IBM Institute for Business Value · July 2026

Cost of a Data Breach Report 2026

IBM's Cost of a Data Breach Report 2026 (July 2026; 602 breached organizations studied by Ponemon Institute) found that one in four malicious breaches were AI-enabled, costing about $6 million on average versus a $4.99 million global average.

Read the original report ↗Cite2 min read · Summary updated
Average cost per breach by type, 2026USD millions per breach
Model inversion attack
$6.07M
AI-enabled malicious breach
~$6M
Prompt injection attack
$5.89M
All breaches (global average)
$4.99M
Source: IBM, Cost of a Data Breach Report 2026, 2026.

Key findings

  1. 01
    The global average cost of a data breach rose 12% to a record $4.99 million.IBM and Ponemon build the figure from interviews at 602 breached organizations, covering breaches from March 2025 to February 2026.
  2. 02
    One in four malicious breaches were AI-enabled, and AI-driven attacks rose 56%, adding about $1 million per breach.IBM attributes the rise to AI deepfake impersonation and AI-enabled malware.
  3. 03
    Roughly one in five organizations reported an attack on AI models or applications, and 92% of those lacked proper AI access controls.This counts breaches of the organization's own AI systems, separate from attackers using AI.
  4. 04
    Model inversion and prompt injection attacks cost an average $6.07 million and $5.89 million per breach.These were the costliest AI-specific incident types IBM reported.
  5. 05
    Organizations with extensive use of AI and automation in security saved an average $1.93 million per breach.The comparison is against organizations not using these tools; it is an association, not a controlled test.

By the numbers

$4.99Mglobal average cost of a breach
92%of orgs with AI-system breaches lacked proper AI access controls
$1.93Maverage savings with extensive security AI and automation

What it means for you Draft

For executives at $10–100M companies

This is one of the few studies that puts a dollar figure on AI-related security failures, and it points both ways: attackers using AI raise costs, while defenders using AI lower them. For a $10–100M company, the practical steps are basic ones: know which AI tools staff use, and put access controls on any AI system that touches company data. The averages come mostly from larger organizations, so your own exposure may differ.

For practitioners

Inventory AI tools and models in use and apply the same access controls you would to any system holding sensitive data. Test customer-facing AI features for prompt injection before launch.

Limitations

Medium trust.Long-running study with disclosed method and sample, but cost figures are modeled estimates and IBM sells security and AI products.

The sample is breached organizations only, and costs are estimated through interviews using Ponemon's activity-based costing, not audited losses. Savings figures are correlations, and the full report is gated behind a registration form.

About the publisher: IBM sells AI software and consulting.

Cite the original

IBM Institute for Business Value. "Cost of a Data Breach Report 2026." July 29, 2026. https://www.ibm.com/reports/data-breach