IBM report: One-quarter of data breaches caused by AI attacks, with average loss per incident 20% higher than the mean.

Technology03.Aug.2026 07:253 min read

The latest report from IBM and the Ponemon Institute shows that AI-driven attacks now account for one-quarter of malicious data breaches, a year-on-year increase of 56%. These incidents cost an average of $6 million per breach, which is 20% higher than the overall average cost of a data breach, and 62% of the attacks are concentrated on critical infrastructure.

IBM report: One-quarter of data breaches caused by AI attacks, with average loss per incident 20% higher than the mean.

The latest survey report jointly released by IBM and the Ponemon Institute shows that AI-driven attacks are rapidly becoming a major source of data breaches. The report notes that these attacks now account for one-quarter of all malicious data breach incidents, up 56% from the same period last year. In terms of impact, AI-driven data breaches cause an average loss of $6 million per incident—20% higher than the average cost of data breaches overall.

Attack Targets Are Highly Concentrated, Putting Critical Infrastructure Under Pressure

The report notes that AI-driven cyberattacks are showing a clear trend toward concentration in their targets. Sixty-two percent of these attacks are aimed at critical infrastructure, with financial services and energy organizations being the most heavily targeted sectors.

This means such incidents can affect more than just individual organizations—they may also create ripple effects for economic activity, supply chain stability, and essential public services.

AI Is Changing the Cost Structure of Cyberattacks

According to Suja Viswesan, Vice President of IBM Security Software, what has truly changed is the “economic logic” of cyberattacks: AI makes attacks faster and cheaper, while the cost of data breaches continues to rise.

“What is truly changing is the economics of cyberattacks—AI makes attacks faster and cheaper, while the cost of data breaches keeps climbing.”

The report’s data supports this conclusion. Bringing AI and automation into security operations can save companies nearly $2 million on average in data breach costs, yet one-quarter of organizations still have not deployed these capabilities.

Companies Are Using More AI in Detection, but Still Lag in Remediation

When it comes to AI agents, more than half of organizations are already using them for threat detection and containment. However, only 18% have actually deployed AI agents in vulnerability remediation and management.

This suggests that while many companies have begun using AI to improve discovery and response capabilities, they are still underinvesting in patching vulnerabilities and shortening remediation cycles.

Attacks on AI Models and Applications Are Also Increasing

Beyond traditional data breach risks, intrusions targeting AI models and application systems themselves are also on the rise. The report shows that more than 20% of organizations have experienced such attacks.

The most common contributing factors include:

  • Weak security in surrounding systems

  • Misconfigured cloud platforms

This shows that the security risks facing AI systems do not come only from the models themselves—supporting infrastructure and deployment environments are also critical weak points.

Report Recommendation: Close the Gap Between Vulnerability Discovery and Remediation

Suja Viswesan emphasized that the current priority is to eliminate, as much as possible, the time gap between discovering vulnerabilities and fixing them, while embedding remediation capabilities into the development process to match the speed of AI-driven attacks.

As AI-powered attacks continue to accelerate, defenders that still rely on manual investigation and traditional remediation timelines will often struggle to keep pace with attackers’ rate of penetration. This also means that, going forward, companies must do more than strengthen detection capabilities in their cybersecurity strategies—they also need to make automated remediation and secure development processes core areas of investment.