Data Breaches Negative 6

26% of India breaches AI‑generated as costs hit ₹25.5 cr: IBM 2026 report

IBM’s latest report reveals India’s average data breach cost surged 15.9% to a record ₹25.5 crore, with AI‑generated attacks now accounting for 26% of malicious incidents. Organizations without AI security automation paid 48% more than those with extensive deployment, exposing a critical defense gap. Phishing remains the top vector, and 73% of firms plan to ramp up security spending.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Data Breaches

2 stories
6 avg impact
0% positive
50% negative
vs prior 7 days 0 Unchanged vs prior 7 days

Impact 6.0/10, unchanged. Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 50 percentage points.

  • 50% neutral
  • 50% negative

This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

6 impact
Negativesentiment
2sources
4min read
  1. IBM’s latest report reveals India’s average data breach cost surged 15.9% to a record ₹25.5 crore, with AI‑generated attacks now accounting for 26% of malicious incidents.
  2. Organizations without AI security automation paid 48% more than those with extensive deployment, exposing a critical defense gap.
  3. Phishing remains the top vector, and 73% of firms plan to ramp up security spending.
Drawn from
  • newkerala.com
  • aninews.in

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Average data breach cost in India reached a record ₹25.5 crore in 2026, a 15.9% increase from ₹22 crore in 2025.
  2. 2Average records compromised per breach rose to 39,500, up from 38,200 in 2025.
  3. 326% of malicious breaches were AI‑generated, highlighting AI’s growing role in crafting sophisticated attacks.
  4. 4Organizations without AI/security automation faced a breach cost of ₹31.6 crore, while those with extensive AI deployment spent ₹21.3 crore—a 48% gap.
  5. 5Only 32% of Indian organizations have extensively deployed AI and security automation; 32% have no adoption at all.
  6. 6Phishing (including vishing and smishing) remained the top attack vector at 19% of breaches, and 73% of firms plan to increase security investments post‑breach.

India's accelerating AI adoption is creating immense opportunities for innovation, but it is also enabling cyber threats to evolve rapidly. The findings underscore that organizations using AI and strong governance, were significantly better positioned to fend off cyberattacks.

Gaurav Agarwal Vice President, Technology, IBM India & South Asia

On the release of IBM's 2026 Cost of a Data Breach Report

Average Breach Cost (India 2026)
₹25.5 crore +15.9% YoY

All-time high for India, driven by AI‑generated attacks and phishing

AI Security Adoption Outlook

Analysis

For security operations teams, the ₹25.5 crore average breach cost isn’t just a number—it’s a direct result of adversaries weaponizing AI. With 26% of malicious breaches now AI‑generated, the attack surface is evolving faster than most defenders can adapt. Yet IBM’s data offers a path forward: organizations that embed agentic AI across the full security lifecycle—from detection to remediation—cut their breach costs by nearly a third.

India’s data breach landscape has crossed a grim milestone. According to IBM’s 2026 Cost of a Data Breach Report, the average cost of a breach in the country has soared to an all-time high of ₹25.5 crore, representing a 15.9% jump from ₹22 crore in 2025. The scale of breaches also widened, with an average of 39,500 records compromised per incident, up from 38,200 the year prior. This twin escalation—cost and volume—underscores a rapidly intensifying threat environment, driven significantly by the adoption of artificial intelligence by adversaries.

The report lays bare the consequence of inaction: only 32% of Indian organizations have achieved extensive AI and security automation; another 36% report limited adoption, and 32% have none at all.

Nearly 26% of malicious breaches in India were AI‑generated, the report notes, illustrating that AI is no longer a fringe tool for cybercriminals. It enables faster reconnaissance, more convincing phishing campaigns, and the ability to launch scalable attacks that evade traditional, signature‑based defenses. The sophistication of these AI‑powered attacks is raising the baseline cost of every breach, from detection and containment to post‑incident response and reputational damage.

Yet the report’s most striking finding is the defensive power of AI and security automation. Organizations that have extensively deployed these technologies experienced an average breach cost of ₹21.3 crore—nearly ₹10 crore less than the ₹31.6 crore average for those with no AI or automation. This cost differential of 48% is a powerful economic signal to chief information security officers and boardrooms. It also explains why 73% of Indian firms now say they plan to increase security investments in the wake of a breach. The report lays bare the consequence of inaction: only 32% of Indian organizations have achieved extensive AI and security automation; another 36% report limited adoption, and 32% have none at all. This leaves a substantial portion of the enterprise landscape dangerously exposed.

Phishing, including voice‑based vishing and SMS‑based smishing, remains the top initial attack vector, accounting for 19% of breaches. This prevalence, combined with AI’s ability to craft hyper‑personalized lures, suggests that the attack surface will only expand. The human element continues to be the weakest link, and AI is making exploitation more efficient.

From a regulatory and compliance perspective, India’s Digital Personal Data Protection Act 2023 is yet to be fully operationalized, but its impending enforcement will add financial and legal penalties to the already high cost of breaches. Companies that have not invested in AI‑driven security and data governance will find themselves doubly vulnerable—to attackers and to regulators.

What to Watch

The report’s call to action is clear. Gaurav Agarwal, VP of Technology for IBM India & South Asia, emphasized that most organizations today apply AI in limited ways, often focused solely on detection. He argues that agentic AI—systems capable of autonomous decision‑making and action across the full security lifecycle, from detection and analysis to prioritization and remediation—must become a strategic imperative. This shift from passive monitoring to proactive, automated defense is what will separate resilient enterprises from those that suffer repeated, costly breaches.

Looking ahead, the trend lines are concerning. Breach costs in India have been rising steadily, and the integration of AI into attack methodologies will accelerate this trajectory. However, the same AI technology is proving to be a powerful ally. The organizations that move decisively to embed AI and automation across their security stack will not only lower their breach costs but also build a competitive advantage by instilling trust among customers and partners. The 2026 report serves as both a warning and a playbook: the cost of inaction is now quantifiable, and the payback for investment is immediate.

Source cluster

Primary reporting

2articles

Cite This Page

"26% of India breaches AI‑generated as costs hit ₹25.5 cr: IBM 2026 report." Cyber Intelligence Brief, August 3, 2026. https://getcyberbrief.com/story/india-data-breach-cost-2026-ibm-ai-attacks

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.