Quick Facts
- Software vulnerability exploitation now accounts for 31% of all confirmed data breaches, while stolen credentials dropped to just 13%
- US organizations face an average breach cost of $10.22 million in 2026, an all-time high
- Average eCrime breakout time dropped to just 29 minutes, a 65% increase in speed from 2024
Software vulnerability exploitation has overtaken stolen passwords as the primary method hackers use to breach US corporate networks. The shift marks the first time in nearly two decades that exploiting software flaws has become the dominant attack vector.
Software vulnerabilities now account for 31% of all confirmed data breaches in 2026, according to the latest security research. Stolen credentials, which previously dominated the threat landscape, have dropped to just 13% of reported incidents.
The financial impact on US organizations has reached unprecedented levels. American companies face an average breach cost of $10.22 million in 2026, representing an all-time high. This compares to a global average of $4.44 million, highlighting the particular vulnerability of US enterprises.
Attackers have dramatically accelerated their operations. The average eCrime breakout time has dropped to just 29 minutes, marking a 65% increase in speed from 2024. Some cybercriminal groups can now break into networks and begin spreading laterally in under 30 seconds, with the fastest recorded breakout time reaching 27 seconds.
‘Attackers have figured out that they don’t need to break through your carefully guarded front door when they can walk right in through your supplier’s back door with valid credentials,’ said Nick Bradley, Director of IBM X-Force Threat Intelligence Malware Team.
Artificial intelligence plays a dual role in this evolving landscape. Nearly three-quarters of organizations report that AI-powered cyber threats are already having a significant impact on their operations. Attackers leverage AI to accelerate the discovery and weaponization of known software flaws, reducing response time from months to mere hours.
However, AI also serves as a defense mechanism. Organizations using AI and automation extensively in their security operations save approximately $1.9 million per breach compared to organizations without these tools. Seventy-seven percent of organizations now use generative AI or large language models in their security stack.
Supply chain attacks have emerged as another critical concern. Major supply chain and third-party breaches have quadrupled over the past five years, creating new vulnerabilities through trusted vendor relationships.
The cybersecurity skills gap continues to hamper organizational defenses. The industry faces a 4.8 million-worker shortage, while existing security teams struggle with alert fatigue from the increasing volume and sophistication of attacks.
Small businesses bear a disproportionate burden in this threat environment. They face average breach costs of $3.31 million in 2026, with SMEs accounting for over 70% of ransomware incidents. Sixty percent of small businesses close within six months of a major breach.
Read more: Forget stolen passwords — this is how hackers are actually breaking into US companies in 2026
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
