Verizon DBIR Tracks AI-Scaled Breaches
Coverage from Help Net Security, PYMNTS, and others
Articles
6
Active Days
30
The Topic

Verizon’s 2026 Data Breach Investigations Report finds that attackers are using generative AI to accelerate familiar techniques while increasingly targeting mobile channels, vulnerabilities, employees, and third parties. The report links human involvement to most breaches, identifies vulnerability exploitation as the leading initial access vector, and finds ransomware and vendor involvement remain widespread. Together, the findings show that organizations face faster attacks across technical infrastructure, phone-based interactions, workforce processes, and external service providers.
First Article: 05/20/26
Latest Article: 06/18/26
Summary
- Generative AI is primarily accelerating established attack methods, including phishing, reconnaissance, malware development, and targeting.
- Phone-centric phishing simulations produced a median click rate of 2%, compared with 1.4% for email, according to cited DBIR data.
- The human element appeared in 62% of breaches, with voice calls, text messages, pretexting, and credential theft remaining important attack paths.
- Vulnerability exploitation accounted for 31% of breaches and overtook credential abuse as the leading initial access vector.
- Ransomware appeared in 48% of breaches, while 69% of affected organizations reportedly did not pay.
- Third-party involvement reached 48% of breaches, increasing exposure through vendors, software providers, cloud services, and contractors.
- The report highlights workforce identity fraud and unauthorized employee use of AI tools as intersecting sources of cyber and data-loss risk.
History
The story now adds a stronger, more operational picture of AI-enabled abuse: it is not only scaling phishing and exploitation, but also intersecting with workforce identity fraud and unauthorized employee use of AI tools. It also becomes more specific about the measured prevalence of phishing channels, ransomware, and third-party exposure.
