AI cyberattacks jump 56%, cost businesses $6.04 million per breach, IBM report finds
By Aboki Forex —
AI-driven cyberattacks rose 56% in the past year, with more than one in four organisations hit by a malicious AI-powered incident, according to IBM's 2026 Cost of a Data Breach Report. The average cost of such an attack now stands at $6.04 million per breach.
IBM said attackers are increasingly using AI to automate attacks, identify vulnerabilities and operate at greater scale, cutting the time needed to exploit weaknesses and raising the financial damage to businesses.
AI attacks cost about $1 million more
“More than one in 4 organizations experienced a malicious, AI-driven attack, a 56% increase over last year,” IBM said. The report found that AI-driven attacks cost about $1 million more per breach, averaging $6.04 million compared with $5.03 million for malicious attacks that did not involve AI.
Deepfake impersonation accounted for 45% of AI-driven attacks, making it the most common form identified in the study. AI-generated malware accounted for 19%, while AI-generated phishing and other communications accounted for 17%.
IBM said generative AI has made social engineering attacks cheaper to create and harder to detect, allowing attackers to produce convincing content and manipulate victims at greater scale. “Attackers are abandoning human speed for machine speed,” IBM said, adding that generative AI has reduced the time, cost and expertise required to launch attacks.
Hackers are now targeting AI systems
Criminals are also increasingly targeting the AI systems that businesses are deploying. IBM found that 21% of organisations experienced a security incident involving an AI model or application, up from 13% a year earlier.
The most expensive incidents involved model inversion, which cost an average of $6.07 million, and prompt injection, which averaged $5.89 million. Model inversion involves attempts to extract sensitive information from an AI model, while prompt injection involves manipulating an AI system through malicious instructions.
IBM said these vulnerabilities are particularly significant as AI becomes increasingly connected to corporate applications, data and workflows.
Africa and the global picture
The growing use of AI in cybercrime is also a major concern across Africa, with artificial intelligence enabling 55% of reported cybercrimes on the continent, according to INTERPOL's African Cyberthreat Assessment Report 2026. The report found that financial losses linked to cybercrime more than doubled, rising from $192 million in 2024 to $484 million in 2025.
The findings are based on survey data from 36 African member countries. INTERPOL said criminal operations are moving from isolated attacks to industrialised and borderless networks increasingly powered by AI tools. Neal Jetton, Director of INTERPOL's Cybercrime Unit, said the scale and sophistication of the threat require countries to move beyond isolated national responses and strengthen coordinated cross-border action.
In the United States, the FBI recorded more than $893 million in losses linked to AI-related cybercrime in 2025, according to its Internet Crime Report published by the Internet Crime Complaint Center (IC3). The report said criminals are using AI to create convincing synthetic content, including fake social media profiles, voice recordings and videos, to impersonate individuals and facilitate fraud.
What it means for Nigerian businesses
With AI now behind the majority of reported cybercrime in Africa, Nigerian businesses face a rising threat from automated and deepfake-enabled attacks. The higher cost of AI-driven breaches, plus the growing vulnerability of AI systems themselves, means companies can no longer treat cybersecurity as a simple IT issue. It is now a core business risk requiring investment in stronger detection, employee awareness and cross-border cooperation.