The financial toll of AI-powered breaches is significant. It adds an average of $1 million in costs per breach, as attackers use AI tools to increase speed, scale, and precision, IBM reports.
AI-based attacks that rely on deepfake impersonation and AI-enabled malware are getting faster and cheaper to launch, which has driven the cost of finding and fixing enterprise data breaches to a record high.
AI-enabled breaches cost an average of $6 million, which is roughly $1 million more than the global breach average of $4.99 million, according to IBM’s 2026 Cost of a Data Breach Report. The 2026 report, conducted by Ponemon Institute and sponsored and analyzed by IBM, is based on breaches experienced by 602 organizations globally between March 2025 and February 2026.
At $4.99 million, the global average cost of a data breach represents a 12% increase over last year’s numbers and a new high. That increase was largely driven by detection, escalation, and lost business costs, according to IBM. One in four malicious breaches were AI-enabled, IBM found.
AI is accelerating the attack lifecycle and changing breach economics, notes Limor Kessem, global lead, X-Force cyber crisis management at IBM, in a blog post about the report.
“Looking at the changes from last year’s report, AI-driven attacks increased by 56%, adding an average of $1 million per breach, as attackers use AI tools to increase speed, scale, and precision. This is not simply an evolution in attacker tooling; it is a structural shift,” Kessem wrote. “When adversaries can automate reconnaissance, generate persuasive phishing content, adapt malware and test exploits at machine speed, the cost and complexity of launching sophisticated attacks drops materially. Breaches become faster, broader and more expensive.”
“When attack velocity increases, the enterprise has less time to detect, validate and contain an incident. That compressed response window directly drives higher losses, whether through operational disruption, data exposure, legal costs, customer remediation or reputational damage,” Kessem continued. “From the report’s findings, two cost categories, detection and escalation alongside lost business, made up the majority (63%) of costs in the data breaches studied.”
On the positive side, AI and automation can successfully reduce breach impact, helping security teams move at machine speed and delivering an average savings of $1.93 million per breach, the IBM study found. But, implementation of these technologies is inconsistent.
“While 50% of breached organizations have deployed AI agents in threat hunting, response, and containment, only 18% have applied them to vulnerability scanning and management. That gap is significant,” Kessem wrote. “It suggests many enterprises are still using AI reactively, after suspicious activity has emerged, rather than proactively, where frontier capabilities deliver outsized advantages.”
The most expensive security incident types involving an organization’s AI model or applications were inversion and prompt injection attacks, which led to average losses of $6.07 million and $5.89 million respectively, the study found. “A model inversion attack occurs when adversaries exploit an AI model to infer or reconstruct sensitive training data, such as personal, proprietary, or confidential information, by analyzing model outputs and responses. These attacks can expose underlying data without direct access to the original dataset,” IBM stated.
The study also found that many AI-related breaches stemmed from structural weaknesses in the enterprise environment rather than from flaws inherent to a specific model.
“This distinction matters for senior leaders. It reframes AI security from a narrow model-risk conversation into a broader operating-model challenge involving architecture, controls, accountability and oversight,” Kessem wrote. “Encouragingly, organizations appear to recognize this. More than half now say they plan to invest in AI security and governance tools post-breach, representing an 88% increase from last year. That shift reflects growing awareness that securing AI requires securing the entire ecosystem around it.”
More IBM findings
- Malicious or criminal attacks accounted for 55% of all data breaches, up almost 8% from last year. These attacks are far more common than breaches caused by IT failures (22%) or human error (23%). Root causes, however, varied by industry. Malicious or criminal attacks were responsible for a little more than half (61%) of breaches in the retail and transportation industries and roughly half of breaches in the healthcare and finance sectors—industries known for storing valuable PII.
- Phishing topped initial attack vectors and led to the costliest breaches. Attackers used impersonation for conducting high-damage data breaches. Voice and SMS phishing, used in 17% of attacks, led to the highest average breach costs among attack vectors, $5.29 million. Social engineering, such as impersonating help desk staff, was used in 13% of attacks and led to average breach costs of $5.23 million.
- Attackers targeted customer PII over other types of data by a wide margin. At 52%, it was the most stolen or compromised data type this year, costing $192 per record on average.
- In most breaches this year, the breached data was stored on premises (30%). That share has crept up from 28% last year and from 20% in 2024. Although many organizations believe on-prem storage is inherently safer, it remains a target because it places the sole responsibility for patching, physical security and access management on the organization’s internal IT staff. It’s where organizations tend to keep their most valuable assets and also where attackers can cause the greatest disruption.
- Among breached organizations, 53% didn’t encrypt sensitive data at rest and in motion at the time of the breach. Another 10% of organizations said they weren’t sure if the data was encrypted. Unencrypted sensitive data enables attackers to gain full, immediate access to genetic, biometric, identity and health-related information.




