Reality Check
Four animated briefs built from the IBM/Ponemon Cost of a Data Breach Report 2026 — AI-driven attacks, quantum decryption, stolen data, and data sprawl.
AI-driven attacks
Attackers use AI to write phishing at scale, generate malware, and impersonate people convincingly.MORE THAN 1 IN 4 organizations reported a malicious AI-driven attack this year, a+56% increase over last year. Deepfake impersonation accounted for45% of those attacks; AI-generated malware accounted for 19%.
The attacks concentrate: 62% targeted critical infrastructure, led by financial services ($6.29M average breach cost) and energy ($5.2M). An AI-driven attack adds +$1.0M to the average breach on top of that. Among organizations that had an AI-related breach,92% lacked proper AI access controls, and shadow AI incidents rose to 43% of breaches, averaging $5.39M each.
Defenses are catching up unevenly. Organizations using AI and automation extensively (36% of those studied) contained breaches 65 DAYSfaster and saved $1.93M on average. Security-spending intent moved from64% to 85% once frontier AI model threats entered the picture. Experts project the AI advantage will still tilt +31.7%toward attackers within two years.
- Global average breach cost (2026)$4.99M
- Year-over-year increase in global average breach cost+12%
- Global average breach cost per hour$1,100/HR
- Global average time to identify and contain a breach247 DAYS
- Increase in AI-driven attacks over last year+56%
- Projected AI advantage for attackers within two years+31.7%
- AI-driven attacks using deepfake impersonation45%
- AI-driven attacks using AI-generated malware19%
- Additional cost added by AI-driven attacks+$1.0M
- AI-driven attacks concentrated on critical infrastructure62%
- Average breach cost, financial services$6.29M
- Average breach cost, energy sector$5.2M
- AI-related breaches lacking proper AI access controls92%
- Security incidents involving shadow AI43%
- Average cost of a shadow AI security incident$5.39M
- Organizations using AI and automation extensively36%
- Faster breach containment with extensive AI use65 DAYS
- Cost savings from extensive use of AI and automation$1.93M
- Organizations planning increased security spending after a breach64%
- Organizations planning increased security spending due to frontier AI threats85%
Source: IBM Cost of a Data Breach Report 2026 (Ponemon Institute).
Quantum decryption
A quantum computer capable of breaking today's public-key encryption does not exist yet. That is not the risk. The risk is data captured today and decrypted once one does — "harvest now, decrypt later."53% of breached organizations had not encrypted sensitive data at rest and in motion at the time of the breach; another 10%were not sure.
26% of organizations have a post-quantum cryptography project underway.69% do not, and 5% are unsure. Most organizations (61%) also lack controls to monitor and secure cryptographic objects — keys, certificates, algorithms — across their environment; only34% have them.
Planned investment is moving: quantum-safe security for data and data transfer rose from24% to 31% of security budgets, alongside 33% planning spend on cryptography management tooling. Breach-cost data already rewards the lifecycle-management side of that work: organizations with key, certificate, and secret lifecycle tooling in place saw lower average breach costs, while mismanaged secrets and keys pushed costs higher.
- Breached organizations with sensitive data unencrypted53%
- Breached organizations unsure if sensitive data was encrypted10%
- Organizations with a post-quantum cryptography project26%
- Organizations without a post-quantum cryptography project69%
- Organizations unsure of post-quantum cryptography project status5%
- Organizations lacking controls to secure cryptography61%
- Organizations with controls to secure cryptography34%
- Planned investment, quantum security for data and data transfer, prior year24%
- Planned investment, quantum security for data and data transfer31%
- Planned investment, cryptography management tools33%
- Key lifecycle management tools−$214,923
- Encryption−$213,478
- Certificate lifecycle management tools−$205,265
- Secret lifecycle management tools−$163,668
- Mismanaged secrets and keys+$198,933
Source: IBM Cost of a Data Breach Report 2026 (Ponemon Institute).
Stolen data
Customer PII is the record type attackers take most often. It appeared in52% of breaches this year, ahead of employee PII (35%), anonymized customer data (34%), intellectual property (32%), and other corporate data (24%).
Frequency and price diverge. Intellectual property is stolen less often but costs more per record than any other type — $196, against$192 for customer PII,$188 for employee PII,$179 for other corporate data, and$130 for anonymized customer data. The record attackers take most is not the one that costs the most to lose.
Customer PII's per-record price also moved. It rose from $160to $192 year over year, while its share of breached data held roughly flat, 53% to 52%. The record type attackers already prioritize is getting more expensive to lose, not less.
- Customer PII, share of breached data52%
- Customer PII, average cost per record$192
- Customer PII, share of breached data (2025)53%
- Customer PII, average cost per record (2025)$160
- Employee PII, share of breached data35%
- Employee PII, average cost per record$188
- Anonymized customer data (non-PII), share of breached data34%
- Anonymized customer data (non-PII), average cost per record$130
- Intellectual property, share of breached data32%
- Intellectual property, average cost per record$196
- Other corporate data, share of breached data24%
- Other corporate data, average cost per record$179
Source: IBM Cost of a Data Breach Report 2026 (Ponemon Institute).
Data sprawl
Breached data is not consolidated. This year, 30% of breaches involved data stored on premises, 20% in private cloud,23% in public cloud, and27% spread across all three.
Cost tracks environment count. Public cloud breaches averaged $5.38M, against $4.56M on premises and$4.62M in private cloud. Data breached across all three locations was the costliest of any environment, at $5.39M.
Detection speed follows the same pattern. Private cloud breaches were identified and contained fastest, in240 DAYS. Data breached across all three locations took longest to resolve, at 256 DAYS. On-premises breaches averaged244 DAYS; public cloud, 251 DAYS. Sprawl is both the most expensive environment to be breached in and the slowest to recover from.
- On-premises storage, share of breaches30%
- On-premises storage, average breach cost$4.56M
- On-premises storage, mean time to identify182 DAYS
- On-premises storage, mean time to identify and contain244 DAYS
- Private cloud storage, share of breaches20%
- Private cloud storage, average breach cost$4.62M
- Private cloud storage, mean time to identify178 DAYS
- Private cloud storage, mean time to identify and contain240 DAYS
- Public cloud storage, share of breaches23%
- Public cloud storage, average breach cost$5.38M
- Public cloud storage, mean time to identify184 DAYS
- Public cloud storage, mean time to identify and contain251 DAYS
- Data breached across all three storage locations, share of breaches27%
- Data breached across all three storage locations, average breach cost$5.39M
- Data breached across all three storage locations, mean time to identify189 DAYS
- Data breached across all three storage locations, mean time to identify and contain256 DAYS
Source: IBM Cost of a Data Breach Report 2026 (Ponemon Institute).