IBM found malicious AI-driven attacks increased 56% from last year’s study, with the average breach now costing $6.04 million.
Key Takeaways
- AI-driven attacks added an average of $1.01 million to malicious data breach costs.
- More than 1 in 4 organizations experienced a malicious AI-driven attack, a 56% increase from last year’s study.
- 21% of organizations experienced a breach involving an AI model or application. Of these, 92% did not adequately restrict who could access their AI systems or require an additional identity check.
- Extensive use of AI and automation in security reduced average breach costs by $1.93 million and shortened incidents by 65 days.
IBM found AI-driven attacks added an average of about $1 million to the cost of a malicious data breach, as attackers increasingly used AI to operate faster and at greater scale.
The average cost of a malicious AI-driven attack was $6.04 million, compared with $5.03 million for malicious attacks that did not involve AI.
The 2026 Cost of a Data Breach Report covered 602 organizations that experienced breaches between March 2025 and February 2026. Ponemon Institute conducted 3,558 interviews with executives, security personnel, and other employees familiar with the incidents.
AI-driven attacks increase
More than 1 in 4 organizations experienced a malicious AI-driven attack. That represents a 56% increase from last year’s study.
Deepfake and impersonation attacks accounted for 45% of these incidents. AI-generated phishing and other fraudulent communications accounted for 19%, as did AI-created or modified malicious software.
Financial services and energy companies accounted for a combined 62% of the AI-driven attacks in the study. Average breach costs reached $6.29 million for financial companies and $5.2 million for energy companies.
IBM said generative AI has reduced the time, cost, and technical expertise needed to create impersonation attacks and other attempts to deceive employees.
Breaches targeting AI systems also rise
The report separately examined breaches where attackers targeted an organization’s AI models or applications.
AI-related breaches affected 21% of the organizations studied, up from 13% last year. Among affected organizations, 92% lacked proper security controls over who could access their AI systems.
In 30% of AI-related breaches, attackers compromised software connected to the AI system rather than the model itself. Problems with cloud security settings accounted for 27%.
68% of breached organizations either lacked policies for managing AI or were still developing them. Only 19% said their AI governance and security teams worked together on the rules and protections for AI systems.
Using AI in cybersecurity reduces costs
When looking at all cyber breaches (both AI- and non-AI-driven), IBM found that organizations extensively using AI and automation in security averaged a breach cost of $4 million. Organizations that did not use the technologies averaged $5.93 million, a difference of $1.93 million.
Those extensively using AI as part of their security protocols identified and contained breaches in 215 days, 65 days faster than organizations that did not use security AI and automation.
However, only 36% of the organizations studied used the technologies extensively. Another 39% reported limited use, while 25% did not use AI at all.

