The average cost of a data breach climbed 12% to a record $4.99 million globally this year, and artificial intelligence is doing much of the driving, according to IBM’s 2026 Cost of a Data Breach Report, released this week.
For firms in the accounts receivable management industry, the numbers hit close to home. Financial services recorded the second-costliest breaches of any sector at $6.29 million per incident, trailing only healthcare at $6.64 million. U.S. organizations fared worst of all, with average breach costs reaching $11.5 million, more than double the global figure, a gap IBM attributes partly to higher regulatory fines.
The report, conducted by Ponemon Institute and based on 602 breached organizations across 17 industries, describes a fundamental shift in attack economics. One in four malicious breaches was AI-driven, a 56% increase over last year, and those attacks added roughly $1 million to average breach costs. Deepfake impersonation accounted for 45% of AI-driven incidents, followed by AI-enabled malware and AI-generated phishing.
The top attack vector should concern any organization running phone-heavy operations: voice and SMS phishing led all entry points, appearing in 17% of breaches and producing the costliest incidents at $5.29 million on average. Social engineering, including help desk impersonation, followed close behind.
Also notable for compliance teams: shadow AI, meaning employee use of unapproved AI tools, was involved in 43% of security incidents, more than double last year’s 20%. Those breaches averaged $5.39 million, and roughly one in five resulted in a regulatory fine. Only about a third of organizations reported strict approval processes for AI deployments.
Ransomware attackers, meanwhile, are shifting tactics. Rather than simply encrypting data, 41% of ransomware incidents involved threats of public shaming and media leaks, and 35% targeted employee data such as Social Security numbers and health records, categories that collection agencies and their healthcare clients hold in volume.
The defensive story is more encouraging. Organizations making extensive use of AI and automation in security operations cut breach costs by $1.93 million and shortened response times by 65 days. Encryption, identity and access management, and DevSecOps practices each shaved more than $200,000 off average breach costs. Yet 53% of breached organizations had not encrypted sensitive data, and only 18% of firms deploying security AI agents applied them to vulnerability management.




