Every year, IBM and the Ponemon Institute pull back the curtain on what a data breach actually costs, and every year, the number gets harder to look away from. In 2026, the global average climbed to $4.99 million, a 12% jump from last year. In the U.S., it's more than double that at $11.5 million per breach.
In the case of the Cost of a Data Breach Report 2026, you can judge a book by its cover. IBM branded this year's edition "The AI Tipping Point," and it's not just a headline, AI's fingerprints show up in nearly every finding in the report. Here are seven that stood out, and what closing the gaps they expose will actually take.
1. Phishing Is Still Attackers' Favorite Way In
For all the buzz around AI-driven attacks, the oldest trick in the book is still the most common one. Phishing, including voice and SMS phishing, leads as the top attack vector across all industries, with an average breach cost of $5.29 million, the highest among all attack vectors. Attackers are also using AI to write better lures, AI-generated phishing showed up in 19% of AI-driven attacks this year.
What this means for you:
- Employees can be your first line of defense or your biggest vulnerability, so ongoing phishing simulation and security awareness training matters more as AI makes lures harder to spot.
- A single click still opens the door, so prevention has to happen before the message lands in an inbox.
2. Shadow AI Incidents More Than Doubled
IT and AI councils may be trying to approve AI tools, but many employees are experimenting with them on their own, and that habit caught up with a lot of organizations. Shadow AI, where employees use unapproved AI, was involved in 43% of security incidents, up from just 20% the year before. And only 38% of organizations have strict approval processes for deploying AI tools, which is a 7% dip from last year.
What this means for you:
- Shadow AI is a data visibility problem; you can't govern data you don't know is moving into a chatbot or plug-in.
- Classifying sensitive data before it reaches an AI tool gives you a chance to stop the exposure before it happens.
3. Deepfake Impersonation Is Fueling the AI Attack Surge
More than one in four organizations experienced a malicious, AI-driven attack in 2026, a 56% increase over last year. Deepfake impersonation drove the highest volume, making up 45% of these attacks. Because gen AI makes social engineering cheap to create and hard to detect, attackers are increasingly using these tactics to trick users and bypass identity controls. AI-generated malware, responsible for 19% of AI-driven attacks, is also becoming more common; altogether, these AI-driven attacks added an average of $1 million to the cost of a breach.
What this means for you:
- Attackers impersonating your brand, executives, or domain is no longer an outlier but a leader of AI-driven crime.
- Monitoring for fraudulent domains, fake social accounts, and malicious apps impersonating your business must be continuous.
4. Only 37% of Organizations Fully Encrypt Sensitive Data
Basic security hygiene is still lagging behind. Cost of a Data Breach Report 2026 found only 37% of breached organizations encrypt sensitive data both at rest and in transit when they were breached, meaning nearly two-thirds have a gap somewhere in their encryption coverage.
What this means for you:
- You can't encrypt, classify, or control what you can't find, so data discovery has to come first.
- Encryption gaps are a fixable problem as closing them removes one of the most common ways attackers turn a compromise into a costly breach.
5. AI Is Deployed to Detect Attacks, Not Prevent Them
More than half of breached organizations have deployed AI agents for threat hunting, response, and containment. But only 18% are using AI agents for vulnerability scanning and management, the proactive work of finding and closing gaps before anyone gets in.
What this means for you:
- Offensive security testing, actively probing your own environment for exploitable weaknesses before attackers do, closes exactly the gap flagged in the report.
- If your AI investment is entirely focused on your security operations center (SOC) and none on finding vulnerabilities first, you're defending against yesterday's attackers, not today's.
6. AI and Automation Save Nearly $2 Million
Organizations using AI and automation across their security operations paid $1.93 million less per breach and contained incidents 65 days faster than organizations using none. Yet the overall average time to identify and contain a breach actually rose to 247 days this year, reversing five years of improvement.
What this means for you:
- The gap between organizations that use AI and automation well and those that don't is widening and the cost difference proves it.
- An integrated approach to security beats a patchwork of point tools, because the organizations winning here aren't using AI in one corner of the security stack, they're using it everywhere.
7. A Single AI Model Rewrote the Vulnerability Timeline
Cost of a Data Breach Report 2026 opens with the story of how in April 2026 “a frontier model that managed to find thousands of high-severity vulnerabilities — including some in every major operating system and web browser — is a signal warning to security teams. In the hands of attackers, these tools will collapse the time between vulnerability discovery and exploitation. Attackers are abandoning human speed for machine speed.”
Organizations are taking the warning seriously, seemingly more seriously than they take real breaches: 85% said they plan to increase security spending after learning about frontier AI capabilities, compared to just 64% who said the same after actually experiencing a breach.
What this means for you:
- The gap between “a vulnerability exists” and “a vulnerability gets exploited” is shrinking to nearly nothing, which means scanning once a quarter, or even once a month, is no longer a defensible cadence
- The fact that a hypothetical future threat motivates more spending than a real, lived breach tells you something important teams already sense that the old assumptions about attacker speed no longer hold, and vulnerability management can't stay reactive.
The Bottom Line
On their own, none of these findings are shocking. Phishing works, shadow AI is spreading faster than governance can keep up, and basic hygiene like encryption still gets skipped. What's new is the speed at which AI is compressing the time attackers need to exploit all of it.
The organizations closing that gap aren't necessarily spending more, they're spending smarter. The data backs this up: organizations using AI and automation extensively saved $1.93 million per breach and closed incidents 65 days faster than organizations using none. The common thread across every finding here is the same one Cost of a Data Breach Report 2026 points to: security that works in silos leaves exactly the gaps attackers are now exploiting.
Turn These Findings Into Action
Every organization’s security gaps look different. Fortra can help you identify where sensitive data, vulnerabilities, human risk, and external threats create exposure, then determine which protections align with your priorities.