The 2026 Verizon Data Breach Investigations Report (DBIR) provides a valuable look at how cybercriminals are gaining access to organizations and where businesses are most vulnerable to current threats. The report highlights several shifts in attacker behavior and reinforces the important reality: many data breaches originate from preventable security gaps.
Attackers Are Increasingly Exploiting Software Vulnerabilities
Exploitation of vulnerabilities (31%) surpasses credential abuse (13%) as the leading method attackers use to gain access to victim networks.
As threats continue to evolve, businesses need to proactively identify and remediate vulnerabilities before attackers have the opportunity to take advantage of them. From our perspective at Curbstone, this serves as a valuable reminder that payment security extends well beyond a payment application itself. Systems that connect to payment environments, such as servers, remote access tools, web applications, and third-party software, must also be patched and maintained properly. PCI compliance should not be treated as a once-a-year exercise; vulnerability management is an ongoing security control.

Third-Party Risk Continues to Grow
The DBIR found that third-party involvement in breaches is up 60% from last year, rising from 2025’s reported 30% of total breaches to this year’s 48%.
Organizations increasingly rely on software providers, cloud platforms, managed service providers, and payment technology partners to support their operations. While these relationships create efficiencies instead of building solutions or managing infrastructure in-house, they also introduce additional points of risk.
Selecting the right third-party technology partner can help you strengthen your cybersecurity as AI-driven attacks become more sophisticated and breach patterns continue to evolve. A PCI-validated Level 1 Service Provider like Curbstone can monitor emerging security threats and deliver technologies that help you reduce your risk while you focus on running your business. Secure payment technologies like tokenization and robust strategies for keeping sensitive cardholder data out of your business system whenever possible can, in turn, reduce your PCI scope, simplify compliance efforts, and strengthen your overall payment security.
Ransomware Remains a Persistent Threat
Ransomware was present in 48% of the breaches analyzed in the 2026 Verizon Data Breach Investigations Report, making it one of the most common and disruptive threats organizations face today. Many of these attacks fall within Verizon’s System Intrusion pattern, where attackers use ransomware to disrupt operations while gaining access to sensitive information.
Although fewer organizations are choosing to pay ransom demands, the impact of a ransomware attack can extend well beyond the initial incident. Downtime, delayed operations, recovery costs, and damage to customer trust can create challenges long after systems are restored. For businesses that process payments, ransomware can also create additional concerns if attackers gain access to systems connected to the payment environment or sensitive cardholder data.
Reducing the amount of payment card data stored within your environment can help limit exposure during a breach. Solutions like tokenization can help protect sensitive payment information while reducing PCI scope. Along with strong payment security practices like never storing card numbers in plain text and not storing call recordings where customers read their phone numbers to an operator on the other end of the line, organizations continue to prioritize measures like vulnerability management, multifactor authentication, access control, and tested backup and recovery procedures to strengthen their overall security posture.
Reducing Payment Risk Across Today’s Industries
Cyber threats continue to impact organizations across industries, with attackers targeting sensitive business systems, payment environments, and third-party connections. According to the DBIR, hacking was involved in 71% of manufacturing breaches, highlighting the ongoing risk organizations face as they manage increasingly complex technology environments.
Although cybersecurity is often viewed as an IT responsibility, protecting payment data requires collaboration across the business. Finance, accounting, and operations teams play an important role in reducing the opportunities for exposure by limiting how sensitive cardholder data is handled during every transaction.
Technologies like tokenization can help organizations reduce the amount of payment data stored and transmitted throughout their environments, helping minimize risk, support PCI compliance efforts, and strengthen security without disrupting payment operations.
The DBIR highlights that organizations across several industries continue to experience significant cyber risk, particularly from breaches classified as System Intrusion:
- The Manufacturing Industry experienced 3,627 incidents, with 2,713 confirmed breaches.
- The Wholesale Trade Industry experienced 1,057 incidents, and 1,048 confirmed breaches.
- The Utilities Industry experienced 638 incidents, with 597 confirmed breaches.
No matter the industry, reducing payment data exposure and working with technology providers that prioritize security can help organizations better protect sensitive information while maintaining efficient payment operations.

AI Is Making Cyberattacks Faster, Not Necessarily Smarter
Artificial Intelligence is giving cybercriminals new ways to work more efficiently. Attackers are using AI to identify vulnerabilities, create more convincing phishing emails, and automate parts of the attack process, allowing them to launch campaigns faster and at a greater scale. Reports of malware and hacking tools incorporating AI-generated code or large language models (LLMs) have increased significantly throughout late 2025 and into 2026.
AI is making established tactics easier to execute, lowering the barrier for less experienced threat actors.
The DBIR and research from Anthropic point to several areas where AI-assisted attacks are becoming more common, including phishing, vulnerability exploitation, credential abuse, and attacks involving third parties. As AI becomes more deeply embedded across technology and business, it’s worth taking a fresh look at your existing security controls to ensure they are keeping pace with today’s evolving threats. This will not only help you meet compliance requirements but also help reduce the real-world risk of a breach.
Reduce Your Exposure
While attack methods continue to evolve, reducing the amount of sensitive data you store can help limit your organization’s exposure if a security incident occurs.
Protecting payment data starts at the point of capture. Technologies like tokenization and end-to-end encryption that are used by EMV/chip card terminals help reduce the number of places that your systems handle sensitive cardholder data.
Curbstone helps businesses implement these payment technologies to improve both security and operational efficiency. Whether you’re exploring tokenization, looking to reduce your PCI compliance scope or evaluating other changes for your current payment environment, our team can help you strengthen your payment security strategy. Contact Curbstone today to learn more.
