How AI-enabled attacks cost companies millions

AI is enabling attackers to launch faster, less expensive attacks while organizations face rising breach costs, according to IBM's 2026 data breach study

Processing Content

One in four data breaches were AI-enabled in 2026, a 56% increase from last year, IBM found. As AI lowers the cost and complexity of launching attacks, organizations are seeing increasingly expensive data breaches, potentially driving up claims severity for cyber insurers. According to the study, AI-led attacks cost an average of $6 million and nearly $1 million more than the global breach average.

The study identified the energy industry and financial services — banking, insurance and investment companies — as the two most targeted sectors by attackers. These two sectors accounted for 62% of all AI-driven breaches studied, with breach costs for the financial services industry averaging at $6.29 million. 

Reported ransomware incidents rose from 34% to 39% this year, as attackers increasingly use AI to generate malware and scale their attack methods, the study said. IBM found that 45% of malicious AI attacks were enabled by an AI deepfake or impersonation, 19% by AI-enabled malware and 17% by AI-generated phishing.

"What's changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs," said Suja Viswesan, vice president of IBM Security Software, in a press release. "The priority now is to eliminate that lag — building remediation into development workflows, securing identity at runtime and fixing risks at the speed attackers are already moving."

The study finds that while more than half of organizations use agents for threat detection and containment, only 18% apply agents to vulnerability management. More than 20% experienced a breach targeting their AI models or applications: 27% had compromised APIs, applications or plug-ins and 27% saw cloud misconfigurations affecting AI workloads.

IBM also notes that companies that report using AI and automation in security operations cut breach costs by an average of almost $2 million dollars, though one in four organizations have yet to adopt these types of security tools. The study finds, though, that 85% of organizations shared plans to increase security spending in response to AI model threats, and about 75% said they will deploy agents at higher rates in alert triage, vulnerability management and scans or penetration testing.


For reprint and licensing requests for this article, click here.
Cyber attacks Cyber Security Artificial Intelligence
MORE FROM DIGITAL INSURANCE
Load More