
In the U.S., too, the cost per data breach continued to rise: U.S. companies recorded a new record average of 11.5 million U.S. dollars per incident (2025: 10.22 million U.S. dollars). This represents the highest cost per data breach worldwide and is more than double the global average. The Middle East ranks second with an average of $8 million, followed by the Benelux countries in third place with $7.37 million.
AI-Driven Attacks on the Rise
AI was used in more than one in four attacks worldwide—a 56 percent increase over the previous year. Attackers primarily rely on identity theft via deepfakes and AI-powered malware. The use of AI accelerates the pace of attacks, enables a personalized approach to a large number of potential victims, and thus increases the resulting damage to companies.
However, AI and automation are also the most effective tools for mitigating the impact of security incidents. Their use reduces costs by an average of $1.9 million per incident. Despite these advantages, they are not yet widely adopted: 64 percent of companies worldwide use AI and automation technologies only to a limited extent—or not at all—in their security processes.
For the first time, this year’s study examined the use of AI agents in the Security Operations Center (SOC). Here, too, it is evident that companies still rely more on detection and response than on prevention:
- More than 50 percent of the companies surveyed use agents to detect and contain threats.
- Only 18 percent use agents for the preventive management of IT vulnerabilities.
The increasing use of AI creates an economic advantage for cybercriminals: Attacks on IT systems can be launched for just a few thousand U.S. dollars. Stopping the attacks and plugging the data leaks, however, costs the affected companies millions—and this is changing the way companies assess cyber risks.
Advanced AI Is Forcing Companies to Rethink Their Approach
It is time for companies to shift from a reactive to a proactive defense strategy. In a follow-up study by the Ponemon Institute, conducted after the capabilities of advanced Frontier AI became known, 85 percent of companies stated that they now plan to increase their security spending in response to this threat. This compares to just 64 percent who reported in the original survey that they intended to increase their security budgets following a data breach. These findings signal a turning point: companies are beginning to take preemptive action to ward off perceived future risks rather than waiting for a specific incident to occur.
However, a gap remains where attackers are advancing the fastest. As a result, known security vulnerabilities persist while AI shortens the exploitation window. Three-quarters of companies say that frontier AI threats are prompting them to rethink the use of agents in their security operations.
Interfaces Are Vulnerabilities in AI Systems
More than 20 percent of companies worldwide reported data breaches related to AI models or applications. Security incidents occurred at similar rates in open-source and third-party environments. The most common cause was not errors in the AI models themselves, but vulnerabilities in surrounding systems: compromised APIs, applications, or plug-ins (27 percent), as well as misconfigurations in the cloud that affected AI workloads (27 percent).
Among AI-related security incidents, attacks involving model inversion and prompt injection caused the highest losses, averaging $6.1 million and $5.9 million, respectively. More than half of the affected companies reported direct financial losses—more than double the figure from the previous year.
Key findings from the report for Germany:
- Manufacturing companies hardest hit – As in 2024 and 2025, manufacturing companies again reported the highest average costs per data breach. These costs rose to 7.02 million euros (2025: 6.67 million euros), followed by technology companies (5.65 million euros) and the financial sector (5.64 million euros).
- AI use significantly reduces the cost of a breach – Companies that rely extensively on AI and automation in the security sector incur a cost of 3.34 million euros in the event of a breach. Companies that do not use AI and automated security features, on the other hand, pay 4.87 million euros. That represents a measurable savings of 1.53 million euros.
- German companies respond to attacks relatively quickly – data breaches in Germany lasted an average of 160 days in total; with security experts taking an average of 121 days to detect the breach and then 39 days to close it. Globally, the average was significantly higher at a total of 247 days (183 days until detection and then 64 days until the attack was stopped).
- Compromised supply chains are the most common attack vector—in 17 percent of cases, criminals infiltrated corporate systems via the supply chain. Social engineering follows in second place with 16 percent of cases, for example, through attackers fraudulently posing as IT or help desk staff. Phishing via phone or text message ranked third, accounting for 15 percent of all cases.
“The resurgence in the amount of damage suffered by German companies shows that attackers are catching up,” said Christine Barbara Müller, Partner & Head of Security Services DACH at IBM Germany. “They are increasingly relying on advanced AI, thereby partially offsetting the technical advances made by IT security departments in recent years. However, the figures also show that the comprehensive use of AI and automated security features still provides companies with a powerful defense tool: Companies that make full use of these technologies can detect and contain a data breach within just 149 days. If, on the other hand, these technologies are not used at all, it takes up to 185 days to stop the attack. That is a significant difference, resulting in average additional costs of 1.53 million euros. Nevertheless, only 32 percent of German companies are currently making full use of AI and automated security features. Those in charge urgently need to rethink their approach. “Our daily practice proves that this shift in thinking pays off immediately from a business perspective; thanks to increased security maturity, we’ve already been able to realize savings in the millions for the majority of our clients.”
Additional Findings for Other Countries
The Cost of a Data Breach Report 2026 also provides data from France, Italy, the United Kingdom, and the Benelux countries. Here is information on the average financial loss and other findings in these countries:
Average financial loss (in millions of euros):
- United Kingdom – 3.66 (2025: 3.84)
- Italy – 3.55 (2025: 3.31)
- France – 3.49 (2025: 3.59)
- Benelux – 6.35 (2025: 6.00)
Average total duration of data breaches in days:
- United Kingdom – 225 (2025: 210)
- Italy – 187 (2025: 186)
- France – 315 (2025: 284)
- Benelux – 239 (2025: 253
Most common initial attack vector:
- United Kingdom – Phishing (21 percent of all cases)
- Italy – Compromised supply chains (18 percent of all cases)
- France – Social engineering (17 percent; e.g., attackers fraudulently posing as IT or help desk staff)
- Benelux – Social engineering and the misuse of valid IT accounts (both vectors each accounting for 15 percent)
Use of AI-based security and automation solutions (percentage of companies that use these extensively or to a limited extent, according to the report):
- United Kingdom – 74 percent
- Italy – 79 percent
- France – 71 percent
- Benelux – 74 percent
About the Cost of a Data Breach Report
The 2026 report was conducted by the Ponemon Institute and sponsored and analyzed by IBM. It is based on an analysis of data breaches reported by 602 companies worldwide between February 2025 and March 2026. The follow-up study was conducted in May 2026, with 456 of the 602 organizations previously surveyed as part of the CODB study participating. Of these organizations, 78 percent—or 356 companies—were aware of recent reports on sophisticated frontier models.
Additional Information
Download the report here: www.ibm.com/reports/data-breach
– – – – –
Related Links
👉 www.ibm.com
👉 View the report
Photo: IBM