AI-Powered Cyberattacks: Why 2026 Data Breaches Cost More Than Ever
A hacking group calling itself ExfilSquad didn’t need months of reconnaissance to pull off AI-Powered cyberattacks on one of the UK’s messiest breaches this year. In early August, it leaked the names, agencies, and work emails of more than 100,000 police staff and government contacts lifted from the Police National Legal Database. No ransom note, no drawn-out negotiation — just a dump on the dark web and a scramble across multiple government departments to assess the damage.
That’s the pattern showing up across breach reports this year. Attacks are getting faster and cheaper to launch, while the cleanup keeps getting more expensive. IBM’s newly released 2026 Cost of a Data Breach Report puts a number on that imbalance, and it’s not a small one.
Why AI-Powered Cyberattacks Are Reshaping the Economics of Cyber Risk
According to the report, one in four malicious breaches this year were AI-enabled — a 56% jump over last year. Those breaches cost companies $6 million on average, roughly $1 million more than the overall global breach average of $4.99 million, which is itself a 12% year-over-year increase and a new record high.
Most of these AI-driven incidents relied on deepfake impersonation and AI-generated malware — tools that used to require serious technical skill and now come pre-packaged for anyone willing to pay for them. Suja Viswesan, VP of IBM Security Software, summed up the shift bluntly in the report: attacks are getting faster and cheaper while breaches keep getting more expensive, and that gap between discovery and remediation is exactly where the costs pile up.
It’s not evenly spread, either. Critical infrastructure absorbed 62% of AI-driven attacks, with financial services and energy the hardest hit. Financial services breaches averaged $6.3 million; energy breaches averaged $5.2 million. When the target is a bank or a power grid, the ripple effects reach a lot further than one company’s balance sheet.
India’s Breach Costs Are Climbing Even Faster
The regional picture backs this up. IBM’s companion report on India found the average cost of a data breach there hit an all-time high of ₹25.5 crore (about $3 million) in 2026, up nearly 16% from the year before. Breach scale grew too, with 39,500 records compromised per incident on average.
The report flagged something worth sitting with: 68% of Indian organizations surveyed still have limited or no use of AI and security automation in their defenses. Companies with no automation paid ₹31.6 crore per breach on average, compared to ₹21.3 crore for those using it extensively — a gap of roughly ₹10 crore that automation alone accounted for.
The Part Nobody Wants to Admit: AI Helps Both Sides
Here’s the twist IBM’s data keeps surfacing: organizations that lean into AI and automation for their own security operations consistently pay less when something goes wrong. Companies using these tools extensively cut breach costs by close to $2 million on average, and detection windows shrink dramatically — India’s fully automated organizations identified breaches in 175 days versus 236 days for those with no automation at all.
The problem is adoption is lopsided. More than half of surveyed organizations use AI agents for threat detection and containment, but only 18% apply them to vulnerability management. That’s a real gap, because it means known weaknesses sit unpatched even as attackers use AI to find and exploit them faster than ever. IBM’s report notes that three-quarters of organizations are now rethinking how they deploy security agents specifically because of frontier AI threats — which suggests most companies know they’re behind and are scrambling to catch up.
How to Defend Your Business Against AI-Powered Cyberattacks
None of this means AI adoption is optional at this point, on either side of the fight. A few places to start, based on what the data shows actually moves the needle:
Close the vulnerability management gap
If your security team uses AI for detection but still patches vulnerabilities manually, that’s the exact seam attackers are exploiting. Extending automation into patching and remediation, not just alerting, is where the report suggests the biggest wins are sitting unclaimed.
Treat deepfakes and AI-generated phishing as a training priority
Voice and video impersonation attacks aren’t a novelty act anymore — they’re a leading initial attack vector. Regular, realistic training that includes deepfake scenarios (not just text-based phishing) matters more this year than it did last year.
Invest in offensive security testing
IBM’s India findings singled out red teaming and penetration testing as the single largest cost-reducing factor in the region, saving organizations an average of ₹2.47 crore per breach. Finding your own weak points before someone else does still pays off.
Encrypt everything, and know where your data lives
Only 37% of breached organizations in the global study had sensitive data encrypted both at rest and in transit, and just 34% had visibility into their cryptographic assets. These are unglamorous basics, but they’re consistently cheaper to fix in advance than after a breach.
The Bottom Line
The PNLD leak, the record numbers out of India, and IBM’s global data all point to the same reality: AI hasn’t just changed who’s attacking — it’s changed the math behind every breach. The businesses coming out ahead aren’t the ones avoiding AI, they’re the ones using it as aggressively in defense as attackers are using it in offense. Given that 85% of organizations now say they’re increasing security spending simply because they’re aware of what frontier AI can do — before any breach even happens — that shift in mindset seems to be catching on.
Read more tech related content here.
