Ten Takeaways from IBM’s 2026 Cost of a Data Breach Report

From the Baker Donelson law firm:

IBM has released its annual Cost of a Data Breach Report for 2026. The 21st edition of the report analyzed 602 data breaches experienced by organizations across 17 industries between March 2025 and February 2026. It provides one of the most comprehensive views available of the financial impact of data breaches on organizations around the globe.

This year’s findings reinforce the way that AI-driven attack vectors are, unfortunately, reshaping the economics of a data breach. The proliferation of shadow AI, exponential increase in AI-based attacks, and persistent gaps in fundamental security controls have resulted in new record highs in the average costs of a data breach both globally and domestically. At the same time, organizations that have embraced AI and automation in their security operations continue to realize significant cost savings and faster response times.

Below are ten takeaways from the report along with recommended best practices for organizations seeking to manage the fluid cyber risk landscape.

1. The Average Cost of a Data Breach Reached New Highs in the U.S. and Globally: The global average cost of a data breach reached $4.99 million in 2026, a 12 percent increase over the prior year and the highest figure recorded in the report’s history. In the U.S., breach costs remained more than double the global average at $11.5 million per incident, an 11 percent increase over last year. This upward trajectory continues a trend that accelerated following the pandemic and reflects the compound effect of regulatory complexity, litigation exposure, and increasingly sophisticated attacks targeting organizations based in the U.S.

2. AI-Driven Attacks Increased by 56 percent: Threat actors are weaponizing AI at an alarming pace. More than one in four organizations experienced an attack leveraging artificial intelligence, a 56 percent increase over last year. These AI-driven attacks have added an average of $1 million in costs per incident. According to IBM, most AI-driven attacks focused on critical infrastructure sectors – with financial services and energy organizations leading the way. Among AI attack vectors, deepfake impersonation drove the highest volume (45 percent of AI attacks), followed by AI-enabled malware (19 percent) and AI-generated phishing (19 percent).

3. Ransomware Attacks Rise with Shift to Targeting Brand Reputation: Thirty-nine percent of organizations reported that their systems were hit by ransomware attacks – marking the fourth consecutive year that incidents have increased. However, the threat actors are weaponizing ransomware in new ways. Although sensitive data and personally identifiable information (PII) remain critical targets, 41 percent of ransomware attacks reported that attackers targeted brand reputation, such as public shaming and media leaks. Therefore, while the threats of data theft and operational disruption remain, it’s clear that threat actors are leveraging public forums to apply pressure and extort ransoms.

Read more at Baker Donelson, via JDSupra.