IBM recently released its Cost of a Data Breach Report 2026, which highlights the changing cyber threat landscape in which artificial intelligence (AI) is accelerating how threat actors identify vulnerabilities, launch attacks, and exploit compromised systems. These trends are reflected in rising average breach costs, with the global average cost rising 12% to a record $4.99 million and the U.S. average reaching $11.5 million, up 14% from last year. Drawing on a survey of 602 organizations that experienced a data security incident between March 2025 and February 2026, the report’s findings underscore the growing financial impact of both AI-driven and traditional cyber threats.
AI Is Reshaping the Threat Landscape
The report found that AI-driven attacks accounted for one-quarter of malicious cyber incidents, representing a 56% increase from the prior year. Deepfake impersonation attacks represented the largest share, followed by AI-enabled malware and AI-generated phishing campaigns.
AI-driven attacks cost organizations approximately $1 million more per breach than traditional malicious attacks. As threat actors automate reconnaissance and scale social engineering, organizations may have less time to detect and contain incidents before significant harm occurs.
The report also highlights increased targeting of AI systems themselves. Incidents involving AI models and applications increased to 21% from 13% year-over-year, with model inversion and prompt injection among the costliest AI-related breaches. These attacks target the AI environment directly by attempting to extract sensitive information from model outputs or manipulate AI applications into disclosing data.
Traditional Attack Vectors Continue to Drive Costly Incidents
Although AI is reshaping the threat landscape, traditional attack methods remain effective. For the fourth consecutive year, phishing was the most common initial attack vector, with voice phishing and SMS phishing generating the highest average breach costs.
Ransomware also remains a significant concern. IBM found that 39% of organizations surveyed experienced ransomware incidents, and in 41% of those incidents, attackers threatened public disclosure of stolen data, media exposure, or other reputational harm.
Customer personally identifiable information remained the most commonly compromised data type, appearing in 52% of breaches surveyed. Healthcare and financial services continued to experience among the highest breach costs.
AI Governance and Security Automation Are Critical to Managing Risk
The report indicates that while organizations are adopting AI faster than they are governing it, those that deploy AI and automation effectively in security operations are better positioned to reduce breach costs and response times.
IBM reported that 68% of breached organizations lacked policies to oversee AI use or manage shadow AI, and 92% of organizations experiencing AI-related breaches lacked adequate AI access controls. Many AI-related breaches stemmed from weaknesses in surrounding controls, including cloud misconfigurations, compromised APIs, insufficient access controls, and inadequate oversight of connected applications. In addition, incidents involving unauthorized employee use of AI tools more than doubled from the prior year, frequently resulting in data compromise, operational disruption, and reputational harm.
At the same time, IBM found that security AI and automation remain among the most effective cost-reduction tools available to organizations responding to cyber incidents. Organizations that extensively deployed AI and automation across security operations reduced average breach costs by approximately $1.93 million and identified and contained breaches approximately 65 days faster than organizations that did not use these technologies.
Recommendations
In light of these findings, the report recommends organizations to consider the following:
- Expanding the use of AI and agentic tools across security operations, including vulnerability management, threat detection, and containment, to keep pace with emerging AI-enabled threats.
- Strengthening identity security through continuous, risk-based verification for both human users and non-human identities.
- Enhancing AI governance and oversight to maintain greater control over how AI systems operate, process data, and interact with users, applications, and cloud environments.
- Preparing for post-quantum security risks by improving encryption practices, cryptography management, and crypto-agility.
As threat actors increasingly leverage AI, organizations’ cyber resilience will depend on both security fundamentals and a comprehensive strategy for identifying, managing, and mitigating enterprise AI risk.