The latest survey released by IBM and the Ponemon Institute reveals a worrying trend: AI-driven attacks account for a quarter of all malicious data breaches, with a 56% year-over-year increase. Each such incident causes an average loss of $6 million, which is 20% higher than the average cost of overall data breaches.

More concerning is the centralization of attack targets. 62% of AI-driven cyberattacks target critical infrastructure, with financial services and energy institutions being the most targeted, increasing the risk of cascading impacts on the economy, supply chains, and essential services.

Severe imbalance in the cost of offense and defense: attacks are cheaper, while defense is more expensive

Suja Viswesan, Vice President of IBM Security Software, pointed out directly: "What is truly changing is the economics of cyberattacks — AI makes attacks faster and cheaper, while the cost of data breaches is becoming increasingly high." Data supports this view: applying AI and automation technologies in security operations can save companies nearly $2 million in breach costs on average, but one-quarter of companies have not yet deployed them.

In terms of the application of AI agents, more than half of enterprises use AI agents for threat detection and containment, but only 18% deploy them in the vulnerability remediation and management process. Additionally, over 20% of enterprises have experienced attacks targeting AI models or application systems, with the most common causes being weak peripheral systems and improper cloud platform configurations. Viswesan emphasized that the top priority at present is to eliminate the time gap between vulnerability discovery and remediation, embedding remediation capabilities into the development process to respond to attacks at the same speed as attackers — while defenders are still manually checking, AI-driven attacks have already completed infiltration.