Since 2008, Verizon’s Verizon Data Breach Investigations Report (DBIR) has tracked the pulse of business data breaches and how cybercrime improvements and trends can affect us all. So, whether we’re employees, everyday users or both, there’s one thing we all have in common – we’re human. And that’s exactly what cybercriminals are counting on and what makes them successful.
It’s All About the Benjamins. The DBIR shows that 44% of breaches involved ransomware. Add to that, companies paid crooks a median amount of $115,000 per incident last year. Espionage is still on the list as well. Those came in at 17% of data breaches. The report found that 28% of the state-sponsored events they found were financially motivated.
System Updates and Patches not Fast Enough. The DBIR shows how software and system vulnerabilities get exploited long before businesses know they exist, much less releasing fixes for them. It finds attacks peaked 17 days after hackers discovered these flaws, not nearly fast enough to prevent the attacks that resulted. The DBIR finds businesses need to step-up monitoring and prioritize quickly releasing software patches and updates to fix flaws.

Partners in Crime. As we know, once a third party is involved, we lose some control over what happens to the data they manage. The report found that indeed, the percentage of breaches involving a third party doubled from 2024 to 30%.
And Then There is AI. While using generative AI to be more productive can be beneficial, it can also lead to unintentional data leaks. The DBIR found that 15% of employees accessed these systems roughly every 15 days. While that may not be a big concern on its own, 72% of them were accessing them using a non-work email address or they were using their corporate credentials without integrated authentication systems.
Other notable stats:
Of all the industries targeted, healthcare is now the top target. Of 1,710 incidents, 1,542 had confirmed data disclosure. System intrusion, which includes ransomware, is the top culprit.
Ninety percent of those in the financial and insurance sector are financially motivated and 78% of the threat actors are external.

Within the manufacturing sector, 90% of organizations that experienced a breach were SMBs with less than 1,000 employees.
The retail industry is still a major target, but the information sought is changing. Where it used to be payment card information, the switch to digital wallets and other types of payments have made that more difficult for attackers. Therefore espionage-related attacks have risen and it’s no surprise that 100% of the threats here are financially motivated.
The public sector is not left out. According to the report, “attackers are not easing up on government targets. Ransomware remains a major threat, hitting 30% of breaches across all levels of government. Errors remain a persistent issue, with Misdelivery in the lead.”
Bigger data security budgets don’t automatically translate to a cyber-secure business. That’s why cyber-education is still the best answer for a secure environment at work and at home. After all, we’re only human.