US Average Data Breach Costs Rise to Almost $11.5 Million
The global average cost of a data breach has increased to almost $5 million, according to IBM’s 2026 Cost of a Data Breach Study, which shows breach costs have increased in all tracked industry sectors.
This is arguably the most comprehensive benchmark study into data breach costs. This year’s report is based on in-depth qualitative data collected in more than 3,558 separate interviews with individuals at 602 organizations that experienced a data breach between March 2025 and February 2026. The data breaches included in the report involved between 2,590 and 115,380 compromised records.
Over the period of the study, IBM determined that the average cost of a data breach had risen by 12% to $4.99 million – The highest global average cost to date, beating the previous record of $4.88 million set in 2024. Average data breach costs are far higher in the United States, where regulatory fines and business costs are higher. This year, U.S. data breach costs rose to a new record level of $11.5 million per breach, which is up 13% year-over-year and more than double the global average.
Data breach costs vary significantly across industry sectors, with highly regulated industries typically having higher data breach costs. For the past 13 years, healthcare has recorded the highest average breach cost, which was $6.64 million this year, although that represents a 10.5% reduction from 2025. The second-highest breach costs were in the financial sector ($6.3m), followed by the industrial sector ($5.5m), technology sector ($5.5m), and the entertainment sector ($5.4m).
Several factors contributed to the increase in data breach costs, with the main drivers being an increase in detection, escalation, and lost business costs, which include costs related to disrupted operations and customer churn. Another factor was the increased use of AI by attackers. There has been a 56% increase in AI-driven attacks over the past 12 months.
These attacks are generally harder to detect, and since the cost of a data breach increases per day of compromise, these attacks are among the most expensive. IBM determined that AI-driven attacks typically add around $1 million to the breach cost. The main driver of the increase was a 45% rise in deepfake impersonations, followed by a 19% increase in AI-generated malware, and a 17% increase in AI-generated phishing and other AI-generated communications. AI-driven attacks were heavily focused on critical infrastructure entities, which accounted for 62% of AI-driven attacks.
“AI has dramatically lowered the barrier for cybercriminals. Attackers can now execute attacks in minutes rather than days with advanced frontier models. Organisations need to move faster from reactive security to a continuous autonomous defence if they want to keep up,” said Mark Hughes, IBM’s global managing partner for cybersecurity services. The threat of attacks by advanced frontier AI models is a growing concern, with 85% of organizations saying the threat from these attacks has driven an increase in cybersecurity spending.
Ransomware attacks have also continued to increase, in part due to ransomware-as-a-service. Out of all tracked attacks, ransomware was used in 39% of attacks, up from 24% of attacks in 2023. Ransomware groups are increasingly targeting employee and health records (35% of attacks), and in 41% of attacks, the attackers weaponized brand reputation, increasingly opting for public shaming and data leaks to pressure victims into paying ransoms. While personally identifiable information (PII) and protected health information (PHI) are commonly targeted, attackers are broadening the scope of their attacks to also include the theft of emails and communications such as Slack messages, which were stolen in 19% of attacks.
While data breaches cannot always be prevented, there are several key actions that businesses can take to reduce risk and limit the harm that a successful attack causes. IBM recommends implementing AI agents more comprehensively across security operations, including using agentic AI for vulnerability identification and management. This is important as security experts expect that within the next two years, AI will favor attackers over defenders. IBM also recommends shifting identity security to continuous, runtime verification, fully implementing zero trust security, and strengthening governance and compliance.
