India's Data Breach Costs Hit Record Rs 25.5 Crore as AI Speeds Up Cyberattacks: IBM Report
The average cost borne by Indian organisations after a data breach has climbed to an all-time high of Rs 25.5 crore in 2026, according to IBM's latest Cost of a Data Breach report, underscoring how artificial intelligence is simultaneously making cyberattacks more damaging and, in some cases, easier to contain.
Costs Keep Climbing
The figure marks an increase of roughly 16 percent over last year's average of about Rs 22 crore, continuing a multi-year trend of rising breach costs in India even as companies pour more money into cybersecurity tooling. The report attributes much of the increase to attackers using AI to scale and speed up their campaigns, from more convincing phishing lures to automated reconnaissance of corporate networks.
Phishing, including voice and SMS-based variants, remains the single most common way attackers first gain access to Indian corporate systems, accounting for close to a fifth of breaches studied. Drive-by compromises and supply chain attacks followed as the next most frequent entry points, reflecting how attackers are increasingly targeting the software and vendor relationships that large organisations depend on rather than attacking a company's own systems head-on.
The AI Paradox
Perhaps the most striking finding is what the report describes as a split outcome from AI adoption. Indian organisations that had not deployed AI and automation tools in their security operations took an average of 236 days to identify a breach, and ended up paying substantially more, with average costs rising to roughly Rs 31.6 crore. By contrast, organisations that had extensively deployed AI and automation in their defences cut that detection window to around 175 days and held average costs down to about Rs 21.3 crore.
That gap illustrates a theme security researchers have flagged repeatedly this year: AI is not inherently good or bad for cybersecurity outcomes, it is a force multiplier that favours whichever side, attacker or defender, uses it more effectively. Roughly a quarter of malicious breaches studied in India were found to involve AI-generated elements on the attacker's side, a sign that automated and AI-assisted attacks have moved from experimental to mainstream over a relatively short period.
Why This Matters for Indian Businesses
For companies operating in India, the widening gap between AI-equipped and AI-lagging security teams adds urgency to a decision many boards have been deferring: whether to invest meaningfully in AI-driven detection and response tools now, or risk falling further behind attackers who are already using similar technology offensively. The report's detection-time figures suggest that the cost of delay is not just reputational but directly financial, since breaches that go undetected for longer periods consistently prove more expensive to remediate.
With India's digital economy continuing to expand rapidly across banking, e-commerce and government services, the scale of financial exposure highlighted in this report is likely to keep cybersecurity spending high on the agenda for corporate India through the rest of the year.
This article is an original editorial summary based on publicly reported information. It has been independently written for publication and does not reproduce content from any single source.
Comments
Sign in to join the discussion.