Artificial intelligence is making cyberattacks much more accessible to evildoers. You no longer need to be some computer genius. Hell, any knucklehead with a device and ill-intent in his heart can arguably launch an attack. And sadly, for businesses dealing with the aftermath, the bill keeps getting larger and larger.
IBM’s 2026 Cost of a Data Breach Report found that more than one in four malicious breaches were enabled by AI, a 56 percent increase compared with last year.
Those AI-driven breaches cost companies an average of $6 million each. That is roughly $1 million more than the global average cost of a data breach, which climbed to a record $4.99 million.
IBM says deepfake impersonation and AI-enabled malware accounted for much of the increase. Attackers can use AI to create more convincing phishing messages, impersonate executives, modify malware, and scale campaigns with less time and expertise.
The result is an uncomfortable imbalance. Cybercriminals can automate more of their work, while companies still have to spend heavily on detection, containment, system recovery, legal response, regulatory issues, and customer support.
“What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” said Suja Viswesan, vice president of IBM Security Software.
“The priority now is to eliminate that lag, building remediation into development workflows, securing identity at runtime, and fixing risks at the speed attackers are already moving.”
AI can also help defenders, assuming companies actually use it properly.
Organizations that extensively used AI and automation in security operations reduced breach costs by an average of $1.93 million. They also shortened the time needed to identify and contain a breach by 65 days.
Adoption remains uneven, though. Only 36 percent of breached organizations said they extensively used AI and automation across prevention, detection, investigation, and response. About one in four had not adopted the technology in security operations at all.
Companies also appear more willing to use AI after an attack begins than to prevent one.
More than half of organizations using AI agents in security deployed them for threat detection, response, and containment. Only 18 percent used agents for vulnerability scanning and management.
That is a strange place to fall behind. Finding an attack quickly matters, but fixing known vulnerabilities before criminals exploit them should be just as important.
Attackers are not only using AI. They are targeting it too.
More than 20 percent of organizations reported a breach involving an AI model or application. Many of those incidents were tied to compromised APIs, vulnerable applications, plug-ins, and cloud misconfigurations rather than a flaw in the model itself.
IBM also found that 92 percent of organizations experiencing an AI-related breach lacked proper AI access controls. Only 40 percent said they used access controls for AI models and data.
That suggests some companies are rushing to deploy AI without securing the systems around it. An expensive AI platform does not help much when weak permissions, exposed APIs, or poorly configured cloud services create an easy path inside.
Critical infrastructure faced a particularly high concentration of AI-driven attacks, accounting for 62 percent of the incidents examined by IBM.
Financial services companies experienced average breach costs of $6.29 million, while energy companies averaged about $5.2 million. Problems in either sector can spread beyond one business, especially when payments, supply chains, or essential services are disrupted.
Basic security problems also remain unresolved.
Only 37 percent of breached organizations said they encrypted sensitive information both at rest and in transit. More than half said they did not, while another 10 percent were unsure.
AI may be the headline, but that number is just as troubling. Some organizations apparently cannot even say with confidence whether their most sensitive data is protected.
Ransomware incidents also increased from 34 percent to 39 percent. IBM says criminals are using AI to automate and expand campaigns, while placing more pressure on victims through threats involving brand reputation, employee information, and intellectual property.
The report is based on breaches experienced by 602 organizations between March 2025 and February 2026. Ponemon Institute conducted the research, while IBM sponsored and analyzed it.
AI is clearly making cyberattacks easier to scale, but companies should not use that as an excuse for poor security. Weak access controls, unpatched vulnerabilities, exposed APIs, and missing encryption remain familiar problems.
Businesses racing to adopt AI without fixing those basics may simply be giving attackers a larger and more expensive target.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz