Verizon’s 2023 Data Breach Investigations Report found that a broad “human element” was involved in 74% of the breaches it analyzed, while ransomware appeared in 24%. The report also put the median ransomware loss at $26,000—but that figure is not the same as the report’s separate $1-to-$2.25-million loss range for 95% of ransomware incidents that experienced a loss. These are findings from the 2023 report’s dataset, not a measurement of threats in 2026.
What the 2023 DBIR measured
Verizon’s 2023 DBIR examined 16,312 security incidents and 5,199 confirmed breaches. An incident is not necessarily a confirmed breach, so those totals describe different groups. The figures below refer to that edition and its analyzed data, not to every organization or breach worldwide.
The official 2023 DBIR report page provides the downloadable report. Verizon’s June 6, 2023 release summarizing the findings supplies the headline figures and additional cost details.
What “human element” means—and what it does not
Verizon said 74% of breaches in the 2023 DBIR involved the human element. That is not a finding that employees made mistakes in 74% of breaches. Verizon’s category includes people and human-influenced activity across several routes: attackers using stolen credentials, social engineering that tricks someone into taking an action, misuse of legitimate privileges, and errors such as misconfiguration or sending sensitive information to the wrong recipient.
#1 Best Overall
That distinction matters for prevention. A breach involving a person’s account may result from a stolen password rather than a careless user; an error may involve a process or configuration rather than an individual’s judgment. Verizon’s discussion of enterprise trends outlines this broader view of human involvement and its suggested mitigations in its 2023 DBIR trends article.
Ransomware prevalence and loss figures
Ransomware was involved in 24% of breaches in Verizon’s 2023 DBIR. Verizon described ransomware as malware that encrypts an organization’s data and then extorts money to restore access. The report’s cost figures describe different measures, so they should not be collapsed into one typical price.
Rank #2
| Figure | What it describes |
|---|---|
| 24% | Share of breaches in the Verizon 2023 DBIR involving ransomware. |
| $26,000 median loss | Verizon’s 2023 DBIR median ransomware loss; Verizon said it was more than double the median two years earlier. |
| $1 to $2.25 million | Range covering 95% of ransomware incidents in the 2023 release that experienced a loss. It is a range, not an average, and does not mean every victim paid a ransom. |
The median and the loss range answer different questions: the median is the midpoint of the measured cost figure, while the range describes the spread of losses among the specified incidents. Neither should be treated as a guaranteed bill for an organization that suffers ransomware.
How attackers gained access, and the business-email figure
For external actors’ entry techniques in the 2023 DBIR, Verizon reported stolen credentials at 49%, phishing at 12%, and vulnerability exploitation at 5%. These percentages describe the entry techniques attributed to external actors; they are not percentages of all incidents or a breakdown of the 74% human-element finding.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
The same June 2023 release cited a $50,000 median amount stolen in business email compromise (BEC), based on IC3 data. Verizon also reported that pretexting cases nearly doubled year over year. BEC and ransomware are distinct attack patterns, and the BEC median should not be substituted for a ransomware cost estimate.
What organizations can do with the findings
Verizon’s recommendations in its follow-up discussion are defensive measures, not guarantees that a breach will be prevented. They address different parts of the problem rather than treating human involvement as a training issue alone.
Rank #4
- Reduce credential risk: protect accounts with access controls and account management, including multi-factor authentication (MFA). Check that the chosen authentication method is supported by the services in use and that recovery procedures are secure.
- Make social engineering harder: pair phishing and pretexting awareness with email and browser protection, and ensure staff know how to report suspicious requests.
- Limit exploitable weaknesses: secure enterprise assets and software, use anti-malware tools, and manage vulnerabilities through a defined process.
- Prepare for disruption: maintain data recovery processes and incident-response management so the organization can respond if prevention fails.
A compatible FIDO2 security key can be one way to support MFA, but the Verizon material does not test or endorse a particular device. Before selecting one, verify that the intended accounts support its authentication standards and consider account recovery and deployment needs.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to read the 2024 follow-up without rewriting 2023
Verizon’s 2024 DBIR analyzed 30,458 incidents and 10,626 confirmed breaches. Its release reported that 68% of breaches involved a non-malicious human element and 32% involved extortion techniques including ransomware. These are figures from the 2024 edition, with different wording and context; they should not be presented as a like-for-like update to the 2023 report’s 74% human-element and 24% ransomware findings.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteBest Value
When comparing DBIR editions, check the report year, dataset scope, definitions, denominator and metric type. A shift in a headline percentage does not, by itself, establish that a threat became more or less common. See Verizon’s 2024 DBIR release for that edition’s own figures.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

