Verizon's 2026 Data Breach Investigations Report, which analyzed more than 31,000 incidents and 22,000 confirmed breaches across 145 countries, finds that the median malicious actor used AI tools across 15 distinct documented attack techniques per campaign, with some actors leveraging AI across as many as 40 to 50 techniques. The report covers incidents recorded between November 2024 and October 2025.
Phishing remains the dominant AI-assisted entry point, accounting for 44% of AI-assisted initial access techniques, and the volume of AI-generated text appearing in malicious emails has doubled compared to the prior reporting period. Verizon's analysts characterize AI's current impact on the threat landscape as primarily operational, automating and scaling attack techniques defenders already know how to detect rather than introducing entirely novel attack surfaces, though the report notes this democratization effect allows less-sophisticated actors to run campaigns that previously required specialized expertise.
The report also flags a separate internal risk, finding that 67% of employees are accessing AI services on corporate devices through personal, non-corporate accounts, while 45% now qualify as regular AI users on company hardware, up sharply from just 15% the year before. That shadow AI usage pattern is creating visibility gaps for security teams even as external AI-assisted attack volume continues to climb.
Source: Verizon -- https://www.verizon.com/business/resources/reports/dbir/
![[Data] Verizon Finds AI Now Used Across 15 to 50 Attack Techniques Per Incident](https://cdn.sanity.io/images/cbhtovty/production/69c0308464445db7d71598a66c0c4ba723cad43c-313x308.png)