Big Launches

AI-driven data breaches hit $5M average cost

 ·  By Isadora Dunmore
AI-driven data breaches hit $5M average cost - ai data breaches
AI-driven data breaches hit $5M average cost

The average cost of a data breach reached $4.99 million in 2026, marking a record high and over a 10% increase from the previous year. The rise stemmed from higher detection and escalation expenses, along with lost business revenue.

AI attacks push breach costs higher

Over a quarter of organizations hit by malicious attacks in the past year reported artificial intelligence played a role. Breaches involving AI cost approximately $1 million more on average than those without it.

Financial services and energy sectors experienced the highest concentration of these attacks.

Attackers are moving faster. A new AI model announced in April 2026 uncovered thousands of high-severity vulnerabilities in major operating systems and web browsers. The time between discovering a flaw and exploiting it has shortened, giving defenders less opportunity to patch systems.

Known exposures stay open longer, and the gap between discovery and exploitation keeps shrinking.

Defenders turn to AI, but gaps remain

Half of the affected organizations used AI agents in their security operations centers, primarily for threat hunting, automated response, and containment. Around 18% employed them for vulnerability scanning, though the report labeled this area as vulnerable to attacks.

Despite these efforts, roughly a third of organizations still avoid automation or AI for front-line prevention tasks. This includes identifying and patching vulnerabilities before attackers strike. Known exposures remain open longer, raising risks.

Security controls are often missing even when AI is in place. Nearly one in five organizations reported incidents involving an AI model or application, up from about one in eight the previous year. Among those cases, 92% lacked role-based access controls, multifactor authentication, or similar protections for their AI systems.

Model inversion—where attackers extract sensitive training data—was the most expensive AI-related incident, averaging $6.07 million. Prompt injection attacks followed. Compromised APIs, cloud misconfigurations, and connected applications were frequent root causes.

Employees using unapproved AI tools contributed to 43% of security incidents, more than double last year’s share. These incidents often led to data loss or operational disruption. More than half of the organizations hit through an AI system reported direct financial loss. Operational disruption and unauthorized access to sensitive data followed, each named by more than four in ten.

Healthcare remains the costliest target

For the 13th consecutive year, healthcare breaches were the most expensive, exceeding the global average. U.S. organizations faced costs over twice as high, with many breaches surpassing $10 million.

Supply chain compromises added more to breach costs than any other factor. These incidents also took the longest to identify and contain, matching cases involving removable media.

Internal security teams discovered about four in ten breaches and resolved them roughly five weeks faster than the global average. Attackers disclosed roughly one in six breaches, and these were the most expensive.

Related: AI safety tests fail to stop secret leaks

Over half of breached organizations had left sensitive data unencrypted at rest and in motion. Another 10% were unsure whether their data was encrypted.

The shift toward AI-driven attacks has led organizations to rethink their defenses.

They are now focusing on vulnerability management, runtime identity security, and integrating fixes into development workflows. The aim is to close the gap between discovery and patching before attackers exploit it.

Suja Viswesan, vice president of IBM Security Software, stated that AI is making attacks faster and cheaper while breaches grow more expensive. She noted that delays between discovery and remediation directly increase costs. The current priority is eliminating that lag.

Organizations using AI and automation across prevention, detection, investigation, and response resolved breaches about two months faster. They also paid nearly $2 million less than those not using these tools.

Challenges persist. Fewer than half of organizations secure the non-human identities their AI workflows rely on. About a quarter have begun post-quantum cryptography projects, but most lack controls to monitor keys, certificates, and algorithms across their systems.

Nearly 70% of breached organizations lack governance policies for managing AI or detecting unapproved use. Fewer than one in five coordinate governance teams with security teams, creating oversight gaps.

Among those aware of new AI model capabilities, 85% plan to increase security spending. This is up from about two-thirds who intended to do so after experiencing a breach. Three-quarters will deploy more AI agents in alert triage, vulnerability management, and penetration testing. The share targeting vulnerability scanning is expected to double.

Recovery times remain slow.

Only 4% of breached organizations fully recovered within seven weeks. About 40% reported complete recovery, an improvement from a third the previous year.

The patch cycle still takes weeks. A model that can read source code finds bugs in an afternoon. The agents meant to close that gap often spend time processing alerts instead.

Recent incidents have shown how quickly vulnerabilities can disrupt operations. Internet outages earlier this year highlighted the risks of delayed responses to security flaws.

Internal security tea

Leave a Comment

Your email address will not be published.