Nineteen years of this report had stolen credentials at or near the top. That changed, and the reason Verizon gives is speed: attackers are using AI to shorten the gap between a disclosure and a working exploit from months to hours.
The identity read on this is not that identity stopped mattering. Entry-point coding assigns one vector per breach, so a compromise that starts at an unpatched edge device and then runs on harvested credentials for three weeks is filed under the vulnerability. Credential abuse remains far more common across full attack chains than at the point of entry.
What actually changed is the window. A patch cycle designed around a monthly maintenance calendar was built for a world where the exploit arrived after the calendar did. For a security leader this is a prioritization argument rather than an identity one: the budget conversation that has been about identity posture for five years now has a competing claim with fresher data behind it.
Common questions
- What is the most common way breaches start in 2026?
- Vulnerability exploitation, at 31% of breach entry points in Verizon's 2026 Data Breach Investigations Report. That is the first time in the report's nineteen year history that exploitation has passed stolen credentials, which Verizon attributes partly to attackers using AI to compress time-to-exploit from months to hours.
- Does this mean identity security matters less?
- No. The DBIR codes one initial access vector per breach, so a compromise that begins at an unpatched service and then runs on harvested credentials is filed under the vulnerability. Credential abuse appears far more often across full attack chains than at the point of entry, and entry-point ranking structurally undercounts it.
- How should a patch program respond to faster exploitation?
- By separating internet-facing assets from everything else and giving them a different clock. A monthly maintenance calendar was designed for a world where working exploits arrived after the calendar did. Verizon reports that window closing to hours, which strengthens the case for an emergency patch path on the external edge specifically.