← All posts / Research

One in Four Breaches Is Now AI-Enabled: 2026's Cyber Attack Surge, by the Numbers

IBM and the ITRC report record breach volumes and AI-driven attack costs in 2026 — deepfakes, malicious insiders, and a widening asymmetry between attackers and defenders.

One in Four Breaches Is Now AI-Enabled: 2026's Cyber Attack Surge, by the Numbers

Two reports published this month paint the same picture from different angles: 2026 is shaping up to be the worst year on record for data breaches, and artificial intelligence is now a structural part of the problem — and, unevenly, part of the defense.

On August 14, CNBC reported on the Identity Theft Resource Center’s (ITRC) half-year tally: 1,803 reported data compromises in the first six months of 2026, up from 1,732 in the same period last year. If the second half stays on pace, 2026 will blow past the 3,321 incidents recorded for all of 2025. Behind those incidents sit more than 471 million victim notices — a figure that already exceeds the 297.5 million notices issued in all of 2025. A single incident at the education platform Canvas accounted for 275 million of them.

The same week’s reporting circles back to IBM’s 2026 Cost of a Data Breach Report, released July 29, and its headline finding: one in four malicious breaches was AI-enabled between March 2025 and February 2026 — a 56% jump over the prior year.

The economics have flipped

The IBM report, conducted by the Ponemon Institute across 602 organizations globally, quantifies a shift that security teams have felt intuitively for the past two years. AI-enabled breaches — driven mostly by deepfake impersonation and AI-enabled malware — cost an average of $6 million, roughly $1 million more than the global breach average of $4.99 million.

“What’s changing is the economics of cyberattacks,” said Suja Viswesan, VP of IBM Security Software. “AI is making attacks faster and cheaper, while breaches keep getting more expensive. When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs.”

That asymmetry — attacks that cost thousands to launch versus breaches that cost millions to remediate — is the report’s central thesis. Attackers are automating reconnaissance, phishing generation, and social engineering at scale, while defenders still pay per incident.

The AI stack itself is under attack

Perhaps the more novel finding: more than 20% of organizations reported a breach targeting their own AI models or applications. The root causes were rarely the models themselves. The most common vectors were the surrounding systems — compromised APIs, applications, or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%).

In other words, enterprises rushing to deploy AI are creating a new attack surface faster than they are hardening it. And the follow-on Ponemon study conducted in May 2026 found that 78% of the 456 responding organizations were aware of recent reporting on highly advanced frontier models — with 85% saying they plan to increase security spending after learning about advanced frontier AI cyber capabilities, versus just 64% who increase spend after actually experiencing a breach. Fear of frontier AI, it turns out, is a stronger budget motivator than being breached.

Critical infrastructure in the crosshairs

Sixty-two percent of AI-driven attacks in the IBM study targeted critical infrastructure sectors, with financial services and energy hit hardest. Financial services breaches averaged $6.3 million; energy breaches averaged $5.2 million. The concentration matters beyond the direct costs: cascading failures across financial networks, power grids, and supply chains are the systemic-risk scenario regulators worry most about.

Ransomware actors, meanwhile, are weaponizing reputation rather than just encryption. Reported ransomware incidents rose to 39% of breaches from 34% a year earlier, with attackers using AI to automate and scale their operations. The most common extortion lever was brand reputation damage (41%), followed by employee data (35%) and intellectual property (31%).

The insider problem, supercharged

The ITRC data adds a quieter but equally striking trend: 21 incidents in the first half of 2026 involved “malicious insiders,” up from just three in all of 2025. ITRC president James Lee noted that insiders have never been a major breach source historically — “we’ve never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months.”

Two drivers stand out. First, laid-off employees “stealing information on their way out the door” — a grim side effect of the tech industry’s ongoing restructuring. Second, and flagged by the report as “arguably the most significant structural driver,” is the North Korean IT worker scheme: remote employees placed inside U.S. companies using stolen identities, deepfake video during interviews, and AI-generated résumés. The same generative tools that power legitimate productivity are powering industrial-grade infiltration.

Detection is getting worse, not better

A troubling data point buried in the ITRC report: only 24% of breach notices sent to consumers in the first half of 2026 included details of what actually happened, down from 93% in 2021. Lee attributes the decline to litigation risk — companies now disclose only the minimum their state requires. “Where you live determines if you find out about a breach, and if you do find out, what you’re told,” he said. The absence of a uniform national disclosure standard means the true scale of AI-driven compromise is almost certainly undercounted.

The defense side of the ledger

The news is not uniformly bad. Organizations using AI and automation extensively in security operations cut breach costs by an average of nearly $2 million. Yet one in four organizations still haven’t adopted these tools at all. Adoption is also uneven across functions: over 50% of organizations use AI agents for threat detection and containment, but only 18% apply them to vulnerability management — leaving known exposures open even as AI shortens the window between a bug’s discovery and its exploitation. Three-quarters of organizations say frontier AI threats are prompting them to rethink how agents are deployed across security operations.

Legacy hygiene gaps compound the problem: only 37% of breached organizations encrypt sensitive data both at rest and in transit, and just 34% have visibility into their own cryptographic assets — a weak position as quantum-safe migration deadlines approach.

Boardrooms are responding, at least on paper. A Deloitte/Center for Audit Quality survey ranks cybersecurity as a top-three priority for 93% of public-company audit committees, and PwC’s global survey found 78% of 3,887 executives across 72 countries planning cybersecurity budget increases over the next 12 months.

The takeaway from the 2026 data is uncomfortable but clarifying: AI did not invent cybercrime, but it has collapsed the cost and skill barriers to executing it, while the defensive half of the ecosystem still runs on human-speed remediation. Closing that gap — automating patching, securing identity at runtime, and governing the AI systems organizations themselves deploy — is no longer a differentiator. It is the baseline cost of operating in 2026.