IBM says one in four malicious breaches in its 2026 report were AI-enabled

IBM says one in four malicious breaches in its 2026 report were AI-enabled

IBM's 2026 breach report says AI-enabled attacks now account for one in four malicious breaches and cost $6 million on average.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Jul 30, 2026

IBM's latest Cost of a Data Breach findings put a sharper number on a concern security teams have been tracking all year: artificial intelligence is now showing up inside real breach activity, not just in forecasts about future attacker behavior.

In a July 29 newsroom release summarizing the 2026 report, IBM said one in four malicious breaches in its study were AI-enabled, up 56% from the prior year. The company also said those incidents cost affected organizations an average of $6 million, compared with a global breach average of $4.99 million.

Why the findings matter

The report's headline is less about a single attack technique than about economics. IBM attributes much of the AI-enabled activity to deepfake impersonation and AI-assisted malware, which can make social engineering and malicious code development faster and cheaper for attackers. On the defensive side, IBM said companies using AI and automation in security operations reduced breach costs by almost $2 million on average, while roughly one in four organizations still had not adopted those tools.

The research also points to a widening operational gap. More than half of organizations reported using agents for threat detection and containment, according to IBM, but only 18% applied agents to vulnerability management. That leaves known exposures sitting in environments while attackers can move more quickly from discovery to exploitation.

Critical infrastructure pressure

IBM said 62% of the AI-driven attacks reported in the study targeted critical infrastructure sectors. Financial services and energy were highlighted as the sectors with the highest concentration, with average breach costs of $6.3 million and $5.2 million respectively. That matters because disruption in those sectors can cascade into payments, supply chains, fuel, utilities, and other essential services.

The study also found that more than 20% of organizations reported breaches targeting AI models or applications. IBM said the most common causes were not exotic model failures, but weaknesses around them: compromised APIs, applications, plug-ins, and cloud misconfigurations affecting AI workloads.

IBM said the 2026 report, conducted by Ponemon Institute and sponsored and analyzed by IBM, is based on breaches at 602 organizations globally between March 2025 and February 2026. A follow-on May 2026 survey asked 456 of those organizations about frontier AI cyber capabilities and security spending plans.

Sources

Cover image: torkildr, source, licensed under BY-SA.

Comments (0)

Leave a Comment

Loading comments...