Cyberdise AG

$4.99 Million: What a Data Breach Costs in 2026

Published Date:

Security operations centre with analysts silhouetted against a wall of dashboards showing rising cost curves in magenta and cyan
Most of what a breach costs is not the break-in — it is the 247 days before anyone notices.

IBM’s Cost of a Data Breach Report 2026 puts the global average at a record USD 4.99 million. But the headline number tells you less than two others buried in the same report: 63% and 247.

A data breach has never been cheap. But in 2026, the numbers moved in the wrong direction again.

According to IBM’s Cost of a Data Breach Report 2026, the global average cost of a breach reached a record USD 4.99 million — up 12% from USD 4.44 million in 2025. Much of that increase came from detection and escalation costs and from lost business after the incident.

Two details make that increase sharper than it first looks. The 12% is not a smooth climb: 2025 had actually fallen to USD 4.44 million from USD 4.88 million the year before. So this is a rebound and a record at once — the highest figure in the eight years IBM has tracked.

And the split is precise. Detection and escalation plus lost business drove 63% of this year’s record, together accounting for USD 3.18 million of the USD 4.99 million total. Each rose 11.5%. The category that grew fastest, though, was post-breach response — regulatory fines, legal costs, credit monitoring — up 15%. If you have been treating NIS2 as a documentation exercise, that line is worth a second look.

Bar chart of the average global data breach cost: USD 4.88 million in 2024, 4.44 million in 2025 and a record 4.99 million in 2026
A record and a rebound at once — 2025 had actually fallen before this year’s 12% rise.

The global average hides enormous differences

In the United States, an average breach now costs USD 11.5 million — more than twice the global average. Germany, meanwhile, saw one of the larger increases in Europe: costs rose 18% to USD 4.93 million.

Industry matters just as much. Healthcare remains the most expensive sector at USD 6.64 million per breach, followed closely by financial services at USD 6.29 million. At the lower end of IBM’s industry comparison, the public sector still averaged USD 3.5 million.

So what does the USD 4.99 million headline really tell us?

Probably less about what your next breach will cost — and more about the direction of travel.

Breach costs are rising again. Geography, regulation, industry, the type of data involved and, above all, how quickly an organisation detects and contains an attack can move the final number dramatically. Marks & Spencer’s £300 million is what the far end of that range looks like in practice.

The number that should worry you isn’t 4.99

It’s 247.

That is the mean number of days organisations needed to identify and contain a breach — 183 days to spot it, another 64 to shut it down. Eight months from break-in to containment. And after five straight years of improvement, that clock went the wrong way this year, up 2.5%.

The cost of the delay is measurable. Breaches running longer than 200 days averaged USD 5.65 million. Those resolved faster averaged USD 4.32 million. A gap of USD 1.33 million — decided not by the sophistication of the attack, but by how long nobody noticed.

Which is really the same point as the 63%: most of what a breach costs is not the break-in. It is everything that happens while the intruder is still inside. That is also why awareness has to become continuous rather than annual — the people closest to an attack are usually the first ones able to raise a hand.

More than one in four organisations were hit by an AI-driven attack

The other shift in this year’s report is who is doing the attacking.

More than a quarter of organisations experienced a malicious AI-driven attack — a 56% increase over last year. Those attacks cost USD 6.04 million on average, against USD 5.03 million for malicious attacks without AI. A million-dollar premium for automation.

Deepfake impersonation was the single largest category at 45% of AI attacks. Generative AI makes social engineering cheap to produce and hard to detect, which is exactly why it is being pointed at people rather than firewalls — and why voice-clone calls stopped being a novelty this year.

Two numbers underneath that are worth sitting with. Security incidents involving shadow AI — staff using unapproved AI tools — more than doubled to 43%, from 20% last year, and cost more when they happened: USD 5.39 million against USD 4.63 million. And ransomware turned up in 39% of breaches, continuing a four-year climb from 24% in 2023.

And with AI-driven attacks increasing the speed and scale of cyberattacks, that last factor may become increasingly important.

The real question for security leaders is therefore not whether a breach costs $4 million, $5 million or $10 million. It is how much of that cost can still be prevented by detecting and containing the attack faster. And: some regulator will punish you anyway…

So Long, Palo

Source

All figures: IBM Cost of a Data Breach Report 2026. Figures 1–5, 17, 21–22 and 30.

Frequently Asked Questions

What is the average cost of a data breach in 2026?

USD 4.99 million globally — a record, and up 12% from USD 4.44 million in 2025. The figure varies enormously by geography and sector: USD 11.5 million in the United States, USD 4.93 million in Germany, USD 6.64 million in healthcare and USD 3.5 million in the public sector.

How long does it take to detect a data breach?

On average, 247 days to identify and contain one — 183 days to detect and a further 64 to contain. That is up 2.5% this year, reversing five consecutive years of improvement.

How much does slow detection actually cost?

Breaches with a lifecycle longer than 200 days averaged USD 5.65 million. Those resolved faster averaged USD 4.32 million. The difference — USD 1.33 million — comes down to elapsed time rather than the sophistication of the attack.

What is driving the increase in breach costs?

Detection and escalation plus lost business accounted for 63% of the record average, or USD 3.18 million of the USD 4.99 million. Each rose 11.5%. Post-breach response — regulatory fines, legal costs, credit monitoring — grew fastest at 15%.

How many breaches now involve AI?

More than one in four organisations experienced a malicious AI-driven attack, a 56% increase year over year. Those attacks averaged USD 6.04 million against USD 5.03 million without AI. Deepfake impersonation was the largest single category at 45%.

What is shadow AI and how expensive is it?

Shadow AI is staff using AI tools that IT has not approved. Security incidents involving it more than doubled to 43% of organisations, from 20% last year, and the resulting breaches cost more: USD 5.39 million against USD 4.63 million.

Enjoyed reading? Subscribe to our blog!