The IBM 2026 Cost of a Data Breach Study reports that the average global cost of a data breach increased by 12% over one year to nearly $5 million, while healthcare continued to record the highest average breach costs among the industries included in the study.
Global Data Breach Costs Increased
The IBM 2026 Cost of a Data Breach Study found that the average global cost of a data breach reached almost $5 million in 2026. The study also reported that the United States had the highest average data breach cost at $11.5 million, which was more than twice the global average.
Data breach costs increased across all sectors represented in the study. IBM attributed the increase primarily to higher detection, escalation, and lost business costs.
Healthcare Recorded the Highest Average Breach Costs
Healthcare continued to have the highest average data breach cost among the industries included in the study. The average healthcare breach cost was $6.64 million per incident in 2026.
The study also found that the global average healthcare breach cost declined by 10.5% from the 2025 average of $7.42 million.
Within healthcare, 59% of breaches resulted from malicious or criminal attacks. Information technology failures accounted for 26% of breaches. Human error accounted for 13% of breaches.
Phishing Remained the Most Common Initial Access Vector
Across all industries included in the study, phishing through voice and SMS phishing methods accounted for 17% of breaches and represented the most common initial access vector.
The study reported an average breach cost of $5.9 million for phishing-related incidents.
Other frequently identified initial access vectors included supply chain compromise, abuse of valid accounts, drive-by compromise attacks, and social engineering.
Breach Identification and Containment Times Increased
The average time required to identify and contain a data breach increased for the first time in five years. IBM reported a 2.5% increase compared with 2025.
Breaches involving removable media and supply chain compromises required the longest time to identify and resolve. These incidents averaged 258 days from identification through containment, compared with an overall average of 247 days across all attack types.
The study stated that these attack vectors do not appear in malware scans or inbound traffic, making detection more difficult.
AI-Driven Attacks Continued to Increase
The study reported a 56% year-over-year increase in AI-driven attacks. One in four organizations experienced an AI-driven breach during the previous year.
AI deepfake and impersonation represented 45% of AI-driven attacks. AI-generated malware accounted for 19% of AI-driven attacks. AI-generated phishing and other AI-generated communications accounted for 17%.
IBM reported that AI-driven attacks increased the average financial impact of a data breach by approximately $1 million.
The study stated that most AI-driven attacks targeted critical infrastructure, with the financial services and energy sectors identified as the most frequently targeted industries.
Shadow AI Incidents More Than Doubled
The study found that incidents involving unauthorized employee use of AI applications increased from 20% of security incidents during the previous year to 43% during the current reporting period.
IBM reported that only around one third of organizations maintained strict approval processes for deploying AI tools.
The average breach cost associated with shadow AI incidents was $5.39 million. One in five of those breaches resulted in a regulatory fine.
Among organizations that were aware of frontier AI models, 85% reported increasing security spending to address the associated threats.
IBM also reported that experts believe AI will favor attackers over defenders by 31.7% within two years.
The study stated that organizations primarily use AI agents for detection and containment, while only a small fraction use AI agents for vulnerability management. IBM recommended using AI to analyze exposures, enforce policies, and coordinate detection and containment with minimal human intervention.
Ransomware Incidents Continued to Increase
The study reported that ransomware attacks continued to increase because of ransomware-as-a-service.
During the previous 12 months, 39% of breached organizations reported experiencing at least one ransomware attack. The study compared that figure with 24% reported in 2023, representing a 62.5% increase over four years.
IBM also reported changes in ransomware tactics. The study found that 41% of ransomware attacks included threats involving public shaming or data leaks. Employee data and health records (including PHI) were targeted in 35% of ransomware attacks.