Verizon (NYSE:VZ) released the 19th Data Breach Investigations Report, highlighting how AI is reshaping cybersecurity risk. For the first time, 31% of breaches begin with vulnerability exploitation, surpassing stolen credentials. The report also notes rising mobile social engineering, growing shadow AI use at work, and increased third-party breach involvement.
Loading...
Loading translation...
Positive
None.
Negative
None.
News Market Reaction – VZ
+2.10%
+2.10%Session close to close
In the May 19 session, VZ gained 2.10%, reflecting a moderate positive market reaction.
This announcement underscores Verizon’s role in cybersecurity intelligence through its 19th Data Bre...
Analysis
This announcement underscores Verizon’s role in cybersecurity intelligence through its 19th Data Breach Investigations Report, spotlighting that 31% of breaches begin with vulnerability exploitation and 48% now involve third parties. It also notes rapid growth in AI bot traffic and rising “shadow AI” usage among employees. In context of recent network and resilience initiatives, investors may watch how Verizon integrates these AI and security insights into services, capital allocation, and future updates, including regulatory filings and debt actions.
Key Figures
Breaches via vulnerabilities:31%Mobile attack success:40% higherEmployee AI tool use (prior):15%+5 more
8 metrics
Breaches via vulnerabilities31%Share of breaches starting with vulnerability exploitation in 2025 DBIR data
Mobile attack success40% higherSuccess rate of mobile social engineering vs traditional email phishing
Employee AI tool use (prior)15%Employees frequently using AI tools at work in prior year
Employee AI tool use (current)45%Employees frequently using AI tools at work in latest DBIR period
Third-party breach increase60%Increase in breaches involving third parties
Breaches with third party48%Share of all breaches now involving a third party
AI bot traffic growth21% month-over-monthGrowth rate of AI bot Internet crawler traffic
Launch of digital twin, expanded satellite fleet and disaster-response assets for hurricanes.
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
Pattern Detected
Recent Verizon headlines, including debt management and technology/network initiatives, generally saw small, aligned price moves, with one divergence on a positive joint venture announcement.
Recent Company History
Over the past weeks, Verizon news has centered on network innovation, capital structure moves, and investor engagement. On May 6, it highlighted hurricane-season readiness with a 2,600-asset satellite fleet and digital twin technology. A joint D2D connectivity venture with AT&T and T-Mobile on May 14 was strategic but saw a modest -0.32% move. Debt tender and private exchange offers announced on May 11 had near-flat reactions. Today’s DBIR release continues the theme of emphasizing resilience, AI, and security capabilities rather than near-term financial shifts.
Key Terms
vulnerability exploitation, data breach investigations report, social engineering, shadow AI, +4 more
8 terms
vulnerability exploitationtechnical
"for the first time in 19 years of the DBIR being published, exploiting vulnerabilities has surpassed"
Vulnerability exploitation is the act of taking advantage of a weakness in a computer system, software, or network to gain unauthorized access, disrupt operations, or steal information. For investors it matters because successful attacks can cause direct financial losses, halt business operations, damage customer trust and trigger regulatory fines—similar to a criminal finding and using an unlocked door to break into a storefront, the resulting harm can reduce a company's revenue and valuation.
data breach investigations reporttechnical
"The 19th edition of the Data Breach Investigations Report (DBIR) confirms AI-driven speed"
A data breach investigations report is a document that summarizes what went wrong when sensitive information was exposed, how the breach occurred, which data was affected, and what steps were taken to stop it and prevent a repeat. For investors it functions like a post‑accident report: it reveals potential legal costs, regulatory fines, lost customer trust, and required fixes that can affect a company’s future earnings and risk profile.
social engineeringtechnical
"threat actors are pivoting to mobile-centric social engineering (fake text messages and voice calls)"
Social engineering is the practice of manipulating people into revealing confidential information, granting access, or taking actions that compromise security, often by posing as a trusted person or using urgent, persuasive stories. For investors it matters because these scams can lead to direct financial loss, theft of sensitive corporate data, disrupted operations, or damage to a company’s reputation — similar to a con artist who tricks a business into handing over its keys.
shadow AItechnical
"Shadow AI, referring to employees using unapproved AI tools at work, is now the third most common"
Shadow AI describes employees using artificial intelligence tools or services without formal approval, oversight, or integration into official systems — for example, personal subscriptions, free web apps, or browser add-ons. For investors this matters because these hidden tools can expose sensitive data, create compliance or legal problems, produce unreliable results, and lead to unexpected costs or reputational damage, much like an unapproved gadget in a factory that creates safety and billing surprises.
data exfiltrationtechnical
"highlighting an elevated risk of data exfiltration associated with unapproved platforms."
Data exfiltration is the unauthorized copying or removal of sensitive information from an organization’s systems, like someone sneaking files out of a locked office. It matters to investors because stolen data can lead to direct financial loss, regulatory fines, legal liability, damage to customer trust, and operational disruption — all of which can reduce revenue and share value and create unpredictable costs for the company.
ai bot internet crawlerstechnical
"AI Bot Internet Crawlers are experiencing a massive 21% month-over-month growth"
AI bot internet crawlers are automated programs that use artificial intelligence to browse, read and extract information from websites at large scale, acting like a digital librarian that scans pages to pull out text, images and data. They matter to investors because they can speed up market research and competitive monitoring but also create risks—such as inaccurate or misused data, strain on a company’s web infrastructure, copyright or privacy disputes, and shifts in web traffic or revenue models—that can affect a business’s costs, reputation and regulatory exposure.
secure by designtechnical
"integrating AI into 'secure by design' frameworks, and leveraging AI within defense-in-depth"
An engineering approach that builds security into a product, system, or process from the very beginning rather than bolting it on later. For investors, it matters because solutions designed this way tend to have fewer costly breaches, lower remediation and compliance expenses, and a stronger reputation—similar to installing a safe during construction instead of adding locks after a break-in, which helps protect long-term value and predictable risk.
defense-in-depthtechnical
"integrating AI into 'secure by design' frameworks, and leveraging AI within defense-in-depth strategies"
A strategy of layered safeguards that combines multiple, different controls to prevent failures, breaches or accidents. Like a series of locked doors, alarms and backup plans protecting the same asset, each layer reduces the chance that a single problem becomes a crisis; for investors, clear defense-in-depth means management is actively lowering operational, cybersecurity and regulatory risk, which can protect earnings, reputation and long-term value.
The 19th edition of the Data Breach Investigations Report (DBIR) confirms AI-driven speed as a new challenge, pushing security strategy toward fundamental resilience
NEW YORK, May 19, 2026 (GLOBE NEWSWIRE) -- Verizon published the annual Data Breach Investigations Report (DBIR) today, which shows how Artificial Intelligence (AI) is impacting the cyber threat landscape as a whole. Although this report uses 2025 data—predating the latest frontier model advancements—the trends are clear: AI is fundamentally reshaping the cybersecurity industry. And at the same time that AI-detected vulnerabilities are in the news, for the first time in 19 years of the DBIR being published, exploiting vulnerabilities has surpassed stolen credentials to become the number one breach entry point.
Key Findings:
Nearly a third (31%) of all breaches start with vulnerability exploitation in an AI world: This is the first time in 19 years that it has surpassed stolen credentials as the biggest point of entry. Further, AI is being leveraged by threat actors to accelerate the time to exploit known vulnerabilities, shrinking the window for defense from months to mere hours.
Interactive, conversational attacks on mobile are on the rise: In terms of the “Human Element” risk of cybersecurity, as people get more savvy about traditional email phishing, threat actors are pivoting to mobile-centric social engineering (fake text messages and voice calls) with a success rate 40% higher than traditional email phishing.
More employees now use ‘shadow AI’ at work, risking company secrets: Shadow AI, referring to employees using unapproved AI tools at work, is now the third most common non-malicious data leakage related activity. Frequent usage of AI tools by employees has surged from 15% to 45% of employees in a single year, highlighting an elevated risk of data exfiltration associated with unapproved platforms.
Supply chains get riskier as third-party involvementin breaches is up 60%: As companies rely more heavily on external vendors, threat actors are exploiting those vulnerabilities, with breaches involving a third party now accounting for 48% of all breaches.
AI Bots are the next frontier: AI Bot Internet Crawlers are experiencing a massive 21% month-over-month growth compared to entirely flat (0.3%) human-led traffic growth, showing where the next set of threats could come from.
What it means:
The rapid weaponization of known vulnerabilities by AI can create a capacity crisis for security teams, underscoring the urgent need to prioritize fundamental security and risk management practices. In response, the DBIR is providing Chief Information Security Officers (CISOs) and cybersecurity professionals with actionable, resilient recommendations tailored with today’s AI environment in mind throughout the report. These include preparing for an influx of patches as AI identifies software flaws at an accelerating rate, integrating AI into 'secure by design' frameworks, and leveraging AI within defense-in-depth strategies to minimize the total attack surface
"While the velocity of cyber threats - driven by AI and faster vulnerability exploitation - is increasing, the foundational principles of security and strong risk management remain the most effective defense," said Daniel Lawson, SVP Global Solutions, Verizon Business. "The DBIR reinforces that these fundamentals still hold as organizations strive for resilience."
Call to Action: Download the full 2026 DBIR and review industry specific information on Verizon’s website.
Verizon Communications Inc. (NYSE, Nasdaq: VZ) powers and empowers how its millions of customers live, work and play, delivering on their demand for mobility, reliable network connectivity and security. Headquartered in New York City, serving countries worldwide and nearly all of the Fortune 500, Verizon generated revenues of $138.2 billion in 2025. Verizon’s world-class team never stops innovating to meet customers where they are today and equip them for the needs of tomorrow. For more, visit verizon.com or find a retail location at verizon.com/stores.
VERIZON’S ONLINE MEDIA CENTER: News releases, stories, media contacts and other resources are available at verizon.com/news. News releases are also available through an RSS feed. To subscribe, visit www.verizon.com/about/rss-feeds/.
Media contact: Carlos Arcila carlos.arcila@verizon.com 908-202-0479
FAQ
What are the key findings of Verizon (VZ) 2026 Data Breach Investigations Report?
The 2026 DBIR finds vulnerability exploitation now leads 31% of breaches, surpassing stolen credentials. According to Verizon, mobile-centric social engineering is rising, third-party involvement reaches 48% of breaches, and shadow AI use at work has sharply increased, elevating data leakage risks.
How does AI impact cyber threats in Verizon (VZ) 2026 DBIR?
AI is described as accelerating cyber threats by shrinking exploitation time from months to hours. According to Verizon, threat actors leverage AI to weaponize known vulnerabilities, while AI bots grow traffic 21% month over month, signaling emerging automated attack vectors across the internet.
What does vulnerability exploitation accounting for 31% of breaches mean in Verizon (VZ) 2026 DBIR?
Vulnerability exploitation being 31% of breaches makes it the top breach entry point for the first time. According to Verizon, AI-driven tools help attackers quickly exploit known software flaws, pressuring security teams to improve patching speed and strengthen basic risk management practices.
How common is shadow AI at work according to Verizon (VZ) 2026 DBIR?
Shadow AI has become the third most common non-malicious data leakage activity in workplaces. According to Verizon, frequent use of AI tools by employees jumped from 15% to 45% in one year, raising concerns about sensitive data flowing through unapproved AI platforms.
What does Verizon (VZ) 2026 DBIR say about third-party and supply chain cyber risk?
Third-party involvement in breaches increased 60%, now present in 48% of all breaches. According to Verizon, greater reliance on external vendors expands the attack surface, as threat actors exploit weaknesses in partners and suppliers to gain access to victim organizations’ environments.
What 2025 revenue and scale does Verizon (VZ) report alongside the 2026 DBIR?
Verizon reports 2025 revenue of $138.2 billion, reflecting its large global customer base. According to Verizon, the company serves countries worldwide and nearly all Fortune 500 firms, providing mobility, network connectivity, and security solutions supported by a global, innovation-focused workforce.