IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average
Rhea-AI Summary
IBM (NYSE:IBM) released findings from its 2026 Cost of a Data Breach Report showing that one in four malicious breaches were AI-enabled, a 56% increase year over year. These AI-driven incidents, largely deepfake impersonation and AI-enabled malware, cost companies an average of $6 million, about $1 million above the global average breach cost of $4.99 million.
According to IBM, organizations using AI and automation in security operations reduced breach costs by nearly $2 million on average, yet 25% have not adopted these tools. Most AI-driven attacks targeted critical infrastructure sectors (62%), with financial services breaches averaging $6.3 million and energy sector breaches $5.2 million. Over 20% of organizations reported breaches targeting AI models or applications, often due to compromised APIs, plugins, and cloud misconfigurations, while encryption and cryptographic visibility remain limited.
Positive
- None.
Negative
- None.
Key Figures
Previous AI Reports
| Date | Event | Sentiment | 24h Move | Catalyst |
|---|---|---|---|---|
| Jul 09 | AI platform upgrade | Positive | -2.2% | Multi-agent development upgrades and specialized modernization workflows were announced. |
| Jul 08 | AI security launch | Positive | -1.3% | IBM and Red Hat launched Lightwell for open-source software risk remediation. |
| Jun 22 | Cybersecurity partnership | Positive | +5.0% | IBM joined OpenAI's cyber partner program and launched managed application security services. |
| Jun 22 | AI platform partnership | Positive | +1.3% | IBM and Wimbledon announced new watsonx AI-powered fan and digital platform features. |
| Jun 17 | AI risk study | Negative | -3.1% | IBM reported enterprise AI control, dependency, sovereignty, and disruption vulnerabilities. |
24h Move is the share-price change in the day after each event; other market factors may also have contributed.
IBM's AI-tagged news produced three aligned and two divergent reactions, with an average move of -0.08%.
Key Terms
deepfake impersonation technical
ai-enabled malware technical
vulnerability management technical
cloud misconfigurations technical
cryptographic assets technical
ransomware technical
AI-generated analysis. How Rhea-AI works. Not financial advice.
More than
These attacks, compromised of mostly deepfake impersonation and AI-enabled malware, are reshaping breach economics. Attacks are getting faster and cheaper to launch, while breaches keep getting more expensive to find and fix. Companies that reported using AI and automation in security operations cut breach costs by an average of almost
This growing imbalance—where attacks can be launched for thousands while breaches cost millions—is fundamentally changing the economics of cyber risk.
Frontier AI Threats Driving Earlier Action
Organizations are starting to act on future risk, rather than waiting for an incident. In separate follow-on research conducted by Ponemon Institute,
But a gap remains where attackers are moving fastest. While more than
"What's changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs," said Suja Viswesan, VP, IBM Security Software. "The priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving."
Critical Infrastructure Face Higher AI-Driven Risk
Most AI-driven attacks reported in the study targeted critical infrastructure sectors (
Other Key Findings:
- AI's Weakest Link. More than
20% of organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27% ) and cloud misconfigurations affecting AI workloads (27% ). - Encryption Gaps Persist as Quantum Risk Looms. Core weaknesses in encryption and cryptographic management continue to expose organizations, even as quantum-safe investments grow. Only
37% of breached organizations stated that they encrypt sensitive data both at rest and in transit, and just34% have visibility into cryptographic assets. - Ransomware Actors Weaponize Reputation. Reported ransomware incidents rose compared to the year prior (
39% vs.34% ), with attackers increasingly using AI to automate and scale. While operational disruption still plays a role, attackers are shifting toward higher-impact pressure—most commonly exploiting brand reputation (41% ), followed by employee data (35% ) and intellectual property (31% ).
The 2026 report, conducted by Ponemon Institute and sponsored and analyzed by IBM, is based on breaches experienced by 602 organizations globally between March 2025 and February 2026. The follow-on study was conducted in May 2026, where 456 organizations of the 602 from the CODB research responded. Of these organizations,
Additional Resources
- Download the full report.
- Register for the webinar.
- Schedule a briefing with IBM experts.
- Understand your AI Cyber Resilience.
About IBM
IBM (NYSE: IBM) is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity and service. Visit www.ibm.com for more information.
Media Contact
IBM
Michele Brancati
mbrancati@ibm.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-study-one-in-four-malicious-breaches-are-ai-enabled-costing-companies-6-million-on-average-302837049.html
SOURCE IBM