AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.

A new IBM report puts the average global cost of a data breach at $6 million for 2026, up 35% in a year, and for the first time, AI-powered attacks account for one in four of those incidents.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Share

Key points

  • The average global cost of a data breach reached $6 million in 2026, a 35% rise from $4.44 million in 2025, according to IBM's annual Cost of a Data Breach report.
  • One in four malicious breaches involved AI-powered techniques such as deepfake impersonation or AI-written malware.
  • One in five organisations suffered a breach that specifically targeted their AI models or applications.
  • US breaches cost an average of $11.5 million, nearly double the global figure and an 11% increase over 2025.
  • Companies that used AI and automation inside their own security teams cut breach costs by an average of almost $2 million.

Data breaches have always been expensive. They are getting more expensive faster now, and artificial intelligence is a big part of why.

IBM's 2026 Cost of a Data Breach report, conducted by the Ponemon Institute research group and published this week, surveyed 600 organisations worldwide. The headline number: a single breach now costs the average company $6 million. That is a 35% jump from the $4.44 million average recorded just a year earlier.

For context, that is more than the annual revenue of most small businesses.

How does AI fit into this?

AI is now a weapon on both sides of the fight. For attackers, it makes fraud cheaper and faster. For defenders, it can cut the bill sharply, but only if companies actually use it.

One in four malicious breaches in this year's report were AI-enabled. Deepfakes (synthetic video or voice recordings that impersonate a real person) and AI-written malware (malicious software coded or improved by AI tools) made up the bulk of those incidents. AI-driven phishing, where criminals send convincing fake messages at scale, and prompt injection, an attack that manipulates an AI assistant by feeding it hidden instructions, also featured prominently.

"AI is making attacks faster and cheaper, while breaches keep getting more expensive," said Suja Viswesan, VP of IBM Security Software.

On the defensive side, organisations that deployed AI and automation inside their security operations spent an average of almost $2 million less on breach costs. One in four organisations still have not adopted those tools at all.

Are AI systems themselves being attacked?

Yes, and the entry points are not what most people expect.

One in five organisations reported a breach that directly targeted their AI models or the applications built on top of them. The most common causes were not some exotic flaw in the AI itself. Attackers broke in through poorly secured APIs (programming interfaces that let software talk to other software), vulnerable plug-ins, and cloud misconfigurations, where a company's cloud storage or computing settings are left open by accident. Both of those weak points appeared in 27% of AI-related breaches.

Despite this, only 40% of organisations had basic access controls in place on their AI models and data.

"If you wouldn't expose your database to the public internet without identity and access controls, why would you do that for your AI model?" said Kayne McGladrey, a cybersecurity advisor and senior member of the IEEE standards body.

Who is worst affected, and what should ordinary people do?

Healthcare remains the hardest-hit industry, at $6.64 million per breach, though that is actually down from $7.42 million last year. Financial services ($6.29 million) and industrial companies ($5.50 million) follow. US breaches cost an average of $11.5 million, almost twice the global figure, driven by steeper regulatory fines and higher operating costs.

Industry 2026 avg. cost 2025 avg. cost Change
Healthcare $6.64M $7.42M -11%
Financial services $6.29M $5.56M +13%
Industrial $5.50M $5.00M +10%
Technology $5.50M $4.79M +15%
Communications $4.71M $3.75M +26%

The average time to detect and contain a breach crept up to 247 days in 2026, reversing a five-year decline. Every extra week a breach goes unnoticed adds to the final bill.

For patients, customers, or employees of a company that suffers a breach: watch your bank statements, be suspicious of any unexpected password-reset emails, and be alert to calls or messages that claim to come from a service you use. AI-generated deepfakes mean a voice on the phone is no longer proof of identity. CSO Online covered the report's full methodology in detail.

Common questions

Does this affect me if I'm not in IT?

Yes. Higher breach costs ultimately filter through as higher prices, disrupted services, and in healthcare, possible delays in care. Your personal data, such as your name, date of birth, and insurance details, is exactly what attackers are after.

What is the single biggest thing that slows a company's response?

A shortage of experienced security staff, according to experts quoted in the report. Every extra week a breach goes undetected adds directly to the cost.

© 2026 Threat Vectr