More than one in four organizations hit by a malicious cyberattack in the past year said artificial intelligence drove the attack, and those AI-driven breaches cost roughly $1 million more on average than malicious attacks without AI involved, according to IBM's 2026 Cost of a Data Breach Report.

The Ponemon Institute, which conducted the research for IBM, interviewed staff at more than 600 organizations breached between March 2025 and February 2026. The average data breach cost reached $4.99 million globally, a record and an increase of more than a tenth over the prior year. Breaches at US organizations averaged more than double the global figure. Healthcare remained the costliest industry for a thirteenth consecutive year.

Roughly one in five organizations reported a security incident involving an AI model or application, up from about one in eight a year earlier. Among those, 92% were missing basic controls such as role-based access and multifactor authentication on their AI systems. Model inversion attacks, in which an attacker extracts sensitive training data from a model, produced the costliest AI-related incidents at $6.07 million on average, followed by prompt injection.

Deepfake impersonation accounted for close to half of all AI-driven attacks, and AI-generated malware made up about a fifth. Mean time to identify and contain a breach rose to 247 days, reversing five consecutive years of decline. Close to seven in ten breached organizations reported lacking governance policies to manage AI use or detect unapproved tools.

Source: Help Net Security - https://www.helpnetsecurity.com/2026/07/30/ibm-cost-of-a-data-breach-2026/