What Does a Data Breach Really Cost in 2026?
We will discuss the core key points of Cost of a Data Breach Report by IBM; we will understand and see what the cost of a data breach is and where the money goes. How time matters, how AI is being used, etc.
Most people don’t understand how serious a data breach is. They have different opinions, and most of them don’t know how this happens.
To understand how a data breach occurs, we have covered so many topics on understanding cybersecurity basics; you can learn from them.
The average cost of a data breach in 2026 is $4.99 million; this is the highest ever in 21 years since the report has been running.

What is the Cost of a Data Breach Report?
Every year, IBM and the Ponemon Institute conduct studies and research about the companies that have been breached.
A breach is when a hacker enters a company and steals organizational data such as employee names, customer details, etc.
This year, they studied 602 organizations in 16 countries for breaches that happened between March 2025 and February 2026.
They didn’t survey; instead, they interviewed 3558 people who dealt with those breaches directly. CEOs, security teams, finance heads, and others related to the breach.
So these numbers come from the people who were involved directly and cleaned up the breach.

Where does USD 4.99 million go?
The price of $4.99 million does not go to the hackers. This is the overall price that has cost to the company because of the breach.
The report splits the cost into four parts:
- Detection and escalation: USD 1.64 million. When a breach occurs, we have to find what happened. So the company needs to spend on Forensic experts, audits, and meetings with the board.
- Lost business: USD 1.54 million. Systems go down. Customers leave. People stop trusting the brand.
- Post-breach response: USD 1.36 million. After the data breach, a company needs a team for Lawyers, regulatory fines, and credit monitoring for affected customers.
- Notification: USD 0.45 million. This is where a company notifies its customers about the data breach by Letters, emails, and calls, telling people their data was exposed.
All these costs went up this year. The total rose 12% compared to last year.
Last year, costs dropped for the first time since the pandemic; that was talked about as the defenders are winning, but this year shows it was just a pause.

Does it cost the same everywhere?
The United States is the most affected country, with a breach at $11.5 million. This is more than double the global average cost. Higher fines and higher business costs are the main reasons.
The Middle East (USD 8 million) and Benelux (USD 7.37 million) are next. Benelux includes Belgium, the Netherlands, and Luxembourg.
Costs rose in every country and region in the study.

While compared to other industries, healthcare is the most expensive industry for the 13th year in a row. At USD 6.64 million per breach.
Patient data are valuable to criminals because they can be used for identity theft and insurance fraud.
Financial services were hit hard at $6.29 million.
The public sector remains cheaper still; the cost grew to 22%.

Why does time matter so much?
We have already discussed how time matters in an attack.
The longer a breach lasts, the more it costs.
Here we can split time into two stages
If you want to see the full attack from the attacker’s side, read our post on how cyberattacks work.

Stage 1 — Identify: finding the breach
It took 183 days on average for companies to find that there is a breach.
That is 6 months almost half a year- the attacker is inside, and nobody knows.
Stage 2 — Contain: stopping the damage
It takes another 64 days for the companies to shut down the breach completely.
That brings the total to 247 days, 6 days longer than last year.
So compare it to the money spent. Breaches that took 200 days cost USD 4.32 million. Breaches that took more than 200 days cost USD 5.65 million.
That’s an extra USD 1.33 million for being slow.
If a company’s security team finds the breach, the whole process takes 209 days.
But in 17% of the cases, the companies only find them when an attacker tells them about the breach.
With a ransom note, that breach costs the most, at USD 5.12 million.
Quick summary. Found by your own team = faster and cheaper. Found by the attacker = slower and more expensive.

How are attackers using AI?
The rise of AI in attacks is spiking.
1 in every 4 attacks, AI is used; that is a 56% increase from last year.
People expect AI to write malware for the attacks. But the truth is not that.
The main use is pretending to be someone else.
Deepfakes and impersonation: This accounts for 45% of AI-driven attacks. Everyone knows what a deepfake is. It makes videos or voices made by AI that look and sound like the real person.
AI-enabled malware: 19%. Malware is harmful software; AI now helps to write, build, and run the malware.
AI-generated phishing: 17%. Phishing is an old trick of hacking, where the attacker sends an email with a fake link attached. Read on what phishing is here. Now, AI writes phishing emails and messages.

Can your own AI tools be attacked?
Yes, and this segment has seen a rise.
21% of organizations reported that there was a breach that involved their own AI models. Last year it was 13%.
Model inversion: USD 6.07 million on average. In this, the attacker asks clever questions until the AI reveals its private data.
Prompt injection: USD 5.89 million. The attacker hides instructions in text the AI reads, like an email or a web page. The AI then follows the attacker instead of its owner.

But here is the surprising part. The most common causes were not fancy AI tricks.
They were basic mistakes. Wrong cloud settings. Poorly protected connections between apps, known as APIs.
The report found that 92% of organizations with an AI-related breach did not have proper access controls on their AI. Access control simply means deciding who is allowed to use what.
In other words, many companies left the door unlocked.
Then there is shadow AI. This is when employees use AI tools the company never approved. Think of someone pasting customer data into a personal chatbot account to save time.
Incidents involving shadow AI more than doubled, from 20% to 43%.

Is AI helping defenders too?
Yes, and this is the good news.
Companies that used security AI and automation extensively had breaches that cost USD 4 million on average. Companies that used none paid USD 5.93 million.
That is a saving of USD 1.93 million. They also dealt with breaches 65 days faster.
So what is the problem?
Most companies use AI in the wrong place. They use it to detect and investigate attacks after they start. Very few use it to prevent attacks in the first place.

Half of companies now use AI agents in their security team. An AI agent is an AI that can take actions on its own, not just answer questions. But only 18% of them use agents to find and fix weaknesses in their systems.
That is exactly the job attackers are now giving to AI.
In April 2026, a frontier AI model was announced that found thousands of serious security holes. Some were in every major operating system and web browser. A frontier model simply means one of the most advanced AI models available.
If you want to know why unknown security holes are so dangerous, read our post on what a zero-day is.
If attackers can find weaknesses at machine speed, defenders need to fix them at machine speed. We will discuss AI agents in security in later posts.
You might be thinking: “I’m not a big company. Why should I care?”
Fair question.
Most of these attacks start with a person. A phone call. A text message. A fake video of your boss.
Voice and SMS phishing was the most common way attackers got in. It also led to the most expensive breaches, at USD 5.29 million on average.
Those same tricks work on you at home. The attacker does not care how big you are. They care whether you will click, pay, or share.
A real case: the deepfake video call
In January 2024, an employee in the Hong Kong office of the engineering firm Arup received an email. It appeared to come from the company’s chief financial officer in the UK. It asked for a secret transaction.
The employee was suspicious. That was the right instinct.
So a video call was arranged. On the call were the CFO and several colleagues the employee recognized. They looked real. They sounded real.
Reassured, the employee made 15 transfers to five bank accounts. The total was about HK$200 million, roughly USD 25 million.
Every other person on that call was a deepfake.
The scam was only discovered when the employee later checked with head office. By then, the money was gone.
This is the 45% from the report, in real life. And the fix is almost free. Before moving money, call the person back on a number you already know.
Can we trust these numbers?
Mostly yes.
The study is a benchmark, not a scientific survey. The costs are estimates from the people interviewed, not audited accounts. It also leaves out very large breaches with more than 115,380 records.
Some groups are small, too. Healthcare, the most expensive industry, is only 2% of the sample. That is about a dozen organizations.
A few percentages in the report’s text also don’t match its own tables. For example, the US cost rose from USD 10.22 million to 11.50 million. That is 12.5%, but the text says 11% in one place and 13% in another.
The overall trends are clear. Just check the exact number before you quote it.
What can organizations do?
The report points to four steps:
- Use AI to prevent attacks: Start with finding and fixing weaknesses, not just spotting attacks.
- Protect every identity: This includes non-human identities. These are accounts used by software, like API keys and AI agents. Less than half of companies (46%) secure them in their AI systems.
- Control your AI: Know which AI tools are in use, approved or not. Lock down the settings and connections around them.
- Fix encryption now: Encryption scrambles data so only the right people can read it. 53% of breached companies had not encrypted their sensitive data. Only 26% have started preparing for quantum computers, which may one day break today’s encryption.
Final thoughts
The average breach now costs USD 4.99 million. But the real lesson of this report is not the number.
It is the speed.
Attackers now move at machine speed. Every day a breach goes unnoticed adds to the bill.
For companies, that means using AI to find weaknesses before attackers do. For you, it means slowing down. If a call, a message or even a video asks you to move money or share details, stop and check.
References
- IBM and Ponemon Institute, Cost of a Data Breach Report 2026: The AI tipping point. https://www.ibm.com/reports/data-breach
- CNN, “Finance worker pays out $25 million after video call with deepfake ‘chief financial officer’,” 2024.
- South China Morning Post, report on the Hong Kong deepfake video meeting scam, February 2024. https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage
