IBM Finds AI Reshaping Breach Economics

One in four malicious data breaches over the past year was AI-enabled, and those breaches cost an average of US$6 million, about US$1 million more than the global average.

The finding comes from IBM's 2026 Cost of a Data Breach Report, which recorded a 56 per cent rise in AI-enabled breaches on the previous year. The attacks were mostly deepfake impersonation and AI-enabled malware. https://www.ibm.com/reports/data-breach

The report found companies using AI and automation in security operations cut breach costs by almost US$2 million on average. Yet one in four organisations have still not adopted these tools.

Most AI-driven attacks targeted critical infrastructure, at 62 per cent, with financial services and energy most affected. Financial services breaches cost an average of US$6.3 million and energy breaches US$5.2 million.

More than 20 per cent of organisations reported a breach targeting AI models or applications. The most common causes were compromised APIs, applications or plug-ins, and cloud misconfigurations affecting AI workloads, each cited by 27 per cent.

Encryption gaps persisted. Only 37 per cent of breached organisations encrypt sensitive data both at rest and in transit, and just 34 per cent have visibility into cryptographic assets.

"AI is making attacks faster and cheaper, while breaches keep getting more expensive," said Suja Viswesan, vice president of IBM Security Software. Separate Ponemon Institute research found 85 per cent of organisations plan to increase security spending after learning of frontier AI cyber capabilities.

 

Business Solution