Skip to content
Menu
Menu

AI-Driven Attacks Add $1 Million to Data Breach Costs

IBM found malicious AI-driven attacks increased 56% from last year’s study, with the average breach now costing $6.04 million.

 

Key Takeaways

  • AI-driven attacks added an average of $1.01 million to malicious data breach costs.
  • More than 1 in 4 organizations experienced a malicious AI-driven attack, a 56% increase from last year’s study.
  • 21% of organizations experienced a breach involving an AI model or application.  Of these, 92% did not adequately restrict who could access their AI systems or require an additional identity check.
  • Extensive use of AI and automation in security reduced average breach costs by $1.93 million and shortened incidents by 65 days.

IBM found AI-driven attacks added an average of about $1 million to the cost of a malicious data breach, as attackers increasingly used AI to operate faster and at greater scale.

The average cost of a malicious AI-driven attack was $6.04 million, compared with $5.03 million for malicious attacks that did not involve AI.

The 2026 Cost of a Data Breach Report covered 602 organizations that experienced breaches between March 2025 and February 2026. Ponemon Institute conducted 3,558 interviews with executives, security personnel, and other employees familiar with the incidents.

AI-driven attacks increase

More than 1 in 4 organizations experienced a malicious AI-driven attack. That represents a 56% increase from last year’s study.

Deepfake and impersonation attacks accounted for 45% of these incidents. AI-generated phishing and other fraudulent communications accounted for 19%, as did AI-created or modified malicious software.

Financial services and energy companies accounted for a combined 62% of the AI-driven attacks in the study. Average breach costs reached $6.29 million for financial companies and $5.2 million for energy companies.

IBM said generative AI has reduced the time, cost, and technical expertise needed to create impersonation attacks and other attempts to deceive employees.

Breaches targeting AI systems also rise

The report separately examined breaches where attackers targeted an organization’s AI models or applications.

AI-related breaches affected 21% of the organizations studied, up from 13% last year. Among affected organizations, 92% lacked proper security controls over who could access their AI systems.

In 30% of AI-related breaches, attackers compromised software connected to the AI system rather than the model itself. Problems with cloud security settings accounted for 27%.

68% of breached organizations either lacked policies for managing AI or were still developing them. Only 19% said their AI governance and security teams worked together on the rules and protections for AI systems.

Using AI in cybersecurity reduces costs

When looking at all cyber breaches (both AI- and non-AI-driven), IBM found that organizations extensively using AI and automation in security averaged a breach cost of $4 million. Organizations that did not use the technologies averaged $5.93 million, a difference of $1.93 million.

Those extensively using AI as part of their security protocols identified and contained breaches in 215 days, 65 days faster than organizations that did not use security AI and automation.

However, only 36% of the organizations studied used the technologies extensively. Another 39% reported limited use, while 25% did not use AI at all.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!