Technology Cybersecurity Statistics 22 min read September 18, 2026
BY: Statistics Fundamentals Team
Reviewed By: Minsa A (Senior Statistics Editor)

Data Breach Statistics: Latest Cybersecurity Data & Trends

Data breach statistics measure the frequency, scale, and financial impact of unauthorized access to protected information. Different organizations use different definitions, population samples, geographic scopes, and reporting periods, which is why two credible sources can produce very different headline numbers. The most recent primary sources (IBM Cost of a Data Breach Report 2025, Verizon DBIR 2025, ITRC 2024 Annual Report, HHS OCR 2024 Report to Congress) show global average breach costs declining for the first time in five years, while total breach volumes remain near record levels.

What This Page Covers
  • ✓ Key statistics at a glance with source, year, and scope labeled
  • ✓ Average breach cost, detection time, and containment time (IBM 2025)
  • ✓ Breach counts and records affected (Verizon 2025, ITRC 2024, HHS OCR 2024)
  • ✓ Industry cost breakdown, causes, ransomware, and third-party statistics
  • ✓ Healthcare breach statistics from HHS OCR
  • ✓ Historical trend table and interactive chart
  • ✓ Calculator, FAQ, methodology notes, and source comparison table
Data last reviewed: September 2026. Primary statistics drawn from IBM Cost of a Data Breach Report 2025, Verizon DBIR 2025, ITRC 2024 Annual Data Breach Report, and HHS OCR 2024 Annual Report to Congress. Statistics marked by year and source throughout.

Key Data Breach Statistics at a Glance

$4.44M
Global avg. breach cost (2025)
241 days
Avg. breach lifecycle to contain (2025)
12,195
Confirmed breaches analyzed (DBIR 2025)
44%
Of breaches involving ransomware (DBIR 2025)
Important: Not all statistics measure the same thing

The figures above come from different studies with different populations, definitions, and time periods. IBM surveys 600 organizations globally about breach costs. Verizon analyzes confirmed security incidents reported by contributors. The ITRC tracks publicly disclosed U.S. data compromises. These numbers cannot be combined or ranked against each other without explaining the methodological differences.

Table 1. Key data breach statistics at a glance. Each figure carries its own scope and definition; consult the source notes before comparing across rows.
Statistic Figure Type Year Scope Source
Global average breach cost$4.44 millionMean2025Global, 600 orgsIBM / Ponemon Institute
U.S. average breach cost (record high)$10.22 millionMean2025United StatesIBM / Ponemon Institute
Average cost per compromised record$160Mean2025GlobalIBM / Ponemon Institute
Mean time to identify a breach181 daysMean2025GlobalIBM / Ponemon Institute
Mean time to contain a breach60 daysMean2025GlobalIBM / Ponemon Institute
Total breach lifecycle241 daysMean2025GlobalIBM / Ponemon Institute
Confirmed data breaches analyzed12,195Count2025 DBIRGlobal, 22,052 incidentsVerizon DBIR 2025
Third-party involvement in breaches30%Percentage2025 DBIRGlobalVerizon DBIR 2025
Ransomware present in breaches44%Percentage2025 DBIRGlobalVerizon DBIR 2025
U.S. data compromises tracked3,158Count2024United States (public disclosures)ITRC 2024 Annual Report
U.S. breach victim notices issued1.35 billionCount2024United StatesITRC 2024 Annual Report
Most common initial attack vectorPhishing (16%)Percentage2025GlobalIBM / Ponemon Institute
Healthcare avg. breach cost (highest industry)$7.42 millionMean2025GlobalIBM / Ponemon Institute
Healthcare large breaches reported to HHS663 notificationsCount2024United States (HIPAA, 500+ individuals)HHS OCR Report to Congress 2024

What Is a Data Breach?

Definition: Data Breach
A data breach is an incident in which protected, sensitive, or confidential information is accessed, disclosed, acquired, or exposed without authorization. The unauthorized party may be an external attacker, a malicious insider, or an inadvertent actor. The key element is that protected data leaves its intended security boundary.
Note: Legal definitions vary. HIPAA defines a breach as the unauthorized acquisition, access, use, or disclosure of protected health information. GDPR defines a personal data breach as a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data. State breach notification laws in the U.S. each define a breach slightly differently.

A breach can involve customer records, employee data, financial information, healthcare data, login credentials, intellectual property, or government records. Common types include network intrusions, phishing attacks that capture credentials, ransomware incidents involving data exfiltration, and accidental exposure due to misconfigured databases or cloud storage.

💡
Key distinction: breach vs. related terms

A cyberattack is any unauthorized attempt to access or damage systems. Not every cyberattack produces a data breach. A data leak or exposure typically refers to data made publicly accessible due to misconfiguration rather than active exploitation. A security incident is a broader category that includes any event potentially threatening information security. These terms are not interchangeable, and mixing statistics that use different definitions produces misleading comparisons.

Latest Data Breach Statistics (2025)

The most current primary source for breach cost data is the IBM Cost of a Data Breach Report 2025, conducted by the Ponemon Institute based on data from 600 organizations across 16 countries and 17 industries. The data collection period was March 2024 through February 2025.

IBM Cost of a Data Breach Report 2025 — Global Average
$4.44 million
The global average total cost of a data breach fell 9% from the 2024 record of $4.88 million. This is the first decline in five years. The U.S. average reached a record $10.22 million. The report covers 600 organizations globally; figures represent mean costs, not median, and a single outlier can shift them.
Source: IBM Cost of a Data Breach Report 2025, published July 30, 2025. Conducted by Ponemon Institute. Scope: 600 organizations in 16 countries and 17 industries. Period: March 2024 - February 2025. Measure: Average total cost per breach incident. ibm.com/security/data-breach

Breach volume and records affected

The Verizon 2025 Data Breach Investigations Report analyzed 22,052 security incidents, of which 12,195 were confirmed data breaches with verified data disclosure. The report notes this represents the highest number of breaches ever analyzed in a single DBIR edition. The study covers incidents that occurred between November 1, 2023 and October 31, 2024, contributed by Verizon's global partner network from 139 countries.

Separately, the Identity Theft Resource Center tracked 3,158 data compromises publicly disclosed in the United States in 2024 -- a count that is 44 events below the 2023 all-time high. These are not the same as the Verizon figures: the ITRC tracks U.S. public disclosures, while Verizon analyzes confirmed incidents globally from contributing organizations.

Source: Verizon 2025 Data Breach Investigations Report, published April 23, 2025. Scope: Global, 22,052 incidents from 139 countries. Measure: Confirmed data breaches (12,195) and total security incidents. verizon.com/business/resources/reports/dbir/
Source: Identity Theft Resource Center 2024 Annual Data Breach Report, published January 28, 2025. Scope: United States, publicly reported compromises. Measure: Data compromises (3,158) and victim notices (1.35 billion). idtheftcenter.org

Data Breach Statistics by Year

The table below draws exclusively from the ITRC's annual U.S. data compromise tracking, which uses a consistent methodology for counting publicly reported U.S. events. IBM breach cost figures are included separately because they use a fundamentally different methodology (survey-based cost estimation, global scope). These two datasets should not be merged into a single trend line.

Table 2. ITRC U.S. data compromises and victim notices by year. Source: ITRC Annual Data Breach Reports. Victim notices count notifications sent, not unique individuals -- one person may receive multiple notices.
Year U.S. Data Compromises Victim Notices (Rounded) Key Context
20243,1581.35 billionNear-record count; 5 mega-breaches drove 83% of notices. Financial services led compromises (737). ITRC 2024 Report.
20233,202~419 millionAll-time high count (since revised slightly). 78% increase over 2022. ITRC 2023 Report.
20221,801~425 millionSignificant increase from 2021. ITRC 2022 Report.
20211,860~301 millionPrevious all-time high at that point. ITRC 2021 Report.
20201,108~310 millionDecline from 2019 partly attributed to pandemic-related operational changes. ITRC 2020 Report.
20191,279~884 millionHigh victim count driven by large-scale incidents. ITRC 2019 Report.
Table 3. IBM average breach cost trend (global, survey-based, mean cost per breach incident). Source: IBM Cost of a Data Breach Reports. This is a separate dataset from the ITRC table above -- do not combine the two.
Year Global Avg. Breach Cost U.S. Avg. Breach Cost Notes
2025$4.44 million$10.22 million (record high)First decline in 5 years. Data period: March 2024 - Feb 2025.
2024$4.88 million$9.36 millionPrevious global and U.S. record highs.
2023$4.45 million$9.48 millionIncrease continued from 2022.
2022$4.35 million$9.44 millionRecord at time of publication.
2021$4.24 million$9.05 millionLargest single-year increase at time of publication.
2020$3.86 million$8.64 millionIBM 2020 report.

Data Breach Cost Trend

IBM Global Average Data Breach Cost, 2020 to 2025

Source: IBM Cost of a Data Breach Reports (Ponemon Institute). Scope: Global survey of ~600 organizations. Measure: Mean total cost per breach incident in USD millions. Hover over bars for exact values.

IBM Global Average Data Breach Cost 2020-2025 $5.5M $4.5M $3.5M $2.5M $1.5M $3.86M 2020 $4.24M 2021 $4.35M 2022 $4.45M 2023 $4.88M 2024 $4.44M 2025
Standard year
Record high
Decline from record

Data Breaches vs Records Exposed: Why Both Matter

Breach statistics are reported in two distinct ways: the number of incidents and the number of records (or individuals) affected. These measure different dimensions of the problem and must be read separately.

📊
Why the numbers diverge dramatically

In 2024, the ITRC tracked 3,158 U.S. data compromises -- nearly the same number as 2023. But victim notices jumped 211% to 1.35 billion. The reason: five mega-breaches (each affecting over 100 million individuals) accounted for 83% of all notices. The Change Healthcare breach alone ultimately affected approximately 190 million individuals. One incident can shift annual totals more than hundreds of smaller events combined.

This is why journalists and researchers need to report both figures. Saying "data breaches are getting worse" based on victim notice counts ignores whether the underlying incident count changed. Saying "breach counts are flat" ignores that scale per event can increase dramatically. A complete picture requires both dimensions.

How Much Does a Data Breach Cost?

The IBM Cost of a Data Breach Report is the most widely cited source for breach cost data. It uses a cost accounting approach developed by the Ponemon Institute, which tracks direct and indirect costs across several categories.

Table 4. IBM average data breach cost components, 2025. Source: IBM Cost of a Data Breach Report 2025. Scope: Global average. Measure: Mean cost per component.
Cost Component Average Cost What It Includes
Detection and escalation$1.47 millionForensic investigation, assessment, crisis management, communications
Lost business$1.38 millionBusiness disruption, revenue loss, customer turnover, reputation-related effects
Post-breach response$1.20 millionHelp desk, credit monitoring, legal and regulatory costs, fines
Notification$0.39 millionNotifying affected individuals, regulators, and other required parties
Total (global average)$4.44 millionSum of above components, global mean across 600 organizations
Source: IBM Cost of a Data Breach Report 2025, Ponemon Institute. Note: These are mean (average) costs. Individual organization costs will vary based on size, industry, regulatory environment, security maturity, and incident specifics. The report does not publish median figures, so the effect of outliers on the mean is not directly quantifiable from public data.
About IBM breach cost figures

IBM surveys ~600 organizations that experienced a breach. The sample is not random -- organizations willing to participate in the study may differ from the broader population. The figures represent means, which can be skewed by a few very expensive breaches. The IBM report does not represent the cost an average small business would experience. It is most useful for benchmarking large organization security investment decisions and identifying which cost drivers (such as detection time) are most significant.

Data Breach Costs by Industry (2025)

IBM breaks down average breach costs by industry. Healthcare has held the top position for 15 consecutive years. The following figures are mean costs per breach incident from the IBM Cost of a Data Breach Report 2025, covering March 2024 through February 2025. Industry rankings reflect IBM's surveyed sample and may not represent the full population of organizations in each sector.

Healthcare

$7.42M

Highest for 15 years. Down from $9.77M in 2024. Breaches take 279 days to identify and contain, 38 days longer than global average. IBM 2025.

Financial Services

$5.56M

Second-highest average. High regulatory scrutiny and complex investigations contribute to cost. IBM 2025.

Industrial

$4.76M

Third-highest in 2025. Operational technology (OT) environments add complexity. IBM 2025.

Energy

$4.72M

Critical infrastructure sector. High impact from operational disruption. IBM 2025.

Technology

$4.38M

Near global average. High IP exposure in breaches. IBM 2025.

Source: IBM Cost of a Data Breach Report 2025. Scope: Global, survey-based, mean cost per breach. Healthcare figure: 15th consecutive year as top industry. These are averages across IBM's sample -- not every organization in these sectors will experience these costs.

Healthcare Data Breach Statistics

Healthcare breach data exists from two distinct sources that measure different things: the IBM cost report (global, survey-based, cost per incident) and the HHS Office for Civil Rights breach portal (U.S.-only, mandatory HIPAA reporting, count of breaches affecting 500 or more individuals). These cannot be directly compared.

HHS OCR data (United States, HIPAA-regulated entities)

Under HIPAA, covered entities and business associates are legally required to report breaches affecting 500 or more individuals to the HHS Secretary. The HHS OCR published its 2024 Annual Report to Congress in 2025, covering breaches reported in calendar year 2024.

663
Large breach notifications to HHS in 2024
~243M
Individuals affected (2024 filings)
74,299
Small breach reports (<500 individuals)
9% decrease
In large breach notifications vs 2023
Source: HHS Office for Civil Rights, Annual Report to Congress on Breaches of Unsecured Protected Health Information, Calendar Year 2024. Scope: United States, HIPAA-covered entities reporting breaches affecting 500+ individuals. Note: The approximately 243 million individuals figure includes the Change Healthcare breach, which was revised upwards multiple times; the final count of ~192 million individuals appears in the 2024 congressional report filed July 2025. One individual may be counted across multiple breach filings.
Interpreting healthcare breach figures

The 2024 HHS OCR figure of approximately 243 million affected individuals is dominated by the Change Healthcare breach (approximately 192 million individuals). Excluding that single breach, approximately 51 million individuals were affected by all other large reported healthcare breaches in 2024. The choice to include or exclude mega-breaches substantially changes the picture. Always check whether a reported figure includes or excludes specific outliers.

What Causes Data Breaches?

Different reports categorize breach causes differently. IBM identifies the "initial attack vector" -- how attackers first gained access. Verizon's DBIR categorizes breaches by incident classification pattern and contributing actor. These categorizations overlap but are not identical. The figures below specify which report produced each figure.

Initial attack vectors (IBM Cost of a Data Breach Report 2025)

Phishing 16%
Vendor/Supply-Chain Compromise 15%
Denial of Service 12.5%
Compromised Credentials 10%
Business Email Compromise ~9%
Malicious Insider ~7%
Source: IBM Cost of a Data Breach Report 2025. Scope: Global, survey-based. Measure: Percentage of breaches by initial attack vector. Note: Malicious insider breaches (approximately 7% of incidents) produced the highest average cost at $4.92 million per breach.

Leading attack vectors (Verizon DBIR 2025)

Verizon's DBIR uses a different categorization. Among the 12,195 confirmed breaches in the 2025 report, credential abuse was involved in 22% and exploitation of vulnerabilities in 20% of breaches. Credential abuse surged substantially compared to prior years, while vulnerability exploitation rose 34% year over year.

Source: Verizon 2025 Data Breach Investigations Report. Scope: Global, 12,195 confirmed breaches. Measure: Percentage of confirmed breaches involving each initial access vector. Note: These percentages reflect Verizon's incident data contributed by partner organizations -- the population differs from IBM's surveyed organizations.

Ransomware and Data Breach Statistics

Ransomware attacks and data breaches are related but distinct. A ransomware attack is a type of malware incident that encrypts data and demands payment. Many modern ransomware attacks also exfiltrate data before encryption -- a tactic called "double extortion" -- which does constitute a data breach. However, not every ransomware attack results in a confirmed data breach, and not every data breach involves ransomware.

Verizon DBIR 2025 — Ransomware
44% of breaches involved ransomware in 2024
Up from 32% the prior year (a 37% increase). Despite rising prevalence, the median ransom payment fell to $115,000. Among IBM's 2025 sample, 63% of ransomware victims declined to pay, up from 59% in 2024. Source: Verizon DBIR 2025 and IBM Cost of a Data Breach Report 2025.
🔒
Ransomware vs. data breach: an important distinction

When ransomware encrypts files without exfiltrating them, it may or may not constitute a reportable data breach depending on applicable regulations. When attackers also steal the data (double extortion), it typically does qualify as a breach requiring notification. Reports that count all ransomware incidents as data breaches will produce higher breach totals than reports that verify actual data disclosure.

Third-Party and Supply-Chain Breach Statistics

A third-party breach occurs when an organization's data is compromised through a vendor, supplier, cloud provider, SaaS application, or other partner rather than through the organization's own systems directly. These breaches are particularly significant because the primary organization may have limited visibility into or control over the third party's security practices.

30%
Of breaches involved a third party (DBIR 2025, up from 15%)
267 days
Average lifecycle for vendor/supply-chain breaches (IBM 2025)

The Verizon 2025 DBIR found that third-party involvement in breaches doubled from 15% to 30% year over year. IBM found that breaches caused by third-party vendor and supply-chain compromise took the longest to resolve on average at 267 days, compared to the 241-day global average across all breach types.

Source (DBIR): Verizon 2025 Data Breach Investigations Report, published April 23, 2025. Source (IBM): IBM Cost of a Data Breach Report 2025, published July 30, 2025.

How Long Does It Take to Detect a Data Breach?

The IBM Cost of a Data Breach Report tracks two time metrics: the mean time to identify (MTTI) a breach and the mean time to contain (MTTC) it. These are measured from the initial compromise through breach identification and then through full containment. The total is called the breach lifecycle.

IBM Cost of a Data Breach Report 2025 -- Detection and Containment
241 days total (181 to identify + 60 to contain)
This is a nine-year low, down from 258 days in 2024 and a peak of 287 days in 2021. However, 241 days is still nearly eight months of potential exposure. Breaches resolved in under 200 days averaged $3.87 million in cost; those exceeding 200 days averaged $5.01 million.
Table 5. Breach lifecycle by source type (IBM 2025). Source: IBM Cost of a Data Breach Report 2025. Faster detection generally correlates with lower costs, but causation cannot be established from this data alone.
Scenario Avg. Lifecycle Avg. Cost
Global average (all breaches)241 days$4.44 million
Healthcare sector279 days$7.42 million
Vendor/supply-chain compromise267 daysNot separately disclosed
Malicious insider260 days$4.92 million
Breach contained under 200 days<200 days$3.87 million
Breach contained over 200 days>200 days$5.01 million
On-premises only breach217 days$4.01 million
Correlation, not causation

The relationship between breach lifecycle and cost is an observed correlation in IBM's survey sample. Longer breaches cost more on average, but this does not prove that reducing detection time mechanically reduces cost. Organizations with better security capabilities may both detect breaches faster and spend less on recovery, making security maturity a confounding factor in both measures.

Global Data Breach Statistics

Direct country-to-country comparisons of breach statistics are difficult because reporting requirements, definitions, regulatory environments, and detection capabilities differ substantially across jurisdictions. Differences in reported breach counts between countries often reflect differences in reporting systems as much as differences in actual breach frequency.

United States

The U.S. has the highest average breach cost of any country in IBM's study ($10.22 million in 2025, a record). The ITRC tracked 3,158 U.S. data compromises in 2024. The U.S. has 50+ state-level breach notification laws plus sector-specific federal requirements (HIPAA for healthcare, SEC rules for public companies), making U.S. breach reporting among the most comprehensive globally.

Middle East

IBM's 2025 report placed the Middle East second in average breach cost at $7.29 million. The region's high cost reflects the significant representation of energy and financial sector organizations in IBM's sample from that region.

European Union

The EU's General Data Protection Regulation (GDPR) requires data breach notification to supervisory authorities within 72 hours of awareness when the breach is likely to result in a risk to individuals' rights and freedoms. GDPR fines can reach 4% of global annual turnover for serious violations. This mandatory reporting framework means EU breach statistics tend to capture incidents that might go unreported in jurisdictions with less stringent requirements.

Global incident scope

Verizon's 2025 DBIR covered incidents from 139 countries. The report notes that Asia-Pacific saw system intrusion breaches increase substantially, and EMEA experienced a near-doubling of system intrusion breaches to 53% of regional breaches. These are not directly comparable to U.S. or EU country-specific statistics because methodology, contributing organizations, and reporting thresholds differ.

Why Data Breach Statistics Differ Between Sources

Understanding why published data breach statistics can differ by factors of 10 or more requires examining how each source defines and counts breaches.

Table 6. Source comparison: major data breach data sources and their methodological characteristics.
Source What It Measures Geography Unit Key Limitation
IBM / Ponemon
Cost of a Data Breach Report 2025
Average total cost of a breach incident across 17 cost categories Global (~600 orgs, 16 countries) Mean cost in USD per breach Non-random sample; participants must have experienced a breach; mean can be skewed by large incidents; no median reported
Verizon Business
Data Breach Investigations Report 2025
Security incidents and confirmed data breaches analyzed by Verizon and partner contributors Global (139 countries, 22,052 incidents) Count of confirmed breaches and incidents; percentage breakdowns by category Relies on contributed data from partner organizations; coverage varies by region; not a probability sample of all organizations
Identity Theft Resource Center
Annual Data Breach Report 2024
Publicly reported U.S. data compromises (breaches, exposures, leaks) United States only Count of data compromise events; victim notice counts Captures only publicly disclosed events; does not include unreported incidents; one individual may appear in multiple victim notice counts
HHS Office for Civil Rights
Breach Portal and Annual Report to Congress
HIPAA breach notifications (500+ individuals) from covered entities and business associates United States, healthcare sector only Count of breach notifications; individuals affected Mandatory reporting only for HIPAA-covered entities; count of notifications, not unique individuals; one individual may be counted across multiple breaches

Additional reasons breach statistics vary: mandatory vs. voluntary reporting, whether suspected incidents count alongside confirmed ones, whether ransomware without data exfiltration is counted, and whether the unit is events or affected individuals. For a statistics-based introduction to how different measurement choices affect observed distributions, see the site's descriptive statistics section, or the specific articles on mean and median.

Mean vs. Median in Breach Cost Statistics

The IBM Cost of a Data Breach Report uses mean (average) costs. This matters because a small number of extremely expensive breaches can substantially increase the mean without affecting typical experience. IBM does not publish median breach costs in public summaries, which makes it difficult to assess how skewed the distribution is.

Illustrative example: why the mean can mislead
Imagine 10 breaches: 9 cost $1M each and 1 costs $37.6M
Mean cost: ($9M + $37.6M) / 10 = $4.66M. Median cost: $1M. The mean suggests a "typical" breach costs $4.66M, but 9 out of 10 organizations spent $1M. The median better reflects the experience of most organizations. This is why looking for median breach cost figures alongside mean figures is useful, even when primary reports only publish the mean.

For a rigorous statistical treatment of why choosing mean vs. median matters for skewed distributions, see the mean vs. median vs. mode article and the site's outlier analysis page. The role of a single mega-breach in annual victim counts illustrates exactly why outliers matter -- the outliers in statistics article covers this in depth.

Notable Documented Data Breaches

The following are among the most significant documented data breaches based on confirmed public disclosures and regulatory filings. Figures come from official company filings or regulatory reports.

Change Healthcare (UnitedHealth Group) 2024
Individuals: ~190-192 million (per HHS OCR filing) Type: Hacking / ransomware

The Change Healthcare ransomware attack (ALPHV/BlackCat group) disrupted healthcare payment processing across the U.S. The HHS OCR 2024 congressional report recorded this as a breach affecting approximately 192 million individuals, representing the largest healthcare data breach by individual count on record. The breach affected HIPAA-covered information including health insurance information, medical records, and Social Security numbers.

National Public Data (Jerico Pictures) 2024
Records: Reported at 2.9 billion by media; disputed Type: Data exposure

A data broker breach in which personal records including names, addresses, and Social Security numbers were exposed. The "2.9 billion records" figure cited widely in media represents row counts in an aggregated database, not unique individuals. The actual number of distinct individuals is substantially lower. The company filed for bankruptcy following the incident. This case illustrates why database row counts and unique individual counts require separate reporting.

Ticketmaster / Snowflake-linked incident 2024
Individuals: ~560 million (company disclosure) Type: Credential theft / cloud misconfiguration

One of several large breaches linked to attackers using stolen credentials to access Snowflake cloud data environments of multiple companies. The Ticketmaster parent company Live Nation disclosed approximately 560 million customer records. The ITRC categorized this as one of five 2024 mega-breaches that collectively drove 83% of that year's U.S. victim notices.

AT&T 2024
Individuals: ~110 million (company disclosure) Type: Hacking / credential theft

AT&T disclosed two separate 2024 data breaches: one involving records of approximately 73 million customers on a hacker forum, and another affecting call and text metadata for approximately 109 million customers. The company confirmed the metadata breach resulted from unauthorized access to a third-party cloud platform.

Data Breach Statistics Calculator

📊 Data Breach Calculations

Calculate the percentage change in breach count or cost between two periods. Formula: ((Current - Previous) / Previous) × 100. This is a descriptive calculation, not an official industry metric.

This is a descriptive percentage change calculation. Verify that both figures come from the same source and use the same definitions before interpreting this as a trend.

Calculate average records affected per reported breach. Formula: Total records / number of breaches. Note: this average is heavily influenced by outliers (mega-breaches).

This mean is highly sensitive to outliers. A single mega-breach can raise the average dramatically. Compare the mean alongside the median for a fuller picture.

Calculate cost per affected record. Formula: Total breach cost / records affected. IBM's 2025 global average is $160 per record. This is a descriptive ratio, not a standardized regulatory measure.

IBM's 2025 average of $160/record uses a different denominator method. This calculator divides your total cost by your record count directly, which is a simpler descriptive ratio.

How to Interpret Data Breach Statistics

Before accepting any data breach statistic at face value, ask these five questions:

✅ Five questions to ask before citing a data breach statistic
  • What is the exact definition? "Breach," "incident," "exposure," and "compromise" are not interchangeable. What did this source actually count?
  • What is the population or sample? Is this global or national? All industries or a specific sector? Organizations of what size? A survey of willing participants or mandatory reporting?
  • What year and time period? IBM's 2025 report covers March 2024 to February 2025. The ITRC 2024 report covers January to December 2024. These are not the same period.
  • Is the figure a mean or a median? Means are sensitive to outliers. A single mega-breach can pull annual averages far from the typical experience. Always check which is being reported.
  • What are the limitations? Every primary source contains a methodology section explaining what it cannot measure. Non-reported breaches, companies that declined to participate, and definitional edge cases all affect what any statistic can claim to represent.

The statistical interpretation guide on this site covers these reasoning principles in more depth. The correlation vs. causation article is also relevant when interpreting claims like "organizations with AI save $1.9 million on breaches" -- the relationship is observed in IBM's survey sample, not experimentally proven.

What Data Breach Statistics Mean for Businesses

Aggregate statistics do not translate directly into personalized risk estimates. An organization's actual breach probability and cost depend on its size, industry, security controls, data sensitivity, geographic location, and regulatory environment. That said, published statistics are useful for several practical purposes.

Security investment prioritization: IBM data consistently shows that organizations using AI and automation extensively saved an average of $1.9 million per breach in 2025 and shortened the breach lifecycle by approximately 80 days. This association does not establish causation, but it suggests that investment in detection and response capability is linked to lower costs. Similarly, faster breach detection (under 200 days total lifecycle) correlated with $3.87 million average cost vs. $5.01 million for slower containment.

Third-party risk: Verizon's finding that third-party involvement doubled to 30% of all breaches underscores the importance of vendor security assessments. IBM data shows supply-chain breaches take 267 days to contain on average.

Incident response planning: IBM's data shows that organizations that detect breaches through their own security teams (rather than being notified by an attacker or third party) save approximately $900,000 on average. This supports the case for investment in internal detection capability.

Data Breach Statistics for Students

If you are researching this topic for an academic assignment, three things to establish before citing any statistic: (1) which organization published the data, (2) what definition of "breach" they used, and (3) the geographic and industry scope. These three elements separate a citable, defensible statistic from a generic headline number.

Good research questions for this topic: How does the ITRC define a "data compromise" compared to Verizon's definition of a "confirmed breach"? Why does the IBM Cost of a Data Breach Report use mean rather than median costs? What effect do mandatory breach disclosure laws (HIPAA, GDPR, state laws) have on the number of breaches reported in a given country compared to countries with weaker requirements?

For statistical concepts used in analyzing this kind of data, the site's descriptive statistics section, the AI for business statistics article, and the statistics and probability section cover the foundational methods.

📚
How to cite a data breach statistic

Record: organization name, report title, publication year, specific statistic, the dataset or survey it came from, geographic scope, and the URL. For example: IBM / Ponemon Institute. "Cost of a Data Breach Report 2025." Global average cost of a data breach: $4.44 million (mean). Covers 600 organizations in 16 countries, March 2024 - February 2025. ibm.com/security/data-breach. Published July 30, 2025.

Frequently Asked Questions

As of 2025, IBM reports the global average data breach cost at $4.44 million, a 9% decline from the 2024 record of $4.88 million. The U.S. average reached a record $10.22 million. Verizon's 2025 DBIR analyzed 12,195 confirmed breaches. The ITRC tracked 3,158 U.S. data compromises in 2024. These figures come from different studies with different populations and definitions -- they measure distinct aspects of the breach landscape.

Counts depend on the source and definition. Verizon analyzed 12,195 confirmed data breaches in its 2025 DBIR (November 2023 - October 2024 period, global). The ITRC tracked 3,158 U.S. data compromises in 2024. The difference reflects different geographic scope, contributing data sources, and definitions of what qualifies as a counted breach. Neither figure represents a census of all breaches globally, since many incidents are never discovered or reported.

According to the IBM Cost of a Data Breach Report 2025, the global mean total cost of a data breach was $4.44 million. This is a mean, not a median, so large outliers affect it. The U.S. mean was $10.22 million. Healthcare averaged $7.42 million globally, the highest of any industry. These are IBM's survey-based averages across 600 organizations; individual organization costs vary based on size, industry, controls, and specific incident factors.

IBM's 2025 Cost of a Data Breach Report found the mean time to identify a breach was 181 days and the mean time to contain it was 60 days, for a total mean lifecycle of 241 days. This is the lowest figure since 2016 and continues a downward trend from the 287-day peak in 2021. Note: "identify" means detecting that a breach occurred; "contain" means stopping ongoing unauthorized access. These are mean figures across IBM's 600-organization sample.

The answer depends on the measure. By breach count, the ITRC found financial services led U.S. data compromises in 2024 with 737 incidents, followed by healthcare (536). By cost per breach, healthcare has ranked highest globally for 15 consecutive years in IBM's report, at $7.42 million average in 2025. These two rankings measure different things -- incident frequency vs. financial impact per incident.

IBM's 2025 report identified phishing as the most common initial attack vector, present in 16% of breaches. Verizon's 2025 DBIR found credential abuse (22%) and exploitation of vulnerabilities (20%) as the leading initial vectors. These reports use different categorization frameworks, so the rankings reflect methodological choices as well as actual incident patterns.

The trend differs by metric. U.S. breach counts tracked by the ITRC remained near record levels from 2023 to 2024 (3,202 then 3,158 events). IBM's global average breach cost declined 9% from 2024's record to 2025, suggesting cost control is improving. Verizon found ransomware involvement rose 37% and third-party involvement doubled. No single answer covers all dimensions -- breach frequency, record counts, and costs each tell a different part of the story.

The terms are not consistently defined across sources. In general usage, a data breach involves an active unauthorized actor accessing or stealing data. A data leak or exposure typically refers to data made accessible due to misconfiguration (such as an unsecured database or cloud bucket) rather than deliberate hacking. A data exposure may or may not qualify as a reportable breach under applicable law, depending on whether unauthorized access is proven to have occurred. Always check which definition a source uses.

Several factors cause divergence: different definitions of "breach," different geographic scope (U.S.-only vs. global), different populations (all organizations vs. surveyed participants vs. mandatory reporters), different time periods, whether estimated/suspected breaches are counted alongside confirmed ones, and whether the unit is incidents or affected individuals. This is why comparing a headline figure from IBM directly against one from ITRC produces a meaningless result -- they do not measure the same thing.

It depends on the report. IBM's cost figures come from a structured survey where participating organizations report detailed cost data across categories (detection, notification, lost business, response). The Ponemon Institute then aggregates and calculates means. Verizon counts incidents contributed by partner organizations and classifies them using defined frameworks. The ITRC reviews publicly reported breach disclosures in U.S. media and government databases. Each method has specific strengths and blind spots described in its methodology section.

Data Sources and Methodology

This page draws statistics from four primary sources selected for methodological transparency, authority, and relevance.

IBM Cost of a Data Breach Report 2025 (Ponemon Institute): The most widely cited source for breach cost figures. Published July 30, 2025. Based on 600 organizations in 16 countries across 17 industries. Measures mean total cost per breach across 17 cost categories. Data period: March 2024 - February 2025. Limitations: survey-based, non-random sample, mean only (no median), participants must have experienced a qualifying breach. URL: ibm.com/security/data-breach.

Verizon 2025 Data Breach Investigations Report: The leading source for breach pattern and attribution analysis. Published April 23, 2025. Analyzed 22,052 security incidents including 12,195 confirmed data breaches from 139 countries, November 2023 - October 2024. Limitations: contributed data, coverage varies by region, not a probability sample. URL: verizon.com/business/resources/reports/dbir/.

ITRC 2024 Annual Data Breach Report: Primary U.S. breach count source. Published January 28, 2025. Tracks publicly reported U.S. data compromises (breaches, exposures, leaks). Measures: compromise count (3,158) and victim notice count (1.35 billion). Limitations: only publicly disclosed events; victim notices, not unique individuals; U.S.-only. URL: idtheftcenter.org.

HHS OCR Annual Report to Congress on Breaches of Unsecured PHI, 2024: Authoritative source for U.S. healthcare breach data. Covers HIPAA-required breach notifications to HHS for breaches affecting 500 or more individuals. Limitations: U.S. healthcare sector only; mandatory reporting threshold means small breaches may be undercounted in large-breach analysis; individual counts can involve duplicates across multiple filings. URL: hhs.gov/ocr.

📝
Editorial note on data freshness and statistics reconciliation

Data breach statistics are time-sensitive. This page uses the most recent primary reports available as of September 2026. Where statistics from multiple sources appear in the same section, differences in definition, scope, and methodology are explicitly noted. Statistics from incompatible sources are not added together or presented as if they measure the same population. If you notice a figure that appears outdated or incorrectly attributed, the editorial team reviews primary sources at least annually or when a new major report is published.