Shapefin

RSA Report Reveals Surge in Identity-Related Data Breaches and Costs

Share It:

A new global report from RSA, the security-first identity leader, reveals that identity-related incidents caused both more frequent and more expensive data breaches in the past year. The 2026 RSA ID IQ Report provides insights from over 2,100 cybersecurity, identity and access management (IAM), and IT professionals regarding the frequency of identity failures, their financial repercussions, perspectives on AI’s potential in cybersecurity, and obstacles to passwordless authentication growth. The report also highlights differences specific to Japanese organizations compared to global trends.

According to the report, 69% of global organizations experienced an identity-related breach in the last three years, marking a 27-percentage-point increase year-over-year. This 64% relative increase suggests a rise in successful identity attacks, improved detection, or a combination of both, indicating an increasingly hazardous identity risk environment.

The financial impact of these breaches has also escalated, with 45% of organizations reporting that the cost of an identity-related breach surpassed the typical cost of a breach, as defined by IBM. Notably, 24% of organizations indicated costs exceeding $10 million, a three-percentage-point increase from the previous year’s survey.

Regional differences are apparent, with 71% of Japanese respondents identifying phishing as the primary threat to their organization, a figure significantly higher than the global average. This heightened concern may be partly due to the frequent reliance on manual passwords among Japanese users. Globally, passwordless adoption faces substantial hurdles, as 90% of organizations reported challenges in transitioning to passwordless authentication. This struggle is reflected in user behavior, with 57% not yet using passwordless methods as their primary authentication. Japan lags further, with 62% of organizations stating that users needed to type credentials for work more than six times daily.

The cybersecurity sector demonstrates considerable optimism regarding AI, with 83% expecting it to benefit cybersecurity more than cybercrime over the next three years. This optimism is translating into action, as 91% of organizations plan to implement AI in their technology stack this year, a 12-percentage-point increase year-over-year.

RSA CEO Greg Nelson stated, “The 2026 RSA ID IQ Report underscores that identity simply fails too many organizations too often. The likelihood of a breach—and the cost of inaction—are too high for leaders to tolerate the status quo.” RSA Chief Marketing and Growth Officer Laura Marx added, “Identity-related breaches exploded in 2026, jumping from impacting 42% of organizations to 69% in just one year, with help desk social engineering emerging as a major new attack vector. It’s urgent that leaders use this data to assess their identity capabilities and prioritize the actions to stay safe.”

Hirofumi Yatsuzuka, RSA APJ North Regional Director, commented on the Japanese context: “The 2026 RSA ID IQ Report details how Japanese organizations differ from their global peers, including where we lead, where we trail, and the areas where we can improve.” RSA executives Greg Nelson, Jim Taylor (President, Chief Product and Strategy Officer), and Laura Marx will discuss the report’s key findings and takeaways during a live English webinar on November 13 at 12:30 PM SGT.

RSA provides mission-critical cybersecurity solutions for security-sensitive organizations. The RSA Unified Identity Platform offers passwordless identity security, risk-based access, automated identity intelligence, and comprehensive identity governance across cloud, hybrid, and on-premises environments. Over 9,000 high-security organizations use RSA to manage more than 60 million identities, detect threats, secure access, and ensure compliance.

Latest Posts