IBM and Ponemon’s 2026 Cost of a Data Breach Report finds global costs hit a record $4.99M as AI-driven attacks surged 56% and added $1M per breach.
The global average cost of a data breach climbed 12% this year to a record USD 4.99 million, according to IBM’s 21st annual Cost of a Data Breach Report, produced in partnership with the Ponemon Institute. The report, subtitled “The AI Tipping Point,” is based on interviews with 3,558 security and business leaders across 602 organizations that experienced breaches between March 2025 and February 2026, spanning 17 industries and 16 countries and regions.
The report’s central finding is that frontier AI models are compressing the gap between vulnerability discovery and exploitation, pushing attackers from human speed to machine speed. IBM points to the April 2026 announcement of a frontier model that found thousands of high-severity vulnerabilities — including flaws in every major operating system and web browser — as a signal of what’s coming for defenders.
Breach Costs Hit Records Across the Board
The global average breach cost of USD 4.99 million works out to roughly USD 1,100 per hour. Detection, escalation, and lost-business costs — including crisis management, disrupted operations, and customer churn — accounted for 63% of total costs this year.
The United States again posted the highest regional costs by far, at a record USD 11.5 million, up 11% year over year and more than double the global average. South Africa saw the largest percentage increase (22%, to USD 3.04 million), while Germany rose 18% to USD 4.93 million and Benelux rose 16% to USD 7.37 million.
By industry, healthcare remained the costliest sector for the 13th consecutive year at USD 6.64 million, though that figure is actually down 10.5% from USD 7.42 million last year. Financial services followed at USD 6.29 million, then industrial and technology (both USD 5.50 million), entertainment (USD 5.38 million), and pharmaceuticals (USD 5.25 million). Communications and entertainment saw the sharpest year-over-year jumps, up 20% and 18% respectively.
Breach lifecycles also got longer: the mean time to identify and contain a breach rose to 247 days, a 2.5% increase that reversed five straight years of improvement, as AI-driven attacks challenge even fast-responding security teams.
AI-Driven Attacks Rose 56%
More than one in four organizations that experienced a malicious attack said it was AI-driven — a 56% increase over last year. Deepfake and impersonation attacks accounted for the largest share of these incidents (45%), followed by AI-enabled malware (19%) and AI-generated phishing or other communications (17%).
These attacks carried a real financial penalty: AI-driven malicious breaches averaged USD 6.04 million, compared with USD 5.03 million for non-AI-driven malicious breaches — a difference of roughly USD 1 million. Financial services and energy organizations bore the brunt, together accounting for 62% of all AI-driven attacks studied, though both sectors also identified and contained breaches about four weeks faster than the global average.
When Attackers Target the AI Itself
Beyond using AI as a weapon, attackers are increasingly targeting the AI models and applications organizations run. Breaches involving an organization’s own AI models or applications grew to 21% of all breaches this year, up from 13% — a 61% increase.
Among organizations that suffered these AI-related breaches, 92% lacked proper AI access controls, and only 40% of organizations overall reported using access controls on AI models and data at all. The costliest incident types were model inversion attacks (averaging USD 6.07 million) and prompt injection attacks (USD 5.89 million), followed by cloud misconfigurations affecting AI workloads (USD 5.25 million), malicious models (USD 4.94 million), and model evasion (USD 4.72 million).
The most common impacts of AI-related breaches were financial loss (51% of organizations), operational disruption (44%), unauthorized access to sensitive data (44%), loss of data integrity (32%), and reputational damage (26%). Notably, breach rates were similar regardless of whether the AI model was open-source, delivered as SaaS by a third-party vendor, or deployed on-premises by a vendor — suggesting the root causes were structural issues like compromised APIs, connected applications, and cloud misconfigurations rather than which model was used.
Shadow AI — employees using AI tools without organizational approval — was involved in 43% of AI-related security incidents this year, more than double last year’s 20%. These incidents were also costlier, averaging USD 5.39 million versus USD 4.63 million last year, and led to data loss or compromise in 49% of cases and operational disruption in 42%.
Governance Is Lagging Adoption
Despite the rising stakes, 68% of breached organizations lacked AI governance policies to manage AI use or detect shadow AI, up from 63% last year. On a more positive note, 33% of organizations said they were actively developing governance policies, up from 22% the year before. Among organizations with governance in place, the most common control was requiring IT approval for AI deployments (38%, though down from 45% last year), followed by governance technology and frameworks (33% each). Only 19% of organizations reported coordination between their governance and security teams.
Ransomware Shifts From Encryption to Extortion
Ransomware hit 39% of breached organizations this year, continuing a four-year climb from 24% in 2023 — a 62.5% increase over that span. While encrypting data and disrupting operations remains common (23% of ransomware attacks), attackers are increasingly weaponizing brand reputation: 41% of ransomware incidents this year involved threats of public shaming or leaking data to the media, making it the single most common extortion tactic. Attackers also expanded their targets to internal communications like Slack messages, cited in 19% of ransomware attacks.
What Actually Reduces Breach Costs
The report identifies AI and automation as the most effective levers for reducing breach costs, though adoption remains uneven. Organizations that used AI and automation extensively in security operations had an average breach cost of USD 4.00 million and identified and contained breaches in 215 days — compared with USD 5.93 million and 280 days for organizations using none. That’s a savings of USD 1.93 million and 65 days for the most advanced adopters. Yet only 36% of organizations qualify as extensive users, and even among those, usage skews toward detection and investigation rather than prevention.
The same pattern holds for agentic AI: among the 50% of breached organizations that deploy AI agents in their security operations center, most use them for threat hunting (56%) and automated response and containment (54%), while only 18% apply agents to vulnerability scanning and management — precisely the area where frontier AI models are proving most capable on the attacker’s side.
Beyond AI, the report’s broader cost-factor analysis found a DevSecOps approach was the single biggest cost reducer, lowering average breach costs by USD 253,805, followed by identity and access management (-USD 225,622) and key lifecycle management tools (-USD 214,923). On the other side, supply chain breaches — where a compromised business partner became the attack vector — were the most expensive amplifying factor, adding USD 227,250 on average, followed by security system complexity (+USD 208,265) and lack of visibility into shadow IT (+USD 201,165).
Other Notable Findings
Just 37% of breached organizations had encrypted their sensitive data at rest and in motion at the time of the breach, while 53% had not and 10% were unsure. Phishing conducted via voice or SMS was the costliest initial attack vector at USD 5.29 million per breach, followed by social engineering such as help-desk impersonation (USD 5.23 million). Malicious or criminal attacks accounted for 55% of all breaches this year, up from 51%, ahead of human error (23%) and IT failures (22%).
On a more encouraging note, 42% of breached organizations reported fully recovering from their breach this year, up from 35% last year and roughly quadruple the 12% recorded in 2024.
Looking ahead, the report found that awareness of frontier AI model capabilities is reshaping security budgets: while 64% of breached organizations said they planned to increase security spending following a breach, that figure jumped to 85% once organizations learned specifically about new frontier AI threats. Three-quarters of organizations said they’re now rethinking where they deploy AI agents in their security operations, with planned increases concentrated in alert triage, penetration testing, and vulnerability scanning — the areas the report identifies as currently underprotected relative to the threat.
The report also flagged newer risk areas gaining attention: only 46% of organizations secure non-human identities (machine and service-account credentials) in their AI workflows, and just 26% have started a post-quantum cryptography project, with 61% lacking controls to monitor and secure cryptographic assets like keys and certificates.