Top 5 ways hackers breach companies in 2026, according to Verizon
Top 5 ways hackers breach companies in 2026: Verizon

Verizon's 2026 Data Breach Investigations Report (DBIR) reveals that System Intrusion remains the dominant breach pattern, accounting for 61% of confirmed breaches. The report, which analyzed more than 31,000 security incidents including over 22,000 confirmed breaches across 145 countries, highlights that one attack pattern alone drove the majority of compromises. Social engineering and web application attacks also accounted for significant shares, while ordinary employee mistakes continue to expose sensitive data without any hacker involvement.

System Intrusion Leads with 61% of Breaches

System Intrusion has been the top breach pattern since 2022, and this year it widened its lead considerably, jumping from 53% of breaches last year to 61% this year. While several breach patterns involve some degree of system intrusion, this pattern specifically covers the more complex, involved breaches, where determined external actors combine malware and other tooling with hacking techniques to compromise closely guarded data.

External actors account for 100% of these breaches. Main motives behind these are financial (88%), with espionage a distant second (12%). What gets compromised is dominated by internal data (93%), followed by credentials (26%), other data types (20%), and secrets (13%). Of 14,309 incidents in this pattern, 13,758 resulted in confirmed data disclosure, the largest incident volume of any pattern in the report.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Looking at the specific techniques involved, ransomware tops the list by a wide margin, appearing in 77% of breaches within this pattern. Use of stolen credentials and exploitation of vulnerabilities follow in a near even split, at 39% and 38% respectively. Other actions account for 29% of breaches, with password dumper and backdoor or C2 functionality each appearing in 16%.

Remote Monitoring Tool Abuse and Ransomware Economics Shift

A few things are reshaping how these attacks unfold within this pattern specifically. Remote monitoring and management (RMM) tool abuse is exploding: attackers are increasingly abusing legitimate administrative software to operate inside victim networks, with these techniques growing 240% year over year, while the backdoor or C2 action declined 27% over the same period. Defenders appear to be getting better at detecting traditional tools, pushing attackers toward blending in with legitimate remote access software instead.

The ransomware economics are also shifting. The median ransom payment dropped again, to $139,875 from $150,000 the year before, and 69% of victims now refuse to pay at all, up from 65% the year before. Attackers are responding by trying to inflict maximum business disruption to pressure victims faster.

Social Engineering: 17% of Breaches

This pattern is mainly focused on attacks that use deception to accomplish a specific objective such as deploying malware, harvesting credentials, or tricking someone into transferring money. The common thread: individuals are targeted directly, not systems. Threat actors continue to largely lean on email-based phishing to compromise organizations. But according to Verizon, these attacks are getting more complex, as attackers increasingly target mobile devices and other unconventional vectors to reach victims.

Despite that shift, email remains the dominant vector by far. Email accounts for 98% of social engineering breaches, followed by social media at 25% and web application at 24%. External actors account for 100% of these breaches. Motives are overwhelmingly financial (86%), with espionage a distant second (25%). What typically gets compromised includes other data types (56%), internal data (51%), credentials (39%), and secrets (31%).

The big shift is happening on mobile. Verizon found that voice calls and text messages had a 40% higher success rate than traditional email phishing. Verizon's researchers also separate two techniques that get lumped together but require very different defenses. Phishing is asynchronous: a malicious email or text sent and left to do its work. Pretexting involves the attacker creating a fabricated scenario in real time, often through a phone call, text or email exchange, to manipulate someone (frequently an IT help desk or customer support agent) into taking a harmful action.

Pickt after-article banner — collaborative shopping lists app with family illustration

Basic Web Application Attacks and Miscellaneous Errors

Basic Web Application Attacks account for 10% of breaches. This pattern covers direct attacks on web applications and services. According to Verizon, it remains widespread and is typically driven by stolen credentials and unpatched vulnerabilities. These attacks are often low in sophistication, but they're highly effective, frequently leading to credential theft, internal data exposure, and further compromise of systems downstream.

Looking at the specific techniques involved, use of stolen credentials leads at 56%, followed closely by exploitation of vulnerabilities at 53%. Other actions account for 30% of breaches. Password dumper shows up in 21% of these breaches, harvesting additional credentials for further use, and brute force follows close behind at 19%. Backdoor or C2 functionality rounds out the top techniques at 17%. This is a 100% external actor pattern with no insiders involved. Financial gain dominates the motive mix at 74%, but espionage accounts for a notable 23%, with ideology-driven attacks making up the remaining 3%.

Miscellaneous Errors account for 8% of breaches. Not every breach involves an attacker at all. This is Verizon's catch-all pattern for breaches caused by mistakes: things employees did (or failed to do) incorrectly or inadvertently, with no malicious intent involved anywhere in the chain. There's no hacker, no malware, no social engineering. Just a person doing their job and getting something wrong in a way that exposes data.

Verizon breaks these mistakes down by type, and the gap between the leader and everything else is wide. Misdelivery – sending data to the wrong recipient – accounts for 64% of errors on its own. Misconfiguration follows at 14%, then loss and publishing errors at around 7% each, and classification errors at 6%. This pattern shows almost no gap between incidents and confirmed breaches. Of 1,757 incidents, 1,750 resulted in confirmed data disclosure. Personal data was compromised in 98% of these breaches, with internal company data (16%), other data types (8%), and bank data (7%) trailing well behind.

Privilege Misuse accounts for 3% of breaches, the smallest of the five major patterns. It refers to where insiders deliberately abuse legitimate access for unauthorized purposes. According to Verizon, privilege misuse has never been a dominant driver of data breaches. Convenience, not malice, is the leading motive, present in 60% of these breaches. Financial motives follow at 33%, with espionage and grudge each around 4%. What typically gets compromised in these cases is personal data (60%), followed by other data types (35%), secrets (27%), and internal data (25%).

The findings show that while attackers continue to change their techniques, many breaches still depend on familiar weaknesses, including unpatched vulnerabilities, compromised credentials, social engineering, and excessive access. Verizon's broader message is that organizations need to strengthen these fundamentals as the speed and scale of attacks increase.