Healthcare organisations averaged $6.64 million per data breach in IBM’s 2026 study of incidents between March 2025 and February 2026 — the costliest of 17 sectors for the 13th year running. Financial services came next at $6.29 million. This post sets out breach counts, costs and attack methods sector by sector, using the current editions from IBM, Verizon, the Identity Theft Resource Center and the FBI.

Data Breaches by Industry Statistics 2026

$6.64MAverage healthcare breach cost, highest of 17 sectors (IBM, Mar 2025–Feb 2026)
387Financial services compromises in the US in H1 2026, the most of any sector (ITRC)
1,438Confirmed healthcare data disclosures logged by Verizon (Nov 2024–Oct 2025)
739US financial services compromises in calendar 2025, first among industries (ITRC)
18%Share of non-critical-sector ransomware complaints from legal services (FBI IC3, 2025)
$4.99MGlobal average breach cost across all sectors, up 12% year over year (IBM, 2026)

Which Industry Has the Most Data Breaches?

Financial services recorded 739 data compromises in the United States during 2025, more than any other industry, according to the Identity Theft Resource Center’s 2025 Annual Data Breach Report. Healthcare followed with 534.

The ITRC counts publicly reported compromises — breaches, leaks and exposures — not the number of people affected. It tracked 3,322 compromises across all sectors in 2025, against 3,152 in 2024.

Professional services showed the sharpest growth. The ITRC describes the sector as a stepping stone used to reach multiple client organisations at once.

IndustryData compromises
Financial services739
Healthcare534
Professional services478
Manufacturing299
Education188

Source: Identity Theft Resource Center, 2025 Annual Data Breach Report, calendar year 2025

Transparency kept sliding. Seventy percent of 2025 breach notices (2,324) carried no information about how the attack happened, compared with 65% in 2024 and 45% in 2023.

Data Breaches by Industry in H1 2026

The ITRC tracked 1,803 data compromises in the first six months of 2026. Q2 alone accounted for 1,029, the second-highest quarterly total in its records.

Financial services again led on frequency with 387 compromises. Healthcare recorded 281, reversing a mild decline from the previous year. Victim notices reached an estimated 471.2 million in six months, above the 297.5 million the ITRC counted for all of 2025.

Volume and frequency point in different directions. A single compromise at Instructure Holdings’ Canvas platform produced an estimated 275 million notices, 58% of the half-year total, while manufacturing generated 74 million notices against 1.97 million in all of 2025.

MeasureH1 2026 (Jan–Jun)
Data compromises tracked1,803
Financial services compromises387
Healthcare compromises281
Estimated victim notices471.2 million
Notices naming an attack vector24%
Insider wrongdoing events21

Source: Identity Theft Resource Center, H1 2026 Data Breach Report, January–June 2026

Supply chain remains the multiplier. Thirty-eight initial breach events touched 206 entities and generated 280.6 million victim notices, and publicly traded companies accounted for 10.3% of compromises but 83.4% of all notices. The dependency pattern mirrors what shows up in shared infrastructure, from managed DNS concentration to hosting.

Data Breach Cost by Industry

The global average cost of a data breach hit $4.99 million in IBM’s Cost of a Data Breach Report 2026, a 12% rise and a record across the study’s 21 years. The report draws on 602 organisations breached between March 2025 and February 2026 across 17 industries and 16 countries.

Healthcare stayed on top at $6.64 million, down 10.5% from $7.42 million a year earlier. US organisations averaged $11.5 million, more than double the global figure.

IndustryAverage cost per breach
Healthcare$6.64M
Financial services$6.29M
Industrial$5.50M
Technology$5.50M
Entertainment$5.40M
Energy$5.20M

Source: IBM Cost of a Data Breach Report 2026, breaches occurring March 2025–February 2026

AI changed the arithmetic. One in four malicious breaches was AI-enabled, a 56% increase on the previous year, and those breaches averaged $6 million.

Critical infrastructure absorbed 62% of AI-driven attacks, with financial services and energy the most concentrated. More than 20% of organisations reported a breach targeting AI models or applications, with compromised APIs, applications or plug-ins and cloud misconfigurations each cited in 27% of those cases — the same cloud workload layer most enterprises now run on.

Detection and escalation costs plus lost business made up 63% of total breach costs. Extensive use of security AI and automation cut an average of $1.93 million per breach, a gap that widens as patch release and deployment timelines stretch.

How Data Breaches Happen Across Industries

Verizon’s 2026 Data Breach Investigations Report examined more than 31,000 security incidents and over 22,000 confirmed breaches in 145 countries, covering 1 November 2024 to 31 October 2025.

Exploitation of vulnerabilities became the leading initial access vector at 31% of breaches, up from 20%. Credential abuse fell to 13%; Verizon added pretexting to its tracked vectors this year and states the figure would have been 16% without that change.

Metric (share of breaches)2025 DBIR2026 DBIR
Exploitation of vulnerabilities (initial access)20%31%
Credential abuse (initial access)22%13%
Ransomware present44%48%
Third-party involvement30%48%
Human element present60%62%

Source: Verizon 2026 Data Breach Investigations Report; 2026 dataset covers 1 Nov 2024–31 Oct 2025, prior-year values as published in the same edition

Patching capacity is the constraint behind the top row. Only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38%, and the median time to full resolution rose to 43 days from 32. Median organisations faced 16 KEV vulnerabilities, up from 11, a workload visible in kernel-level CVE counts as well.

Ransom economics moved the other way. Sixty-nine percent of ransomware victims did not pay, and the median ransom paid fell to $139,875 from $150,000. Encryptor targeting still follows the workloads, a pattern set out in this breakdown of ransomware by operating system.

Healthcare Data Breaches by the Numbers

Verizon logged 1,492 healthcare incidents (NAICS 62) with 1,438 confirmed data disclosures. System Intrusion, Miscellaneous Errors and Social Engineering together accounted for 81% of healthcare breaches.

External actors drove 81% of them, with a financial motive in 99% of cases. Errors are the sector’s chronic pattern: misdelivery, loss of unencrypted devices and misconfiguration have kept Miscellaneous Errors in the healthcare top three since 2014.

Metric (share of healthcare breaches)2026 DBIR
External actors81%
Internal actors19%
Human element present54%
Third-party involvement32%
Exploitation of vulnerabilities (initial access)20%
Phishing (initial access)14%
Credential abuse (initial access)11%

Source: Verizon 2026 DBIR Healthcare Snapshot, incidents 1 Nov 2024–31 Oct 2025

Verizon links part of the 32% third-party figure to the Oracle E-Business Suite vulnerability, which affected healthcare organisations among many others and is largely attributed to the Cl0p criminal group.

Ransomware Complaints by Industry

The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025 with $20.877 billion in reported losses. Ransomware accounted for 3,611 complaints and $32,320,105 in reported losses; data breach complaints numbered 3,963.

Of complaints classed as cyber threats, data breach made up 39% and ransomware 36%. The FBI says its top 10 reported ransomware variants most affected critical manufacturing, healthcare and public health, and government facilities.

Outside the 16 critical infrastructure sectors, IC3 received more than 1,400 ransomware complaints, concentrated in professional trades.

IndustryShare of non-critical-sector ransomware complaints
Legal services18%
Contracting services17%
Engineering, architectural services10%
Consulting services7%
Non-critical manufacturing5%

Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report, calendar year 2025

Losses reported to IC3 for ransomware exclude downtime, wages, equipment and third-party remediation, so the $32.3 million total sits far below the per-incident averages IBM records. Server-side exposure is where the two datasets meet, and the server OS split across public sites shapes which encryptors are worth building.

FAQs

Which industry has the most data breaches?

Financial services. The ITRC recorded 739 US data compromises in the sector in 2025 and 387 in the first half of 2026, more than any other industry in both periods. Healthcare ranked second.

Which industry has the most expensive data breaches?

Healthcare, at an average $6.64 million per breach in IBM’s 2026 report covering March 2025 to February 2026. That is the 13th consecutive year it has led, ahead of financial services at $6.29 million.

How many data breaches happened in the first half of 2026?

The ITRC tracked 1,803 US data compromises in January–June 2026, including 1,029 in Q2. An estimated 471.2 million victim notices were issued over those six months.

Are Reddit threads a reliable source for data breaches by industry?

Reddit threads circulate breach news quickly, but the figures posted there trace back to primary reports. The counts here come from the ITRC, Verizon’s 2026 DBIR, IBM and the FBI, not forum summaries.

What causes most data breaches across industries?

Verizon puts exploitation of vulnerabilities at 31% of breaches as the initial access vector in its 2026 report. Ransomware featured in 48% of breaches and third parties in 48%.

Sources

https://www.ibm.com/reports/data-breach
https://www.verizon.com/business/resources/reports/dbir/
https://www.idtheftcenter.org/post/mega-breaches-malicious-insiders-h1-2026-data-breach-report/
https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

Willie has over 15 years of experience in Linux system administration and DevOps. After managing infrastructure for startups and enterprises alike, he founded Command Linux to share the practical knowledge he wished he had when starting out. He oversees content strategy and contributes guides on server management, automation, and security.