IBM Cost of a Data Breach Report 2026

Traditionally, the IBM and Ponemon Institute Cost of a Data Breach Report reflects current technological changes, new attacker tactics, and cybersecurity trends. In 2026, the main theme of the study was the confrontation between attackers and security teams, who are increasingly using artificial intelligence.

The results show that AI accelerates attacks, helps scale social engineering, and increases the financial impact of incidents. At the same time, the widespread use of AI and automation in cybersecurity significantly reduces response times and lowers the average cost of a breach.

The study covered 602 organizations from 17 industries in 16 countries and regions that suffered data breaches between March 2025 and February 2026.

Key findings from the IBM Cost of a Data Breach Report 2026

The global average cost of a data breach increased by 12% and reached a record $4.99 million.

The bulk of the losses — 63% — came from detection and escalation costs, as well as lost business. These include downtime, operational disruption, crisis management, customer churn, and reputational damage.

The average time to identify and contain a breach increased to 247 days:

  • 183 days – to identify;
  • 64 days – to contain.

This is the first deterioration of this metric after five years of gradual reduction in the breach lifecycle.

Artificial Intelligence as a new risk

The number of AI-powered attacks increased by 56% compared to the previous year. More than a quarter of organizations that experienced a malicious attack reported that the incident was amplified by artificial intelligence.

AI-driven attacks increased the average cost of a malicious breach by approximately $1 million.

The most common types of AI-based attacks were:

  • deepfakes and AI-assisted impersonation – 45%;
  • AI-powered malware – 19%;
  • AI-generated phishing and other messages – 17%.

The number of incidents involving AI models and AI-based applications rose from 13% to 21%. Among organizations affected by such an incident, 92% lacked proper access control for AI systems.

The most expensive types of AI attacks were:

  • model inversion – $6.07 million;
  • prompt injection – $5.89 million;
  • cloud misconfigurations affecting AI workloads – $5.25 million;
  • malicious model usage – $4.94 million;
  • model evasion attack – $4.72 million.

Shadow AI

The share of incidents related to shadow AI – the unauthorized use of AI tools by employees – more than doubled: from 20% to 43%.

The average cost of such incidents reached $5.39 million, compared to $4.63 million the year before.

Most expensive attack vectors

For the fourth consecutive year, phishing remains the most common initial attack vector. Supply chain compromise took second place.

The most expensive initial vectors:

  • voice phishing (vishing) and smishing $5.29 million, 17% of incidents;
  • social engineering, in particular impersonating IT support and MFA – $5.23 million, 13%;
  • abuse of legitimate accounts – $5.07 million;
  • external remote services – $5.11 million;
  • compromise via a malicious web resource – $4.99 million;
  • supply chain compromise – $4.96 million.

Organizations took the longest to identify and contain:

Malicious attacks accounted for 55% of all breaches. Human error caused 23% of incidents, and IT failures – 22%.

The impact of AI and automation on cost reduction

Organizations that extensively used AI and automation in cybersecurity saved an average of $1.93 million per incident.

Extensive use of AI and automation also reduced the time to identify and contain an incident by 65 days.

Despite the financial impact, only 36% of organizations extensively applied AI and automation across the entire cybersecurity lifecycle.

Half of the surveyed organizations reported using AI agents in Security Operations Centers (SOCs). Following news about the new capabilities of an advanced AI model, 74% of organizations revised their plans for using AI agents in SOCs.

Location of compromised data

Recovery after an incident

Only 42% of organizations fully recovered from a data breach. The remaining 58% were still in the process of recovery at the time of the study.

At the same time, this metric improved compared to the previous year, when only 35% of organizations had fully recovered.

For most organizations, recovery took more than 100 days. It included not only technical remediation but also business process restoration, regulatory compliance, regaining customer trust, and implementing additional security controls.

Most expensive industries

For the thirteenth consecutive year, healthcare remains the industry with the highest average cost of a data breach.

Average cost by industry:

  • healthcare – $6.64 million;
  • financial sector – $6.29 million;
  • manufacturing/industrial sector – $5.50 million;
  • technology sector – $5.50 million;
  • entertainment industry – $5.38 million;
  • pharmaceuticals – $5.25 million;
  • energy – $5.24 million;
  • professional services – $5.08 million.

The financial and energy sectors combined were the targets of 62% of all AI-based attacks studied. This concentration creates systemic risk, as the consequences of a successful attack could spread to payment systems, the economy, and critical infrastructure.

Post-quantum cryptography risks

For the first time, the report highlights the approaching era of quantum computing and the risks to modern encryption. Most companies turned out to be unprepared for these challenges:

  • 69% of organizations have no post-quantum cryptography implementation projects;
  • 61% lack controls to monitor and protect cryptographic assets (keys, certificates, algorithms) in their environment.

Key factors influencing incident costs

Top cost-mitigating factors

Top cost-amplifying factors

  • supply chain compromise – +$227,250;
  • security systems complexity – +$208,265;
  • lack of visibility into applications and shadow IT – +$201,165;
  • regulatory non-compliance – +$201,112;
  • improper management of secrets and keys – +$198,933;
  • inability to properly prioritize threats – +$188,172;
  • cybersecurity skills shortage – +$179,635;
  • excessive privileges and improper role management+$177,313.

Conclusion

The IBM 2026 report shows that artificial intelligence has simultaneously become an attack tool, a distinct target for threat actors, and one of the most effective means of reducing the financial impact of breaches.

Separate priorities should include the protection of AI models, controlling shadow AI, the security of non-human identities, data encryption, and reducing the time to identify and contain incidents.

Subscribe to news