The average cost associated with data breaches has surged to nearly $5 million, reflecting a significant increase in the financial repercussions borne by organizations following cyber incidents over the past year. This alarming statistic emerged from the latest study, the 2026 edition of the annual IBM Cost of a Data Breach Report, which was made public on July 29. The report is based on a thorough analysis of breaches experienced by 602 organizations worldwide from March 2025 to February 2026, underscoring the growing threats posed by cybercriminals.
According to the findings presented by IBM, the global average cost of a data breach saw a 12% rise in the past year, landing at a record $4.99 million (£3.75 million). One of the central contributors to the financial strain of such breaches is the lost business costs incurred when operations are disrupted. These interruptions prevent organizations from offering their products or services, and the long-term loss of customer trust can stifle recovery efforts once a breach has occurred.
Notably, cybercriminals are evolving their strategies, understanding that the potential for loss of customer trust significantly elevates the stakes for organizations. This understanding has influenced their tactics, particularly in the realm of ransomware and extortion attacks. While the traditional approach of encrypting systems to disrupt operations remains prevalent, attackers are increasingly employing diverse methods to exert pressure on their victims. They employ threats of reputational damage should details of an incident become public, further complicating the decision-making process for organizations contemplating whether to pay a ransom.
The report highlights that a staggering 41% of organizations that fell victim to ransomware attacks reported that attackers threatened to damage their brand reputation by exposing customer data or preventing service delivery as a tactic to compel them to pay the ransom. The report concludes that this trend marks a significant shift from solely technical disruptions to multilayered extortion strategies that target trust, public perception, and the far-reaching impacts of business operations.
In terms of costs across different sectors, healthcare emerged as the primary target for cyber incidents, marking the 13th consecutive year that it experienced the highest average breach costs at an alarming $6.6 million. The report warns that attackers continue to place a high value on personal identifiable information (PII) from patients, which can be exploited for identity theft, insurance fraud, and various financial crimes. Following the healthcare industry, the financial sector incurred costs averaging $6.3 million, while the industrial sector and the technology industry recorded an average cost of $5.5 million each. The entertainment sector rounded out the top five, with average costs hitting $5.4 million.
The report also alerts organizations to the increasing prevalence of AI-powered attacks, noting the rise of artificial intelligence and advanced large language models (LLMs) in shaping the cyber threat landscape. Data revealed that over one in four organizations that experienced a malicious attack reported it was driven by AI—this marks a staggering 56% increase compared to the previous year. Victims noted that AI-driven threats included deepfake impersonation and AI-enabled malware, both of which significantly contributed to the overall financial burdens of breaches. The report estimates that AI-driven attacks add an average of $1 million per breach, revealing the substantial impact of this emerging technology on cybersecurity threats.
Mark Hughes, global managing partner for cybersecurity services at IBM, emphasized the urgency with which organizations need to respond to these evolving threats. He stated that AI has dramatically lowered the barriers for cybercriminals, enabling them to execute attacks in mere minutes rather than days. Hughes advocated for a shift from reactive security measures to continuous autonomous defenses in order to keep pace with the evolving landscape.
In light of the increasing risks associated with AI-based cyber threats, the study indicates that organizations are preparing to bolster their cybersecurity strategies. Approximately 85% of respondents expressed plans to increase their security spending in response to threats posed by frontier AI models.
IBM has provided several recommendations for organizations aiming to preemptively guard against data breaches. Monitoring data flow—both its entry, transformation within, and exit from systems—can significantly enhance an organization’s ability to identify sensitive data exposure risks proactively. Additionally, establishing robust governance and compliance frameworks, along with a steadfast commitment to a zero-trust cybersecurity model, are crucial actions organizations should undertake to enforce trusted identity controls. Such measures are essential to effectively monitor for potentially malicious behavior, especially in the context of identity-based attacks.

