TL;DR · 30-second read
The Short Version
Criminals used artificial intelligence in about one in four serious hacking attacks last year, according to a yearly study backed by IBM. Many of those attacks used fake videos or voices to impersonate real people.
Each of those attacks cost the victim about $6 million to deal with, roughly $1 million more than a typical break-in. Launching one can cost the attacker only thousands.
The surprise: about half of companies use automated tools to spot attacks, but fewer than one in five use them to fix known weak spots before criminals get there.
IBM said on July 29, 2026 that one in four malicious breaches in its 2026 Cost of a Data Breach Report were AI-enabled, which it described as a 56% increase over last year. Those breaches, mostly deepfake impersonation and AI-enabled malware, cost an average of $6 million, roughly $1 million more than the $4.99 million global average across all breaches in the study.
The report, conducted by Ponemon Institute and sponsored and analyzed by IBM, covers breaches at 602 organizations worldwide between March 2025 and February 2026. A follow-on survey in May 2026 drew responses from 456 of those organizations.
Executive Summary
The headline number is the cost premium. By IBM’s account, AI-enabled breaches cost about 20% more than the average breach, while the attacks themselves are getting cheaper and faster to launch. IBM frames this as a shift in the economics of cyber risk: attacks that cost thousands to mount now produce losses in the millions.
The more useful finding for security and infrastructure teams sits further down. More than half of organizations use AI agents, meaning software that can take actions on its own, to detect and contain threats. Only 18% use them for vulnerability management, the work of finding and fixing known flaws. IBM ties breach costs directly to the lag between discovering a problem and fixing it.
The report also finds that more than 20% of organizations had a breach aimed at their AI models or applications. The most common causes were not exotic attacks on the models but ordinary weaknesses around them: exposed APIs and plug-ins, and misconfigured cloud environments running AI workloads.
Thousands to Launch, Millions to Clean Up
IBM’s central argument is that AI has widened a cost asymmetry that already favored attackers. Deepfake impersonation, in which synthetic audio or video of a real executive or colleague is used to trick staff into sending money or granting access, costs little to produce. AI-enabled malware can be adapted and scaled with less human effort. On the other side of the ledger, IBM puts the average AI-enabled breach at $6 million, against a global average of $4.99 million.
That premium deserves careful reading. The release says AI-driven attacks were concentrated in financial services and energy, where average breach costs were $6.3 million and $5.2 million respectively. Some of the $1 million gap may therefore reflect which industries AI-enabled attackers targeted rather than anything intrinsic to AI-enabled techniques. The release does not say whether IBM controlled for sector or company size, so the premium is best treated as an observed average, not a measured effect of AI.
The 56% increase is also stated without its base. Readers can infer that AI-enabled breaches were a meaningfully smaller share of the total a year earlier, but the release does not give last year’s figure.
Finding Is Automated. Fixing Is Not.
This is where the report’s numbers point to an operational conclusion. More than 50% of organizations reported using AI agents for threat detection and containment. Only 18% apply them to vulnerability management. In practice, many security teams have automated the alarm but not the repair: they can see an intrusion faster, but the known software flaws and misconfigurations that let attackers in are still patched on human timelines.
IBM argues that this gap matters more as AI shortens exploit windows, the time between a weakness becoming known and attackers using it. Suja Viswesan, VP of IBM Security Software, put it directly: “When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs.” IBM’s stated priority is to build remediation into development workflows and secure identity at runtime.
The report’s other findings fit the same pattern of known, fixable exposure. Only 37% of breached organizations encrypt sensitive data both at rest and in transit, and just 34% have visibility into their cryptographic assets. The leading causes of AI-model breaches, compromised APIs and cloud misconfigurations, are well-understood problem classes rather than novel ones. Organizations using AI and automation in security operations cut breach costs by almost $2 million on average, per IBM, yet one in four have not adopted them at all. The release does not isolate the cost of slow remediation as a single number, so this conclusion rests on the deployment gap and the pattern of causes rather than a direct measurement. It is nonetheless the clearest reading of the data IBM published.
AI Workloads Get Breached Through the Plumbing
For data center and cloud operators, the most relevant statistic is that more than 20% of organizations reported a breach targeting AI models or applications. The two leading causes tied at 27% each: compromised APIs, applications or plug-ins, and cloud misconfigurations affecting AI workloads. APIs are the interfaces that let software systems talk to each other, and plug-ins extend what an AI application can reach. Both widen the surface an attacker can probe.
This shifts attention away from attacks on model internals and toward the infrastructure surrounding them. AI workloads tend to sit in cloud environments with broad data access, many service connections and fast-changing configurations. Responsibility for those settings is typically split between the provider and the customer. When the weak point is a permissive storage setting or an unauthenticated endpoint, the fix is configuration discipline and access control, not a new class of AI security product.
Critical Infrastructure and a Shift in Spending Intent
IBM reports that 62% of AI-driven attacks targeted critical infrastructure sectors, with financial services and energy most affected. The company warns of cascading effects across supply chains and essential services. Energy is directly relevant to the AI buildout, since utilities and grid operators are central to powering new data center capacity. The release does not break down attacks on energy by subsector or describe any operational disruption.
The follow-on research suggests awareness of advanced AI capabilities is moving budgets more than breaches do. Among surveyed organizations, 85% said they plan to increase security spending after learning about frontier AI cyber capabilities, compared with 64% that planned increases after experiencing a breach. These are stated intentions, not committed budgets, and 78% of follow-on respondents were aware of reports about frontier models such as Mythos. Three quarters said frontier AI threats are prompting them to rethink how agents are deployed across security operations. That suggests the remediation gap is recognized, even if it has not yet closed.
Background
The Cost of a Data Breach Report is a long-running annual benchmark produced by Ponemon Institute, a privacy and security research firm, and sponsored and analyzed by IBM. It surveys organizations that suffered breaches and estimates the full cost of each incident, including detection, containment, notification, lost business and recovery. Security leaders and insurers widely cite its averages when setting budgets and pricing risk.
The 2026 edition is the first in which AI appears across nearly every finding. It covers AI as an attack tool through deepfakes and malware, as a defensive tool through agents and automation, and as a target through breaches of AI models and the cloud systems that host them. IBM is a hybrid cloud, AI and consulting company that also sells security software and services. Source: IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average, IBM Newsroom’s July 29, 2026 announcement of its 2026 Cost of a Data Breach Report findings.Sources

