Skip to main content
VA Horizon
Book a Call
Statistics

PCI DSS and Small-Business Data Breach Statistics 2026

Quick answer

In extreme cases, the top 2.5% of small and midsize businesses, financial loss from a data breach accounted for more than 7% of the business’s revenue, per Verizon’s 2026 Breach Impact Study, drawn from roughly 70,000 cyber-insurance claims. Separately, Verizon’s 2026 Data Breach Investigations Report Retail Snapshot recorded 997 retail-sector incidents with 806 confirmed data disclosures in its dataset, with three patterns, System Intrusion, Basic Web Application Attacks, and Social Engineering, accounting for 95% of retail breaches.

The retail data also shows the type of data attackers compromise has shifted: internal data rose from 65% of compromised data types last year to 84% this year, as attackers increasingly monetize whatever data they can reach rather than targeting payment cards specifically. Verizon’s own report frames the old “retail breach means payment-card breach” assumption as outdated, so this piece does not assert a standalone payment-card-share figure in its place.

The Financial Tail Risk for the Worst-Hit Small Businesses

Verizon’s 2026 Breach Impact Study, a companion analysis to its Data Breach Investigations Report built on roughly 70,000 cyber-insurance claims, found that in extreme cases, the top 2.5% of small and midsize businesses affected, financial loss from a data breach accounted for more than 7% of that business’s revenue. That is the tail-risk scenario rather than the typical outcome, but a small business operating on thin margins can feel a loss of that size in a way a larger company might not.

The figure is a useful anchor for a compliance or security conversation with a small-business merchant precisely because it comes from actual insurance-claims data, not a modeled estimate of hypothetical exposure.

How Many Retail Breaches Verizon’s 2026 Dataset Counted

The retail-sector snapshot inside Verizon’s 19th edition Data Breach Investigations Report, covering a dataset window of October 2024 through November 2025 and published May 19, 2026, recorded 997 incidents with 806 confirmed data disclosures. Three attack patterns, System Intrusion, Basic Web Application Attacks, and Social Engineering, together accounted for 95% of retail breaches in that dataset, a striking concentration in just three named categories out of the full range of breach patterns the report tracks.

That concentration is useful, practically: a merchant or ISO thinking about where to focus a security conversation does not need to guard against every conceivable attack type equally, three named patterns cover nearly all of what happened in retail this dataset year.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

How Attackers Are Getting In

Within retail breaches, the initial access vector broke down as exploitation of vulnerabilities at 42%, credential abuse at 14%, and phishing at 9%, per the same retail snapshot. Exploitation of vulnerabilities leading the list points at unpatched software and systems as the single largest entry point, ahead of the credential-theft and social-engineering routes that often get more attention in a general security conversation.

Third-party involvement showed up in 68% of retail breaches, and a human element was present in 58%, both signals that a breach is rarely purely a technical failure in isolation, it usually involves either an outside vendor relationship or a human decision somewhere in the chain.

Why Payment Card Data Is No Longer the Whole Story

Retail breaches have historically been associated with payment-card data specifically, but Verizon’s own 2026 report states that framing is now outdated. Internal data compromise rose from 65% of the data types affected in the prior year’s dataset to 84% in this year’s, as threat actors increasingly target whatever data they can monetize rather than focusing narrowly on payment cards. Across all data types compromised in retail breaches this dataset year: internal data 84%, credentials 26%, secrets 20%, other 14%.

That shift is exactly why this piece does not assert a standalone “X% of retail breaches are payment-card breaches” figure. The report itself makes clear that framing understates how diversified the actual target list has become, even though payment-card exposure remains a real and present risk inside that broader mix.

A Named Breach at Retail Scale

Verizon’s own incident database cites clothing retailer Hot Topic as an example from this past year, a breach affecting 57 million customers. A single named incident at that scale is a useful, concrete illustration of what the aggregate statistics above translate into once one specific retailer is affected, rather than an abstract percentage.

These breach patterns sit inside a payments ecosystem that keeps growing in scale, US card network purchase volume reached $2.909 trillion in the first quarter of 2026 alone, up 7.9% year over year, the transaction base every one of these retail breaches ultimately touches in some form.

The Numbers

1

In extreme cases, the top 2.5% of small and midsize businesses, financial loss from a data breach accounted for more than 7% of the business’s revenue, per Verizon’s 2026 Breach Impact Study.

Verizon, 2026 Breach Impact Study, Cybersecurity Insights for SMBs

2

Verizon’s 2026 DBIR Retail Snapshot recorded 997 retail-sector incidents with 806 confirmed data disclosures, dataset window October 2024 through November 2025.

Verizon, 2026 Data Breach Investigations Report, Retail Snapshot

3

Three patterns, System Intrusion, Basic Web Application Attacks, and Social Engineering, accounted for 95% of retail breaches in the same dataset.

Verizon, 2026 Data Breach Investigations Report, Retail Snapshot

4

Internal data compromise in retail breaches rose from 65% of data types affected last year to 84% this year, as attackers target a broader mix of monetizable data beyond payment cards.

Verizon, 2026 Data Breach Investigations Report, Retail Snapshot

5

US card network purchase volume reached $2.909 trillion in Q1 2026, up 7.9% year over year, the transaction base every retail breach in this dataset sits alongside.

Nilson Report, US Card Network Results First Quarter 2026

Sources

The external data in this article draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

How much revenue can a small business lose to a data breach?
In extreme cases, the top 2.5% of affected small and midsize businesses, financial loss accounted for more than 7% of the business’s revenue, per Verizon’s 2026 Breach Impact Study, based on roughly 70,000 cyber-insurance claims.
How many retail data breaches did Verizon’s 2026 report count?
997 incidents with 806 confirmed data disclosures, in a dataset window of October 2024 through November 2025, per the 2026 DBIR Retail Snapshot.
What are the most common ways attackers get into retail systems?
Exploitation of vulnerabilities (42%), credential abuse (14%), and phishing (9%) were the leading initial access vectors in retail breaches, per Verizon’s 2026 Retail Snapshot.
Are most retail data breaches still about stolen payment card numbers?
Verizon’s own 2026 report says that framing is now outdated. Internal data compromise rose from 65% to 84% of affected data types year over year, as attackers target a broader mix of monetizable data.
What is a real example of a large retail breach from this dataset?
Clothing retailer Hot Topic, cited in Verizon’s own incident database as affecting 57 million customers in the past year.

Turn a breach headline into a real conversation.

Book a 15-minute call and see how Human + AI SDRs qualify merchants on their actual security and compliance posture over SMS, before a rep ever brings up a breach statistic.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement

Recommended next steps