AI-led attacks push India's average data breach cost to record ₹25.5 crore

The average cost of a data breach in India has climbed to an all-time high of ₹25.5 crore in 2026, underscoring how artificial intelligence is simultaneously making cyberattacks more sophisticated while exposing gaps in enterprise cyber defence, according to IBM's latest Cost of a Data Breach Report.
The average breach cost rose 15.9% year-on-year from ₹22 crore in 2025, while the average number of compromised records also increased to 39,500, highlighting the growing financial and operational impact of cybersecurity incidents on Indian organisations.
The report comes at a time when enterprises are rapidly deploying AI across business operations but are yet to embed the technology comprehensively into cybersecurity.
According to IBM, 26% of malicious breaches investigated in India involved AI-generated attacks, signalling a shift in the threat landscape as cybercriminals increasingly leverage AI to automate phishing campaigns, craft more convincing social engineering attacks and scale malicious operations.

"India's accelerating AI adoption is creating immense opportunities for innovation, but it is also enabling cyber threats to evolve rapidly," said Gaurav Agarwal, Vice President, Technology, IBM India & South Asia.
"AI with agentic capabilities must be embedded across the full security lifecycle—from detection and analysis to prioritisation and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage," he said.
AI adoption gap raises breach costs
Despite growing awareness, enterprise adoption of AI-driven security remains limited.
Only 32% of Indian organisations surveyed reported extensive deployment of AI and security automation, while 68% said they either use the technology only in limited ways or not at all.

The difference translated directly into financial impact.
Organisations without AI and security automation incurred an average breach cost of ₹31.6 crore, compared with ₹21.3 crore for organisations that had extensively deployed AI-powered security capabilities.
Automation also shortened breach response timelines. Organisations with mature AI security identified breaches in an average of 175 days, compared with 236 days for those without automation.
The report suggests AI is increasingly becoming an economic imperative rather than simply another cybersecurity tool.
Shadow AI emerges as a new enterprise risk

The rapid adoption of generative AI across organisations is also creating new security blind spots. IBM identified Shadow AI—the unauthorised use of AI applications by employees—as one of the three biggest cost amplifiers for data breaches in India. Where Shadow AI was involved, breach costs increased by an average ₹1.79 crore.
The report places Shadow AI alongside regulatory non-compliance and cloud migration complexity as the largest contributors to rising breach costs, highlighting the governance challenges organisations face as employees increasingly experiment with public AI tools.
Financial services remain the biggest target
Among industries, financial services continued to record the highest breach costs at ₹40.9 crore, followed by technology (₹35.7 crore) and communications (₹34.5 crore). Phishing remained the dominant initial attack vector, accounting for 19% of incidents. Voice phishing and SMS phishing were identified as growing concerns, followed by drive-by compromises and supply chain attacks.

The report also found that proactive security measures delivered measurable financial benefits. Red teaming and penetration testing emerged as the biggest cost-saving initiatives, reducing breach costs by an average ₹2.47 crore, followed by proactive threat hunting and AI governance technologies.
Security spending shifts toward resilience
The findings indicate Indian enterprises are responding by increasing investments in cyber resilience. About 73% of organisations surveyed said they plan additional investments in cybersecurity following a breach.
Incident response planning topped the investment agenda, followed by threat detection and response platforms such as SIEM, SOAR and EDR, identity and access management, AI security governance tools and employee awareness programmes.

The report suggests that as AI becomes central to both enterprise operations and cybercrime, organisations can no longer rely solely on conventional security models. Instead, the competitive advantage may increasingly lie with enterprises that integrate AI across the entire cybersecurity lifecycle—from threat detection and analysis to prioritisation, remediation and governance—before attackers widen the gap further.
