IBM and Ponemon Institute: IBM: AI-Enabled Breaches Cost $6M on Average

IBM and Ponemon Institute: IBM: AI-Enabled Breaches Cost $6M on Average

AI-Enabled Breaches Surge, Costing Organizations $6 Million on Average in 2026

A new IBM study reveals that one in four malicious data breaches in 2026 were AI-enabled, marking a 56% increase from the previous year. These attacks primarily involving deepfake impersonation and AI-driven malware are accelerating breach economics, making attacks faster and cheaper to execute while driving up recovery costs. The average AI-related breach now costs $6 million, nearly $1 million more than the global average of $4.99 million.

The 2026 Cost of a Data Breach Report, conducted by the Ponemon Institute and analyzed by IBM, surveyed 602 organizations worldwide between March 2025 and February 2026. A follow-up study in May 2026 found that 85% of organizations plan to increase security spending in response to advanced AI threats, compared to 64% that would do so after experiencing a breach. Despite this shift, only 18% of organizations use AI-driven agents for vulnerability management, leaving critical gaps in defense as exploit windows shrink.

Critical infrastructure sectors particularly financial services and energy were the most targeted, with 62% of AI-driven attacks directed at these industries. Breaches in financial services averaged $6.3 million, while energy sector incidents cost $5.2 million, raising concerns about systemic economic and supply chain disruptions.

The report also highlights key vulnerabilities in AI systems, with 20% of organizations reporting breaches targeting AI models or applications. The most common attack vectors were compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations (27%). Additionally, encryption gaps persist, with only 37% of breached organizations encrypting sensitive data both at rest and in transit, and just 34% maintaining visibility into cryptographic assets.

Ransomware attacks also rose, accounting for 39% of incidents (up from 34% the prior year), with threat actors increasingly leveraging AI to automate attacks and exploit brand reputation (41%), employee data (35%), and intellectual property (31%).

IBM Security VP Suja Viswesan noted that the growing imbalance between attack costs and breach expenses is reshaping cyber risk, emphasizing the need for faster remediation, runtime identity security, and integrated vulnerability management to match attackers’ speed. The findings underscore the urgency for organizations to adopt AI-driven security tools, as those using automation in security operations reduced breach costs by nearly $2 million yet 25% of organizations still lack these capabilities.

Source: https://www.stocktitan.net/news/IBM/ibm-study-one-in-four-malicious-breaches-are-ai-enabled-costing-4g761ve46nws.html

IBM cybersecurity rating report: https://www.rankiteo.com/company/ibm

Ponemon Institute cybersecurity rating report: https://www.rankiteo.com/company/ponemon-institute

"id": "IBMPON1785321521",
"linkid": "ibm, ponemon-institute",
"type": "Cyber Attack",
"date": "3/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': ['financial services',
                                     'energy',
                                     'critical infrastructure'],
                        'location': 'worldwide',
                        'type': 'organization'}],
 'attack_vector': ['deepfake impersonation',
                   'AI-driven malware',
                   'compromised APIs, applications, or plug-ins',
                   'cloud misconfigurations'],
 'data_breach': {'data_encryption': ['37% encrypted at rest and in transit'],
                 'data_exfiltration': True,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'high',
                 'type_of_data_compromised': ['employee data',
                                              'intellectual property',
                                              'brand reputation data']},
 'date_publicly_disclosed': '2026-05',
 'description': 'A new IBM study reveals that one in four malicious data '
                'breaches in 2026 were AI-enabled, marking a 56% increase from '
                'the previous year. These attacks primarily involving deepfake '
                'impersonation and AI-driven malware are accelerating breach '
                'economics, making attacks faster and cheaper to execute while '
                'driving up recovery costs. The average AI-related breach now '
                'costs $6 million, nearly $1 million more than the global '
                'average of $4.99 million.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'financial_loss': '$6 million (average for AI-related breaches)',
            'identity_theft_risk': True,
            'operational_impact': ['systemic economic disruptions',
                                   'supply chain disruptions'],
            'systems_affected': ['AI models', 'applications', 'cloud systems']},
 'lessons_learned': 'The growing imbalance between attack costs and breach '
                    'expenses is reshaping cyber risk, emphasizing the need '
                    'for faster remediation, runtime identity security, and '
                    'integrated vulnerability management to match attackers’ '
                    'speed.',
 'motivation': ['financial gain',
                'brand reputation exploitation',
                'intellectual property theft'],
 'post_incident_analysis': {'corrective_actions': ['AI-driven security tools',
                                                   'automation in security '
                                                   'operations',
                                                   'improved encryption '
                                                   'practices'],
                            'root_causes': ['AI-driven attack vectors',
                                            'encryption gaps',
                                            'cloud misconfigurations']},
 'ransomware': {'data_encryption': True, 'data_exfiltration': True},
 'recommendations': ['Adopt AI-driven security tools',
                     'Increase security spending',
                     'Use automation in security operations',
                     'Improve encryption practices',
                     'Enhance visibility into cryptographic assets'],
 'references': [{'date_accessed': '2026-05',
                 'source': 'IBM 2026 Cost of a Data Breach Report (Ponemon '
                           'Institute)'}],
 'response': {'remediation_measures': ['AI-driven security tools',
                                       'automation in security operations']},
 'title': 'AI-Enabled Breaches Surge, Costing Organizations $6 Million on '
          'Average in 2026',
 'type': ['AI-enabled breach', 'data breach', 'ransomware'],
 'vulnerability_exploited': ['AI models or applications',
                             'encryption gaps',
                             'cloud misconfigurations']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.