Malicious attacks using artificial intelligence increased 56% over the previous year, according to the 2026 Cost of a Data Breach Report.


One in four malicious data breaches are now enabled by artificial intelligence (AI), driving the average cost of these incidents to $6 million, according to the 2026 Cost of a Data Breach Report from IBM. This figure represents a $1 million increase over the global average breach cost of $4.99 million.

The global average cost of a data breach rose 12% this year. Healthcare remains the most expensive industry for breaches for the 13th consecutive year, with an average cost of $6.64 million per incident, according to the report. Although this is a 10.5% decrease from $7.42 million last year, the sector continues to be a primary target for attackers seeking patient personally identifiable information.

The report, conducted by Ponemon Institute and analyzed by International Business Machines, indicates that AI-driven attacks increased 56% compared to the prior year. These incidents primarily involve deepfake impersonation and AI-enabled malware. The study suggests that AI is making attacks faster and cheaper to launch while making breaches more expensive to identify and remediate.

“What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” says Suja Viswesan, vice president, IBM Security Software, in a release. “The priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving.”

Gaps in AI Security

Among organizations that experienced a security incident involving an AI model or application, 92% lacked proper access controls. Only 40% of organizations reported using access controls on AI models and data.

The report also found that security incidents involving shadow AI—unapproved tools used by employees—more than doubled to 43% this year. These incidents resulted in higher average breach costs of $5.39 million and often led to data loss, compromise, and disrupted operations.

Furthermore, most organizations reported a lack of oversight for these technologies. According to the study, 68% of breached organizations lacked governance policies to manage AI or detect shadow AI. Only 19% of organizations reported coordination between their governance and security teams.

Impact of Defensive Automation

Organizations that extensively used AI and automation in their security operations shortened breach identification and response times by 65 days. These organizations saved an average of $1.93 million in breach costs compared to those that did not use such tools.

However, adoption remains uneven across security functions. While 77% of organizations use these technologies for threat detection and response, only 18% apply AI agents to vulnerability scanning and management. This gap leaves known exposures unresolved longer, potentially increasing the advantage for attackers who use machine speed to find vulnerabilities.

Proactive Spending and Future Risks

Awareness of advanced frontier AI capabilities is driving a shift toward proactive defense. While 64% of organizations originally planned to increase security investments after experiencing a breach, that number rose to 85% among those aware of new frontier model threats.

The report also highlights emerging risks related to quantum computing. Roughly 69% of breached organizations do not have a post-quantum cryptography project in place to secure data against future quantum attacks. Additionally, 61% of organizations reported they lack the controls necessary to monitor and secure cryptographic assets, such as keys and certificates, across their environments.

The 2026 report is based on an analysis of breaches experienced by 602 organizations globally between March 2025 and February 2026. Researchers conducted 3,558 interviews with security and business leaders to determine the financial and operational impacts of these incidents.

ID 443540850 © Parin Kiratiatthakun | Dreamstime.com