IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average
| Source: IBM Newsroom AI
Tags: IBM, cybersecurity, AI attacks, data breach, deepfakes, enterprise security, AI malware
IBM's 2026 Cost of Data Breach Report finds 25% of malicious breaches are now AI-enabled — a 56% jump year-over-year — costing an average $6M each, $1M above the global average, with deepfake impersonation and AI malware as the dominant attack vectors.
Details
IBM's annual breach cost study, drawing on Ponemon Institute research, documents the growing financialization of AI-powered attacks. One in four malicious breaches now involves AI tools — primarily deepfake impersonation and AI-enabled malware — up 56% from the prior year. The $6M average breach cost for AI-enabled attacks is approximately $1M above the global average of $4.99M.\n\nThe report identifies a meaningful defense asymmetry: companies that deployed AI and automation in their security operations cut breach costs by nearly $2M on average. Yet one in four organizations still have not adopted these tools. The cost gap between defenders who use AI and those who do not is widening as attack speed and complexity both increase.\n\nCritical infrastructure sectors absorbed the highest concentration of AI-driven attacks (62% of cases), with financial services ($6.3M average) and energy ($5.2M average) facing the highest per-breach costs. Separately, Ponemon follow-on research found that 85% of organizations plan to increase security spending after learning about frontier AI cyber capabilities — significantly above the 64% who planned increased spending after an actual breach. More than 20% of organizations reported a breach specifically targeting AI models or applications, establishing AI infrastructure itself as an actively exploited attack surface.