IBM Report: AI-Driven Attacks Account for 25% of Data Breaches, Causing 20% Higher Losses

iconMetaEra
Share
AI summary iconSummary
IBM and the Ponemon Institute report that AI-driven attacks now account for 25% of data breaches, a 56% increase from last year. Each breach averages $6 million in losses—20% higher than the overall average. On-chain data reveals that 62% of these attacks target critical infrastructure, particularly the financial and energy sectors. Inflation data shows rising defense costs as AI reduces the cost of attacks. Over half of firms use AI for threat detection, but only 18% for vulnerability management. More than 20% have experienced AI model intrusions.
A joint survey report by IBM and the Ponemon Institute found that AI-driven attacks now account for 25% of all malicious data breaches, representing a 56% year-over-year increase. The average cost per incident is $6 million—20% higher than the average cost of all data breaches. 62% of AI-driven cyberattacks target critical infrastructure such as financial services and energy institutions, triggering cascading effects on the economy, supply chains, and essential services. AI enables attacks to become faster and cheaper, while defense costs continue to rise. Over half of organizations use AI agents for threat detection, but only 18% apply them to vulnerability remediation, and more than 20% have experienced breaches of their AI models or application systems.

Article author and source: IBM and the Ponemon Institute survey report

A recent joint survey by IBM and the Ponemon Institute reveals a alarming trend: AI-driven attacks now account for one-quarter of all malicious data breaches, a 56% year-over-year increase. These incidents cost an average of $6 million per occurrence—20% higher than the average cost of all data breaches.

IBM and the Ponemon Institute survey report reveals critical infrastructure faces significant challenges.

More concerning is the centralization of attack targets. 62% of AI-driven cyberattacks target critical infrastructure, with financial services and energy institutions facing the highest concentration of attacks, increasing the risk of cascading impacts on the economy, supply chains, and essential services.

Cost imbalance between attack and defense: attacks are cheaper, while defense is more expensive.

IBM Security Software Vice President Suja Viswesan aptly noted: "What's truly changing is the economics of cyberattacks—AI makes attacks faster and cheaper, while the cost of data breaches continues to rise." Data supports this assessment: applying AI and automation in security operations can save companies an average of nearly $2 million in breach costs, yet a quarter of enterprises still have not implemented them.

Current Status and Security Challenges of AI Agent Applications

In terms of agent applications, over half of enterprises have deployed AI agents for threat detection and containment, but only 18% have integrated them into vulnerability remediation and management. Additionally, more than 20% of enterprises have experienced intrusions targeting AI models or application systems, with the most common causes being weak peripheral systems and misconfigured cloud platforms. Viswesan emphasized that the top priority now is eliminating the time gap between vulnerability discovery and remediation by embedding remediation capabilities directly into the development process to match the speed of attacks—while defenders are still manually investigating, AI-driven attacks have already completed their infiltration.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.