Skip to main content

Morning Overview

One in four data breaches this year was powered by AI, and the share keeps climbing

Cybersecurity researchers who spent months examining hundreds of corporate breaches found a shift they had not measured at this scale before: attackers are increasingly using artificial intelligence not just to write more convincing phishing emails, but to run entire intrusions. The analysis, based on breaches experienced by more than 600 organizations worldwide, found that AI-enabled attacks are no longer a rare or theoretical category. They cost more than an average breach, spread through specific industries more than others, and are exposing a gap in how companies protect the AI systems they have already deployed.

AI-Enabled Breaches Cost About a Million Dollars More

According to IBM’s 2026 Cost of a Data Breach Report, conducted by the Ponemon Institute, one in four malicious breaches were AI-enabled, a 56 percent increase over the prior year’s study, and those breaches cost an average of $6 million, roughly $1 million above the global average breach cost of $4.99 million. The attacks were composed mostly of deepfake impersonation and AI-enabled malware, and the report’s authors describe them as reshaping the basic economics of a breach: attacks are becoming faster and cheaper to launch, even as the process of finding and fixing the resulting damage keeps getting more expensive for the companies on the receiving end. The report is based on breaches experienced by 602 organizations worldwide between March 2025 and February 2026, conducted for IBM by the Ponemon Institute, and Suja Viswesan, IBM Security Software’s vice president, said in the release that the priority now is closing the gap between discovery and remediation by building security fixes directly into development workflows rather than treating them as a separate, slower step.

Security Teams That Automate Cut Costs, But Most Still Haven’t

The same research found that companies using AI and automation inside their own security operations cut breach costs by an average of nearly $2 million, yet one in four organizations still had not adopted those tools as of the study period. A separate follow-on survey conducted by Ponemon found 85 percent of organizations planned to increase security spending simply after learning about advanced frontier AI capabilities being used by attackers, compared with 64 percent that said the same only after actually experiencing a breach themselves. Even so, a gap remains in where that spending goes: more than half of organizations reported using AI agents for threat detection and containment, but only 18 percent had applied agents to vulnerability management, leaving known software flaws to linger even as AI shortens the window attackers have to exploit them. A separate follow-on study of 456 of the original organizations, conducted in May 2026, found that 78 percent were already aware of specific reports about highly advanced frontier AI models, and three-quarters of respondents said that awareness alone was prompting them to rethink how automated agents get deployed across their own security operations.

Financial Services and Energy Carry the Concentrated Risk

The report found that 62 percent of AI-driven attacks targeted critical infrastructure sectors, with financial services and energy companies experiencing the highest concentration of incidents. Financial services breaches in the study cost an average of $6.3 million, while energy-sector breaches averaged $5.2 million, both well above the overall global average. Because those sectors sit at the center of broader economic and supply-chain networks, the report’s authors warn that a successful AI-driven attack against one target in either industry carries a higher risk of cascading into disruptions well beyond the company that was actually breached. That concentration also helps explain why the overall AI-enabled share of breaches climbed as sharply as it did: attackers appear to be directing automated tools disproportionately at the sectors where a single successful intrusion pays off the most, rather than spreading AI-assisted attacks evenly across industries.

The Access-Control Gap Inside AI Systems Themselves

More than 20 percent of organizations in the study reported a breach that specifically targeted an AI model or application, and the most common causes were not exotic attacks on the models themselves but ordinary weaknesses in the systems surrounding them: compromised APIs, applications or plug-ins accounted for 27 percent of those incidents, and cloud misconfigurations affecting AI workloads accounted for another 27 percent. The full Cost of a Data Breach Report also found that only 37 percent of breached organizations encrypted sensitive data both at rest and in transit, and just 34 percent had visibility into their own cryptographic assets, gaps that predate the rise of AI-enabled attacks but that those attacks are now exploiting more efficiently. Reported ransomware incidents rose as well, to 39 percent of breaches from 34 percent the year before, with attackers increasingly using AI to automate the process and shifting their pressure tactics toward threatening a company’s brand reputation rather than relying solely on encrypting files for ransom. Reputation-based pressure was the most common tactic, cited in 41 percent of ransomware cases in the study, ahead of threats to leak employee data at 35 percent and threats to release intellectual property at 31 percent, a shift that suggests operational disruption alone is no longer viewed by attackers as leverage enough to guarantee payment.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview