AI is drastically lowering the technical and cost barriers to cyberattacks, while the cost to businesses for data breaches grows heavier. IBM's (NYSE: IBM) latest '2026 Cost of a Data Breach Report' shows that one in four malicious data breaches involves AI technology, with incident numbers rising 56% from the previous year. The average loss per incident is $6 million (approximately NT$195 million), about $1 million more than typical data breaches. More alarmingly, 62% of AI-driven attacks target critical infrastructure, with financial services and energy industries attacked most frequently.
IBM warns that deepfake impersonation and AI-powered malware are changing the 'economic structure' of data breaches. Hackers can use AI to shorten attack preparation time, reduce costs, and even automate and scale attacks. However, victimized enterprises still bear the costs of incident investigation, system recovery, operational disruption, regulatory compliance, and reputational damage—creating an asymmetric situation where hackers may invest only thousands of dollars, while companies face multi-million-dollar losses.
AI Rewrites Attack Economics: Speed of Vulnerability Remediation Is Key
"What's changing is the economics of cyberattacks. AI makes attacks faster and cheaper, but the losses from security vulnerabilities are growing larger," said Suja Viswesan, Vice President of Security Software at IBM. She noted that the longer the time gap between a company discovering a vulnerability and completing remediation, the more this imbalance directly reflects in data breach costs.
She emphasized that the top priority for enterprises is to shorten this 'time lag,' including integrating remediation mechanisms into software development processes, strengthening identity security during system operation, and addressing risks with the same mindset and speed as hackers.
However, IBM's survey shows that while organizations have started using AI for threat detection, their vulnerability management speed has not kept pace. Over half of the surveyed organizations already use AI agents for threat detection and defense, but only 18% apply AI agents to vulnerability management.
In other words, companies may be able to 'see' attacks faster, but not necessarily fix them at the same speed. While hackers use AI to shorten the time to find, test, and exploit vulnerabilities, known internal vulnerabilities may persist for long periods due to development processes, responsibility divisions, or system dependencies, further widening the gap between attack and defense speeds.
62% Target Critical Infrastructure: Financial Sector Loses Over $20 Million per Breach
By industry, AI-driven attacks are clearly concentrating on critical infrastructure. The report shows that 62% of related attacks target critical infrastructure, with financial services and energy industries attacked most frequently.
Among them, the financial services sector suffers an average loss of $6.3 million per data breach, equivalent to approximately NT$204 million; the energy sector averages $5.2 million, or about NT$169 million.
Since financial and energy industries drive payments, capital flows, electricity, and energy supply, a large-scale intrusion could impact not just a single enterprise but spread outward to supply chains, financial transactions, and essential public services, increasing the risk of systemic outages and cascading disruptions.
AI Not Just for Attacks: Enterprise AI Models Themselves Become New Entry Points
As enterprises accelerate the adoption of generative AI and AI agents, AI is not only a tool for hackers to launch attacks but also the AI models and applications deployed by enterprises themselves that are becoming new attack targets.
The report shows that over 20% of surveyed organizations reported their AI models or AI applications had been attacked, resulting in data breaches. However, the actual breached components are not necessarily the core of the AI model—more risks stem from peripheral systems and integration environments.
In related incidents, the rate of API, application, or plugin compromise was 27%, and misconfigured cloud settings affecting AI workloads also accounted for 27%. This reflects that if enterprises pursue rapid AI application deployment without simultaneously managing identity permissions, API integration, plugin sources, and cloud configurations, the larger the scale of AI deployment, the more attack surfaces may expand.
Adopting AI Security Automation Can Reduce Data Breach Costs by $2 Million
While AI accelerates hackers' attack speed, it can also become a defensive tool for enterprises to reduce losses. IBM research shows that organizations using AI and automation to strengthen security operations can reduce the average cost per data breach by $2 million, equivalent to approximately NT$64.91 million.
However, despite the clear cost difference, one in four surveyed organizations has not yet adopted AI and automation tools in security operations.
A follow-up survey conducted by the Ponemon Institute further found that 85% of surveyed organizations have noticed next-generation AI security solutions and plan to increase related investments; three-quarters also said that innovative AI threats are prompting enterprises to rethink how to deploy AI agents across their entire security operations.
This means the issue enterprises will face next is not just whether to adopt AI security tools, but how to integrate threat detection, vulnerability remediation, identity management, and software development processes—ensuring AI does not become merely a point detection tool but actually reduces risk exposure time.
Ransomware Shifts to Target Corporate Reputation: Basic Encryption Governance Still Lacking
Beyond AI-driven attacks, ransomware tactics are also expanding. The report shows that the proportion of organizations experiencing ransomware attacks has risen from 34% the previous year to 39%. As hackers use AI for automation and scale attacks, their extortion methods are no longer limited to encrypting files or disrupting operations.
The most common way hackers pressure enterprises is through brand reputation, accounting for 41%; followed by employee data at 35%, and intellectual property at 31%. The impact of ransomware attacks has extended from information systems to corporate trust, talent relationships, and long-term competitiveness.
On the other hand, existing data encryption governance within enterprises still has clear gaps. Among surveyed organizations that experienced data breaches, only 37% encrypted both at-rest and in-transit sensitive data; only 34% clearly understood their own encryption asset status. At a time when quantum computing may threaten existing encryption mechanisms, many enterprises have not even completed basic encryption asset inventories.
The '2026 Cost of a Data Breach Report' was conducted by the Ponemon Institute, sponsored and analyzed by IBM, covering 602 organizations globally that experienced data breaches between March 2025 and February 2026. A follow-up survey was conducted in May 2026, with 456 organizations responding.
FACT BOX
- Source: PR Times
- Category: Survey