One in Four Breaches Is Now AI-Enabled. Here's Every Way That's Shown Up in This Series.
For most of this year, the AI-powered attacks we've covered read like isolated, almost freakish stories — a subscription phishing kit, a ransomware attack that fixed its own error in 31 seconds, an email assistant that helped rob its own employer. IBM's newest global breach research shows they were never isolated. One in four malicious breaches now involve AI, up 56% in a single year, and they cost businesses a million dollars more than an ordinary breach. Here's the number, and every place it's already shown up in stories we've told this year.
Every time this series has covered an AI-related attack, there's been an implicit question sitting underneath it: is this a genuine trend, or a handful of striking anecdotes that make for a good headline? A subscription phishing kit is alarming. So is a ransomware attack that fixes its own mistakes. But two or three vivid stories don't prove a pattern, and it's fair to wonder whether the coverage was chasing novelty rather than describing something businesses actually need to plan around.
IBM's newest global data breach research answers that question with a number, not an anecdote. Drawing on 602 organisations that experienced a breach over the past year, the study found that AI-enabled attacks aren't a rounding error anymore — they're a quarter of all malicious breaches, and growing fast.
malicious breaches were AI-enabled — a 56% increase over the prior year
This isn't a projection or a survey of opinions about the future. It's a measurement of breaches that already happened, in the twelve months to February 2026. A year ago, AI-enabled attacks were a meaningfully smaller share of the total. The growth rate — 56% in a single year — is the detail that matters most: this isn't a plateauing trend, it's an accelerating one.
And these breaches aren't just more common. They're more expensive. AI-enabled breaches cost an average of six million dollars — roughly a million dollars more than the already-record global average. The category most responsible for that cost isn't some exotic new hacking technique. It's deepfake impersonation, the single largest share of AI-enabled breaches, followed by AI-generated malware and AI-written phishing campaigns.
Where this has already shown up, story by story
Read back through what this series has covered since the spring, and the IBM figures stop being an abstract statistic. They're a name for something we've already documented happening, piece by piece, all year.
The numbers behind the number
That last figure is worth sitting with, because it complicates any instinct to treat AI purely as a threat to defend against. Organisations using AI and automation in their own security operations saw breach costs fall by almost two million dollars on average. The same category of technology that's accelerating attacks is also, when deployed on the defending side, one of the most effective cost reducers available. The problem isn't AI. It's an imbalance — attackers adopting it faster than most defenders have.
Why the trend matters more for small businesses, not less
It would be easy to read "critical infrastructure" and "financial services" in the sector breakdown and conclude this is a large-enterprise problem. That reading gets the mechanism backwards. What's driving the 56% growth isn't attackers becoming more selective about high-value targets — it's the cost of running an attack collapsing across the board. A subscription phishing kit doesn't check your revenue before it works. An autonomous ransomware agent doesn't decide you're too small to bother with; it doesn't decide anything, it just runs.
The businesses most exposed to this shift are the ones that relied on being an uneconomical target — too small, too much effort, not enough payoff. That protection was always partial, and this year's data suggests it's eroding faster than most owners have registered.
What the research says still works
The reassuring part of the report is the same reassuring part that has run through every post in this series: the fundamentals haven't changed, and they still work. Phishing remains the single most common way attackers get in — for the fourth year running — which means the basics that stop conventional phishing still matter enormously, even against an AI-polished version of it. Ransomware defence still comes down to patching exposed systems, protecting credentials, and having a tested recovery plan. None of that got obsolete because the attacker started using better tools.
What has changed is the margin for delay. If the floor for running a damaging attack keeps dropping, the controls that used to be optional — monitoring for unusual AI tool usage, verifying anything AI-assisted before acting on it, knowing your exposure before an autonomous scanner finds it for you — stop being optional too.
The short version
Every AI-related story this series has told this year — the rented phishing kit, the cloned voice, the ransomware that fixed itself, the email assistant that helped rob its own employer — turns out to have been one data point in a measured, accelerating trend, not an unlucky coincidence. One in four breaches is AI-enabled now. A year ago it was noticeably fewer. The direction of travel is the only part of this story that isn't up for debate.
The response isn't a new category of defence bought from scratch. It's the same list this series has repeated in every one of those stories — patch what's exposed, verify anything urgent by a second channel, know what's connected to your systems, keep backups that have actually been tested — applied with a little more urgency than it deserved a year ago, because the tools working against you have gotten quietly, measurably better in the meantime.
Know your exposure today, not what it looked like when you last checked.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series — Read the full series

Comments
Post a Comment