IBM
Reports
All Statistics
62% of AI-driven attacks targeted critical infrastructure sectors.
41% of ransomware attacks exploited brand reputation.
Manufacturing accounted for 27.7% of incidents observed by IBM X‑Force.
Active ransomware and extortion groups increased by 49% year over year.
Vulnerability exploitation accounted for 40% of incidents observed by IBM X‑Force in 2025.
Healthcare breaches remained the most expensive, averaging $7.42 million.
There was a significant reduction in the number of organisations that planned to invest in security following a breach: 49% in 2025 compared to 63% in 2024.
Organisations using AI and automation extensively throughout their security operations saved an average of $1.9 million in breach costs.
Credentials or data were stolen in nearly half of all cyberattacks.
Manufacturing organisations experienced 24% of attacks involving data theft.
The percentage of companies integrating AI into at least one business function has dramatically increased to 72% in 2024, up 55% from the previous year.
AI-enabled malicious breaches increased by 56% over the previous year.
25% of organizations have not adopted AI and automation in their security operations.
Financial services breaches cost on average $6.3 million.
64% of organizations plan to increase security spending after experiencing a breach.
More than 50% of organizations use agents for threat detection and containment.
75% of organizations said frontier AI threats are prompting them to rethink how agents are deployed across security operations.
More than 20% of organizations reported a breach targeting AI models or applications.
27% of breaches were caused by compromised APIs, applications, or plug-ins.
35% of ransomware attacks exploited employee data.
31% of ransomware attacks exploited intellectual property.
25% of malicious breaches were AI-enabled.
AI-enabled breaches cost roughly $1 million more than the global breach average.
AI-enabled breaches cost an average of $6 million.
Energy sector breaches cost on average $5.2 million.
27% of breaches were caused by cloud misconfigurations affecting AI workloads.
18% of organizations apply agents to vulnerability management.
Using AI and automation in security operations cuts breach costs by almost $2 million on average.
37% of breached organizations encrypted sensitive data both at rest and in transit.
North America accounted for 29% of total cases observed by IBM X‑Force.
Manufacturing is the top targeted sector for the fifth consecutive year.
North America became the most-attacked region for the first time in 6 years.
Publicly disclosed victim counts increased by roughly 12%.
North America's share of total cases increased from 24% in 2024 to 29%.
Attacks that begin with exploitation of public-facing applications increased by 44%, largely driven by missing authentication controls and AI-enabled vulnerability discovery.
Infostealer malware led to the exposure of over 300,000 ChatGPT credentials in 2025.
Large supply chain and third-party compromises have nearly quadrupled since 2020.
Security incidents involving shadow AI led to more personally identifiable information (65%) being compromised compared to the global average (53%).
Organisations that detected a breach internally observed a $900,000 savings on breach costs compared to those disclosed by an attacker.
Of those compromised by an AI-related breach, 97% report not having AI access controls in place.
8% of organisations reported not knowing if they had been compromised by an AI-related breach.
63% of organisations opted not to pay ransom demands last year, compared to 59% the year prior.
Organisations that used high levels of shadow AI observed an average of $670,000 in higher breach costs.
31% of AI-related security incidents led to operational disruption.
One in five organisations (which is 20%) reported a breach due to shadow AI.
Security incidents involving shadow AI led to more intellectual property (40%) being compromised compared to the global average (33%).
The healthcare sector saw a $2.35 million reduction in costs compared to 2024.
60% of AI-related security incidents led to compromised data.
Organisations using AI and automation extensively throughout their security operations reduced the breach lifecycle by an average of 80 days.