返回新聞
安全性AI Understanding 簡報

IBM 報告將不斷上升的違規成本與更快的人工智慧驅動攻擊連結起來

CoinGeek 報導稱,IBM 的 2026 年資料外洩成本報告發現,隨著人工智慧驅動的攻擊比 2025 年增加 56%,全球平均外洩成本上升了 12%,達到 499 萬美元。

5 min readRead the linked source
Source-provided image accompanying IBM report links rising breach costs to faster AI-driven attacks
來源參考來源記錄
出版商
coingeek.com
來源連結
coingeek.comhttps://coingeek.com/organizations-turn-to-ai-as-data-breach-costs-jump-12-ibm/
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

關鍵術語

分類
模型將輸入分配給一個或多個預定義類別的任務。
生成式 AI
產生文字、圖像、音訊、視訊或程式碼等新內容的人工智慧系統。
提示
提供給生成模型的輸入指令和上下文。
測試一下自己AI 模型解釋測驗

發生了什麼事

CoinGeek reported on IBM’s 2026 Cost of a Data Breach Report, which surveyed organizations across 16 countries and regions. According to the report, AI-driven attacks rose 56% from 2025, while the average global breach cost increased 12% to $4.99 million. IBM said AI-driven attacks added about $1 million to the average cost of a breach.

CoinGeek reported on August 24 that IBM’s 2026 Cost of a Data Breach Report found the global average cost of a data breach rose 12% to $4.99 million. The source says IBM’s survey covered 16 countries and regions and counted detection and containment costs, regulatory fines, legal expenses, and credit monitoring for affected people. CoinGeek also reported IBM’s estimate that AI-driven attacks increased 56% from 2025. The supplied source does not independently verify the report’s methodology, sample size, or underlying data. The supplied account presents these points as findings from the report, but it does not provide additional detail about how the figures relate to one another, how the categories were defined, or how the reported costs were calculated. Those limitations remain relevant when interpreting the figures as a group.

According to CoinGeek’s account of the IBM report, AI-driven attacks are becoming more attractive to attackers because the tools are cheaper to launch and can operate rapidly at scale. IBM said that speed is changing the economics of breaches and reported that AI-driven attacks added an average of $1 million per incident. The article does not provide case studies, technical descriptions, or independent forensic evidence showing how the attacks were conducted, so the figures should be treated as reported estimates rather than a complete measurement of all AI-enabled cybercrime.

The source says phishing remained the most common attack vector, followed by supply-chain compromise. It identifies attacks involving data replication on removable media as the most complex and longest to resolve among the categories surveyed. CoinGeek reported that the United States had the highest average breach cost at $11.5 million, followed by the Middle East at $8 million and the Benelux region at $7.37 million. ASEAN was reported at $4.12 million, Brazil at $1.41 million, and South Africa at $3.04 million, with South Africa recording the largest percentage increase at 22%.

來源詳情: coingeek.com ↗

為什麼這很重要

The figures suggest that AI is affecting both the speed and economics of cyberattacks, while organizations are also turning to AI for defense. The source reports that 74% of businesses planning higher security spending expect to deploy AI agents in security operations centers, but it does not establish that those tools reduce breach costs or improve outcomes in practice.

The report matters because it frames AI as both an offensive capability and a defensive response. CoinGeek reported IBM’s warning that AI-driven attacks can raise breach costs by accelerating reconnaissance, execution, or the scale of malicious activity. However, the supplied article does not identify specific incidents behind the estimate or prove that AI caused the overall 12% increase in breach costs. Other factors may also contribute, and the source does not quantify their relative importance.

IBM’s sector figures point to potential systemic consequences. CoinGeek reported average breach costs of $6.29 million for financial services and $5.2 million for energy organizations when discussing AI-related attacks. IBM warned that concentration in those sectors could create cascading effects across consumer finances, economic systems, and power grids. That warning describes a plausible public-risk pathway, but the source does not document an actual cascade or establish how frequently such events occur.

The defensive shift is also significant. CoinGeek reported that 85% of surveyed businesses planned to increase security spending after experiencing a breach, compared with 65% the prior year. Of those organizations, 74% reportedly intended to use AI agents in security operations centers, especially for alert triage, penetration testing, vulnerability scanning, and vulnerability management. These are intended deployments, not evidence of successful implementation. The article gives no results showing that AI agents lower costs, catch more threats, reduce response times, or operate safely without human review.

For the public, the practical issue is not simply whether companies buy more AI security products. It is whether they can use them while preserving reliable oversight, protecting sensitive data, and maintaining clear accountability when automated recommendations are wrong. The source’s statistics support attention to the trend, but they do not support claims that AI is already solving the breach-cost problem.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Models Explained Quiz

Which component of an AI application is the machine-learning model itself?

接下來看什麼

Watch for the full IBM methodology, the definition of an AI-driven attack, and independent analysis of the reported increases. The practical test will be whether AI agents improve alert triage, vulnerability management, penetration testing, and response without creating additional errors, privacy risks, or attack surfaces.

The first priority is verification of IBM’s underlying report. The supplied article names the Cost of a Data Breach Report 2026 but does not provide the report’s sample size, respondent profile, survey dates, definitions, or statistical methods. Those details are necessary to assess whether the reported 56% increase reflects a broad change in attacks, a change in reporting or , or a different survey composition. The source also does not explain whether the $4.99 million average is directly comparable with the prior year’s figure.

The definition of an AI-driven attack deserves particular scrutiny. The article does not say whether IBM counted attacks that used for phishing, automated discovery, code generation, social engineering, or other purposes. It also does not distinguish attacks primarily enabled by AI from conventional attacks that used an AI tool incidentally. Without that distinction, organizations may find it difficult to translate the headline statistic into specific defensive priorities.

The next test is operational evidence from the planned AI deployments. Organizations should disclose whether AI agents are limited to recommending actions or can change configurations, block traffic, run scans, or access sensitive systems. Metrics worth watching include false-positive rates, time to contain incidents, missed threats, human-review requirements, and the cost of maintaining the systems. The source reports intended use in alert triage, penetration testing, and vulnerability management, but no deployment results.

Finally, security teams will need to assess whether defensive AI introduces new risks. The supplied source does not discuss data retention, model errors, manipulation, unauthorized access, or supply-chain exposure in AI security tools. Those unknowns are material because the same article identifies supply-chain compromise as the second most common attack vector and removable-media attacks as especially difficult to resolve. Independent testing and transparent incident reporting will be needed before reported spending plans can be treated as evidence of improved security.

相關指引和測驗

人工智慧模型解釋人工智慧代理AI 倫理人工智慧培訓測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?