The Verizon 2026 Data Breach Investigations Report is the closest thing the security industry has to a census, analysing more than 22,000 breaches from contributors worldwide. Unlike a lot of vendor threat reporting, it runs a dedicated breakdown for small- and medium-sized businesses and a regional breakdown that covers Australia. Both sections are worth reading directly if you run a Perth business, because most of the headline findings apply to you more than they apply to the enterprises the report's scarier stories tend to be about.
What Verizon Found When It Looked Specifically at Small Businesses
Verizon classes any organisation under 1,000 employees as "small" for this analysis, so it covers a wide range, but the findings are consistent enough to be useful. In SMB breaches, three patterns, System Intrusion, Basic Web Application Attacks, and Social Engineering, accounted for 100% of confirmed breaches. External, financially motivated attackers were behind all of them.
The report makes a point of addressing a common assumption directly: being a small organisation doesn't mean your threat profile is meaningfully different from anyone else's, and roughly 96% of ransomware victims in the dataset (where organisation size was known) were SMBs, not enterprises. Most of these cases weren't targeted. Attackers were opportunistic, casting a wide net for compromised credentials (38% of ransomware cases) or unpatched, internet-facing edge devices (29%), rather than picking victims by industry or revenue.
Three Numbers Worth Sitting With
1. Patching is losing ground, not gaining it
Exploiting unpatched vulnerabilities is now the single most common way attackers get in, at 31% of breaches, overtaking stolen credentials (down to 13%). But the report also found that only 26% of critical vulnerabilities were fully patched in 2025, down from 38% the year before, and the median time to fully resolve one stretched from 32 days to 43. Attackers are getting faster at exploiting gaps while, on average, organisations are getting slower at closing them. A consistent patch management routine, checked with an IT security audit, is what closes that gap.
2. Ransomware keeps climbing, but paying is going out of fashion
Ransomware appeared in 48% of all breaches this year, up from 44%. At the same time, 69% of ransomware victims in the report didn't pay, and the median ransom paid dropped again, to $139,875 from $150,000. Not paying, and having a tested restore process to fall back on instead, is increasingly the norm rather than the exception.
There's also a compliance angle Perth businesses should know about. Since 30 May 2025, under Part 3 of the Cyber Security Act 2024, any business with annual turnover of AUD $3 million or more (plus operators of critical infrastructure regulated under the SOCI Act) must report a ransomware or cyber extortion payment to the Australian Government within 72 hours of making it. That's a separate obligation from the Notifiable Data Breaches scheme, which covers reporting breaches of personal information, and it's worth knowing whether your turnover puts you inside it before you're ever in a position to need it.
3. Shadow AI has become a tracked insider-risk category, not just a habit
Verizon found that 67% of users are accessing AI tools through personal, non-corporate accounts on work devices, and that shadow AI is now the fourth most common non-malicious insider action in its data loss prevention dataset, a fourfold increase on the year before. The most common type of data leaking into unauthorised AI tools was source code, followed by images and structured business data. This is the same shadow AI risk we covered in our look at AI-driven cybercrime, now showing up in one of the industry's largest breach datasets rather than a single vendor's research. If you haven't set a written AI usage policy yet, this is a second, larger data source saying the same thing.
A Reminder Closer to Home: The Qantas Breach
Verizon's regional analysis of Asia-Pacific breaches points to the July 2025 breach affecting Qantas as an example of the third-party risk it describes, calling it one of Australia's largest breaches since 2022. Personal data belonging to more than five million customers was stolen through a third-party platform, not a direct attack on Qantas's own systems, and the group responsible placed extortion demands before releasing the data when the ransom wasn't paid. It's a large-scale version of a pattern the report says is becoming more common at every size: breaches with third-party involvement rose to 48% of the total, up 60% on last year, as businesses connect more of their systems to vendors and platforms outside their direct control.
The same regional data shows System Intrusion still dominates breaches across Asia-Pacific at 60%, and Basic Web Application Attacks have doubled to 22%, largely fuelled by the use of stolen credentials to get in. None of this changes the fundamentals a Perth business needs in place, it just underlines why they matter: knowing what your vendors can access, and keeping MFA enforced everywhere, including on the third-party accounts your business depends on.
What This Actually Means for Your Business
- Patch on a schedule you can prove, not one you assume is happening. The gap between when a fix is available and when it's applied is where most of this year's breaches happened.
- Assume ransomware is opportunistic, not targeted. Weak or reused credentials and unpatched edge devices are what get SMBs picked, not company size or industry.
- Check whether the new ransomware payment reporting obligation applies to you. If your turnover is near or above AUD $3 million, know the 72-hour reporting requirement before you need it.
- Know what your vendors can touch. Third-party involvement is now present in nearly half of all breaches, review access the same way you'd review a staff account.
- Put a written AI usage policy in place. Two large, independent datasets now point at shadow AI as a real and growing exposure, not a theoretical one.
Frequently Asked Questions
Is my business too small to be a ransomware target?
No. Verizon's 2026 report found that around 96% of ransomware victims (where organisation size was known) were small or medium businesses, not enterprises. Most ransomware operators aren't targeting a specific company, they're opportunistically hitting whoever has compromised credentials or an unpatched, internet-facing device.
Does Australia have a mandatory ransomware payment reporting law?
Yes. Since 30 May 2025, under Part 3 of the Cyber Security Act 2024, businesses with annual turnover of AUD $3 million or more (along with operators of critical infrastructure regulated under the SOCI Act) must report any ransomware or cyber extortion payment to the Australian Government within 72 hours of making it. This is separate from the Notifiable Data Breaches scheme, which covers reporting breaches of personal information.
What is "third-party breach exposure" and why does it matter?
It means your business was compromised through a vendor, platform, or supplier rather than directly. Verizon's report found third-party involvement in 48% of breaches this year, up 60% on the year before. The July 2025 breach affecting Qantas, one of Australia's largest since 2022, happened via a third-party platform, not a direct attack on Qantas's own systems.
What is "shadow AI" and why is a breach report tracking it?
Shadow AI is staff using AI tools through personal, unmanaged accounts on work devices. Verizon's report found 67% of users do this, and flagged shadow AI as the fourth-largest driver of newly detected insider-risk events in its data loss prevention dataset, with source code the most common thing leaked into unauthorised AI tools.
We help Perth businesses close the gaps this year's breach data points to most: slow patching, weak credentials, and unmanaged third-party and AI access.
Cybersecurity Services →Not sure if the new ransomware reporting rules apply to you?
Call 0433 087 091 for a free, no-obligation conversation about where your business currently stands.
Book a Free ConsultationFor related reading, see The Notifiable Data Breaches Scheme, Ransomware Recovery, and AI Is Reshaping Cybercrime.
Source: Verizon 2026 Data Breach Investigations Report. Statistics referenced in this article belong to Verizon and its contributors; for the full dataset, methodology, and regional and industry breakdowns, refer to the report directly at verizon.com/dbir. Details of Australia's ransomware and cyber extortion reporting regime are summarised from the Australian Department of Home Affairs' contribution to that report and are general information only, not legal advice, refer to cyber.gov.au or homeaffairs.gov.au for authoritative guidance on whether and how the obligation applies to your business.