# IBM: AI-driven attacks increased 56% last year, and data breach costs are up 12%

> Source: <https://www.networkworld.com/article/4202554/ibm-ai-driven-attacks-increased-56-last-year-and-data-breach-costs-are-up-12.html>
> Published: 2026-07-29 17:26:18+00:00

AI-based attacks that rely on deepfake impersonation and AI-enabled malware are getting faster and cheaper to launch, which has driven the cost of finding and fixing enterprise data breaches to a record high.

AI-enabled breaches cost an average of $6 million, which is roughly $1 million more than the global breach average of $4.99 million, according to [IBM’s 2026 Cost of a Data Breach Report.](https://www.ibm.com/reports/data-breach) The 2026 report, conducted by Ponemon Institute and sponsored and analyzed by IBM, is based on breaches experienced by 602 organizations globally between March 2025 and February 2026.

At $4.99 million, the global average cost of a data breach represents a 12% increase over [last year’s numbers](https://www.networkworld.com/article/4030807/ibm-cost-of-u-s-data-breaches-reaches-all-time-high-and-shadow-ai-isnt-helping.html) and a new high. That increase was largely driven by detection, escalation, and lost business costs, according to IBM. One in four malicious breaches were AI-enabled, IBM found.

AI is accelerating the attack lifecycle and changing breach economics, notes [Limor Kessem](https://www.linkedin.com/in/limor-sylvie-kessem/), global lead, X-Force cyber crisis management at IBM, in a [blog post](https://www.ibm.com/think/x-force/2026-cost-of-a-data-breach-ai-adversaries-enterprise-risk) about the report.

“Looking at the changes from last year’s report, AI-driven attacks increased by 56%, adding an average of $1 million per breach, as attackers use AI tools to increase speed, scale, and precision. This is not simply an evolution in attacker tooling; it is a structural shift,” Kessem wrote. “When adversaries can automate reconnaissance, generate persuasive phishing content, adapt malware and test exploits at machine speed, the cost and complexity of launching sophisticated attacks drops materially. Breaches become faster, broader and more expensive.”

“When attack velocity increases, the enterprise has less time to detect, validate and contain an incident. That compressed response window directly drives higher losses, whether through operational disruption, data exposure, legal costs, customer remediation or reputational damage,” Kessem continued. “From the report’s findings, two cost categories, detection and escalation alongside lost business, made up the majority (63%) of costs in the data breaches studied.”

On the positive side, AI and [automation](https://www.networkworld.com/article/4102599/ai-driven-network-management-gains-enterprise-trust.html) can successfully reduce breach impact, helping security teams move at machine speed and delivering an average savings of $1.93 million per breach, the IBM study found. But, implementation of these technologies is inconsistent.

“While 50% of breached organizations have deployed AI agents in threat hunting, response, and containment, only 18% have applied them to vulnerability scanning and management. That gap is significant,” Kessem wrote. “It suggests many enterprises are still using AI reactively, after suspicious activity has emerged, rather than proactively, where frontier capabilities deliver outsized advantages.”

The most expensive security incident types involving an organization’s AI model or applications were inversion and [prompt injection attacks](https://www.csoonline.com/article/4184455/prompt-injection-breaks-todays-ai-agents-study-warns.html), which led to average losses of $6.07 million and $5.89 million respectively, the study found. “A model inversion attack occurs when adversaries exploit an AI model to infer or reconstruct sensitive training data, such as personal, proprietary, or confidential information, by analyzing model outputs and responses. These attacks can expose underlying data without direct access to the original dataset,” IBM stated.

The study also found that many AI-related breaches stemmed from structural weaknesses in the enterprise environment rather than from flaws inherent to a specific model.

“This distinction matters for senior leaders. It reframes AI security from a narrow model-risk conversation into a broader operating-model challenge involving architecture, controls, accountability and oversight,” Kessem wrote. “Encouragingly, organizations appear to recognize this. More than half now say they plan to invest in AI security and governance tools post-breach, representing an 88% increase from last year. That shift reflects growing awareness that securing AI requires securing the entire ecosystem around it.”
