Skip to content

Illustration by iStock; Security Management

Threat Actors Embrace AI, Helping Push the Average Cost of a Data Breach to $6 Million

Threat actors used artificial intelligence (AI) to carry out one in four data breaches in the past year, a 56 percent increase from 2025 figures, according to new research published today.

IBM’s 2026 Cost of a Data Breach Report assessed that threat actors are using deepfake impersonation and AI-enabled malware to breach their targets, who are in turn increasingly deploying AI to automate their security operations. This confluence of technology is raising the average cost of a data breach to $6 million per incident—up from the $4.99 million average of a year ago.

Despite many organizations investing in technology solutions to speed up detection of suspicious activity, it still took them a mean time of 247 days to identify and contain a breach—six days longer than the mean time of IBM’s 2025 analysis.

“What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive,” said Suja Viswesan, vice president, IBM Security Software, in a statement. “When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs. The priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving.”

While the global average cost of a data breach is now $6 million, for U.S. companies the average price tag is a whopping $11.5 million—an 11 percent increase from 2025 figures—due to higher regulatory fines and higher business costs.

“Meanwhile, South Africa saw the largest percentage increase in average breach costs (22 percent), even though the actual cost ($3.04 million) was lower than in other regions,” according to the report. “Average breach costs also rose in Germany (up 18 percent to $4.93 million) and Benelux (up 16 percent to $7.37 million).”

IBM studied 602 organizations impacted by data breaches between March 2025 through February 2026, including organizations across 17 industries, in 16 countries and regions, and breaches that ranged from 2,590 to 115,380 compromised records. The years referenced in this article refer to the publication date of the IBM annual report, not the year the breach occurred.

Attack Trends and Tactics

Attackers are using impersonation techniques to carry out the most high-damage data breaches. IBM assessed that threat actors used voice and SMS phishing in 17 percent of attacks, which cost an average of $5.29 million. They also used social engineering, like impersonating help desk staff, in 13 percent of attacks that cost an average of $5.23 million.

“In nearly 10 percent of data breaches, attackers illicitly replicated data on removable media, showing that even in the age of cloud computing and AI, it’s important not to overlook these decades-old threat vectors,” the report said. “Sometimes data still walks out the door on a thumb drive.”

Breaches where attackers used removable media also took the longest to contain since these intrusions aren’t picked up by malware scans or inbound traffic screening (258 days, compared to the 247 mean time).

On the flip-side, attackers are also embracing generative AI to create cheap and difficult to detect social engineering attacks (45 percent of attacks) to trick users and bypass security controls. They are also using AI-generated malware (19 percent of attacks) and targeting financial services and energy organizations (62 percent of attack targets).

“The concentration of AI-driven attacks on these sectors, or on a single organization in one of these sectors, is concerning,” according to the report. “A successful attack can cascade into broader impacts across consumer finances, economic systems, and power grids.”

Attackers are still most likely to use their access to steal customer personally identifiable information (PII). Fifty-two percent of the breaches IBM reviewed involved compromised customer data. Attackers also picked up employee PII data in 35 percent of attacks and took intellectual property in 32 percent of breaches.

During the past year, the EU and other regions have made a significant push to embrace the principle of data sovereignty. IBM identified that a greater share of breaches (30 percent, compared to 28 percent in 2025) now involve data stored on premises (on prem) than in any other location.

“Although many organizations believe on-prem storage is inherently safer, it remains a target because it places the sole responsibility for patching, physical security, and access management on the organization’s internal IT staff,” the report explained. “It’s where organizations tend to keep their most valuable assets and also where attackers can cause the greatest disruption.”

Yet on-prem breaches had the lowest average breach cost ($4.56 million, an increase of 12 percent from 2025), compared to public cloud ($5.38 million) and data stored in a combination of on-prem, private cloud, and public cloud storage ($5.39 million).

Wanted: Controls and Governance

Almost all organizations that reported an AI-related breach—92 percent—lacked proper AI access controls. Just 40 percent of organizations reported using access controls at all on AI models and data, which IBM said created a predictable outcome of “expanded attack paths, higher financial impact, and incidents driven by basic enforcement gaps that don’t even require attacker sophistication.”

Most organizations (53 percent) also failed to encrypt their sensitive data at rest and in motion. Another 10 percent of organizations said they were unsure if their data was encrypted.

“Unencrypted sensitive data enables attackers to gain full, immediate access to genetic, biometric, identity, and health-related information,” the report explained. “Under certain regulations, exposing this data is considered a severe risk to an individual’s and organization’s rights, and a violation of the foundational components of digital sovereignty.”

The 2026 report flagged that, similar to 2025, AI oversight is not keeping pace with its adoption. More organizations reported that they did not have AI governance to manage AI or detect shadow AI (68 percent compared to 63 percent in 2025); only 38 percent said they required IT approval before AI was deployed, a marked decrease from 45 percent in 2025.

“One organizational challenge we studied for the first time this year involved coordinating among governance and security teams,” the report explained. “Only 19 percent of organizations reported they coordinated these efforts. That lack of collaboration could lead to blind spots, policy conflicts, and slower response times to security incidents.”

To learn more about how the cost of a data breach has changed, revisit Security Management’s coverage of the 2025 and 2024 IBM reports.

arrow_upward