www.swif.ai/blog/cost-of-a-data-breach
Help Center

Cost of a Data Breach: 50+ Statistics for 2026 (Updated August)

August 6, 2026

5 minutes

Human Written & Fact Checked

Cite this Webpage

Copy

The average cost of a data breach reached a record $4.99 million in 2026, a 12% jump that erased the previous year's decline, according to IBM's 2026 Cost of a Data Breach Report. US organizations paid more than double that, averaging $11.5 million per incident. The single biggest reason costs reversed course is AI: one in four malicious breaches were AI-enabled this year, and those breaches cost roughly $1 million more than the global average.

This page collects the breach cost statistics that matter for 2026, from IBM, Verizon, the Identity Theft Resource Center, Sophos, the FBI, cyber insurance claims data, and European regulators. Every figure below comes from research published in 2026.

Methodology

Every statistic on this page is drawn from research published in 2026. Where a report analyzes a prior-year dataset, that reporting window is stated so you know exactly what period the number covers.

We used seven primary sources: IBM's 2026 Cost of a Data Breach Report (conducted by Ponemon Institute), the 2026 Verizon Data Breach Investigations Report, the Identity Theft Resource Center's 2026 breach tracking, Sophos' State of Ransomware 2026, Coalition's 2026 Cyber Claims Report, the FBI's 2025 Internet Crime Report (published April 2026), and DLA Piper's January 2026 GDPR Fines and Data Breach Survey. No aggregator blogs or secondhand statistics roundups were used as sources. If you are looking for more in depth cybersecurity statistics we have an article about that here

Key Cost of a Data Breach Insights for 2026

  • Breach costs hit a record. The global average reached $4.99 million, up 12% year over year, after a brief dip in 2025.
  • The US premium keeps widening. US breaches averaged $11.5 million, up 11% and more than double the global figure.
  • AI is the new cost multiplier. AI-enabled attacks rose 56% and cost around $6 million each.
  • Detection got slower for the first time in five years. Mean time to identify and contain rose to 247 days.
  • Third-party exposure is now the norm. Nearly half of all breaches involve a vendor or partner.
  • Ransoms are falling, recovery bills are not. Median demands dropped sharply while average recovery costs rose 11% to $1.7 million.
  • Most companies are not paying enterprise-scale costs. The average cyber insurance claim in 2025 was $116,000, not millions.
  • Breach volume is on a record pace. More US victim notices were issued in the first half of 2026 than in all of 2025.
  • Regulatory exposure is steady, not spiking. European authorities issued roughly EUR 1.2 billion in GDPR fines, in line with the prior year.
  • Basic controls are still missing. Only 37% of breached organizations encrypt sensitive data both at rest and in transit.

How Much a Data Breach Costs in 2026

After a one-year dip, breach economics turned sharply against defenders. The headline number is back above its previous peak, and the gap between the US and everywhere else has never been wider.

The global average is at an all-time high

  • The average cost of a data breach is $4.99 million in 2026, a 12% increase and the highest figure IBM has recorded in the study's 21-year history. Detection and escalation expenses plus lost business from downtime and customer churn accounted for close to two-thirds of the total. (IBM, July 2026)

  • The figure is based on 602 breached organizations across 16 countries, covering incidents between March 2025 and February 2026. (IBM, July 2026)

  • US organizations averaged $11.5 million per breach, an 11% increase and more than twice the global average, driven by regulatory exposure and business disruption costs. (IBM, July 2026)

Healthcare and financial services remain the most expensive sectors

  • Healthcare recorded the highest average breach cost at $6.64 million, its thirteenth consecutive year at the top of the rankings. (IBM, July 2026)

  • Financial services breaches averaged $6.3 million, and energy breaches averaged $5.2 million. Those two sectors also absorbed the heaviest concentration of AI-driven attacks. (IBM, July 2026)

  • 62% of AI-driven attacks targeted critical infrastructure, raising the risk of cascading disruption across supply chains and essential services. (IBM, July 2026)

AI Is Now the Single Biggest Cost Driver

For the first time, AI is a measurable line item in breach economics on both sides of the ledger. Attackers use it to move faster and cheaper; defenders who deploy it save close to $2 million per incident.

AI-enabled attacks cost about $1 million more

  • One in four malicious breaches were AI-enabled, a 56% increase over the prior year. These breaches cost an average of $6 million, roughly $1 million above the global average. (IBM, July 2026)

  • Deepfake impersonation and AI-enabled malware make up the bulk of these attacks. The economics have inverted: attacks can now be launched for thousands of dollars while the resulting breaches cost millions. (IBM, July 2026)

  • AI has compressed exploit timelines from months to hours, and vulnerability exploitation (31%) has overtaken stolen credentials as the top initial access vector for the first time in the DBIR's 19-year history. (Verizon, May 2026)

Shadow AI is creating a new exposure class

  • More than 20% of organizations reported a breach targeting AI models or applications. The most common causes were compromised APIs, applications or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%). (IBM, July 2026)

  • Employee use of unapproved "shadow AI" tripled to 45%, spiking data leakage through channels most security stacks were never built to see. (Verizon, May 2026)

This is the datapoint most IT teams underestimate, because unsanctioned tools do not show up in procurement records. Shadow IT discovery is the only reliable way to build an accurate inventory of what employees are actually pasting company data into.

Defensive AI is the largest single cost reducer

  • Organizations using AI and automation in security operations cut breach costs by nearly $2 million on average. Yet one in four organizations still use no AI or automation in their security operations at all. (IBM, July 2026)

  • More than 50% of organizations use agents for threat detection and containment, but only 18% apply them to vulnerability management, leaving known exposures open even as AI shortens exploit windows. (IBM, July 2026)

  • 85% of organizations plan to increase security spending after learning about advanced frontier AI capabilities, compared with 64% who said the same after actually experiencing a breach. Anticipated risk now moves budgets more than lived experience. (IBM, July 2026)

What Makes a Breach More Expensive

Breach cost is not a fixed number. It is largely a function of how long the intrusion goes undetected and which basic controls were in place beforehand.

Dwell time is the most controllable variable

  • Mean time to identify and contain a breach rose to 247 days, reversing five consecutive years of improvement. (IBM, July 2026)

  • Breaches that ran past 200 days cost about a third more than those closed faster. Internal security teams found close to four in ten breaches and closed them roughly five weeks faster than average. (IBM, July 2026)

  • The median time to fully resolve an incident rose to 43 days, up from 32 days, while organizations faced 50% more critical vulnerabilities to patch than in the previous dataset. (Verizon, May 2026)

  • Only 26% of known exploited vulnerabilities were fully remediated in 2025, down from 38% the year before. (Verizon, May 2026)

Encryption and access control gaps persist

  • Just 37% of breached organizations encrypt sensitive data both at rest and in transit, and only 34% have visibility into their cryptographic assets. (IBM, July 2026)

  • Third-party involvement now appears in 48% of breaches, a 60% year-over-year increase, as attackers pivot through vendors, SaaS platforms, and OAuth integrations. (Verizon, May 2026)

  • Mobile social engineering success rose 40%, and AI bot crawler traffic is growing 21% month over month against essentially flat human traffic growth. (Verizon, May 2026)

Ransomware Economics Have Split in Two

The most counterintuitive finding of 2026: ransom demands and payments are falling while the total cost of recovering from ransomware keeps climbing. Victims have learned to negotiate. Nobody negotiates the rebuild.

  • The average cost to recover from a ransomware attack, excluding any ransom paid, rose 11% to $1,700,200. (Sophos, July 2026)

  • The median ransom demand fell to $698,000, down from $1.32 million in 2025 and $2 million in 2024. The median payment was $769,000. (Sophos, July 2026)

  • 56% of attacks still succeeded in encrypting data, up from 50%, and 48% of encrypted victims paid. Local and state government paid at the highest rate of any sector, at 72%. (Sophos, July 2026)

  • 79% of ransomware attacks began with a compromised identity rather than a software exploit. Malicious email (26%) and phishing (24%) together account for half of all incidents. (Sophos, July 2026)

  • Only 34% of small organizations (100 to 250 employees) stopped attacks before encryption, against 46% at organizations with 3,001 to 5,000 employees. (Sophos, July 2026)

  • Reported ransomware incidents rose to 39% of breached organizations, up from 34%, with attackers increasingly exploiting brand reputation (41%), employee data (35%), and intellectual property (31%) as leverage instead of encryption alone. (IBM, July 2026)

  • Ransomware grew to 48% of all breaches, up from 44%, but 69% of ransomware victims did not pay, and the median ransom paid in the DBIR dataset fell to $139,875. (Verizon, May 2026)

What a Breach Actually Costs a Normal Company

Enterprise survey averages are useful for boardroom framing but misleading for a 200-person company. Cyber insurance claims data gives a much better picture of what most organizations actually pay.

  • The average cyber insurance claim in 2025 was $116,000, a 19% decrease year over year, even as overall claims frequency rose 3%. (Coalition, March 2026)

  • Businesses with over $100 million in revenue saw a 5.72% claims frequency, nearly five times the 1.21% rate at businesses under $25 million. Average losses ran $268,000 for the largest band and $77,000 for the smallest. (Coalition, March 2026)

  • Ransomware was the costliest claim type at an average loss of $269,000, while initial ransom demands surged 47% and a record 86% of targeted businesses refused to pay. (Coalition, March 2026)

  • Business email compromise and funds transfer fraud made up 58% of all cyber claims. BEC averaged $27,000 per loss and funds transfer fraud averaged $141,000. (Coalition, March 2026)

  • Dual extortion accounted for 70% of ransomware claims, and incidents involving data theft were more than twice as expensive as encryption-only events. (Coalition, March 2026)

The takeaway for mid-market IT leaders: your realistic exposure is a six-figure incident dominated by downtime and fraud, not a $5 million enterprise headline. That changes which controls are worth funding first.

Breach Volume, Victims, and Disclosure

Cost per breach is only half the equation. The other half is how many breaches are happening and how many people they touch.

  • The ITRC tracked 1,803 data compromises in the first half of 2026, with Q2 alone at 1,029, the second-highest single quarter on record. The full year is tracking toward roughly 3,600 events. (Identity Theft Resource Center, July 2026)

  • An estimated 471.2 million victim notices were issued in the first six months of 2026, more than the 297.5 million issued across all of 2025. (Identity Theft Resource Center, July 2026)

  • Malicious insider incidents jumped roughly sevenfold, from 3 in all of 2025 to 21 in the first half of 2026. (Identity Theft Resource Center, July 2026)

  • Financial services recorded the highest compromise frequency at 387 events, followed by healthcare at 281, which reversed a modest downward trend. (Identity Theft Resource Center, July 2026)

  • Total losses reported to the FBI's Internet Crime Complaint Center reached $20.877 billion in 2025, a 26% increase and the first year past $20 billion. (FBI IC3, April 2026)

  • The IC3 logged 1,008,597 complaints, its first million-complaint year, with an average reported loss of $20,699 per complaint. Business email compromise alone accounted for $3.046 billion. (FBI IC3, April 2026)

  • AI-related fraud produced more than 22,000 complaints and close to $900 million in losses, the first year the FBI broke out AI as a distinct category. (FBI IC3, April 2026)

Regulatory and Legal Costs

Fines are the most visible line item, but they are rarely the largest one. What has changed in 2026 is notification volume, which drives legal review, forensic work, and customer communication costs long before any penalty is assessed.

  • European supervisory authorities issued approximately EUR 1.2 billion in GDPR fines, closely matching the prior year and reversing a downward trend. (DLA Piper, January 2026)

  • Cumulative GDPR fines since May 2018 to date now total EUR 7.1 billion across the jurisdictions surveyed. Ireland leads by value, with EUR 4.04 billion issued to date. (DLA Piper, January 2026)

  • Notified personal data breaches rose 22% to an average of 443 per day, the first time the daily average has passed 400 since GDPR took effect. (DLA Piper, January 2026)

  • Processors, not just controllers, are being fined directly for failures of the security principle, extending liability across the vendor chain. (DLA Piper, January 2026)

For teams mapping controls to SOC 2, ISO 27001, or HIPAA, the encryption and access control gaps above are the fastest place to reduce both audit friction and breach cost at the same time.

What Changed in 2026

Five shifts define this year's breach cost data and separate it from the 2024 and 2025 numbers still circulating in most coverage:

  1. The cost curve reversed. The 2025 dip to $4.44 million was an anomaly, not a trend. The 2026 record of $4.99 million reset the baseline.
  2. Detection got slower. After five years of steady improvement, mean time to identify and contain went the wrong way, to 247 days.
  3. AI became measurable on both sides. For the first time there is a specific dollar figure for AI-enabled attacks ($6 million) and for AI-assisted defense (nearly $2 million saved).
  4. The vendor perimeter overtook the network perimeter. Third-party involvement in 48% of breaches means most organizations are now inheriting risk they cannot directly patch.
  5. Ransom and recovery decoupled. Demands fell 47% in insurer data while recovery costs rose 11%. The ransom is now the negotiable part of a ransomware bill, and the smaller part.

The practical implication for IT and security leaders is that spending aimed at shortening detection time, closing encryption gaps, and inventorying unsanctioned tools now has clearer measured returns than any other category of control.

How Swif.ai Helps

Swif.ai gives IT and security teams a single console for device compliance across macOS, Windows, and Linux, with real-time discovery of unsanctioned SaaS and AI tools before they become an unmonitored data path. Pre-built policies map directly to SOC 2, ISO 27001, and HIPAA controls, so encryption and access enforcement produce audit evidence as a byproduct. Explore our unified endpoind management platform to see how we can help you stay compliant and reduce your risk of a data breach.