Observed telemetry. Counted from systems rather than asked of people. The limit is whose systems were visible to the party counting.
Nineteen years of this report had stolen credentials at or near the top. That changed, and the reason Verizon gives is speed: attackers are using AI to shorten the gap between a disclosure and a working exploit from months to hours.
The identity read on this is not that identity stopped mattering. Entry-point coding assigns one vector per breach, so a compromise that starts at an unpatched edge device and then runs on harvested credentials for three weeks is filed under the vulnerability. Credential abuse remains far more common across full attack chains than at the point of entry.
What actually changed is the window. A patch cycle designed around a monthly maintenance calendar was built for a world where the exploit arrived after the calendar did. For a security leader this is a prioritization argument rather than an identity one: the budget conversation that has been about identity posture for five years now has a competing claim with fresher data behind it.
What this does not mean
This does not mean credential controls matter less than patching. Entry-point coding records only the first step, so it structurally undercounts techniques that dominate later in the chain, and credential abuse is the clearest example. It also does not mean the shift is permanent. One year of movement in a report whose contributor pool changes year to year is a signal worth watching rather than a trend worth restructuring a program around.
Take this to your board
Thirty-one percent of breaches start with an exploited vulnerability, per Verizon's 2026 Data Breach Investigations Report.
Say the peer figure and your own in the same breath. A number without a comparison invites the board to supply one from memory.
Sources
Every external figure on this page, with its origin, sample, and the date it was last checked by hand.
Vulnerability exploitation accounted for 31% of breach entry points, surpassing stolen credentials for the first time in the report's nineteen year history. Verizon attributes part of the shift to attackers using AI to compress time-to-exploit from months to hours.
Entry-point coding assigns one initial access vector per breach, so a breach that began with an unpatched service and then moved laterally on harvested credentials is counted only once, under the vulnerability. Reading the entry-point table as a ranking of which technique matters most understates credential abuse, which appears far more often across full attack chains than at the front door.
Common questions
What is the most common way breaches start in 2026?
Vulnerability exploitation, at 31% of breach entry points in Verizon's 2026 Data Breach Investigations Report. That is the first time in the report's nineteen year history that exploitation has passed stolen credentials, which Verizon attributes partly to attackers using AI to compress time-to-exploit from months to hours.
Does this mean identity security matters less?
No. The DBIR codes one initial access vector per breach, so a compromise that begins at an unpatched service and then runs on harvested credentials is filed under the vulnerability. Credential abuse appears far more often across full attack chains than at the point of entry, and entry-point ranking structurally undercounts it.
How should a patch program respond to faster exploitation?
By separating internet-facing assets from everything else and giving them a different clock. A monthly maintenance calendar was designed for a world where working exploits arrived after the calendar did. Verizon reports that window closing to hours, which strengthens the case for an emergency patch path on the external edge specifically.