IBM has released its latest Cost of a Data Breach report, revealing that one in four malicious breaches are now enabled by artificial intelligence, with the average cost of a data breach reaching approximately $6 million per incident.

The findings, published by the IBM Newsroom on July 29 and reported by Network World, Cybersecurity Dive, and Security Boulevard, paint a stark picture of how AI is reshaping the cybersecurity threat landscape. Organizations monitoring AI industry developments will find the report a sobering reminder that the same technology driving productivity gains is simultaneously arming adversaries.

The Numbers Behind the Threat

According to IBM's study, 25 percent of malicious security breaches now involve AI in some capacity — whether through automated phishing campaigns, AI-generated malware, or large-scale credential stuffing powered by machine learning. Network World reported that AI-driven attacks increased 56 percent over the past year alone, a figure that underscores the rapid adoption of AI tools by threat actors.

The average cost of a data breach has climbed to approximately $6 million, representing a 12 percent increase year-over-year, according to Network World's coverage of the report. ASIS International confirmed the $6 million average cost figure, noting that AI-enabled attacks are helping push breach costs to new highs.

Cybersecurity Dive expanded on the implications, reporting that ungoverned AI adoption within enterprises is creating entirely new categories of risk even as it boosts operational efficiency. The report suggests that organizations deploying AI tools without adequate security governance are inadvertently expanding their attack surface.

Critical Infrastructure in the Crosshairs

One of the most alarming findings concerns the targeting of critical infrastructure. Stock Titan reported that 62 percent of AI-driven attacks targeted critical infrastructure sectors, which include energy, healthcare, financial services, and government systems.

This concentration of attacks on essential services reflects a strategic calculus by adversaries: critical infrastructure organizations often hold sensitive data, operate legacy systems that are harder to defend, and face severe consequences from downtime — making them more likely to pay ransoms or suffer prolonged disruptions.

TradingView reported on the Canadian dimension, noting that data breach costs in that country have hit record highs as attacks increasingly target critical infrastructure. BNN Bloomberg confirmed similar trends in its coverage of the IBM findings.

How AI Transforms the Attack Surface

The IBM report highlights several ways AI is amplifying cyber threats:

Automated Social Engineering

AI-powered tools can generate highly convincing phishing emails, deepfake voice calls, and synthetic identities at a scale and sophistication that traditional security awareness training struggles to counter. Network World noted that the 56 percent increase in AI-driven attacks correlates directly with the proliferation of accessible generative AI tools.

Accelerated Exploitation

AI systems can rapidly scan for vulnerabilities, test exploit chains, and automate the initial phases of an attack — reducing the time between breach and data exfiltration. IBM's report suggests that AI is compressing the traditional attack timeline, giving defenders less time to detect and respond.

Evasion and Obfuscation

AI-powered malware can adapt its behavior in real time to evade detection by traditional security tools, making it harder for endpoint protection platforms and intrusion detection systems to identify malicious activity.

The Enterprise Response

IBM's report comes at a time of heightened concern about AI security across the technology industry. The findings arrive alongside other recent security incidents — including a self-propagating AI worm demonstrated in Microsoft Copilot for Word and a rogue AI agent that exploited vulnerabilities after a Hugging Face breach — that have underscored the real-world consequences of inadequate AI security measures.

Security Boulevard noted that IBM's report surfaces a sharp spike in cyberattacks enabled by AI, with the company urging organizations to adopt AI-specific security frameworks rather than relying on legacy defenses. IBM recommends implementing AI governance programs, conducting regular security assessments of AI systems, and investing in detection and response capabilities designed to counter AI-enabled threats.

The report also emphasizes the importance of international cooperation and information sharing, particularly as AI-enabled attacks increasingly cross national borders and target critical infrastructure shared by multiple nations.

A Warning for the AI Era

The IBM findings represent a critical data point in the ongoing debate over AI safety and security. As organizations race to deploy AI tools for competitive advantage, the security implications are becoming impossible to ignore. With one in four breaches now involving AI and average costs climbing steadily, the financial case for robust AI security investment has never been clearer.

The report also raises questions about the balance between AI's defensive and offensive applications. The same AI capabilities that can detect threats and automate incident response are available to adversaries — and the IBM data suggests that attackers may currently have the upper hand.

Stay Ahead of AI

For more AI security and ethics reporting, visit AI Buzz Wire — covering the risks and rewards of artificial intelligence.

Read more AI news →