What lenders need to know about rising costs of data breaches

Artificial intelligence is fueling the rising cost of data breaches. 

Processing Content

Attacks involving AI were up 56% in the past year and added on average $1 million to companies’ data breach expenses, according to IBM’s annual Cost of a Data Breach report. The IBM and Ponemon Institute study of affected organizations also found the average incident costs for U.S. businesses rising to $11.5 million in the past year, up from $10.22 million in 2025.

“Attackers are abandoning human speed for machine speed,” the report said. “They’re already doing it with generative AI, which has lowered the time, cost and expertise needed to launch attacks, pushing organizations toward continuous business disruption.”

chart visualization

Companies with their own AI applications are also particularly vulnerable, as methods such as prompt injection attacks led to average losses of around $6 million, the study found. Of the firms which reported an AI-related breach, 92% said they lacked proper AI access controls.

The study described data breach expenses for financial services and technology organizations, although it did not specify the real estate sector. Lenders continue to be pestered with cyberattacks, and those firms have not said whether the consistent threats have involved the use of AI, or whether their own AI models were compromised.

How attacks are evolving

Ransomware incidents are on the rise, and those perpetrators seem increasingly malevolent, according to the 602 international businesses studied who suffered breaches between March 2025 and February 2026. Attackers most frequently threatened leaks to harm businesses’ reputations, over weaponizing compromised identifiable information.

Those hackers most frequently broke into companies via phishing, followed by compromising a supply chain vendor. Voice and text message phishing was used in 17% of incidents, and generated the highest average data breach expenses, the report found. 

Most breaches in the past year affected data stored on-premises. IBM cautioned that on-premises storage may be more vulnerable because it places the sole responsibility for patching, physical security and access management on a company’s internal information technology staff. 

chart visualization

Cloud attacks were more expensive to recover from than on-premises attacks and took longer to resolve, the report said. Factors such as crisis management, disrupted operations and customer churn accounted for a combined 63% of data breach expenses. 

Mitigation

Companies on average took 247 days to identify and contain a breach, a slight increase over last year. Fewer than 1 in 20 businesses recovered from a data breach in less than 50 days, IBM found. 

The report’s authors said a DevSecOps approach to cybersecurity, in which security for development is monitored from start-to-finish, was the top factor to reduce incident costs. Most breached organizations also lacked data encryption.

Security teams extensively using AI and automation meanwhile shortened their data breach turnaround times by 65 days on average, while reducing their expenses by almost $2 million. Still, 64% of the firms surveyed said they aren’t using AI extensively in security. Further, just 19% of all companies surveyed said they coordinate governance and security teams. 

“That lack of collaboration could lead to blind spots, policy conflicts and slower response times to security incidents,” the report said.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *