AI-fuelled cyberattacks drive up breach costs as firms without automation face higher losses, longer detection times and mounting regulatory, cloud and shadow AI risks

India recorded its highest-ever average cost of a data breach in 2026, with organisations losing an average of ₹25.5 crore per incident, even as artificial intelligence is reshaping both cyberattacks and cyber defence, according to IBM’s latest Cost of a Data Breach Report 2026.
The report found that the average cost of a data breach in India rose 15.9% year-on-year from ₹22 crore in 2025 to ₹25.5 crore in 2026. The scale of breaches also increased, with organisations compromising an average of 39,500 records, up from 38,200 a year earlier. At the same time, 26% of malicious breaches in India were AI-generated, underscoring how artificial intelligence is making cyberattacks faster, more sophisticated and easier to scale.
The report also points to a growing divide between organisations that have adopted AI-driven security tools and those that have not. Companies extensively deploying AI and security automation reported significantly lower breach costs and faster response times, while nearly 73% said they plan to increase investments in security tools and governance following a breach.
“India’s accelerating AI adoption is creating immense opportunities for innovation, but it is also enabling cyber threats to evolve rapidly. The findings underscore that organizations using AI and strong governance, were significantly better positioned to fend off cyberattacks,” said Gaurav Agarwal, Vice President, Technology, IBM India & South Asia.
“Today, most organizations apply AI in limited ways, often focused on detection. To keep pace, AI with agentic capabilities must be embedded across the full security lifecycle—from detection and analysis to prioritization and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage,” he added.
Varied AI adoption in cybersecurity
Despite AI’s growing role in cybersecurity, adoption remains uneven. According to the report, only 32% of organisations surveyed said they extensively use AI and security automation. Another 36% reported limited use, while 32% said they do not use these technologies at all. IBM noted that organisations with no AI or automation in their security operations incurred an average breach cost of ₹31.6 crore, compared with ₹21.3 crore for those with extensive deployment and ₹23.1 crore for organisations with limited deployment.
The absence of automation also prolonged incident response. Organisations without AI and security automation took an average of 236 days to identify a breach, compared with 175 days for organisations with extensive automation. Shadow AI or unauthorised use of AI tools by employees, emerged as another significant concern, increasing the average cost of a breach by ₹1.79 crore when present. IBM said this was among the top three factors driving up breach costs in India, alongside regulatory non-compliance and cloud migration.
Among industries, the financial services sector recorded the highest average breach cost at ₹40.9 crore, followed by the technology sector at ₹35.7 crore and the communications sector at ₹34.5 crore. Phishing, including voice and SMS phishing, remained the leading initial attack vector, accounting for 19% of incidents, ahead of drive-by compromises (16%) and supply chain compromises (15%).
The report also found that proactive security measures can significantly reduce the financial impact of cyberattacks. Offensive security testing, including red teaming and penetration testing, delivered the biggest savings, reducing breach costs by an average of ₹2.47 crore. Proactive threat hunting and AI governance technologies were also among the most effective cost-reduction measures.
Looking ahead, organisations are prioritising investments in cyber resilience. According to IBM, the top areas for planned spending include incident response planning and testing (67%), threat detection and response technologies such as SIEM, SOAR and EDR (51%), identity and access management (49%), AI security and governance tools (39%), and employee awareness and training (36%).