2026 Cost of a Data Breach Report: The $6M AI threat no one's fixing

A data breach now costs $1,100 for every hour it stays unresolved. In 2026, breaches averaged 247 days to contain — adding up to a record $4.99 million per incident. According to IBM's 2026 Cost of a Data Breach Report, produced with Ponemon Institute from 602 breached organizations across 16 countries, this year's data reveals one critical theme: AI has become the deciding factor in breach economics.

Attackers using AI now account for 1 in 4 malicious breaches (+56% YoY). Defenders using AI extensively save $1.93 million per incident. Both statements are true at once, and the gap between them is the real story. This article translates the report's core numbers into decisions a CISO can bring to a budget meeting, not just a summary of the findings.


Key statistics at a glance

  • Global average breach cost: $4.99M (+12% YoY). Every unresolved breach drains roughly $1,100/hour.
  • US average breach cost: $11.5M (+11% YoY). US regulatory and business costs run 2.3x the global average.
  • AI-driven attacks: 1 in 4 malicious breaches (+56% YoY). Attackers are adopting AI faster than defenders in the areas that matter most.
  • Mean time to identify and contain: 247 days, a reversal after 5 years of decline. Five years of containment progress erased in a single cycle.
  • Security AI and automation savings: $1.93M. Extensive AI deployment cuts breach costs by roughly a third.
  • The 85% reckoning: 85% of organizations raised security spending after a frontier AI model demo, versus 64% after an actual breach. Fear of future threats now outweighs the memory of real incidents.
  • The 18% vulnerability gap: half of breached organizations run AI agents in their SOC, but only 18% point them at vulnerability management. Defenders deploy AI everywhere except the front door attackers use.
  • The access control disaster: 92% of AI-breached organizations had no proper AI access controls. IAM is the second most effective cost reducer in the study, and most companies still aren't applying it to their AI systems.

What is the IBM Cost of a Data Breach Report 2026

The IBM Cost of a Data Breach Report 2026 is the 21st annual edition of IBM's flagship breach-economics study. It is based on interviews with 602 organizations across 16 countries and 17 industries that experienced a breach between March 2025 and February 2026, plus a May 2026 follow-on study of 456 of those same respondents.

One caveat worth stating upfront: the sample is non-statistical, so margins of error do not apply in the traditional sense, and it skews toward organizations with more mature security programs willing to participate. Treat the figures as directional benchmarks for planning, not actuarial predictions for your specific organization.


What's new in the 2026 IBM Cost of a Data Breach Report

This year's is the first edition to measure agentic AI deployment inside security operations centers (SOCs), the first to track post-quantum cryptography readiness, and the first built on a follow-on study triggered by a live AI threat event.

The original interviews closed in February 2026. Two months later, Anthropic's Claude Mythos preview shifted threat perception. IBM and Ponemon surveyed 456 original respondents in May 2026 with a direct question: did this change your spending plans?

The answer produced what this article calls the 85% reckoning: a real breach convinced 64% of organizations to raise security spending, but news of a frontier AI model's capabilities convinced 85%. Fear of a future threat outweighed the memory of an actual incident.

Four other firsts define the year:

  • Mean time to identify and contain (MTTI/MTTC) rose after five straight years of improvement.
  • Shadow AI incidents doubled to 43% of all AI-related incidents.
  • A quarter of organizations still use no AI or automation in security at all.
  • The report measures, for the first time, exactly which SOC functions organizations assign to AI agents. That breakdown is what this article calls the 18% vulnerability gap, covered below.

The $4.99 million breach: Global costs hit a record

The global average cost of a data breach reached an all-time high of $4.99 million in 2026, a 12% increase driven primarily by detection and escalation expenses and lost business costs, which together accounted for 63% of the total. Regulatory fines, the line item most boards fixate on, carry less weight in the total than forensics, crisis management, downtime, and customer churn combined.

After dipping to $4.44M in 2025, costs surged back to $4.99M in 2026, erasing a year of progress and hitting a new record.

 Line chart showing global average data breach cost from 2019 to 2026, rising from $3.92 million to a record $4.99 million, IBM Cost of a Data Breach Report 2026]

Breach duration compounds the cost directly. Incidents that took longer than 200 days to resolve cost organizations $5.65 million on average, compared to $4.32 million for breaches contained faster.


Country by country: Where breaches cost the most

The United States broke its own record with an average breach cost of $11.5 million, more than double the global average and an 11% increase over last year, driven by higher regulatory fines and business disruption costs. No other country comes close to the US figure, but the regional spread tells its own story.

Country / region 2026 average cost YoY change
United States $11.5M +11%
Middle East $8.0M
Benelux $7.37M +16%
Canada $5.20M
Germany $4.93M +18%
United Kingdom $4.17M
South Africa $3.04M +22%

South Africa posted the largest percentage increase in the study at 22%, even though its absolute cost remains below the global average. That combination, a low base rising fast, usually signals a market where security spending has not kept pace with digitization (not one where breaches have become uniquely severe). Benelux, by contrast, already sits among the highest per-incident costs globally and still grew 16%.


AI-driven attacks surge 56%: The numbers behind the headline

AI-driven attacks now account for more than 1 in4 malicious breaches, a 56% increase over last year, and add approximately $1 million to the average breach cost, pushing AI-enabled incidents to $6.04 million.

Attack type breakdown

Break down the attack types and a clear pattern emerges. This is attackers automating the social-engineering and malware-development steps that used to require skilled human time.

  • AI deepfake impersonation: 45% of AI-enabled attacks, the largest single category
  • AI-generated malware: 19%
  • AI-generated phishing or other communications: 17%

Critical infrastructure concentration

Critical infrastructure absorbed the concentrated damage: 62% of AI-driven attacks in the study hit these sectors, with financial services ($6.29M average) and energy ($5.24M average) carrying the largest share.

Note: IBM has not published which of its 17 industry categories it classifies as critical infrastructure, so the 62% figure describes the sector group as a whole rather than isolating financial services and energy specifically. Treat it as directional, not a precise attribution.

Attacks on AI systems themselves

Attackers are also going after AI systems directly, and both figures below sit above the global all-cause average, which tells you these are not edge-case curiosities anymore.

  • AI model inversion attacks (an adversary reconstructs sensitive training data from a deployed model): $6.07M average
  • Prompt injection attacks (malicious input manipulates a model's behavior): $5.89M average

The 18% gap: Where defenders are losing the AI arms race

Half of breached organizations deployed AI agents in their SOCs, but only 18% aimed them at vulnerability management. This is the 18% vulnerability gap: defenders deploy AI everywhere except where attackers break in.

Where SOC agents actually go

Most SOC agent deployment clustered around detection and response, not the front door attackers use:

  • Threat hunting: 56%
  • Response and containment: 54%
  • Vulnerability scanning and management: 18%

Vulnerability management, the unglamorous work of finding and closing the holes attackers walk through, got the least attention despite being exactly where frontier AI models threaten to change the math fastest.

Why the gap is dangerous now

In April 2026, Anthropic previewed Claude Mythos, a frontier model that identified thousands of high-severity vulnerabilities across major operating systems and browsers during testing. Anthropic's Frontier Red Team research put the cost of developing a working exploit from a discovered vulnerability at under $1,000 to $2,000, achievable in under a day.

The industry is already reacting

IBM's own respondents recognized the mismatch after the fact, following the Mythos announcement:

  • 74% of organizations said they had rethought their AI agent deployment strategy in the SOC
  • Planned use of agents for vulnerability management rose from 18% toward 37% in stated intent
Board translation: if your SOC has AI agents but none of them are scanning for vulnerabilities, you are running the same defensive posture as an organization with no AI at all, against attackers who no longer have that limitation.

The industry breakdown: Healthcare, finance, and the biggest movers

Healthcare remained the costliest industry for data breaches for the 13th consecutive year at $6.64 million, though it was the only sector to see costs decline, down 10.5% from $7.42 million in 2025.

Industry 2026 average cost YoY change
Healthcare $6.64M −10.5%
Financial services $6.29M +13%
Industrial $5.50M
Technology $5.50M
Entertainment $5.38M +18%
Communications $4.71M +20%

Communications posted the steepest increase in the entire study at 20%, followed by entertainment at 18%. Financial services climbed 13% to $6.29 million, continuing a multi-year rise that has closed most of the gap with healthcare. Customer PII appeared in 52% of breaches, at $192 per record on average. Intellectual property theft was less frequent, 32% of breaches, but the costliest data type per record at $196.

Healthcare's decline masks a shift: attacks are moving to suppliers rather than direct targets. Lower per-breach costs don't mean lower total risk if supply chain incidents are rising.

How attackers get in: Phishing, supply chains, and social engineering

Phishing, including voice and SMS-based variants, remained the leading initial attack vector for the fourth consecutive year, involved in 17% of breaches and costing an average of $5.29 million, the highest among all vectors.

Attack vector Share of breaches Average cost
Phishing (including vishing/smishing) 17% $5.29M
Social engineering 13% $5.23M
Valid account abuse $5.07M
Supply chain compromise 258 days to identify and contain

Where breaches originate

Malicious and criminal attacks accounted for 55% of all breaches, up 8 points year over year, ahead of two other causes:

  • Human error: 23%
  • IT failures: 22%

Why supply chain attacks take so long to catch

Supply chain compromise and removable media both took an average of 258 days to identify and contain, well above the 247-day overall average. Neither shows up reliably in malware scans or inbound network traffic, which is what stretches detection time past the norm for every other vector.

Why voice and SMS phishing cost more

Phishing and social engineering are converging on the same target: credential access. Voice and SMS phishing cost more precisely because a successful call or text often hands attackers direct access to higher-value systems, skipping the malware-delivery step entirely.


The breach lifecycle: 247 days, and why the clock reversed

The mean time to identify and contain a data breach rose to 247 days, a 2.5% increase that reversed five years of steady improvement. Internal security teams still outperform the average, resolving breaches 15% faster, in 209 days.

Chart for breach response time

Who finds the breach, and how long it takes

Who finds the breach changes the timeline substantially:

Discovery method Time to identify and contain Share of breaches
Internal security teams 209 days 38%
Managed security service providers (MSSPs) 230 days 31%
Attacker disclosure 268 days 17%
Third-party disclosure 281 days

The uncomfortable number in that table

Attacker disclosure is the worst-case discovery method, and it is not rare. Internal teams and MSSPs together caught 69% of breaches. Attacker disclosure accounted for 17%, meaning nearly 1 in 5 breached organizations found out from the people attacking them.


Ransomware evolves: From encryption to reputation extortion

Ransomware was involved in 39% of data breaches, up from 34% last year, with 41% of those attacks now including threats to damage brand reputation, reflecting a shift from purely technical disruption toward multilayered extortion that targets trust and public perception.

Encrypting files and demanding payment for a decryption key used to be the whole playbook. Threatening to publicize a breach to customers, regulators, and the press, regardless of whether encryption succeeded, adds a second pressure point that does not depend on backup quality. An organization with flawless backups can restore its systems in hours and still face a reputation-extortion demand it cannot engineer its way out of.


Security AI and automation: The $1.93 million defense

Organizations that extensively deployed security AI and automation reduced average breach costs by $1.93 million and shortened breach lifecycles by 65 days compared to those using no AI or automation, a roughly 33% cost reduction that also cuts containment time by nearly a quarter.

AI/automation usage level Average breach cost Share of organizations
Extensive use $4.00M 36%
Limited use $5.05M 39%
No use $5.93M 25%

One in four organizations in the study still uses no AI or automation in its security operations at all. That quarter of the sample is paying nearly $2 million more per incident than the extensive-use group, for a capability gap that has existed long enough to have a well-documented return on investment.


The access control disaster: 92% of AI-breached organizations had none

Among organizations that experienced an AI-related breach, 92% lacked proper AI access controls, despite identity and access management (IAM) ranking as the second most effective cost reducer in the entire study, at $225,622 saved per breach. Only 40% of organizations extend any access controls to their AI models and the data those models touch.

Top cost reducers, for context

  • DevSecOps practices: $253,805 saved per breach, the single most effective reducer in the study
  • Identity and access management: $225,622 saved per breach, close behind

The weakness both AI attack types exploit

Model inversion attacks ($6.07M average) and prompt injection attacks ($5.89M average) target the same underlying weakness: access that was never scoped tightly enough in the first place. Neither attack requires breaking encryption or bypassing a firewall. Both need only a model, or a prompt path to it, with broader reach than the task requires.

Why this matters beyond AI systems

This is where foundational identity practices become critical. For a security team managing thousands of credentials across on-prem systems, cloud services, and SaaS tools, the IAM savings figure is not abstract. It is the difference between a 247-day breach lifecycle and a 209-day one.

Security teams managing credentials across human and non-human identities, including API keys, service accounts, and AI agent credentials, need centralized access governance with rotation, auditing, and role-based controls to close the gap that 92% of breached organizations left open.

Closing the 92% gap starts with knowing who, or what, has access to which credentials. Start your free trial of Passwork and see how it scopes permissions for human and non-human identities alike.

Shadow AI, non-human identities, and post-quantum: The three emerging threats

Three 2026-first findings define the report's forward-looking section: shadow AI incidents doubling, non-human identity security lagging AI adoption, and post-quantum cryptography readiness remaining rare.

Shadow AI

Shadow AI, meaning AI tools employees adopt without security approval, accounted for 43% of AI-related incidents in 2026, more than double the 20% recorded the prior year. Roughly one in five of these incidents resulted in a regulatory fine, and only about a third of organizations enforce strict approval processes for deploying AI tools internally.

Non-human identities

Fewer than half of organizations (46%) report securing non-human identities such as API keys, service accounts, and machine credentials within their AI workflows, creating an expanding attack surface as AI agents proliferate across enterprise environments.

Of that 46%, 55% apply machine identity lifecycle management, 39% use dedicated secrets management, 36% run behavioral monitoring on non-human accounts, and 30% apply role-based access control to them specifically.

Post-quantum cryptography

Only 26% of breached organizations have a post-quantum cryptography project underway, and 61% lack controls to monitor and secure cryptographic assets at all, leaving them exposed to "harvest now, decrypt later" attacks as quantum computing capability advances. Just 37% encrypt sensitive data comprehensively at rest and in motion today, a baseline gap that predates any quantum concern.


IBM's four recommendations, translated for action

IBM's recommendations center on one imperative: closing the gap between AI-accelerated attacks and human-speed defense by deploying agentic AI to vulnerability management, shifting identity to continuous verification, establishing AI sovereignty, and beginning the post-quantum cryptography transition.

  1. Operate security at the speed of attack. IBM frames this as closing the reaction-time gap. In practice, it means deploying at least one AI agent to vulnerability scanning in your CI/CD pipeline this quarter, not just to threat detection.
  2. Shift identity security to continuous, runtime verification. This applies zero trust principles to machines as well as humans. Start by auditing every non-human identity touching an AI workflow and moving toward just-in-time access instead of standing credentials.
  3. Strengthen AI control through AI sovereignty. IBM's language covers comprehensive security across data, applications, identities, and cloud. The first concrete step is mapping every place an AI model touches sensitive data and applying access controls there specifically.
  4. Prepare for post-quantum security risk. With 61% of organizations lacking basic cryptographic asset controls, the starting point is an inventory: which systems still rely on RSA or ECC, and which of those protect data with a long confidentiality shelf life.

What this means for your team

IBM's 2026 report describes asymmetric acceleration. Attackers are adopting AI faster in the areas that hurt most, while defenders deploy their best tools everywhere except the front door. The 18% vulnerability gap, the 92% access control failure rate, and the 85% reckoning all point to the same conclusion: the breach economics equation has shifted, and speed is now the variable that decides the outcome.

For security teams, identity remains the battleground. With IAM ranking as the second most effective cost reducer and 92% of AI-breached organizations lacking access controls, centralized credential management for human and non-human identities is a direct financial lever.

Passwork gives enterprise teams role-based access control, automated credential rotation, and audited vault access, the kind of identity governance that closes the specific gaps this report quantifies.

If your organization still manages privileged credentials through spreadsheets, shared accounts, or API keys nobody has rotated in a year, the $1,100-per-hour breach clock is already running somewhere in your environment.

Every unrotated API key and shared account is a line item in next year's breach report. See how Passwork centralizes access control, rotation, and audit logging for human and non-human identities alike — request a free demo.

Frequently asked questions

What is the average cost of a data breach in 2026?

According to IBM's 2026 Cost of a Data Breach Report, the global average reached a record $4.99 million, a 12% increase from 2025. In the United States, the average was $11.5 million, more than double the global figure. Breach costs include detection, escalation, notification, post-breach response, and lost business.

How much have AI-driven attacks increased?

AI-driven attacks surged 56% year over year, now accounting for more than one in four malicious breaches. These AI-enabled incidents cost an average of $6.04 million, roughly $1 million more than malicious breaches without AI involvement.

Which industries have the highest data breach costs?

Healthcare tops the list for the 13th consecutive year at $6.64 million, followed by financial services ($6.29M), industrial and technology (both $5.50M), and entertainment ($5.38M). Healthcare was the only sector to see costs decline year over year.

Does security AI actually reduce breach costs?

Yes. Organizations using AI and automation extensively across security operations reduced breach costs by $1.93 million and contained breaches 65 days faster on average compared to those using no AI or automation, a roughly 33% cost reduction.

What is the most common cause of data breaches?

Phishing, including voice and SMS-based attacks, remained the leading initial attack vector for the fourth consecutive year, involved in 17% of breaches and costing an average of $5.29 million, the highest among all attack vectors tracked in the report.

Shadow AI: The hidden threat costing enterprises $670K per breach
Shadow AI costs enterprises $670K extra per breach — and most of it traces back to credentials pasted into public LLMs. Learn what shadow AI actually looks like, why it’s harder to stop than shadow IT, and how to govern it.
Why password complexity rules are dead (and what to use instead)
NIST droped mandatory password complexity rules. Here’s why composition requirements backfired, what SP 800-63B-4 recommends instead, and a 5-step checklist to migrate your Group Policy off the 2010-era checklist.
Passwork wins Top Performer Summer 2026 on SourceForge
Passwork earns SourceForge’s Top Performer badge for Summer 2026 — its second straight quarter, backed by verified reviews and a 4.9/5 overall rating.