What 20,000+ Breaches Taught Us: The 2025–26 Ransomware & Human-Element Data Every SMB Should Know

Every October, Cybersecurity Awareness Month brings a wave of familiar advice: use strong passwords, watch for phishing, back up your data. It’s good advice. It’s also advice most organizations have heard a hundred times. What’s changed isn’t the checklist, it’s the scale and speed of the threat behind it. 

The 2026 Verizon Data Breach Investigations Report (DBIR) analyzed more than 22,000 confirmed data breaches and 31,000+ security incidents across 145 countries, the largest dataset in the report’s history. Layer in Proofpoint’s phishing research, ransomware-payment tracking from Coveware and Sophos, and what CyberClan’s incident responders see when they’re called in at 2 a.m., and a clear picture forms: ransomware statistics for 2026 aren’t just trending up, they’re pointing at exactly where your organization is most exposed. Here’s what the numbers actually say, and what to do about it before you become one of them. 

Ransomware Is Still Climbing, and Victims Are Fighting Back 

Ransomware appeared in 44% of breaches in last year’s DBIR. In the 2026 report, that number rose to 48%, nearly one in two confirmed breaches now involves ransomware in some form. Other trackers tell a similar story: HIPAA Journal reported a 58% surge in ransomware attacks during 2025, and Halcyon counted 95 active ransomware groups operating at scale, up roughly 40% year-over-year. 

There’s a genuinely encouraging countertrend, though. The DBIR found that 69% of ransomware victims in 2025 refused to pay, up from 64% the year before. Organizations are getting better at deciding not to fund their attackers, but that shift has consequences. When encryption alone doesn’t guarantee a payout, threat actors escalate: 

  • Double extortion is now the default, not the exception. Travelers Insurance found that 87.6% of ransomware claims involved both encryption and data exfiltration. Attackers steal your data before they lock it, so refusing to pay doesn’t mean the incident is over, it means the negotiation shifts to what gets published. 
  • The cost of recovery keeps climbing regardless of payment. Sophos put the average recovery cost (excluding any ransom) at $1.53 million globally in 2025. IBM’s Cost of a Data Breach research puts the average total breach cost at $5.08 million, and $3.31 million specifically for organizations under 500 employees. 
  • Payment amounts remain substantial for those who do pay. The median ransom payment sat around $115,000 in the most recent DBIR cycle, with Coveware’s Q4 tracking showing a similar $110,890 median, a fraction of the roughly $1.32 million median demand, but still enough to sink an unprepared SMB. 

The takeaway isn’t “never pay” or “always pay” that decision belongs to your legal counsel, your insurer, and your incident response team, weighed case by case. The takeaway is that the ransom is often the smallest line item in the actual cost of an attack. 

Small Businesses Are Not Flying Under the Radar 

One of the most persistent myths CyberClan’s IR team hears in the first hour of a breach call is some version of “we didn’t think we were a target, we’re too small.” The data says otherwise, emphatically. 

  • Small organizations show up in a disproportionate share of ransomware activity: recent DBIR data puts ransomware in roughly 88% of confirmed breaches at small organizations, compared with a much smaller share among large enterprises. Attackers aren’t chasing headlines, they’re chasing weak defenses and fast payouts, and smaller environments tend to offer both. 
  • Verizon’s research also found that close to one in five breached small businesses (19%) reported the incident put them at risk of bankruptcy, a very different outcome than the line-item cost absorbed by a Fortune 500 company. 
  • Nearly half of businesses with fewer than 50 employees report having effectively no dedicated cybersecurity budget, according to 2025 CrowdStrike/StrongDM research. Attackers know this. It’s why ransomware-as-a-service affiliates increasingly automate their targeting rather than hand-pick victims, smaller, under-resourced networks simply surface more often as easy wins. 

If your organization has been treating cybersecurity spend as optional because “no one would bother with us,” the 2026 data is a direct rebuttal. 

The Human Element Still Decides Most Outcomes 

Firewalls and EDR tools matter, but the 2026 DBIR’s headline finding is one CyberClan has also observed: 62% of breaches involved the human element, someone clicking, someone reusing a password, someone misconfiguring a system, someone falling for a well-timed pretext. That’s up from 60% the year prior, despite record spending on technical controls. 

A few findings explain why: 

  1. Credential abuse is still everywhere. Stolen or reused credentials factored into 39% of breaches overall, and for the first time, vulnerability exploitation (31%) edged past stolen credentials (13%) as the single most common initial access vector, meaning attackers are increasingly walking in through unpatched software, then using credentials to move around once inside. 
  2. Employees still take the bait at scale. Proofpoint’s State of the Phish research found more than 70% of employees admit to at least one risky action, clicking a suspicious link, reusing a password, sharing credentials that leaves their organization exposed. 
  3. Shadow AI is the newest human-element risk. The 2026 DBIR flagged a fourfold year-over-year jump in “shadow AI” incidents, employees pasting sensitive data, including source code, into AI tools using personal accounts on corporate devices. Roughly 45% of employees now use AI tools regularly at work, and 67% of that usage runs through non-corporate accounts your IT team can’t see or control. 
  4. Attackers are using AI too. The median threat actor in 2025 leveraged AI across 15 distinct attack techniques, with the most sophisticated campaigns spanning 40–50 of them, automating everything from more convincing phishing copy to faster reconnaissance. 

None of this means training doesn’t work, it means training alone was never going to be enough. The organizations that fare best treat the human element as a system to design around, not a box to check once a year. 

Vendors and Third Parties Widen the Blast Radius 

Your own defenses are only part of the equation. The 2026 DBIR found that 48% of breaches involved a third party in some capacity, a vendor, a supplier, a managed service provider, and that supply-chain-related breaches increased 60% year-over-year. Meanwhile, only 26% of known-exploited vulnerabilities were fully remediated in 2025 (down from 38% the year before), with a median remediation time of 43 days for the ones that do get patched. 

Put together, that’s a lot of open doors: unpatched systems sitting exposed for well over a month on average, and nearly half of breaches touching a partner’s environment rather than your own. If your vendor risk management program hasn’t been touched since before 2025, it’s overdue. 

What This Means for Your October Security Priorities 

Cybersecurity Awareness Month is a natural checkpoint to turn statistics into action. Based on what the 2026 data shows and what CyberClan’s incident responders consistently see in real engagements, three priorities stand out: 

  • Assume ransomware means data theft, not just encryption. Build your response plan (and your communications plan) around the near-90% likelihood that attackers already exfiltrated data before you noticed anything was wrong. 
  • Fix the human-element gap with more than annual training. Simulated phishing, least-privilege access, MFA on every credential that matters, and clear policies for AI tool use will move the needle further than a once-a-year slideshow. 
  • Extend your risk assessment to vendors and patch cadence. A 43-day median remediation window is an open invitation. Combine faster patching with real oversight of third-party access. 

Don’t Wait for Your Own Data Point 

Statistics are only useful if they change what you do next. If it’s been more than six months since your incident response plan was tested, or you’re not sure your team could answer “did they take data?” within the first hour of an incident, Cybersecurity Awareness Month is the moment to fix that, not the month after a breach. 

CyberClan’s incident response team is available 24/7/365. If you want a second opinion on where your organization stands against this year’s data, schedule a complimentary Cyber Resilience Consultation or download our 2026 Ransomware Readiness Checklist to benchmark your defenses against the trends above. 

Suspect you’re already dealing with an incident? Call our 24/7 emergency hotline now — every hour matters. 

Sources cited 

Under Attack? Guaranteed 15 minute response time.

Please call our emergency hotline below or fill out the form with your name, email, and phone number.

US/CA

1 800 762 3290

UK

0800 368 8731

AU

61 1800 413 128

Email

response@cyberclan.com

The information you provide in this form is only used exclusively to assist you. We do not share your data.

Sugandha Sood

Executive Vice President, Finance

As a professional accountant Sugandha, CPA, CGA has over 15 years of progressive finance and accounting experience across multiple industries including healthcare, medical, nuclear waste, and transportation.

Prior to joining CyberClan she worked at Energy Solutions Canada and was responsible for various aspects of accounting, financial reporting, internal controls, process improvements and taxation. Sugandha is eager to leverage her professional skills and play a vital role in the growth of the company by providing information to make informed decisions.