A major cyber security report suggests that hackers are increasingly breaking into organisations through software vulnerabilities rather than stolen passwords.
The findings come from Verizon’s 2026 Data Breach Investigations Report, which analysed more than 31,000 security incidents across 145 countries.
According to the report, exploiting software vulnerabilities now accounts for 31% of confirmed data breaches, making it the most common way organisations are compromised. Stolen credentials, which were previously the leading cause, accounted for 13% of breaches.
However, while software vulnerabilities are now the leading way attackers gain access to organisations, people still play a role in many incidents.
The report found that a human element was involved in 62% of breaches, whether through phishing, social engineering, mistakes or other forms of user behaviour.
Why this matters
For years, cyber security advice has focused heavily on passwords.
Strong passwords, password managers and two-factor authentication remain important.
However, the latest findings suggest that attackers are increasingly looking for weaknesses in the software systems organisations use, rather than targeting individual users directly.
In practice, this means that even people who follow good cyber security habits can still be affected if a company holding their personal information suffers a breach.
The report also found that third-party involvement in breaches increased by 60% year-on-year, highlighting the growing risks associated with supply chains and outsourced services. For consumers, this means that personal information can be exposed through organisations they may never have heard of, but which process data on behalf of companies they use every day.
Why organisations are struggling to keep up
According to the report, organisations took a median of 43 days to apply security patches during 2025, while only 26% of critical vulnerabilities were fully remediated. This can leave systems exposed for weeks or months after security flaws have been identified.
The report also suggests that attackers are increasingly using automation and AI-assisted tools to identify vulnerabilities and accelerate attacks, often leaving organisations with less time to respond.
One finding highlighted concerns around so-called “shadow AI” – where employees use personal AI accounts rather than approved workplace systems. According to the report, 67% of employees using AI tools at work are doing so through unauthorised personal accounts. This can increase the risk of sensitive information being shared outside approved systems, potentially creating new avenues for data exposure.
What does this mean for consumers?
The findings are another reminder that data breaches are not always caused by individual mistakes. Many breaches occur because organisations fail to secure the systems, software and suppliers they rely on.
If your personal information is exposed in a data breach, the impact can range from inconvenience and increased scam risk through to financial loss, identity fraud or significant distress.
While not every data breach will give rise to legal action, some incidents may result in investigations, complaints or compensation claims where organisations have failed to adequately protect personal information.
Staying informed
Data breaches continue to affect organisations across a wide range of sectors, including retail, healthcare, financial services, education and technology.
As cyber criminals adapt their tactics, organisations face increasing pressure to identify vulnerabilities quickly, secure their systems, and protect the personal information they hold.
At Join the Claim, we continue to monitor major data breaches and cyber security incidents that could affect UK consumers. If you believe your personal information has been exposed in a data breach, you can explore our data breach claim updates and register your interest in relevant investigations.