According to IBM’s 2026 Cost of a Data Breach Report, one in four malicious breaches was AI-enabled during the 12-month period covered by the report.
The AI-enabled attacks behind these breaches consisted mostly of deepfake impersonation and AI-enabled malware and are reshaping breach economics. Attacks are getting faster and cheaper to launch, while breaches keep getting more expensive to find and fix. However, companies that reported using AI and automation in security operations had breach costs that were, on average, almost $2 million lower.
“What’s changing is the economics of cyber attacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” said Suja Viswesan, VP, IBM Security Software. “The priority now is to eliminate that lag – building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving.”
Critical infrastructure faces higher AI-enabled risk
62% of AI-enabled attacks reported in the study targeted critical infrastructure sectors, with financial services and energy organizations experiencing the highest concentration, raising the risk of broader systemic disruption and cascading impacts.
Other key findings include:
- AI’s weakest link: more than 20% of organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).
- Encryption gaps persist as quantum risk looms: core weaknesses in encryption and cryptographic management continue to expose organizations, even as quantum-safe investments grow. Only 37% of breached organizations stated that they encrypt sensitive data both at rest and in transit, and just 34% have visibility into cryptographic assets.
- Ransomware actors weaponise reputation: reported ransomware incidents rose compared with the previous year (39% vs 34%), with attackers increasingly using AI to automate and scale. While operational disruption still plays a role, attackers are shifting towards higher-impact pressure – most commonly exploiting brand reputation (41%), followed by employee data (35%) and intellectual property (31%).
The research for the 2026 report was conducted by the Ponemon Institute and sponsored and analysed by IBM. It is based on breaches experienced by 602 organizations globally between March 2025 and February 2026.






