💸 Data Breach Cost Statistics 2026: 55 Data-Backed Facts
A data breach is a confirmed disclosure of protected data to an unauthorised party. The statistics here measure the financial dimension of breaches — what they cost organisations and victims, why credential theft drives costs up, how long breaches take to contain, and which controls cut the bill. Sources are the IBM/Ponemon Cost of a Data Breach Report 2024, the Verizon Data Breach Investigations Report (DBIR) 2025, the FBI Internet Crime Complaint Center (IC3) 2024 Annual Report, the Microsoft Digital Defense Report 2024–2025, and the NordPass Most Common Passwords Report 2024. Every figure is current as of August 2026.
Key Statistics at a Glance
Average Breach Cost — The Headline Numbers
IBM and the Ponemon Institute have tracked the per-breach cost since 2004. The IBM Cost of a Data Breach Report 2024 covered 604 organisations across 17 industries and 16 countries, making it the most methodologically consistent longitudinal dataset available.
- The global average cost of a data breach hit $4.88 million in 2024, the highest ever recorded. (IBM/Ponemon, 2024)
- That figure represents a 10% increase over 2023 ($4.45 million). (IBM/Ponemon, 2024)
- The average cost per compromised record was $173 in 2024, up from $156 in 2023. (IBM/Ponemon, 2024)
- The United States posted the highest average breach cost for the 14th consecutive year at $9.36 million. (IBM/Ponemon, 2024)
- Healthcare remained the most expensive sector for the 14th year running, averaging $9.77 million per breach. (IBM/Ponemon, 2024)
- The financial sector averaged $6.08 million per breach, second highest of all industries. (IBM/Ponemon, 2024)
- Industrial organisations averaged $5.56 million per breach. (IBM/Ponemon, 2024)
- Technology firms averaged $5.45 million per breach. (IBM/Ponemon, 2024)
- The education sector averaged $3.58 million — among the lower-cost industries, yet record numbers of students were affected in 2026 breaches. (IBM/Ponemon, 2024)
- Breaches involving more than 50 million records — mega-breaches — cost an average of $375 million. (IBM/Ponemon, 2024)
The Credential-Theft Premium
Stolen passwords are not just the most common entry point — they are among the most expensive. The 2025 Verizon DBIR and the IBM 2024 report both quantify the surcharge that compromised credentials add to an organisation's bill.
- Breaches caused by stolen or compromised credentials cost an average of $4.81 million — $150,000 more than the global average. (IBM/Ponemon, 2024)
- Phishing — the primary method for credential theft — was the costliest attack vector, averaging $4.88 million per breach. (IBM/Ponemon, 2024)
- Stolen credentials were the initial access vector in 22% of all breaches, the single most common root cause. (Verizon DBIR, 2025)
- 88% of successful basic web-application attacks used stolen credentials rather than exploited vulnerabilities. (Verizon DBIR, 2025)
- On infostealer-infected devices, the median share of distinct (non-reused) passwords was just 49% — meaning every stolen password also compromised roughly one other account. (Verizon DBIR, 2025)
- In single-sign-on logs studied by Verizon, credential-stuffing accounted for a median 19% of all daily authentication attempts. (Verizon DBIR, 2025)
- Microsoft observed more than 7,000 password attacks per second in 2024 — roughly 600 million each day. (Microsoft Digital Defense Report, 2025)
- 97% of identity attacks are password-spray attacks — trying one common password against millions of accounts. (Microsoft, 2025)
Time Is Money: Detection and Containment
Breach cost grows with dwell time. IBM tracks the number of days from breach to full containment and prices the difference.
Data visualisation: a horizontal bar chart. Stolen-credential breaches take the longest to detect and contain at 292 days — 34 days more than the global average of 258 days. Insider-malicious breaches are the worst at 321 days.
- The average time to identify and contain a breach was 258 days in 2024 (197 to identify + 61 to contain). (IBM/Ponemon, 2024)
- Breaches involving stolen credentials took an average of 292 days to identify and contain — 34 days longer than the global mean. (IBM/Ponemon, 2024)
- Breaches contained in under 200 days cost an average of $3.87 million; those contained after 200 days averaged $5.01 million. (IBM/Ponemon, 2024)
- That time-gap creates a $1.14 million premium for every breach that runs long. (IBM/Ponemon, 2024)
- Organisations with high-level security AI and automation identified and contained breaches in a median of 51 days fewer than those without such tools. (IBM/Ponemon, 2024)
- Those same organisations saved an average of $2.22 million in breach costs compared to organisations with no AI or automation deployed. (IBM/Ponemon, 2024)
What the FBI Recorded: Reported Cybercrime Losses
The FBI Internet Crime Complaint Center (IC3) compiles losses reported by victims. Phishing — the dominant method for stealing credentials — is consistently the top complaint category.
- The IC3 received 859,532 complaints of suspected internet crime in 2024. (FBI IC3, 2024)
- Reported losses totalled $16.6 billion — a 33% increase from $12.5 billion in 2023. (FBI IC3, 2024)
- Phishing and spoofing led all complaint categories with 193,407 reports. (FBI IC3, 2024)
- Investment fraud (largely cryptocurrency) was the costliest category at $6.57 billion in losses. (FBI IC3, 2024)
- Business Email Compromise (BEC) — which relies on credential theft or impersonation — caused $2.77 billion in losses in 2024. (FBI IC3, 2024)
- Personal data breaches reported to the IC3 resulted in $1.45 billion in losses in 2024. (FBI IC3, 2024)
- Victims over 60 years old reported the most losses — $4.89 billion in 2024. (FBI IC3, 2024)
- Identity theft alone accounted for more than 33,000 complaints in 2024. (FBI IC3, 2024)
How Many Records Are at Stake
Cost per breach is one lens; the volume of exposed data — credentials, health records, financial data — is another. Both matter for understanding why prevention outperforms remediation.
- U.S. data breaches hit a record 3,158 incidents in 2024, according to the Identity Theft Resource Center. (ITRC, 2024)
- Have I Been Pwned now indexes over 2 billion unique email addresses from confirmed breaches and credential-stuffing datasets. (Have I Been Pwned, 2025)
- The service handles more than 18 billion API requests per month from developers screening user passwords against known-breached lists. (Have I Been Pwned, 2025)
- NordPass analysed public breach data for 2024 and found that "123456" remained the world's most common password, with more than 3 million exposures in a single year. (NordPass, 2024)
- 78% of the world's most common passwords can be cracked in under one second using readily available tools. (NordPass, 2024)
- 40% of the most common passwords used by individuals and business employees are identical — meaning corporate accounts inherit the same weak choices. (NordPass, 2024)
The Human-Behaviour Tax
The LastPass Psychology of Passwords study demonstrates that people understand the rules but don't follow them — and that gap is directly priced into breach costs.
- 91% of people know that reusing passwords is insecure — yet the majority do it anyway. (LastPass, Psychology of Passwords)
- 65% of users reuse the same password across multiple accounts. (LastPass, 2023)
- Even after receiving cybersecurity training, only 31% stopped reusing passwords. (LastPass)
- Only 55% of users would change a password even after that account was confirmed hacked. (LastPass)
- The average person now manages roughly 170 passwords, a number that keeps growing year on year. (NordPass, 2024)
- 29% of people write passwords down in a notebook, the single most common offline storage method. (Security.org, 2024)
- 45% of Americans manage passwords by saving them unencrypted or on paper. (Security.org, 2024)
🔐 One habit change that cuts your personal breach cost to near zero
Every figure on this page has a common denominator: password reuse. When one site leaks your credentials, every account sharing that password becomes a victim. NordPass generates a cryptographically strong, unique password for every account, stores all of them behind XChaCha20 encryption and a zero-knowledge architecture, and alerts you when any saved password appears in a public breach — the same data that feeds the cost figures above.
Get NordPass →Affiliate link — we may earn a commission at no extra cost to you.
Controls That Actually Cut Breach Costs
IBM tracks whether specific security controls measurably lower breach costs. The findings consistently point to two categories: MFA and AI-powered detection.
- Organisations with a mature DevSecOps programme saved $1.68 million on average compared to those without one. (IBM/Ponemon, 2024)
- Organisations that involved law enforcement in a ransomware attack saved an average of $1.0 million on breach costs. (IBM/Ponemon, 2024)
- Microsoft found that phishing-resistant MFA blocks over 99% of identity-based attacks. (Microsoft Digital Defense Report, 2025)
- More than 99.9% of accounts compromised by password attacks had no MFA enabled. (Microsoft)
- As of 2025, only 70% of enterprise users are covered by MFA — meaning nearly one in three employees still relies on a password alone. (Okta Secure Sign-in Trends, 2025)
- At the smallest firms (under 25 employees), MFA coverage drops to just 27%. (Okta, 2025)
- Organisations using AI and automation extensively in security operations averaged breach costs of $3.84 million — $2.22 million less than organisations with no such tools ($6.06 million). (IBM/Ponemon, 2024)
What NIST Says About Reducing the Risk
NIST Special Publication 800-63B (Digital Identity Guidelines, Third Revision) is the foundational U.S. standard for password policy. Its guidance translates directly into cost reduction — fewer weak passwords mean fewer credential-theft entry points.
- NIST recommends a minimum password length of 8 characters but supports at least 64, because longer passwords resist brute-force far more effectively. (NIST SP 800-63B)
- NIST advises against mandatory periodic password changes unless there is evidence of compromise — forced rotation leads users to create predictable variants. (NIST SP 800-63B)
- NIST recommends screening all new passwords against known-breached password lists and rejecting matches — exactly what Have I Been Pwned's Pwned Passwords API enables. (NIST SP 800-63B)
- NIST advises against forced composition rules (requiring uppercase, number, and symbol), which tend to produce predictable patterns like
Password1!. (NIST SP 800-63B) - NIST recommends allowing all printable ASCII characters, spaces and Unicode so that long passphrases are practical for users. (NIST SP 800-63B)
What These Numbers Mean
The math is straightforward: a stolen password costs the organisation it breaches roughly $4.88 million, takes 258 days to clean up, and starts with a credential that probably cost the attacker nothing — because 65% of users reuse passwords and 78% of the most common ones crack in under a second. The asymmetry is the whole story: offence is cheap, defence is expensive, and the cheapest possible defence — a unique, strong password for every account — is the one behaviour that most people have not adopted.
MFA and a strong password generator are the two controls that break the chain. MFA means a leaked password is not sufficient to break in. A unique password means a breach at one service cannot cascade into dozens of account takeovers. For the full attack picture see our companion post on password attack statistics; for the behavioural side see password reuse statistics.
Frequently Asked Questions
What is the average cost of a data breach in 2026?
The most recent verified figure is $4.88 million, from the IBM/Ponemon Cost of a Data Breach Report 2024 — a 10% increase over the 2023 average of $4.45 million. That figure covers 604 organisations across 17 industries; healthcare and financial services are consistently the most expensive sectors.
How much do stolen credentials add to breach costs?
Breaches where stolen or compromised credentials were the initial access vector cost an average of $4.81 million — roughly $150,000 more than the global mean — and take 292 days to identify and contain, according to the IBM 2024 report. Stolen credentials are also the most common breach root cause at 22% of all breaches (Verizon DBIR, 2025).
How much money does cybercrime cost victims each year?
The FBI Internet Crime Complaint Center recorded $16.6 billion in reported losses in 2024 — a 33% rise from $12.5 billion in 2023. This includes $2.77 billion from Business Email Compromise, $6.57 billion from investment fraud, and $1.45 billion from personal data breaches. Unreported losses make the real total substantially higher.
Does MFA actually reduce breach costs?
Yes, significantly. Microsoft's data shows that phishing-resistant MFA blocks over 99% of identity-based attacks, and more than 99.9% of compromised accounts had no MFA at the time of the attack. IBM found organisations with extensive security automation saved $2.22 million per breach versus those with none. The biggest gap: 30% of enterprise users still have no MFA.
What does NIST recommend to reduce breach risk?
NIST SP 800-63B recommends: passwords of at least 8 characters (64+ supported), no mandatory periodic rotation unless a breach is confirmed, screening new passwords against known-breached lists, no forced complexity rules, and allowing all printable characters so long passphrases are viable. These policies shift users toward stronger credentials without the churn that drives predictable substitutions.
Methodology and Sources
All statistics are attributed inline to the organisation that published them, with the year of the source. Figures are quoted as reported and were current as of August 2026. Where a number depends on a defined sample (e.g., IBM's 604-organisation study or Verizon's SSO log analysis), that context is stated with the figure. Primary sources:
- IBM / Ponemon Institute — Cost of a Data Breach Report 2024
- Verizon — 2025 Data Breach Investigations Report (DBIR)
- FBI Internet Crime Complaint Center (IC3) — 2024 Internet Crime Report
- Microsoft — Digital Defense Report 2024 and 2025
- LastPass — Psychology of Passwords
- NordPass — Top 200 Most Common Passwords, 2024
- Okta — Secure Sign-in Trends Report 2025
- Have I Been Pwned — Live breach database statistics
- NIST — Special Publication 800-63B, Digital Identity Guidelines
- Identity Theft Resource Center (ITRC) — 2024 Annual Data Breach Report
- Security.org — 2024 Password Manager Annual Report