Verizon has published its annual Data Breach Investigations Report (DBIR), which shows how AI is impacting the cyber threat landscape as a whole. Although this report uses 2025 data, predating the latest frontier model advancements, the trends are clear: AI is fundamentally reshaping the cyber security industry. And for the first time in 19 years of the DBIR being published, exploiting vulnerabilities has surpassed stolen credentials to become the number one breach entry point.
Other key findings include:
Interactive, conversational attacks on mobile are on the rise
As people get more savvy about traditional email phishing, threat actors are pivoting to mobile-centric social engineering (fake text messages and voice calls) with a success rate 40% higher than traditional email phishing.
More employees now use ‘shadow AI’ at work, risking company secrets
Shadow AI, referring to employees using unapproved AI tools at work, is now the third most common non-malicious data leakage-related activity. Frequent usage of AI tools by employees has surged from 15% to 45% of employees in a single year, highlighting an elevated risk of data exfiltration associated with unapproved platforms.
Supply chains get riskier as third-party involvement in breaches is up 60%
As companies rely more heavily on external vendors, threat actors are exploiting those vulnerabilities, with breaches involving a third party now accounting for 48% of all breaches.
AI bots are the next frontier
AI bot internet crawlers are experiencing a massive 21% month-over-month growth compared to entirely flat (0.3%) human-led traffic growth, showing where the next set of threats could come from.
Resilience good practices
The rapid weaponisation of known vulnerabilities by AI can create a capacity crisis for security teams, underscoring the urgent need to prioritise fundamental security and risk management practices. In response, the DBIR is providing actionable recommendations for resilience, tailored for today’s AI environment.






