PP113: Patch Gaps, Pretexting, and AI Use for Crimes and Crimefighting: 2026 Verizon DBIR Highlights
Hosts Jennifer Jabush and Drew Connery-Murray discuss highlights from the 2026 Verizon Data Breach Investigations Report, covering shifts in attack vectors, ransomware trends, third-party risk, and AI's role in both cybercrime and enterprise security. The report is based on 31,000 incidents and over 22,000 confirmed breaches across 145 countries from November 2024 to October 2025. Key findings include vulnerability exploitation surpassing credential abuse as the top initial access vector, and 60% of breaches now involving third-party relationships.
Summary
The episode opens with a brief listener shoutout about the book 'Krakatoa' by Simon Winchester before transitioning to the main topic: the 2026 Verizon Data Breach Investigations Report (DBIR), now in its 19th year. The hosts note the report covers incidents from November 2024 through October 2025, a distinction they flag as relevant given subsequent AI developments like 'Mythos.'
The most significant shift in this year's report is that vulnerability exploitation has overtaken credential abuse as the number one initial access vector, now accounting for 31% of incidents — more than doubling year-over-year. The hosts attribute this to the rising volume of unpatched vulnerabilities, particularly in internet-facing devices like VPNs, firewalls, and RDP. They discuss that only 26% of critical vulnerabilities from the CISA Known Exploited Vulnerability (KEV) catalog were fully remediated in 2025, down from 38% the prior year, with median resolution time rising from 32 to 43 days. The hosts emphasize that partial remediation (58% of vulnerabilities) covers a wide range of outcomes and shouldn't be equated with full resolution.
Ransomware remains pervasive, appearing in 48% of all breaches. However, fewer victims are paying ransoms — 69% did not pay — and median payouts dropped to just under $140,000, down roughly 6.75%. The hosts speculate on reasons for declining payments, including legal deterrents in some jurisdictions, improved disaster recovery practices, and distrust of ransomware actors to honor agreements. They note that publicly available data on ransom payments may undercount instances, as non-public companies aren't required to disclose.
Third-party involvement in breaches rose sharply from 48% to 60%, which the hosts highlight as a major concern given the inadequacy of most third-party risk management programs, which typically rely on self-reported questionnaires rather than independent audits. They reference CMMC and PCI DSS as examples of more rigorous third-party validation frameworks, while noting these are neither cheap nor universally applicable.
Pretexting — a social engineering technique involving real-time, synchronous interaction (phone calls, live chats, texts) to manipulate victims — has been added as a distinct initial access vector in this year's report. The hosts note it is harder for users to detect than traditional phishing, with mobile-centric attack success rates 40% higher than email. They suggest organizations update security awareness training to address pretexting specifically.
On threat actor demographics, 88% are external, with 87% of those being criminal gangs and 15% state-affiliated. Of the 12% who are insiders, 75% acted inadvertently through misconfiguration or mistakes rather than malicious intent. The report notes black market prices for user credentials: approximately $700 for a regular account and $1,300 for an admin account. The hosts also highlight a buried finding that 1 in 500 employees accessed high-risk compromising material on enterprise devices, making them more susceptible to coercion or blackmail.
The AI section, developed in partnership with Anthropic, analyzed interactions on Anthropic's own tools that violated acceptable use policies. Findings show threat actors are primarily using AI to scale and automate existing attack techniques rather than discover novel ones, with less than 5% of observed malicious queries involving truly novel tactics. The analysis was mapped against the MITRE ATT&CK framework. On the defensive/enterprise side, 67% of employees are using non-corporate AI accounts on corporate devices, creating significant data leakage risks. Source code accounted for 28% of data leaked through shadow AI. The hosts also flag AI-enabled browser extensions as a significant and underappreciated risk vector.
The episode wraps with brief mentions of additional report sections: memory safety issues accounting for 89% of vulnerability root causes, DDoS attacks increasing 200% over prior years, VPNs representing 44% of initial access broker entry points, and industry-specific breakdowns for healthcare, financial services, and retail.
About this episode
The Verizon Data Breach Investigations Report (DBIR) is a postmortem of a year’s worth of cyber incidents and breaches, and a snapshot of how well organizations are responding to actual threats. Drew and JJ share highlights from the 2026 installment, including: For the first time, vulnerability exploits top the list for initial access What a<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/packet-protector/pp113-patch-gaps-pretexting-and-ai-use-for-crimes-and-crimefighting-2026-verizon-dbir-highlights/" title="ReadPP113: Patch Gaps, Pretexting, and AI Use for Crimes and Crimefighting: 2026 Verizon DBIR Highlights">... Read more »</a>
Key Insights
- The report finds that vulnerability exploitation now accounts for 31% of initial access incidents, more than doubling year-over-year and overtaking credential abuse for the first time, driven largely by unpatched internet-facing devices like VPNs and firewalls.
- Only 26% of critical vulnerabilities from the CISA KEV catalog were fully remediated in 2025, down from 38% the prior year, with median resolution time growing from 32 to 43 days despite the KEV catalog representing a very small subset of all CVEs.
- Anthropic's analysis of its own policy-violating interactions, mapped to the MITRE ATT&CK framework, found that malicious actors primarily use AI to automate and scale existing attack techniques rather than discover novel ones, with fewer than 5% of queries involving truly novel tactics.
- The report found that 67% of employees are using non-corporate AI accounts on corporate devices, leaking sensitive data including source code (28% of leaked content), structured data, and intellectual property into non-enterprise AI environments.
- Third-party involvement in breaches rose from 48% to 60% year-over-year, yet most enterprise third-party risk programs rely on self-reported questionnaires, which the hosts argue provide little assurance compared to independent audits.
- The report identifies that 1 in 500 employees accessed high-risk or compromising material (e.g., explicit content, extremism) on enterprise devices, and argues these individuals are significantly more susceptible to coercion or blackmail by threat actors.
- Pretexting — synchronous, real-time social engineering via phone, text, or live chat — has been added as a distinct attack vector, with mobile-centric attack success rates 40% higher than email-based phishing, reflecting a meaningful shift from asynchronous phishing.
- VPNs represent 44% of entry points used by initial access brokers, and 89% of vulnerability root causes are still tied to memory safety and memory handling issues, suggesting foundational software development practices remain a persistent systemic failure.
Topics
Transcript
Hey, everybody, and welcome to this episode of Pocket Protector, the podcast at the intersection of networking and security. I'm Jennifer Jabush, aka JJ, here with Drew Connery-Murray, and we're going to be talking about the Verizon DBIR. But I first wanted to give a quick call out to one of our listeners that wrote in. Mike was talking to us about listening to the episode where we were talking about the undersea cables. I don't remember which episode number that was, but he said it reminded him of a book he really liked called Krakatoa, The Day the World Exploded by Sam Winchester. I've not heard of this book, but I did just find it on Amazon and add…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
HW083: Inside the WLAN Pros Toolbox – A Free, Multipurpose App
Keith Parsons introduces the WLAN Pros Toolbox, a free cross-platform app containing over 100 Wi-Fi tools, calculators, and references available on iPhone, iPad, Mac, Android, and web browsers. Built using Flutter and AI-assisted development, the app is intentionally free with no ads, subscriptions, or data collection because Parsons believes essential professional tools should be accessible to all engineers worldwide.
NB582: Infoblox Adds Network Observability with Kentik Buy; Satellite Data Centers vs. the Environment
Network Break covers major tech news including Infoblox's acquisition of Kentik for network observability, alarming electricity consumption by data centers (especially in Ireland), security advances in AI agent detection, and developments in space infrastructure including Rocket Lab's acquisition of Iridium and environmental concerns about orbital data centers.
TCG079: Why Your State File is Actually a Distributed Systems Problem
Malcolm Matalka argues that Terraform's value lies not in its HCL syntax but in its state management, which is fundamentally a distributed systems problem inadequately solved by file-based locking. He discusses how StateGraph reimagines infrastructure state as a database rather than a JSON file, enabling concurrent operations, better queryability, and solving the scalability issues that plague teams as they grow.
NAN126: Fine-Tuning Open Source LLMs for Network Engineering
Edward Tuharu, founder of VXpert AI, discusses his career pivot from pursuing CCIE certification to building AI-powered NOC/SOC systems after recognizing the transformative potential of transformer architecture in 2022. He outlines the progression of AI technologies from prompting to RAG to fine-tuning to agentic systems, drawing parallels with networking protocol evolution and emphasizing the importance of domain-specific knowledge and fundamentals.
D2DO306: Platform Engineering in the Agentic Era (Sponsored)
Jad Elzane and Miles Gray from VMware by Broadcom discuss how platform engineering evolved from DevOps to address developer cognitive overload, and how Platform Engineering 2.0 must now accommodate AI agents as consumers alongside human developers, requiring new security guardrails and observability controls.