There is a rapidly growing imbalance, where attack costs in the thousands of dollars can easily inflict millions in damages on the companies being attacked, fundamentally changing the economics of cyber risk, according to a new research report from IBM.
Entitled Cost of a Data Breach Report 2026: The AI tipping point, their survey of 3,558 security and c-suite executives in 602 organizations impacted by data breaches between March 2025 and February 2026, found that one in four malicious breaches were artificial intelligence (AI) enabled, a 56 per cent increase over last year’s findings. The breaches this year cost an average of $6-million in U.S. dollars.
In Canada, in Canadian dollars, the average cost of a data breach reached a record C$7.11-million. Energy targets suffered the costliest breaches, averaging C$9.21-million per breach. “Organizations using AI and security automation extensively experienced significantly lower breach costs and faster response times,” researchers write in an announcement about the Canadian findings. Using AI extensively reduced breach costs by approximately C$3.41-million in Canadian cases.
Globally, companies which reported using AI and automation in security operations cut their breach costs by an average of almost USD $2-million. That said, they add that one in four organizations still have not adopted the tools in their security operations.
IBM says globally, the attacks being reported are made up predominantly of deepfake impersonation and AI-enabled malware. These, they say, are reshaping breach economics, as attacks become faster and cheaper to launch while breaches keep getting more expensive to find a fix.
“This growing imbalance – where attacks can be launched for thousands while breaches cost millions – is fundamentally changing the economics of cyber risk,” IBM’s researchers write.
Although 85 per cent of organizations say they plan to increase security spending after becoming aware of advanced frontier AI cyber capabilities, the report continues saying the increase is important and needed “as AI agents proliferate across organizations, requiring a focus on securing non-human identities in AI workflows. This year’s research shows fewer than half of organizations securing those identities. Meanwhile, attackers are not only using AI, they’re targeting AI. Among the roughly one-in-five organizations that reported an AI-related breach, we found that security incidents were less about model selection than model and environmental security.”
They add that the root causes of these incidents were often structural, including compromised application programming interfaces (APIs), applications and cloud misconfigurations. These, they say, indicate governance failures, not model risk.
Among the report’s findings, IBM also notes the growing prevalence of incidents involving “shadow AI” where workers use unapproved AI. Shadow AI-related security incidents more than doubled to 43 per cent this year, up from 20 per cent last year. They say these incidents lead to a higher average breach cost this year too, costing USD $5.39-million, on average, up from USD $4.63-million each on average in the previous year.
In about one-in-five incidents, organizations reported paying a fine because of a breach stemming from shadow AI use. They add that most breached organizations this year lacked AI governance to manage AI or detect shadow AI use.
“A gap remains where attackers are moving the fastest. While more than 50 per cent reported using agents for threat detection and containment, only 18 per cent apply agents to vulnerability management, leaving known exposures to linger even as AI shortens exploit windows.”
They add that organizations with an extended gap between discovery and remediation are directly impacted with higher breach costs. “The priority now is to eliminate that lag-building remediation into development workflows, securing identity at runtime and fixing risks at the speed attackers are already moving,” says IBM Security’s vice president, Suja Viswesan.
Financial services and energy organizations experienced the highest concentrations of attacks. In Canada, energy companies took this top spot, followed by technology organizations (which lost C$9.02-million on average per attack) and industrial companies and organizations (where attacks cost C$8.89-million each, on average). In USD, financial services breaches were reported to cost an average of USD $6.3-million, up from the USD $5.2-million average.
“The concentration of attacks across these sectors increased the potential for cascading impacts across economies, supply chains and essential services,” they write.
The report is extensive, covering encryption gaps, ransomware, areas of agentic AI use, types of controls being used in different areas, attack vectors, root causes, the data breach lifecycle, factors that increase or decrease breach costs and more.
Notably in the Canadian findings, they say supply-chain compromise is now the largest factor increasing breach costs in Canada, adding approximately C$367,899 to costs. Security skills shortages and challenges prioritizing threats were also identified as factors increasing breach costs. They quantify these costs, saying each factor adds C$314,500 and C$311,300 respectively to the average breach cost.
In Canada, those organizations extensively deploying AI in the security operations, reported average breach costs of C$5.5-million, compared with C$8.91 million for organizations with no such deployment in place. “They also identified and contained breaches significantly faster, helping reduce the overall financial and operation impact of cyber incidents,” they write. “Breaches were detected in 124 days and contained in 57 days, compared with 154 days and 71 days respectively for organizations without AI deployment in their security operations. The organizations gaining the biggest security advantage are the ones using AI and automation extensively across their operations.”