STOCK TITAN

IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average

(Neutral)
(Negative)
Tags
AI

IBM (NYSE:IBM) released findings from its 2026 Cost of a Data Breach Report showing that one in four malicious breaches were AI-enabled, a 56% increase year over year. These AI-driven incidents, largely deepfake impersonation and AI-enabled malware, cost companies an average of $6 million, about $1 million above the global average breach cost of $4.99 million.

According to IBM, organizations using AI and automation in security operations reduced breach costs by nearly $2 million on average, yet 25% have not adopted these tools. Most AI-driven attacks targeted critical infrastructure sectors (62%), with financial services breaches averaging $6.3 million and energy sector breaches $5.2 million. Over 20% of organizations reported breaches targeting AI models or applications, often due to compromised APIs, plugins, and cloud misconfigurations, while encryption and cryptographic visibility remain limited.

Loading...
Loading translation...

Positive

  • None.

Negative

  • None.

Market Context

Across IBM's five AI-tagged events, the recorded average move was -0.08%. That history places this c...
Analysis

Across IBM's five AI-tagged events, the recorded average move was -0.08%. That history places this cybersecurity study in a mixed evidence set; the main risk to watch is whether reported remediation gaps translate into demand for security tools.

Key Figures

AI-enabled malicious breaches: one in four breaches Year-over-year increase: 56% Average AI-enabled breach cost: $6 million +5 more
8 metrics
AI-enabled malicious breaches one in four breaches 2026 Cost of a Data Breach Report
Year-over-year increase 56% AI-enabled malicious breaches versus last year
Average AI-enabled breach cost $6 million versus $4.99 million global breach average
AI security savings almost $2 million average breach-cost reduction from AI and automation
Planned security-spending increase 85% organizations aware of advanced frontier AI capabilities
Vulnerability-management agent adoption 18% organizations applying agents to vulnerability management
Critical-infrastructure targeting 62% AI-driven attacks reported in the study
Organizations studied 602 organizations breaches experienced globally between March 2025 and February 2026

Previous AI Reports

5 past events · Latest: Jul 09 (Positive)
Same Type Pattern 5 events
Date Event Sentiment 24h Move Catalyst
Jul 09 AI platform upgrade Positive -2.2% Multi-agent development upgrades and specialized modernization workflows were announced.
Jul 08 AI security launch Positive -1.3% IBM and Red Hat launched Lightwell for open-source software risk remediation.
Jun 22 Cybersecurity partnership Positive +5.0% IBM joined OpenAI's cyber partner program and launched managed application security services.
Jun 22 AI platform partnership Positive +1.3% IBM and Wimbledon announced new watsonx AI-powered fan and digital platform features.
Jun 17 AI risk study Negative -3.1% IBM reported enterprise AI control, dependency, sovereignty, and disruption vulnerabilities.

24h Move is the share-price change in the day after each event; other market factors may also have contributed.

Pattern Detected

IBM's AI-tagged news produced three aligned and two divergent reactions, with an average move of -0.08%.

Key Terms

deepfake impersonation, ai-enabled malware, vulnerability management, cloud misconfigurations, +2 more
6 terms
deepfake impersonation technical
"These attacks, compromised of mostly deepfake impersonation and AI-enabled malware"
Deepfake impersonation is the use of artificial intelligence to create realistic audio, video, or image recreations that mimic a specific person's appearance, voice, or mannerisms. It matters to investors because convincing fakes can spread false statements or misleading endorsements that move share prices, harm corporate reputation, prompt regulatory scrutiny, or spark legal claims—similar to receiving a believable fake phone call or video that appears to make market-moving announcements in someone’s name.
ai-enabled malware technical
"deepfake impersonation and AI-enabled malware, are reshaping breach economics"
Malicious software that uses artificial intelligence or machine learning to plan, adapt, and automate attacks, such as crafting convincing fake messages, choosing high-value targets, or evading security tools. Think of it as a burglar that learns from each attempt to get better at breaking in. It matters to investors because it raises the likelihood, cost, and complexity of cyber incidents, influencing company losses, insurance, regulatory scrutiny, and long‑term business risk.
vulnerability management technical
"only 18% apply agents to vulnerability management"
Vulnerability management is the ongoing process of finding, fixing and tracking weak spots in a company’s computer systems and software before attackers exploit them. It matters to investors because unchecked weaknesses can lead to costly breaches, fines, downtime and harm to customer trust — similar to routinely inspecting and repairing locks on a storefront to avoid break-ins and protect future revenue and reputation.
cloud misconfigurations technical
"cloud misconfigurations affecting AI workloads"
Cloud misconfigurations are mistakes or gaps in the setup of cloud-based systems and services—such as improperly set permissions, unsecured storage buckets, or lax network rules—that leave data, applications, or access controls exposed. Like leaving a door or window unlocked in a building, these errors can lead to data leaks, service outages, regulatory violations, or reputation harm, all of which can affect a company's costs, revenue, compliance status and investor perception.
cryptographic assets technical
"just 34% have visibility into cryptographic assets"
Digital items created, recorded, and transferred using cryptography and distributed ledger technology (like blockchains); this category includes cryptocurrencies, tokenized assets, stablecoins, and non-fungible tokens that represent value, rights, or ownership. They matter to investors because they can be bought, sold, or used as collateral, often show high price swings, and interact with markets, custody systems and regulations—think of them as digital bearer instruments or collectible cards kept on a shared, tamper‑resistant ledger.
ransomware technical
"Reported ransomware incidents rose compared to the year prior"
Ransomware is malicious software that locks or encrypts a company’s computer files and systems, then demands payment for their release — like a thief changing the locks on a business and asking for a ransom. It matters to investors because attacks can halt operations, trigger large cleanup costs, damage customer trust, lead to regulatory fines or legal claims, and reduce future revenue, all of which can hurt a company’s financial value.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google

More than 20% of organizations reported a breach targeting AI models or applications

ARMONK, N.Y., July 29, 2026 /PRNewswire/ -- One in four malicious breaches were AI-enabled – a 56% increase over last year – and these breaches cost an average of $6 million, roughly $1 million more than the global breach average of $4.99 million, according to IBM's 2026 Cost of a Data Breach Report.

IBM Corporation logo.

These attacks, compromised of mostly deepfake impersonation and AI-enabled malware, are reshaping breach economics. Attacks are getting faster and cheaper to launch, while breaches keep getting more expensive to find and fix. Companies that reported using AI and automation in security operations cut breach costs by an average of almost $2 million dollars, yet one in four organizations have still not adopted these tools in their security operations.

This growing imbalance—where attacks can be launched for thousands while breaches cost millions—is fundamentally changing the economics of cyber risk.

Frontier AI Threats Driving Earlier Action

Organizations are starting to act on future risk, rather than waiting for an incident. In separate follow-on research conducted by Ponemon Institute, 85% of organizations said they plan to increase security spending after becoming aware of advanced frontier AI cyber capabilities – compared to just 64% that reported in the initial research that they plan to increase security spend after experiencing a breach.

But a gap remains where attackers are moving fastest. While more than 50% reported using agents for threat detection and containment, only 18% apply agents to vulnerability management, leaving known exposures to linger even as AI shortens exploit windows. Three quarters of organizations say frontier AI threats are prompting them to rethink how agents are deployed across their security operations.

"What's changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs," said Suja Viswesan, VP, IBM Security Software. "The priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving."

Critical Infrastructure Face Higher AI-Driven Risk

Most AI-driven attacks reported in the study targeted critical infrastructure sectors (62%), with financial services and energy organizations experiencing the highest concentration, raising the risk of broader systemic disruption. Financial services breaches were reported to cost  on average $6.3 million, while energy breaches cost on average $5.2 million. The concentration of attacks across these sectors increases the potential for cascading impacts across economies, supply chains, and essential services.

Other Key Findings:

  • AI's Weakest Link. More than 20% of organizations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).
  • Encryption Gaps Persist as Quantum Risk Looms. Core weaknesses in encryption and cryptographic management continue to expose organizations, even as quantum-safe investments grow. Only 37% of breached organizations stated that they encrypt sensitive data both at rest and in transit, and just 34% have visibility into cryptographic assets.
  • Ransomware Actors Weaponize Reputation. Reported ransomware incidents rose compared to the year prior (39% vs. 34%), with attackers increasingly using AI to automate and scale. While operational disruption still plays a role, attackers are shifting toward higher-impact pressure—most commonly exploiting brand reputation (41%), followed by employee data (35%) and intellectual property (31%).

The 2026 report, conducted by Ponemon Institute and sponsored and analyzed by IBM, is based on breaches experienced by 602 organizations globally between March 2025 and February 2026. The follow-on study was conducted in May 2026, where 456 organizations of the 602 from the CODB research responded. Of these organizations, 78% or 356 of organizations were aware of recent reports about highly advanced frontier models such as Mythos. 

Additional Resources

About IBM
IBM (NYSE: IBM) is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of governments and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM's hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM's breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM's long-standing commitment to trust, transparency, responsibility, inclusivity and service. Visit www.ibm.com for more information.

Media Contact

IBM
Michele Brancati
mbrancati@ibm.com

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/ibm-study-one-in-four-malicious-breaches-are-ai-enabled-costing-companies-6-million-on-average-302837049.html

SOURCE IBM

FAQ

What did IBM (IBM) reveal about AI-enabled data breaches in its 2026 report?

IBM reported that one in four malicious breaches were AI-enabled in 2026, a 56% year-over-year increase. According to IBM, these AI-driven breaches, mainly deepfake impersonation and AI-enabled malware, cost organizations an average of $6 million, above the global breach average of $4.99 million.

How much do AI-enabled breaches cost companies on average according to IBM's 2026 study (IBM)?

AI-enabled breaches cost companies an average of $6 million, according to IBM’s 2026 Cost of a Data Breach Report. IBM highlighted that this is roughly $1 million higher than the global average breach cost of $4.99 million across all malicious incidents studied worldwide.

How does using AI and automation in security operations affect breach costs, according to IBM (IBM)?

Using AI and automation in security operations reduced breach costs by almost $2 million on average, according to IBM. The company noted that despite this reduction, one in four organizations surveyed have not yet adopted AI and automation tools in their security operations environments.

Which sectors face the highest AI-driven cyber risk in IBM's 2026 Cost of a Data Breach Report (IBM)?

IBM found that 62% of reported AI-driven attacks targeted critical infrastructure sectors. According to IBM, financial services breaches averaged $6.3 million and energy sector breaches $5.2 million, raising concerns about potential cascading impacts on economies, supply chains, and essential services globally.

How common are breaches targeting AI models or applications in IBM's 2026 findings (IBM)?

More than 20% of organizations reported breaches targeting AI models or applications, according to IBM. The study found the leading causes were weaknesses in surrounding systems, with compromised APIs, applications or plug-ins, and cloud misconfigurations each accounting for 27% of these AI-related breach incidents.

How are organizations planning security spending in response to frontier AI threats, according to IBM (IBM)?

IBM cited follow-on Ponemon research showing 85% of organizations plan to increase security spending after learning about advanced frontier AI cyber capabilities. According to IBM, this compares to 64% that reported plans to increase spend only after experiencing a breach, indicating earlier risk recognition.