One in Four Malicious Breaches Are Now AI-Enabled: IBM
By Diego Valverde | Journalist & Industry Analyst -
Wed, 07/29/2026 - 10:50
IBM's 2026 Cost of a Data Breach Report finds that one in four malicious cyberattacks now involve AI, driving average breach costs to US$6 million and prompting organizations to increase investment in AI-powered security operations as attackers exploit vulnerabilities faster and at lower cost.
AI is reshaping the economics of cybercrime, making attacks cheaper to launch while significantly increasing the financial impact of data breaches on organizations. According to IBM's 2026 Cost of a Data Breach Report, AI-enabled attacks accounted for one in four malicious breaches worldwide, with organizations facing average losses of US$6 million per incident, roughly US$1 million higher than the global average breach cost of US$4.99 million.
The findings suggest that enterprises are entering a new phase of cybersecurity, where AI is accelerating both offensive and defensive capabilities. While threat actors increasingly use AI-powered malware and deepfake impersonation campaigns to compromise organizations, businesses that have adopted AI and automation within their security operations report substantially lower breach costs.
AI Changes the Economics of Cyberattacks
IBM report reveals that AI-enabled malicious breaches increased 56% compared to the previous year. IBM attributes this rise primarily to the growing use of AI-generated malware and deepfake-based social engineering attacks, which reduce the cost and time required for attackers to execute sophisticated campaigns.
Organizations using AI and automation across their security operations reduced breach costs by nearly US$2 million on average. However, IBM says one in four organizations has yet to deploy these technologies, leaving many businesses exposed as attackers accelerate their capabilities.
"What is changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs," says Suja Viswesan, Vice President, IBM Security Software. Viswesan says organizations should prioritize eliminating delays between identifying vulnerabilities and remediating them by embedding security into development workflows, protecting identities during runtime and addressing risks at the pace attackers now operate.
The report also indicates that organizations are becoming more proactive in response to emerging AI threats. Separate research conducted by Ponemon Institute found that 85% of respondents plan to increase cybersecurity spending after learning about advanced frontier AI cyber capabilities, compared to 64% that reported increasing investment following a data breach.
Despite growing awareness, implementation gaps remain. More than half of organizations report using AI agents for threat detection and incident containment, but only 18% apply AI agents to vulnerability management, allowing known security weaknesses to remain unresolved while AI continues to shorten exploit timelines.
Critical Infrastructure Faces Greater Exposure
Critical infrastructure organizations represented 62% of reported AI-enabled attacks in the study, with financial services and energy emerging as the sectors experiencing the highest concentration of incidents. Financial services organizations reported average breach costs of US$6.3 million, while breaches affecting energy companies averaged US$5.2 million. IBM warns that the concentration of AI-driven attacks across these industries raises the risk of broader disruptions affecting supply chains, economies and essential services.
The report highlights that AI applications themselves are becoming an increasingly attractive target. More than 20% of surveyed organizations reported experiencing a breach involving AI models or applications. Rather than exploiting flaws within the models, attackers most frequently compromised surrounding technologies, including APIs, applications and plug-ins, each accounting for 27% of incidents, alongside cloud misconfigurations affecting AI workloads.
IBM also identifies persistent weaknesses in encryption and cryptographic management despite growing interest in quantum-safe security. Only 37% of breached organizations reported encrypting sensitive data both at rest and in transit, while just 34% said they maintain visibility into their cryptographic assets.
Meanwhile, ransomware continues to evolve alongside AI adoption. Reported ransomware incidents increased to 39% from 34% the previous year, with attackers increasingly using AI to automate and scale operations. Beyond operational disruption, ransomware groups are shifting toward reputational pressure, with 41% of incidents targeting brand reputation, followed by employee data at 35% and intellectual property at 31%.
The 2026 Cost of a Data Breach Report, conducted by Ponemon Institute and sponsored and analyzed by IBM, examined breaches affecting 602 organizations worldwide between March 2025 and February 2026.
A follow-up survey conducted in May 2026 included responses from 456 of those organizations, with 78% reporting awareness of advanced frontier AI models such as Mythos, underscoring how rapidly AI capabilities are influencing cybersecurity strategies and enterprise risk management.


