurred; "contain" means stopping ongoing unauthorized access. These are mean figures across IBM's 600-organization sample.
The answer depends on the measure. By breach count, the ITRC found financial services led U.S. data compromises in 2024 with 737 incidents, followed by healthcare (536). By cost per breach, healthcare has ranked highest globally for 15 consecutive years in IBM's report, at $7.42 million average in 2025. These two rankings measure different things -- incident frequency vs. financial impact per incident.
IBM's 2025 report identified phishing as the most common initial attack vector, present in 16% of breaches. Verizon's 2025 DBIR found credential abuse (22%) and exploitation of vulnerabilities (20%) as the leading initial vectors. These reports use different categorization frameworks, so the rankings reflect methodological choices as well as actual incident patterns.
The trend differs by metric. U.S. breach counts tracked by the ITRC remained near record levels from 2023 to 2024 (3,202 then 3,158 events). IBM's global average breach cost declined 9% from 2024's record to 2025, suggesting cost control is improving. Verizon found ransomware involvement rose 37% and third-party involvement doubled. No single answer covers all dimensions -- breach frequency, record counts, and costs each tell a different part of the story.
The terms are not consistently defined across sources. In general usage, a data breach involves an active unauthorized actor accessing or stealing data. A data leak or exposure typically refers to data made accessible due to misconfiguration (such as an unsecured database or cloud bucket) rather than deliberate hacking. A data exposure may or may not qualify as a reportable breach under applicable law, depending on whether unauthorized access is proven to have occurred. Always check which definition a source uses.
Several factors cause divergence: different definitions of "breach," different geographic scope (U.S.-only vs. global), different populations (all organizations vs. surveyed participants vs. mandatory reporters), different time periods, whether estimated/suspected breaches are counted alongside confirmed ones, and whether the unit is incidents or affected individuals. This is why comparing a headline figure from IBM directly against one from ITRC produces a meaningless result -- they do not measure the same thing.
It depends on the report. IBM's cost figures come from a structured survey where participating organizations report detailed cost data across categories (detection, notification, lost business, response). The Ponemon Institute then aggregates and calculates means. Verizon counts incidents contributed by partner organizations and classifies them using defined frameworks. The ITRC reviews publicly reported breach disclosures in U.S. media and government databases. Each method has specific strengths and blind spots described in its methodology section.
Data Sources and Methodology
This page draws statistics from four primary sources selected for methodological transparency, authority, and relevance.
IBM Cost of a Data Breach Report 2025 (Ponemon Institute): The most widely cited source for breach cost figures. Published July 30, 2025. Based on 600 organizations in 16 countries across 17 industries. Measures mean total cost per breach across 17 cost categories. Data period: March 2024 - February 2025. Limitations: survey-based, non-random sample, mean only (no median), participants must have experienced a qualifying breach. URL: ibm.com/security/data-breach.
Verizon 2025 Data Breach Investigations Report: The leading source for breach pattern and attribution analysis. Published April 23, 2025. Analyzed 22,052 security incidents including 12,195 confirmed data breaches from 139 countries, November 2023 - October 2024. Limitations: contributed data, coverage varies by region, not a probability sample. URL: verizon.com/business/resources/reports/dbir/.
ITRC 2024 Annual Data Breach Report: Primary U.S. breach count source. Published January 28, 2025. Tracks publicly reported U.S. data compromises (breaches, exposures, leaks). Measures: compromise count (3,158) and victim notice count (1.35 billion). Limitations: only publicly disclosed events; victim notices, not unique individuals; U.S.-only. URL: idtheftcenter.org.
HHS OCR Annual Report to Congress on Breaches of Unsecured PHI, 2024: Authoritative source for U.S. healthcare breach data. Covers HIPAA-required breach notifications to HHS for breaches affecting 500 or more individuals. Limitations: U.S. healthcare sector only; mandatory reporting threshold means small breaches may be undercounted in large-breach analysis; individual counts can involve duplicates across multiple filings. URL: hhs.gov/ocr.
Data breach statistics are time-sensitive. This page uses the most recent primary reports available as of September 2026. Where statistics from multiple sources appear in the same section, differences in definition, scope, and methodology are explicitly noted. Statistics from incompatible sources are not added together or presented as if they measure the same population. If you notice a figure that appears outdated or incorrectly attributed, the editorial team reviews primary sources at least annually or when a new major report is published.