Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
Vector File VE / Vulnerability ExploitationIBM 2025, Figure 9

Attack vector

Vulnerability exploitation costs $4.24M, the lowest of the six principal attack vectors.

A breach that begins with the exploitation of an unpatched or zero-day software flaw averaged $4.24M in the IBM Cost of a Data Breach Report 2025, the cheapest per incident of the six principal attack vectors IBM ranks and 5% below the $4.44M all-breach average. That is the counterintuitive part: the vector most defenders can actually close, by patching, is also the least expensive when it does land, because a known-CVE intrusion tends to be identified and contained faster than a stealthy trusted-channel one.

Average cost

$4.24M

IBM 2025, Figure 9

Vector ranking

Lowest of 6

Cheapest of six principal vectors

vs global average

-5%

$0.2M below the $4.44M avg

Containment premium

+$1.14M

Breaches over 200 days vs under (+29%)

Section VE.1

Why the most preventable vector is the cheapest

Vulnerability exploitation sits at the bottom of the six principal attack vectors at $4.24M, below the $4.44M all-breach average. That does not make it low-risk, it makes it the vector where the cost lever is clearest.

When an attacker exploits a known software vulnerability, the intrusion leaves a recognisable signature: a malformed request to a public-facing application, an exploit payload matching a published CVE, a crash or anomaly in a service that vulnerability scanners and intrusion-detection tooling are specifically tuned to catch. Compared with a supply-chain compromise that arrives on a trusted vendor channel, or a malicious insider using legitimate access, a CVE exploit is comparatively noisy. Noisier intrusions get found sooner, and IBM's data is unambiguous that a shorter breach lifecycle means a lower cost.

That lifecycle relationship is the whole story of this vector's cost. Breaches contained in under 200 days averaged $3.87M in 2025; those that ran beyond 200 days averaged $5.01M, a $1.14M (29%) premium. Because exploited-vulnerability breaches skew toward the faster-contained end of that distribution, their average lands below the mean. The catch is that this only holds when the flaw is known and being watched for. A zero-day, exploited before any patch or signature exists, inverts the advantage entirely: it behaves like the stealthy vectors, and MOVEit is the case that proves it.

Section VE.2

Vulnerability exploitation against the other initial vectors

IBM's 2025 Figure 9 ranks initial attack vectors by average breach cost. Among the six principal attack vectors, vulnerability exploitation sits at the bottom, one of only two (with denial-of-service) to fall below the all-breach average, while malicious insider and supply chain sit at the top.

Malicious Insider$4.92M
Supply Chain Compromise$4.91M
Phishing$4.80M
Credential Theft$4.67M
Denial-of-Service$4.41M
Vulnerability Exploitation$4.24M

Unpatched or zero-day software flaws. The spread across these six vectors is narrow, from $4.24M to $4.92M, so the ranking reflects containment speed and detection difficulty more than any inherent difference in the damage a breach does once it succeeds. IBM's full Figure 9 also ranks non-malicious causes that cost less still, such as physical theft ($4.07M), human error ($3.62M), and system error ($3.61M); among the six deliberate attack vectors, vulnerability exploitation is the cheapest.

Primary source:IBM Cost of a Data Breach Report 2025, Figure 9 (average cost of a breach by initial attack vector). Vulnerability exploitation is the lowest of the six principal (deliberate) attack vectors at $4.24M; IBM's full chart also ranks cheaper non-malicious causes (physical theft, human error, system error).

Section VE.3

The two faces of the vector: known-CVE and zero-day

Vulnerability exploitation splits into two very different breaches. One exploits a flaw the vendor has already patched, and the cost is a failure to apply it in time. The other exploits a flaw nobody has patched yet, and there is no window to have acted. Equifax and MOVEit are the landmark cases for each.

Equifax 2017 / Apache Struts

$1.4B+

147M records, a patch left unapplied for months

The Apache Struts flaw (CVE-2017-5638) was disclosed and patched in March 2017. Equifax did not apply the fix, and attackers exploited the unpatched web application in mid-May, moving undetected until late July. This is the archetypal known-CVE breach: the cost was entirely a failure of patch management, and it ran to over $1.4B including a $575M FTC settlement.

$1.4B+, 147M records. The unpatched-Struts breach that redefined executive accountability.

MOVEit 2023 / Cl0p zero-day

~$15.8B

Estimated aggregate across 2,700+ organisations

The Cl0p group exploited a zero-day SQL-injection flaw (CVE-2023-34362) in Progress Software's MOVEit Transfer before any patch existed, reaching 2,700+ organisations and ~95.8M individuals. No amount of patch discipline would have closed this window in advance, which is why a zero-day exploit behaves like the stealthy, expensive vectors rather than the cheaper known-CVE ones. It also doubles as the decade's largest supply-chain breach.

~$15.8B aggregate, 2,700+ orgs. A file-transfer zero-day, exploited at scale.

Section VE.4

The 2026 update

In the IBM Cost of a Data Breach Report 2026 (released 29 July 2026) the overall global average rose to a record $4.99M and the US average to $11.5M, while the mean time to identify and contain a breach lengthened to 247 days, reversing five years of improvement. For a vector whose cost advantage rests entirely on fast containment, that lengthening clock matters: the same AI tooling that helps attackers weaponise a disclosed CVE faster also, on IBM's numbers, cuts breach cost by about $1.93M when defenders deploy it in security operations. The $4.24M figure on this page is the 2025 report's per-vector average, the edition in which IBM ranked initial vectors most explicitly; the lever it points to, patching known flaws before they are exploited and containing fast when they are, is the same one both cases on this page confirm.

Primary source:IBM Cost of a Data Breach Report 2026 (released 29 July 2026): global average $4.99M, US average $11.5M, mean time to identify and contain 247 days, AI/automation savings about $1.93M. Vulnerability-exploitation initial-vector cost ($4.24M) from the IBM Cost of a Data Breach Report 2025, Figure 9.

Cross-references

Schedule F / Reference Q&A

Frequently Asked Questions

Primary source:Vulnerability-exploitation initial-vector cost and the under/over-200-day lifecycle premium from the IBM Cost of a Data Breach Report 2025 (Figures 9 and 12); 2026 headline figures from the IBM Cost of a Data Breach Report 2026; Equifax and MOVEit case facts as cited on their case files.