What the Verizon DBIR keeps finding about credentials
The 2025 DBIR put stolen credentials, phishing, and the human element at the centre of breach patterns. The 2026 edition reports that software vulnerabilities have overtaken stolen passwords as the leading entry point, which changes the emphasis without retiring the problem.
The 2025 Data Breach Investigations Report again put stolen credentials, phishing, and the human element at the centre of how breaches begin. That had been the report's steady finding for years, and it is the empirical backing behind most arguments for phishing-resistant MFA.
The 2026 edition, covering incidents from November 2024 to October 2025, reports a genuine shift: 31% of breaches now start with software vulnerabilities, overtaking stolen passwords as the single most common entry point. Verizon frames this as attackers moving from tricking people toward exploiting systems.
Why it matters
Read that shift carefully, because the obvious inference is wrong. Credentials did not stop mattering; something else grew faster. The human element still runs through the common breach patterns, and the report continues to name social engineering, phishing, and stolen credentials among them.
The practical reading is that identity controls and patching are not competing budgets. An unpatched edge device is frequently how an attacker gets the credentials or the session token they use next, and credential stuffing still works against anything left without MFA. If you have used earlier DBIR editions to justify an identity programme, the 2026 numbers are worth reading before you cite them again: the headline changed, and someone in the room will know.