
IBM's 2026 Cost of a Data Breach Report reveals that AI-enabled breaches have surged 56% year-over-year, now comprising one in four malicious incidents and costing an average of $6 million(約9.6億円) per breach—$1 million(約1.6億円) above the global average. The threat is reshaping cybersecurity economics: attackers can launch strikes for thousands of dollars while defense and remediation consume millions. Organizations deploying AI in their security operations cut costs by nearly $2 million(約3.2億円) on average, but a critical gap remains: most lack AI tools for vulnerability management, leaving known exposures vulnerable as attack windows shrink.
Summaries like this, in your inbox every morning.
Sign up free →What happened
One in four malicious breaches were AI-enabled in 2026, a 56% increase over the prior year, costing companies an average of $6 million(約9.6億円)—roughly $1 million(約1.6億円) more than the global breach average of $4.99 million(約8億円), according to IBM's 2026 Cost of a Data Breach Report. More than 20% of organizations reported a breach targeting AI models or applications directly.
Why it matters
Attacks are becoming faster and cheaper to launch while breaches grow more expensive to find and fix, fundamentally shifting cyber-risk economics. Yet companies using AI and automation in security operations cut breach costs by an average of almost $2 million(約3.2億円), suggesting a widening gap between those prepared and those not. Critical infrastructure sectors—especially financial services (average $6.3 million(約10億円) per breach) and energy ($5.2 million(約8.3億円))—face the highest concentration of AI-driven attacks, raising the risk of cascading disruption across economies and supply chains.
What to watch
Only 18% of organizations apply AI agents to vulnerability management, even though more than 50% use them for threat detection, leaving known exposures unpatched. Meanwhile, 85% of organizations plan to increase security spending after learning about advanced frontier AI capabilities (compared to 64% who increase spending only after experiencing a breach), signaling a shift toward proactive rather than reactive investment.
IBM's 2026 Cost of a Data Breach Report, conducted by Ponemon Institute and based on breaches at 602 organizations globally between March 2025 and February 2026, documents a sharp rise in AI-enabled attacks and their financial toll. One in four malicious breaches were now AI-enabled, representing a 56% increase over the prior year, with an average cost of $6 million(約9.6億円) per breach—approximately $1 million(約1.6億円) more than the global breach average of $4.99 million(約8億円). These attacks are primarily comprised of deepfake impersonation and AI-enabled malware, which are reshaping the economics of cyber risk by making attacks faster and cheaper to launch while breaches become more expensive to find and fix.
More than 20% of organizations reported breaches targeting AI models or applications directly. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%). A separate follow-on study by Ponemon Institute, conducted in May 2026 with 456 organizations from the original breach research, found that 78% (356 organizations) were aware of recent reports about highly advanced frontier models such as Mythos, and this awareness is driving behavioral change. Eighty-five percent of those aware said they plan to increase security spending after learning of advanced frontier AI cyber capabilities—compared to just 64% who reported plans to increase spending after experiencing a breach.
Critical infrastructure sectors face the highest concentration of AI-driven attacks (62% of reported incidents), with financial services and energy organizations hit hardest. Financial services breaches cost an average of $6.3 million(約10億円), while energy breaches cost an average of $5.2 million(約8.3億円). This concentration raises the risk of cascading impacts across economies, supply chains, and essential services. However, organizations that have deployed AI and automation in their security operations are seeing measurable benefits: these companies cut breach costs by an average of almost $2 million(約3.2億円). Yet adoption remains incomplete. While more than 50% of organizations reported using AI agents for threat detection and containment, only 18% apply agents to vulnerability management, leaving known exposures to persist even as AI shortens exploit windows. Three quarters of organizations say frontier AI threats are prompting them to rethink how agents are deployed across their security operations. Suja Viswesan, VP of IBM Security Software, noted that "the priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving."
The 2026 Cost of a Data Breach Report, based on breaches experienced by 602 organizations globally between March 2025 and February 2026, reveals a fundamental inversion in cybersecurity economics. While traditional breaches cost $4.99 million(約8億円) on average, AI-enabled attacks—which jumped 56% year-over-year—now average $6 million(約9.6億円), driven primarily by deepfake impersonation and AI-enabled malware. The underlying issue is asymmetry: attackers can launch strikes for thousands of dollars, but organizations must spend millions to detect and remediate them.
A critical finding is that organizations are aware of this shift but slow to act. Eighty-five percent say they plan to increase security spending after learning about frontier AI capabilities, yet adoption of AI-based defenses remains spotty. More than 50% of organizations use AI agents for threat detection and containment, but only 18% apply agents to vulnerability management—leaving known exposures to linger even as AI accelerates exploit windows. This gap directly translates to higher breach costs when incidents occur. The concentration of AI-driven attacks on critical infrastructure (62%), particularly financial services and energy, compounds systemic risk, as breaches in these sectors can cascade across economies and supply chains.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime