Skip to content

IBM report: Data breaches to cost $6 million on average in 2026 — AI drives the increase

Auf den Punkt: According to the 2026 IBM-Ponemon report, the average cost of a data breach rose to $6 million, with a quarter of malicious attacks being AI-powered and only 40 percent of organizations securing their AI models with access controls.

The current “Cost of a Data Breach” report by IBM and the Ponemon Institute puts the average cost of a data breach for the period March 2025 to February 2026 at $6 million US dollars – an increase of 35 percent compared to $4.44 million the previous year. The study identifies AI-powered attacks as a key cost driver.

The study is based on an analysis of data breaches at 600 organizations worldwide. According to the findings, one in four malicious data breaches was AI-powered, with deepfake identity fraud and AI-enabled malware accounting for the majority of these attacks. At the same time, the report shows an opposing trend: the use of AI and automation in security operations reduced the cost of data breaches by an average of almost $2 million. Nevertheless, according to the survey, one in four organizations has not yet integrated these tools into its security operations. In a follow-up study, more than half of organizations stated that they use agents for threat detection and containment, but only 18 percent for vulnerability management. Three out of four surveyed companies said frontier AI threats are prompting them to rethink the use of agents in their security operations.

Suja Viswesan, VP of IBM Security Software, sums up the dynamic: AI is making attacks faster and cheaper, while data breaches are simultaneously becoming more expensive. Given the large time gap between the discovery and remediation of an incident, this imbalance is directly reflected in costs.

A separate finding concerns attacks on AI models themselves: one in five organizations reported a data breach specifically targeting AI models or applications. The most common causes were vulnerabilities in surrounding systems – compromised APIs, applications or plug-ins (27 percent) as well as cloud misconfigurations affecting AI workloads (27 percent). The vast majority of affected organizations did not have adequate access controls in place; overall, only 40 percent used any access controls at all for their AI models and data. Kayne McGladrey, Senior Member of the IEEE and former CISO of Hyperproof, describes improving access controls as the most obvious security gap that needs to be closed: models and their APIs should be treated like crown jewels. Udaya Bhaskar Vemuri, Senior Application Security Analyst, adds that organizations should also review integrations and plug-ins, monitor for unusual activity, protect sensitive data, and designate a clearly defined owner for each AI system.

In addition to deepfakes and AI malware, the report finds that AI-powered phishing and direct attacks on AI models, such as prompt injection, are also becoming costly blind spots for companies. Dray Agha, Senior Manager Security Operations at Huntress, points out that the threat does not only come from outside: unauthorized use of AI applications by employees creates uncontrolled vulnerabilities within corporate environments. CISOs need to move toward proactive governance, embed security into development workflows, consistently manage attack surfaces, and enforce strict access controls for AI workloads.

Peter Garraghan, CSO and founder of AI security testing company Mindgard, warns against blindly trusting the effectiveness of AI security guardrails. Research has shown that existing guardrails have various blind spots and that a defense-in-depth approach is required. Since attackers continuously adapt, organizations must continuously test their AI models and applications against realistic adversarial attacks to identify weaknesses in their protective mechanisms. By validating guardrails before and during deployment, CISOs can ensure that AI systems are robust enough to protect sensitive data.


Source: www.csoonline.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: