News
AI-Powered Cyberattacks Surged 56 Percent, IBM Report Finds

IBM's latest Cost of a Data Breach report shows AI-assisted malicious data breaches rose 56 percent year over year, with such incidents now costing companies an average of one million dollars more than a typical breach.
Contents
IBM has published the latest edition of its annual Cost of a Data Breach report, and the findings show that artificial intelligence has stopped being a mere add-on to cyberattacks and become their main accelerator. The number of malicious data breaches involving AI rose 56 percent year over year, with one in four recorded attacks now relying on tools built on language models.
A new attack economy
The report, prepared by the Ponemon Institute on IBM's behalf, draws on data from 602 organizations worldwide that experienced data breaches between March 2025 and February 2026. It is one of the largest studies of its kind in the industry, and the first edition in which the authors treat AI-assisted attacks as a separate, measurable category distinct from those carried out using conventional methods.
The conclusions are unambiguous: artificial intelligence is lowering the barrier to entry for criminals. Automating target reconnaissance, generating convincing phishing messages, or tailoring malware to a specific victim's environment used to require an experienced team, but today these tasks can be handed to a language model in a matter of minutes.
The economics of cyberattacks are changing. AI is making attacks faster and cheaper, while breaches themselves are becoming ever more costly - Suja Viswesan, Vice President, IBM Security Software
The bill for an AI-assisted breach
The global average cost of a data breach reached $4.99 million in this year's edition of the report, marking a 12 percent year-over-year increase and a new record in the study's history. But for attacks involving AI, the cost climbs to $6 million, a million more than the average across all incidents covered by the study.
The sectoral differences are even starker. AI-involved breaches in the financial sector cost an average of $6.3 million, and $5.2 million in the energy sector. Critical infrastructure proved to be the main target, accounting for 62 percent of all AI-assisted attacks recorded during the study period.
Defenders are using AI too
The report also shows the other side of the coin. Organizations that have deployed AI and automation on the defensive side, in incident detection, log analysis, or alert response, cut the average cost of a breach by nearly $2 million compared to companies without such tools. This suggests the technological edge is not one-sided, but rather depends on how quickly each side of the fight adopts these tools.
IBM also conducted a supplementary follow-up study in May 2026 among 456 of the 602 originally surveyed organizations. It found that 78 percent of respondents are already familiar with advanced frontier-class models and regard them as a real source of risk, not merely a theoretical threat of the future.
What it means for companies in Poland
For Polish businesses and security teams, the report is another signal that investments in basic cybersecurity hygiene, multi-factor authentication, identity management, and prompt patching of actively exploited vulnerabilities, are losing relevance more slowly than one might expect in the AI era. The growing automation of attacks means security teams have less time to react before an incident escalates into a full-blown data breach.
85 percent of the companies covered by the study said that after learning the scale of AI-related threats, they plan to increase their cybersecurity budgets. That share is markedly higher than in previous editions of the report, showing that the issue is no longer treated as a distant technological risk but has become a line item in companies' current financial planning.
IBM's findings fit into a broader trend described in recent months by other research organizations and technology companies warning about the growing autonomy of AI-based offensive tools. The scale and pace at which such attacks are increasing mean the topic is likely to keep surfacing in industry reports for many months to come.


