IBM today released the 2026 Cost of a Data Breach Report, showing that AI-driven cyberattacks have surged 56% globally over the past year, and these breaches cost an average of $6 million, fundamentally changing the economics of cyber risk. As cybercriminals increasingly leverage AI to automate and amplify attacks, businesses are under growing pressure to keep pace.
More than one in four organisations globally, and 22% in the UK, reported experiencing AI-generated attacks. Despite this risk, the average cost of a data breach for UK organisations decreased to £3.13 million compared with the previous year, suggesting that investments in cyber resilience, detection capabilities and incident response are helping to limit the financial impact when breaches occur.
Deepfake impersonation was the most common AI-enabled attack types (45%), followed by AI-enabled malware (19%) and phishing campaigns (17%). Advances in generative AI are enabling attackers to create highly convincing, targeted campaigns at an accelerated pace, significantly reducing the cost, time, and expertise required to launch attacks at scale.
Further UK findings include:
- The average UK data breach now costs £3.13 million compared with last year’s figure of £3.29 million in 2025. However, the number of records breached has increased slightly to 29,870, (up from 29,000 in 2025).
- Sectors such as financial services (£5.46 million), services (£4.23 million) and energy (£4.03 million) saw the highest breach costs in the UK. Energy and financial services also saw the highest concentration of AI-enabled attacks globally.
- 61% of UK organisations plan to increase cybersecurity investment following a breach, with growing focus on incident response, data protection, and AI governance.
- However, foundational gaps remain, only 32% of UK organisations report using AI and automation in security operations extensively – even as more attackers are levering this technology to scale.
- 62% reported having formal cryptographic controls in place, and 45% plan to increase investment in quantum security following a breach.
Mark Hughes, Global Managing Partner, Cybersecurity Services IBM said: “AI has dramatically lowered the barrier for cybercriminals. Attackers can now execute attacks in minutes rather than days with advanced frontier models. Organisations need to move faster from reactive security to a continuous autonomous defence if they want to keep up.”
The findings highlight a clear imperative: organisations must close the gap between attack speed and defence capability or risk falling further behind. To stay ahead, businesses should focus on the following priorities: establishing clear AI governance, investing in AI-powered security, maintaining visibility across AI deployments, and regularly testing cyber resilience.
Key global findings:
- AI’s Weakest Link. More than 20% of organisations reported a breach targeting AI models or applications. The most common causes were weaknesses in surrounding systems: compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).
- Ransomware Actors Weaponize Reputation. Ransomware incidents rose compared to the year prior (39% vs. 34%), with attackers increasingly using AI to automate and scale. While operational disruption still plays a role, attackers are shifting toward higher impact pressure, most commonly exploiting brand reputation (41%), followed by employee data (35%) and intellectual property (31%).
- Anticipated Risk Drives Earlier Investment. Organisations are beginning to invest in cybersecurity based on emerging threats rather than waiting for an incident to occur. In follow-on research conducted by Ponemon Institute, 85% of organisations reported that they plan to increase security spending after becoming aware of advanced frontier AI cyber capabilities – compared to just 64% that reported in the initial research that they plan to increase security spend after experiencing a breach.
About 2026 Cost of a Data Breach Report
The 2026 report, conducted by Ponemon Institute and sponsored and analysed by IBM, is based on breaches experienced by 602 organizations globally between March 2025 and February 2026. The follow-on study was conducted in May 2026, where 456 organizations of the 602 from the CODB research responded. Of these organizations, 78% or 356 of organizations were aware of recent reports about highly advanced frontier models such as Mythos.
Additional Resources
About IBM
IBM is a leading provider of global hybrid cloud and AI, and consulting expertise. We help clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Thousands of government and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM’s hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently and securely. IBM’s breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and consulting deliver open and flexible options to our clients. All of this is backed by IBM’s long-standing commitment to trust, transparency, responsibility, inclusivity, and service. Visit www.ibm.com for more information.
Media Contact
Rebecca Butler
IBM UK External Communications
rebecca.butler@ibm.com
