AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
IBM's 2026 Cost of a Data Breach report puts the average global figure at $6 million, up 35% on last year, with one in four malicious incidents now involving AI-powered techniques.

Key points
- The average global cost of a data breach reached $6 million in 2026, a 35% rise from $4.44 million in 2025, according to IBM's annual Cost of a Data Breach report.
- One in four malicious breaches involved AI-powered techniques such as deepfake impersonation or AI-written malware.
- One in five organisations suffered a breach that specifically targeted their AI models or applications.
- US breaches averaged $11.5 million, nearly double the global figure and an 11% increase over 2025.
- Organisations that deployed AI and automation inside their security teams spent an average of almost $2 million less per breach.
Data breaches have always been expensive. They're getting more expensive faster now, and artificial intelligence is a large part of why.
IBM's 2026 Cost of a Data Breach report, conducted by the Ponemon Institute research group and published this week, surveyed 600 organisations worldwide. The headline number: a single breach now costs the average company $6 million, a 35% jump from the $4.44 million average recorded a year earlier.
How does AI fit into this?
AI is now a weapon on both sides of the fight, and the gap between attackers and defenders is widening.
One in four malicious breaches were AI-enabled. Deepfakes (synthetic video or voice recordings that impersonate a real person) and AI-written malware (malicious software coded or improved by AI tools) made up the bulk of those incidents. AI-driven phishing, where criminals send convincing fake messages at scale, and prompt injection, an attack that manipulates an AI assistant by feeding it hidden instructions, also featured prominently.
"AI is making attacks faster and cheaper, while breaches keep getting more expensive," said Suja Viswesan, VP of IBM Security Software, speaking to the report's authors.
Organisations that deployed AI and automation inside their security operations spent an average of almost $2 million less per breach. One in four organisations still haven't adopted those tools at all. That gap will be difficult to close quickly, and every month without those defences is a month of elevated exposure.
Are AI systems themselves being attacked?
Yes, and the entry points are not what most people expect.
One in five organisations reported a breach that directly targeted their AI models or the applications built on top of them. Attackers broke in through poorly secured APIs (programming interfaces that let software talk to other software), vulnerable plug-ins, and cloud misconfigurations, where a company's cloud storage or computing settings are left open by accident. Both weak points appeared in 27% of AI-related breaches.
Despite this, only 40% of organisations had basic access controls in place on their AI models and data.
"If you wouldn't expose your database to the public internet without identity and access controls, why would you do that for your AI model?" said Kayne McGladrey, a senior IEEE member and CISSP-certified cybersecurity advisor, speaking to CSO Online.
Who is worst affected, and what should ordinary people do?
Healthcare remains the hardest-hit industry. We've tracked a string of incidents in this sector: the CareCloud breach in late July and the Madera Community Hospital case a few days later are recent examples of exactly the kind of patient data theft the IBM report says attackers prize most.
| Industry | 2026 avg. Cost | 2025 avg. Cost | Change |
|---|---|---|---|
| Healthcare | $6.64M | $7.42M | -11% |
| Financial services | $6.29M | $5.56M | +13% |
| Industrial | $5.50M | $5.00M | +10% |
| Technology | $5.50M | $4.79M | +15% |
| Communications | $4.71M | $3.75M | +26% |
Healthcare's average of $6.64 million per breach is actually down from $7.42 million last year, though the sector still leads the table. Financial services ($6.29 million) and industrial companies ($5.50 million) follow. US breaches averaged $11.5 million, nearly twice the global figure, driven by steeper regulatory fines and higher operating costs.
The average time to detect and contain a breach crept up to 247 days in 2026, reversing a five-year decline. Every extra week a breach goes unnoticed adds to the final bill.
For anyone whose employer, insurer or bank suffers a breach: watch your bank statements and treat unexpected password-reset emails as suspicious. AI-generated deepfakes mean a voice on the phone is no longer proof of identity.
Common questions
Does this affect me if I'm not in IT?
Yes. Higher breach costs filter through as higher prices and disrupted services, and in healthcare, possible delays in care. Patient records, including names, dates of birth, and insurance details, are precisely what attackers are after.
What is the single biggest thing that slows a company's response?
A shortage of experienced security staff, according to sources quoted in the report. Every extra week a breach goes undetected adds directly to the cost, and the report's 247-day average suggests most organisations are still far too slow.



