Why AI Data Breaches Cost $1 Million More
/ IBM finds the real reason costs surge.
by /
Published: July 29, 2026 at 8:35 AM EDT
Image: Stephanie Smith / TheTweaks
Others
/ IBM finds the real reason costs surge.
Liam Ortiz is a tech journalist who covers AI related big tech and breaking news at TheTweaks. Before joining TheTweaks he worked for almost four years in corporate and national tech news in different companies. Few are quick but Liam is quicker, he breaks news before anyone else and that makes her special. His passion is somewhere connected with profession as his hobby is watching documentary movies.
The annual Cost of a Data Breach Report is back. Again, the cost is higher than ever, but there is one additional nuance. This year, the reason for the rise in the number is different. According to the latest report by IBM and the Ponemon Institute, in 2026, one out of four malicious data breaches was AI-enabled, up from 56% compared to 2025. The total cost of those breaches amounted to roughly $6 million, $1 million more than a typical breach. At first glance, the report paints the picture of smart hackers becoming a major threat. In reality, it tells the story of a slow reaction to the problem by the security forces. (IBM Newsroom)
As one of the details revealed in the report shows, over 50% of companies use AI-powered solutions for threat detection and containment. However, only 18% employ it for vulnerability management. In other words, companies have grown quite good at identifying threats. They haven’t become good at fixing the issues.
It becomes crucial since, thanks to the power of AI, the time between a vulnerability discovery and an exploit is getting shorter and shorter. Hackers no longer have to spend days and even weeks creating a weapon based on a vulnerability found. Automation allows them to do it within hours. Meanwhile, most patching processes are still taking place through a manual process opening tickets, getting approvals, planning the patching window.
Simply put, the issue is that organizations are using a week long solution against a day long attack.
That’s the unpleasant truth behind the Cost of a Data Breach. Report breaches caused by the use of AI are becoming more expensive not so much due to what attackers are doing, but rather what companies are failing to do to counter it.
The industries which are experiencing the biggest financial burden as a result of data breaches are also the most sensitive ones. According to the study, over 62% of AI-based attacks targeted the critical infrastructure, with the financial sector and energy industry taking the majority of the cost of damage. Breaches in the former amounted to an average of $6.3 million. Meanwhile, breaches in the latter resulted in average losses of $5.2 million.
Apart from that, as IBM notes, the breaches of such sectors come with an additional systemic threat: there is a high probability of them having a domino effect and causing economic disruptions in other areas.
Not only is AI becoming a tool for launching an attack, it’s becoming an attack surface. Nearly 20% of organizations experienced a breach targeting the AI model/application. Interestingly enough, in the majority of such cases (27%), the model wasn’t attacked. The targets included compromised API, application and plug in. Similarly, 27% of such attacks involved the cloud misconfigurations of the AI workload.
In other words, companies add powerful tools to infrastructure which wasn’t initially prepared for increased exposure.
Among all the discussions about AI and its impact on cybersecurity, there is a reminder that some problems remain the same. Only 37% of organizations have both encrypted their sensitive data in transit and at rest an alarmingly low number given that data encryption has long been a basic part of security practices. As for the control over the cryptographic assets of the organization, it’s available in just 34% of the cases.
Investment in quantum safe cryptography, as well as other quantum technologies, is increasing. However, it’s built upon the gap in basic data encryption that predates the idea of quantum computing as a threat.
Ransomware continues to evolve the share of such incidents in total breaches has risen from 34% to 39%. What’s changed is the method of pressuring the victim. While shutting down an organization was previously the main way, nowadays, hackers tend to expose the company revealing damaging data (in 41% of cases), leaking data of employees (35%) and threatening to steal intellectual property (31%).
However, there is good news too. Companies which have implemented AI/automation in their security operations have been able to cut the cost of breaches by almost $2 million on average. In addition to saving money, companies should be able to easily prove to their finance departments that it’s worth investing in.
Meanwhile, there is still a quarter of organizations that haven’t adopted the technology at all, leaving a lot of potential on the table.
Another interesting observation in the report is the shift in mindset. 85% of companies noted that their awareness of advanced frontier AI cyber capabilities pushes them to invest more into security higher than 64% who mentioned that a breach forced them to raise budget. For the first time, the fear of something yet to happen became the bigger motivation for security investments than a recent experience.
It’s a big behavioral shift and a sign that corporate boards started seeing AI capabilities as a threat class rather than a tool hackers happen to use.
According to TheTweaks, headline “$6 million” will get the most clicks, the number that should change the companies’ approach to AI is 18%. That’s the percentage of organizations which use AI for vulnerability management as opposed to over 50% for detection. While investing in more advanced alarm systems, companies leave doors unlocked. As long as remediation speed doesn’t catch up with detection speed, breaches caused by AI are going to be more expensive. Not because of the hackers becoming unbeatable, but due to the fact that defenders are focusing on solving the wrong half of the problem. Our take: the Cost of a Data Breach Report of 2026 isn’t an AI story. It’s a patch management story wearing an AI headline.






Tim Cook’s 15 years as Apple’s chief executive officially ended on September 1 and now the torch has been passed on to John Ternus, who is the company’s long-time hardware. It’s Apple’s first leadership change…










Be respectful and constructive. Have a question or feedback? We’d love to hear from you. Contact us at contact@thetweaks.com