As rapidly as Artificial Intelligence (AI) is transforming business and technology, cybercriminals are also taking advantage of it. A new IBM report reveals that one in four malicious data breaches is now being carried out with the help of Artificial Intelligence (AI). These attacks include methods such as deepfakes, AI-based malware, and automated attacks. According to the report, such attacks are not only increasing rapidly but are also causing greater financial damage to companies than ever before.
According to IBM’s 2026 Cost of a Data Breach Report, the number of AI-enabled cyberattacks has increased by 56 percent compared to last year. The report states that companies affected by AI-based data breaches suffered an average loss of $6 million. This is nearly $1 million more than the global average data breach cost of $4.99 million.
According to the report, AI is enabling cybercriminals to launch attacks quickly and at a lower cost, while companies are incurring significant costs in detecting and preventing these attacks.
The report states that the use of deepfake identity spoofing and AI-enabled malware is rapidly increasing in AI-based attacks. These techniques allow cybercriminals to misuse people’s identities and circumvent security systems.
Furthermore, in many cases, AI models or AI applications are not directly targeted, but rather attacks exploit vulnerabilities in their associated APIs, plug-ins, and cloud configurations.
The report also revealed that companies that used AI and automation in their cybersecurity systems reduced the average cost of a data breach by approximately $2 million.
Despite this, one in four organizations still does not use AI-based tools in their security systems. Experts believe this could further widen the security gap between cybercriminals and companies.
Critical infrastructure sectors were most impacted by AI-based attacks. According to the report, 62 percent of such attacks occurred in the critical infrastructure sector.
Financial institutions suffered an average loss of $6.3 million, and energy companies suffered approximately $5.2 million. Such attacks are not limited to a single company; they can also impact supply chains, the economy, and essential services.
According to a separate survey included in the report, 85 percent of organizations said they plan to increase their cybersecurity budgets in light of advanced AI-based cyber threats. This number is higher than those who report increasing security spending after experiencing a data breach.
Experts believe that companies must develop robust security strategies in advance, rather than simply reacting after an attack. In the age of AI, cybersecurity means more than just protecting data, but also rapidly adapting to constantly evolving threats.

