US data compromises reached a record 3,322 in 2025, according to figures from the Identity Theft Resource Center summarized in 2026, the highest annual total the organization has ever tracked. The record volume signaled that even as the average cost of an individual breach eased, the sheer number of incidents continued to climb.

The rising count reshaped how analysts describe the overall threat. A falling per-incident cost paired with a growing number of incidents means aggregate economic damage from breaches likely reached new highs, since more organizations were affected across the year. The improvement in average cost, driven by faster detection, did little to offset the expanding attack surface.

Artificial intelligence sat on both sides of the ledger. Defensive AI and automation reduced breach costs by roughly $1.9 million for organizations that had adopted them before an incident, while unauthorized employee use of AI tools, often called shadow AI, added an average of about $670,000 to breach costs where such use ran high. The pattern illustrated how the same technology can strengthen defenses or open new exposure depending on how it is governed.

Detection timelines helped explain the cost dynamics. The mean time to identify and contain a breach fell to 241 days, the lowest in nine years, and breaches contained more quickly cost substantially less than those that lingered past the 200-day mark.

For organizations, the data reinforced a straightforward lesson. Reducing the number and impact of compromises depends on both faster detection and disciplined control over how AI tools enter the workflow, since ungoverned adoption measurably raises the cost when an incident occurs.

Source: Digital Applied -- https://www.digitalapplied.com/blog/cybersecurity-statistics-2026-data-points