
A data breach now costs $1,100 for every hour it stays unresolved. In 2026, breaches averaged 247 days to contain — adding up to a record $4.99 million per incident. According to IBM's 2026 Cost of a Data Breach Report, produced with Ponemon Institute from 602 breached organizations across 16 countries, this year's data reveals one critical theme: AI has become the deciding factor in breach economics.
Attackers using AI now account for 1 in 4 malicious breaches (+56% YoY). Defenders using AI extensively save $1.93 million per incident. Both statements are true at once, and the gap between them is the real story. This article translates the report's core numbers into decisions a CISO can bring to a budget meeting, not just a summary of the findings.
Key statistics at a glance
- Global average breach cost: $4.99M (+12% YoY). Every unresolved breach drains roughly $1,100/hour.
- US average breach cost: $11.5M (+11% YoY). US regulatory and business costs run 2.3x the global average.
- AI-driven attacks: 1 in 4 malicious breaches (+56% YoY). Attackers are adopting AI faster than defenders in the areas that matter most.
- Mean time to identify and contain: 247 days, a reversal after 5 years of decline. Five years of containment progress erased in a single cycle.
- Security AI and automation savings: $1.93M. Extensive AI deployment cuts breach costs by roughly a third.
- The 85% reckoning: 85% of organizations raised security spending after a frontier AI model demo, versus 64% after an actual breach. Fear of future threats now outweighs the memory of real incidents.
- The 18% vulnerability gap: half of breached organizations run AI agents in their SOC, but only 18% point them at vulnerability management. Defenders deploy AI everywhere except the front door attackers use.
- The access control disaster: 92% of AI-breached organizations had no proper AI access controls. IAM is the second most effective cost reducer in the study, and most companies still aren't applying it to their AI systems.
What is the IBM Cost of a Data Breach Report 2026
The IBM Cost of a Data Breach Report 2026 is the 21st annual edition of IBM's flagship breach-economics study. It is based on interviews with 602 organizations across 16 countries and 17 industries that experienced a breach between March 2025 and February 2026, plus a May 2026 follow-on study of 456 of those same respondents.
One caveat worth stating upfront: the sample is non-statistical, so margins of error do not apply in the traditional sense, and it skews toward organizations with more mature security programs willing to participate. Treat the figures as directional benchmarks for planning, not actuarial predictions for your specific organization.
What's new in the 2026 IBM Cost of a Data Breach Report
This year's is the first edition to measure agentic AI deployment inside security operations centers (SOCs), the first to track post-quantum cryptography readiness, and the first built on a follow-on study triggered by a live AI threat event.
The original interviews closed in February 2026. Two months later, Anthropic's Claude Mythos preview shifted threat perception. IBM and Ponemon surveyed 456 original respondents in May 2026 with a direct question: did this change your spending plans?
The answer produced what this article calls the 85% reckoning: a real breach convinced 64% of organizations to raise security spending, but news of a frontier AI model's capabilities convinced 85%. Fear of a future threat outweighed the memory of an actual incident.
Four other firsts define the year:
- Mean time to identify and contain (MTTI/MTTC) rose after five straight years of improvement.
- Shadow AI incidents doubled to 43% of all AI-related incidents.
- A quarter of organizations still use no AI or automation in security at all.
- The report measures, for the first time, exactly which SOC functions organizations assign to AI agents. That breakdown is what this article calls the 18% vulnerability gap, covered below.
The $4.99 million breach: Global costs hit a record
The global average cost of a data breach reached an all-time high of $4.99 million in 2026, a 12% increase driven primarily by detection and escalation expenses and lost business costs, which together accounted for 63% of the total. Regulatory fines, the line item most boards fixate on, carry less weight in the total than forensics, crisis management, downtime, and customer churn combined.
After dipping to $4.44M in 2025, costs surged back to $4.99M in 2026, erasing a year of progress and hitting a new record.
![Line chart showing global average data breach cost from 2019 to 2026, rising from $3.92 million to a record $4.99 million, IBM Cost of a Data Breach Report 2026]](https://storage.ghost.io/c/ea/f1/eaf1376c-e95e-464e-9e89-2c384ddf359d/content/images/2026/07/image-32.png)
Breach duration compounds the cost directly. Incidents that took longer than 200 days to resolve cost organizations $5.65 million on average, compared to $4.32 million for breaches contained faster.
Country by country: Where breaches cost the most
The United States broke its own record with an average breach cost of $11.5 million, more than double the global average and an 11% increase over last year, driven by higher regulatory fines and business disruption costs. No other country comes close to the US figure, but the regional spread tells its own story.
| Country / region | 2026 average cost | YoY change |
|---|---|---|
| United States | $11.5M | +11% |
| Middle East | $8.0M | — |
| Benelux | $7.37M | +16% |
| Canada | $5.20M | — |
| Germany | $4.93M | +18% |
| United Kingdom | $4.17M | — |
| South Africa | $3.04M | +22% |
South Africa posted the largest percentage increase in the study at 22%, even though its absolute cost remains below the global average. That combination, a low base rising fast, usually signals a market where security spending has not kept pace with digitization (not one where breaches have become uniquely severe). Benelux, by contrast, already sits among the highest per-incident costs globally and still grew 16%.
AI-driven attacks surge 56%: The numbers behind the headline
AI-driven attacks now account for more than 1 in4 malicious breaches, a 56% increase over last year, and add approximately $1 million to the average breach cost, pushing AI-enabled incidents to $6.04 million.
Attack type breakdown
Break down the attack types and a clear pattern emerges. This is attackers automating the social-engineering and malware-development steps that used to require skilled human time.
- AI deepfake impersonation: 45% of AI-enabled attacks, the largest single category
- AI-generated malware: 19%
- AI-generated phishing or other communications: 17%
Critical infrastructure concentration
Critical infrastructure absorbed the concentrated damage: 62% of AI-driven attacks in the study hit these sectors, with financial services ($6.29M average) and energy ($5.24M average) carrying the largest share.
Attacks on AI systems themselves
Attackers are also going after AI systems directly, and both figures below sit above the global all-cause average, which tells you these are not edge-case curiosities anymore.
- AI model inversion attacks (an adversary reconstructs sensitive training data from a deployed model): $6.07M average
- Prompt injection attacks (malicious input manipulates a model's behavior): $5.89M average
The 18% gap: Where defenders are losing the AI arms race
Half of breached organizations deployed AI agents in their SOCs, but only 18% aimed them at vulnerability management. This is the 18% vulnerability gap: defenders deploy AI everywhere except where attackers break in.
Where SOC agents actually go
Most SOC agent deployment clustered around detection and response, not the front door attackers use:
- Threat hunting: 56%
- Response and containment: 54%
- Vulnerability scanning and management: 18%
Vulnerability management, the unglamorous work of finding and closing the holes attackers walk through, got the least attention despite being exactly where frontier AI models threaten to change the math fastest.
Why the gap is dangerous now
In April 2026, Anthropic previewed Claude Mythos, a frontier model that identified thousands of high-severity vulnerabilities across major operating systems and browsers during testing. Anthropic's Frontier Red Team research put the cost of developing a working exploit from a discovered vulnerability at under $1,000 to $2,000, achievable in under a day.
The industry is already reacting
IBM's own respondents recognized the mismatch after the fact, following the Mythos announcement:
- 74% of organizations said they had rethought their AI agent deployment strategy in the SOC
- Planned use of agents for vulnerability management rose from 18% toward 37% in stated intent
The industry breakdown: Healthcare, finance, and the biggest movers
Healthcare remained the costliest industry for data breaches for the 13th consecutive year at $6.64 million, though it was the only sector to see costs decline, down 10.5% from $7.42 million in 2025.
| Industry | 2026 average cost | YoY change |
|---|---|---|
| Healthcare | $6.64M | −10.5% |
| Financial services | $6.29M | +13% |
| Industrial | $5.50M | — |
| Technology | $5.50M | — |
| Entertainment | $5.38M | +18% |
| Communications | $4.71M | +20% |
Communications posted the steepest increase in the entire study at 20%, followed by entertainment at 18%. Financial services climbed 13% to $6.29 million, continuing a multi-year rise that has closed most of the gap with healthcare. Customer PII appeared in 52% of breaches, at $192 per record on average. Intellectual property theft was less frequent, 32% of breaches, but the costliest data type per record at $196.
How attackers get in: Phishing, supply chains, and social engineering
Phishing, including voice and SMS-based variants, remained the leading initial attack vector for the fourth consecutive year, involved in 17% of breaches and costing an average of $5.29 million, the highest among all vectors.
| Attack vector | Share of breaches | Average cost |
|---|---|---|
| Phishing (including vishing/smishing) | 17% | $5.29M |
| Social engineering | 13% | $5.23M |
| Valid account abuse | — | $5.07M |
| Supply chain compromise | — | 258 days to identify and contain |
Where breaches originate
Malicious and criminal attacks accounted for 55% of all breaches, up 8 points year over year, ahead of two other causes:
- Human error: 23%
- IT failures: 22%
Why supply chain attacks take so long to catch
Supply chain compromise and removable media both took an average of 258 days to identify and contain, well above the 247-day overall average. Neither shows up reliably in malware scans or inbound network traffic, which is what stretches detection time past the norm for every other vector.
Why voice and SMS phishing cost more
Phishing and social engineering are converging on the same target: credential access. Voice and SMS phishing cost more precisely because a successful call or text often hands attackers direct access to higher-value systems, skipping the malware-delivery step entirely.
The breach lifecycle: 247 days, and why the clock reversed
The mean time to identify and contain a data breach rose to 247 days, a 2.5% increase that reversed five years of steady improvement. Internal security teams still outperform the average, resolving breaches 15% faster, in 209 days.

Who finds the breach, and how long it takes
Who finds the breach changes the timeline substantially:
| Discovery method | Time to identify and contain | Share of breaches |
|---|---|---|
| Internal security teams | 209 days | 38% |
| Managed security service providers (MSSPs) | 230 days | 31% |
| Attacker disclosure | 268 days | 17% |
| Third-party disclosure | 281 days | — |
The uncomfortable number in that table
Attacker disclosure is the worst-case discovery method, and it is not rare. Internal teams and MSSPs together caught 69% of breaches. Attacker disclosure accounted for 17%, meaning nearly 1 in 5 breached organizations found out from the people attacking them.
Ransomware evolves: From encryption to reputation extortion
Ransomware was involved in 39% of data breaches, up from 34% last year, with 41% of those attacks now including threats to damage brand reputation, reflecting a shift from purely technical disruption toward multilayered extortion that targets trust and public perception.
Encrypting files and demanding payment for a decryption key used to be the whole playbook. Threatening to publicize a breach to customers, regulators, and the press, regardless of whether encryption succeeded, adds a second pressure point that does not depend on backup quality. An organization with flawless backups can restore its systems in hours and still face a reputation-extortion demand it cannot engineer its way out of.
Security AI and automation: The $1.93 million defense
Organizations that extensively deployed security AI and automation reduced average breach costs by $1.93 million and shortened breach lifecycles by 65 days compared to those using no AI or automation, a roughly 33% cost reduction that also cuts containment time by nearly a quarter.
| AI/automation usage level | Average breach cost | Share of organizations |
|---|---|---|
| Extensive use | $4.00M | 36% |
| Limited use | $5.05M | 39% |
| No use | $5.93M | 25% |
One in four organizations in the study still uses no AI or automation in its security operations at all. That quarter of the sample is paying nearly $2 million more per incident than the extensive-use group, for a capability gap that has existed long enough to have a well-documented return on investment.
The access control disaster: 92% of AI-breached organizations had none
Among organizations that experienced an AI-related breach, 92% lacked proper AI access controls, despite identity and access management (IAM) ranking as the second most effective cost reducer in the entire study, at $225,622 saved per breach. Only 40% of organizations extend any access controls to their AI models and the data those models touch.
Top cost reducers, for context
- DevSecOps practices: $253,805 saved per breach, the single most effective reducer in the study
- Identity and access management: $225,622 saved per breach, close behind
The weakness both AI attack types exploit
Model inversion attacks ($6.07M average) and prompt injection attacks ($5.89M average) target the same underlying weakness: access that was never scoped tightly enough in the first place. Neither attack requires breaking encryption or bypassing a firewall. Both need only a model, or a prompt path to it, with broader reach than the task requires.
Why this matters beyond AI systems
This is where foundational identity practices become critical. For a security team managing thousands of credentials across on-prem systems, cloud services, and SaaS tools, the IAM savings figure is not abstract. It is the difference between a 247-day breach lifecycle and a 209-day one.
Security teams managing credentials across human and non-human identities, including API keys, service accounts, and AI agent credentials, need centralized access governance with rotation, auditing, and role-based controls to close the gap that 92% of breached organizations left open.
Shadow AI, non-human identities, and post-quantum: The three emerging threats
Three 2026-first findings define the report's forward-looking section: shadow AI incidents doubling, non-human identity security lagging AI adoption, and post-quantum cryptography readiness remaining rare.
Shadow AI
Shadow AI, meaning AI tools employees adopt without security approval, accounted for 43% of AI-related incidents in 2026, more than double the 20% recorded the prior year. Roughly one in five of these incidents resulted in a regulatory fine, and only about a third of organizations enforce strict approval processes for deploying AI tools internally.
Non-human identities
Fewer than half of organizations (46%) report securing non-human identities such as API keys, service accounts, and machine credentials within their AI workflows, creating an expanding attack surface as AI agents proliferate across enterprise environments.
Of that 46%, 55% apply machine identity lifecycle management, 39% use dedicated secrets management, 36% run behavioral monitoring on non-human accounts, and 30% apply role-based access control to them specifically.
Post-quantum cryptography
Only 26% of breached organizations have a post-quantum cryptography project underway, and 61% lack controls to monitor and secure cryptographic assets at all, leaving them exposed to "harvest now, decrypt later" attacks as quantum computing capability advances. Just 37% encrypt sensitive data comprehensively at rest and in motion today, a baseline gap that predates any quantum concern.
IBM's four recommendations, translated for action
IBM's recommendations center on one imperative: closing the gap between AI-accelerated attacks and human-speed defense by deploying agentic AI to vulnerability management, shifting identity to continuous verification, establishing AI sovereignty, and beginning the post-quantum cryptography transition.
- Operate security at the speed of attack. IBM frames this as closing the reaction-time gap. In practice, it means deploying at least one AI agent to vulnerability scanning in your CI/CD pipeline this quarter, not just to threat detection.
- Shift identity security to continuous, runtime verification. This applies zero trust principles to machines as well as humans. Start by auditing every non-human identity touching an AI workflow and moving toward just-in-time access instead of standing credentials.
- Strengthen AI control through AI sovereignty. IBM's language covers comprehensive security across data, applications, identities, and cloud. The first concrete step is mapping every place an AI model touches sensitive data and applying access controls there specifically.
- Prepare for post-quantum security risk. With 61% of organizations lacking basic cryptographic asset controls, the starting point is an inventory: which systems still rely on RSA or ECC, and which of those protect data with a long confidentiality shelf life.
What this means for your team
IBM's 2026 report describes asymmetric acceleration. Attackers are adopting AI faster in the areas that hurt most, while defenders deploy their best tools everywhere except the front door. The 18% vulnerability gap, the 92% access control failure rate, and the 85% reckoning all point to the same conclusion: the breach economics equation has shifted, and speed is now the variable that decides the outcome.
For security teams, identity remains the battleground. With IAM ranking as the second most effective cost reducer and 92% of AI-breached organizations lacking access controls, centralized credential management for human and non-human identities is a direct financial lever.
Passwork gives enterprise teams role-based access control, automated credential rotation, and audited vault access, the kind of identity governance that closes the specific gaps this report quantifies.
If your organization still manages privileged credentials through spreadsheets, shared accounts, or API keys nobody has rotated in a year, the $1,100-per-hour breach clock is already running somewhere in your environment.
Frequently asked questions
What is the average cost of a data breach in 2026?
According to IBM's 2026 Cost of a Data Breach Report, the global average reached a record $4.99 million, a 12% increase from 2025. In the United States, the average was $11.5 million, more than double the global figure. Breach costs include detection, escalation, notification, post-breach response, and lost business.
How much have AI-driven attacks increased?
AI-driven attacks surged 56% year over year, now accounting for more than one in four malicious breaches. These AI-enabled incidents cost an average of $6.04 million, roughly $1 million more than malicious breaches without AI involvement.
Which industries have the highest data breach costs?
Healthcare tops the list for the 13th consecutive year at $6.64 million, followed by financial services ($6.29M), industrial and technology (both $5.50M), and entertainment ($5.38M). Healthcare was the only sector to see costs decline year over year.
Does security AI actually reduce breach costs?
Yes. Organizations using AI and automation extensively across security operations reduced breach costs by $1.93 million and contained breaches 65 days faster on average compared to those using no AI or automation, a roughly 33% cost reduction.
What is the most common cause of data breaches?
Phishing, including voice and SMS-based attacks, remained the leading initial attack vector for the fourth consecutive year, involved in 17% of breaches and costing an average of $5.29 million, the highest among all attack vectors tracked in the report.



Table of contents
- Key statistics at a glance
- What is the IBM Cost of a Data Breach Report 2026
- What's new in the 2026 IBM Cost of a Data Breach Report
- The $4.99 million breach: Global costs hit a record
- Country by country: Where breaches cost the most
- AI-driven attacks surge 56%: The numbers behind the headline
- The 18% gap: Where defenders are losing the AI arms race
- The industry breakdown: Healthcare, finance, and the biggest movers
- How attackers get in: Phishing, supply chains, and social engineering
- The breach lifecycle: 247 days, and why the clock reversed
- Ransomware evolves: From encryption to reputation extortion
- Security AI and automation: The $1.93 million defense
- The access control disaster: 92% of AI-breached organizations had none
- Shadow AI, non-human identities, and post-quantum: The three emerging threats
- IBM's four recommendations, translated for action
- What this means for your team
- Frequently asked questions
Table of contents
- Key statistics at a glance
- What is the IBM Cost of a Data Breach Report 2026
- What's new in the 2026 IBM Cost of a Data Breach Report
- The $4.99 million breach: Global costs hit a record
- Country by country: Where breaches cost the most
- AI-driven attacks surge 56%: The numbers behind the headline
- The 18% gap: Where defenders are losing the AI arms race
- The industry breakdown: Healthcare, finance, and the biggest movers
- How attackers get in: Phishing, supply chains, and social engineering
- The breach lifecycle: 247 days, and why the clock reversed
- Ransomware evolves: From encryption to reputation extortion
- Security AI and automation: The $1.93 million defense
- The access control disaster: 92% of AI-breached organizations had none
- Shadow AI, non-human identities, and post-quantum: The three emerging threats
- IBM's four recommendations, translated for action
- What this means for your team
- Frequently asked questions
Self-hosted password manager for business
Passwork provides an advantage of effective teamwork with corporate passwords in a totally safe environment. Double encryption and zero-knowledge architecture ensure your passwords never leave your infrastructure.
Learn more
