AI Is Rewriting Data Breach Economics, and BFSI and Energy Are Paying the Price

Home Opinion AI & Emerging Tech AI Is Rewriting Data Breach Economics, and BFSI and Energy Are Paying the Price
AI Is Rewriting Data Breach Economics, and BFSI and Energy Are Paying the Price, Infosec Federation

AI is no longer just a tool defenders reach for, it has become the reason breaches cost more. IBM’s 2026 Cost of a Data Breach Report found that AI-enabled attacks accounted for one in four malicious breaches this year, a 56 percent jump in incidence over 2025, and that those breaches cost organizations $6 million on average, roughly $1 million above the global breach average of $4.99 million, according to Business Standard’s coverage of the report. Financial services and energy were named the sectors most frequently targeted by AI-driven attacks, both prized by attackers for their outsized economic footprint.

What did IBM’s report actually find?

The 2026 Cost of a Data Breach Report, conducted by the Ponemon Institute and sponsored by IBM, surveyed 602 breached organizations across 17 industries and 16 countries, covering incidents between March 2025 and February 2026, with follow-up research among 456 organizations completed in May 2026. Suja Viswesan, vice president of IBM Security Software, framed the shift bluntly: \”What’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive,\” according to IBM’s own announcement of the findings. Deepfake impersonation, AI-generated malware and AI-assisted phishing were named as the tools letting attackers automate reconnaissance and social engineering at a scale human-run crews could never match, a pattern our earlier coverage of AI-driven voice cloning and deepfake fraud has tracked on the consumer side of the same trend.

Why are AI-enabled breaches so much more expensive?

The premium is not spread evenly. Attacks that manipulate AI models directly are the costliest: model inversion attacks averaged $6.07 million per incident and prompt injection attacks $5.89 million, according to IBM’s own analysis, figures in line with what Cybersecurity Dive reported from the same dataset. IBM’s researchers described these as attacks that undermine how AI models reason and respond, rather than simply compromising a system outright, a distinction we explored in our own reporting on prompt injection as a narrative-style jailbreak threat. Ninety two percent of organizations that suffered an AI-related security incident lacked adequate access controls on their AI systems, and only 40 percent limited who could reach them at all. The leading causes were mundane rather than exotic: compromised APIs, applications and plug-ins accounted for 27 percent of AI-related breaches and cloud misconfigurations another 27 percent. Basic hygiene lagged too, with only 37 percent of breached organizations encrypting sensitive data at rest and in transit, and just 34 percent able to say they had visibility into their own cryptographic assets. IBM also flagged a governance blind spot: security incidents involving unsanctioned shadow AI tools more than doubled year over year to 43 percent of AI-related incidents, and over two thirds of affected organizations had no process to rein it in, a gap our recent look at agentic AI as an untrained insider threat examined from the workforce side.

Why are financial services and energy the hardest hit?

Sixty two percent of AI-driven attacks targeted critical infrastructure, IBM found, which explains why financial services and energy sit at the top of the cost table: financial services breaches cost $6.3 million on average and energy breaches $5.2 million, both above the $4.99 million global figure, Business Standard reported. Both sectors combine high-value data with services the public cannot do without, making them natural targets for automated, AI-assisted campaigns that scale phishing and impersonation cheaply. India’s banking sector has already supplied recent examples of that exposure: Bank of Baroda faced an alleged 1 TB data breach with banking records surfacing on the dark web, and SEBI has separately warned listed companies about the deepfake boss scam impersonating executives to authorize fraudulent transfers.

What happenedIBM’s 2026 Cost of a Data Breach Report found AI-enabled attacks are pushing breach costs higher, hitting financial services and energy hardest, according to Business Standard’s coverage of the report.
WhenPublished July 29, 2026, covering breaches between March 2025 and February 2026.
Who is affected602 breached organizations across 17 industries and 16 countries; financial services, energy and India-based organizations singled out.
ScaleAI-enabled breaches cost $6 million on average, up 56 percent in incidence year over year; India’s average breach cost rose to $2.79 million.
TakeawayOrganizations using AI and automation in security operations cut breach costs by nearly $2 million, per IBM, though one in four have yet to adopt these tools.

What does this mean for India?

India recorded its own increase, with the average cost of a breach rising to $2.79 million (Rs 24.27 crore) in 2026 from $2.51 million (Rs 21.84 crore) in 2025, Business Standard reported, citing the IBM findings. That keeps India a lower-cost market than the US or West Asia, but the direction matters more than the absolute number: costs are climbing as Indian enterprises expand both their digital footprint and their AI adoption, the same two forces IBM’s report says are driving the global trend. The rise lands as Indian regulators sharpen personal liability for security failures, a shift our earlier analysis of India’s CISO liability landscape has laid out.

Global average
$4.99M
AI-enabled breach
$6M
Financial services
$6.3M
Energy
$5.2M
India average
$2.79M

Can AI defenses actually make breaches cheaper?

IBM’s report offers a genuine counterweight: organizations that used AI and automation in their security operations cut breach costs by nearly $2 million compared with those that did not. The catch is adoption. One in four organizations have still not deployed these tools in their security operations at all, and among those that have, most lean on AI for threat detection, where more than half report usage, while fewer than one in five apply it to vulnerability management, arguably the more preventive use case. Ransomware incidents also climbed to 39 percent of breaches this year from 34 percent the year before, with attackers increasingly threatening brand reputation, employee data and intellectual property to extract payment, IBM found.

What should security leaders do now?

  • Treat AI model and application access like any other privileged system: enforce access controls and log who can query them, given 92 percent of AI-related incidents involved inadequate controls.
  • Inventory shadow AI use across the organization before it becomes the entry point; governance was absent in over two thirds of the cases IBM tracked.
  • Prioritize encryption of sensitive data at rest and in transit; IBM found only 37 percent of breached organizations had this covered.
  • Extend AI-assisted defense beyond threat detection into vulnerability management, where adoption lags furthest behind the payoff.
  • Budget breach response around sector reality: financial services and energy teams should assume AI-driven, automated attack attempts are already routine, not hypothetical.

The report’s broader message is that AI has changed the cost curve on both sides of the fight: cheaper for attackers to launch, more expensive for defenders to clean up, and the sectors with the most to lose are the ones seeing it first. That is the calculation every board overseeing a bank, a utility or a large Indian enterprise should be running now, not after the next incident report lands.

Frequently asked questions

How much does an AI-enabled data breach cost compared to a regular one?

IBM’s 2026 Cost of a Data Breach Report found AI-enabled breaches cost organizations $6 million on average, about $1 million more than the global average of $4.99 million. These attacks, which include deepfake impersonation, AI-generated malware and AI-assisted phishing, made up one in four malicious breaches, a 56 percent increase from the prior year.

Why are financial services and energy the biggest targets of AI-driven attacks?

IBM found 62 percent of AI-driven attacks targeted critical infrastructure, with financial services breaches averaging $6.3 million and energy breaches $5.2 million, both above the global average. Both sectors combine high-value data with services the public depends on, making them attractive targets for automated, AI-assisted campaigns at scale.

How has the cost of a data breach changed in India?

According to IBM’s 2026 report, cited by Business Standard, the average cost of a data breach in India rose to $2.79 million in 2026 from $2.51 million in 2025. India remains cheaper than the US or West Asia, but costs are climbing as Indian enterprises expand digital and AI adoption.

Leave a Reply

Your email address will not be published.