Data breach cost in India hits record ₹25.5 crore in 2026: IBM Report
Synopsis
Key Takeaways
The average total organisational cost of a data breach in India climbed to an all-time high of ₹25.5 crore in 2026, a 15.9 per cent rise over the previous year, according to a new report released on Monday, 3 August. The findings, published by IBM, signal a sharp escalation in cyber risk exposure for Indian organisations at a time when artificial intelligence is reshaping the threat landscape.
Scale of Breaches Growing
Beyond the financial toll, breaches in India also expanded in scope. The average number of records compromised per incident rose to 39,500 in 2026, up from 38,200 in 2025. Nearly 26 per cent of malicious breaches were AI-generated, underscoring how threat actors are leveraging automation to launch faster, more sophisticated, and increasingly scalable attacks.
AI Adoption Cuts Costs — But Most Firms Lag Behind
The IBM report draws a stark contrast between organisations that have embraced AI-driven security and those that have not. Firms with no AI and security automation paid an average of ₹31.6 crore per breach, compared with ₹21.3 crore for those with extensive AI deployment and ₹23.1 crore for those with limited deployment. The gap in response speed was equally significant: organisations without AI took an average of 236 days to identify a breach and 75 days to contain it — longer than their AI-equipped counterparts.
Despite these clear advantages, only 32 per cent of organisations reported extensive use of AI and security automation, while 36 per cent reported limited use and 32 per cent reported none at all.
What IBM Said
Gaurav Agarwal, Vice President, Technology, IBM India & South Asia, said India's accelerating AI adoption is creating opportunities for innovation but simultaneously enabling cyber threats to evolve rapidly. 'The findings underscore that organisations using AI and strong governance were significantly better positioned to fend off cyberattacks,' he said.
Agarwal added that most organisations apply AI in limited ways, often focused on detection. 'To keep pace, AI with agentic capabilities must be embedded across the full security lifecycle — from detection and analysis to prioritisation and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage,' he said.
Top Attack Vectors and Where Firms Are Investing
Phishing — including voice and SMS phishing — was the most common initial attack vector in India, accounting for 19 per cent of breaches. It was followed by drive-by compromise (16 per cent) and supply chain compromise (15 per cent).
In response, 73 per cent of organisations indicated plans to increase security investments following a breach. The top five priority areas are: incident response plans and testing (67 per cent), threat detection and response technologies such as SIEM, SOAR, and EDR (51 per cent), identity and access management (49 per cent), AI security and governance tools (39 per cent), and employee awareness and training (36 per cent).
With AI-powered attacks becoming the norm rather than the exception, the data suggests Indian enterprises face a widening security gap — and the cost of inaction is now measurable in tens of crores per incident.