logo svg
logo

October 10, 2025

Updated: August 18, 2026

AI Cyber Attack Statistics 2026: Costs, Cases & Defense

Verified 2026 data on AI-enabled attacks, breach costs, documented campaigns, exposed AI systems, and the controls that reduce risk.

Khaled Hassan

Khaled Hassan

Featured Image

Last updated: August 2026

Executive Answer

AI is now a measured factor in real cybercrime, but there is no credible single percentage for all AI cyber attacks. IBM found that one in four malicious breaches in its 2026 study were AI-enabled, while the FBI recorded 22,364 U.S. complaints involving AI and nearly $893 million in reported losses during 2025. Separate provider and threat-intelligence datasets show attackers using AI most heavily for preparation, social engineering, malware development, and evasion. Autonomous operations are documented, but human-led, AI-assisted activity remains the more common pattern.

Key AI Cyber Attack Statistics for 2026

The numbers below are the strongest current signals we found. They do not share a universal denominator, so each row names the population or measurement behind it.

StatisticWhat was measuredScope and interpretation
1 in 4 malicious breaches were AI-enabled, up 56% year over yearBreach studyIBM/Ponemon study of 602 breached organizations globally, March 2025–February 2026
$6 million average cost for an AI-enabled breachBreach cost studyAbout $1 million above IBM’s $4.99 million global breach average in the same study
22,364 AI-related complaints and nearly $893 million in reported lossesU.S. complaint dataFBI IC3 complaints for 2025; not a global attack count and not limited to enterprise intrusions
89% increase in attacks by AI-enabled adversariesVendor threat telemetryCrowdStrike intelligence for activity observed in 2025; not the share of every attack worldwide
832 banned malicious accounts used 482 unique ATT&CK sub-techniques across all 14 tacticsAI-provider misuse datasetAnthropic sample selected where sufficient detail existed to map behavior, March 2025–March 2026
Medium-or-higher AI-enablement risk rose from about 33.5% to 56.1%AI-provider misuse datasetChange within two halves of Anthropic’s selected sample; detection improvements may contribute
69% of the sampled actors used AI for capability developmentAI-provider misuse dataset574 of 832 accounts; 560 were observed in malware-development activity
6.5% of the sampled actors used AI for lateral movementAI-provider misuse dataset54 of 832 accounts, showing that observed in-network adaptive use remained less common
More than 20% of breached organizations reported an attack targeting AI models or applicationsBreach studyIBM’s breached-organization sample; 27% cited compromised surrounding APIs, apps, or plug-ins and 27% cited cloud misconfiguration
More than 113,000 confirmed Ollama instances and 2,500 Chroma servers were internet-exposedExposure scanTrend Micro/Shodan observations from September to mid-December 2025; exposure does not prove compromise

IBM’s 2026 Cost of a Data Breach announcement supplies the clearest current breach-cost evidence. The study covers organizations that had already experienced a breach, so its one-in-four result is not a prevalence estimate for every organization or every cyber event.

The FBI’s 2025 Internet Crime Report announcement is a direct measure of reports received by IC3. Complaint totals depend on victim reporting, classification, and U.S. jurisdiction; they should not be relabeled as confirmed incidents or global losses.

CrowdStrike reported an 89% increase in attacks by AI-enabled adversaries and more than 90 organizations where legitimate AI tools were exploited to generate malicious commands or steal sensitive data. Those findings come from the company’s threat-intelligence visibility and should be cited as vendor telemetry, not a census of the internet.

Anthropic’s LLM ATT&CK Navigator study analyzed 832 accounts banned for malicious cyber activity. It offers unusually detailed behavioral evidence, but the company explicitly says this was a selected subset of banned accounts with enough information to map not a random sample of attackers.

For broader context on ransomware, vulnerability exploitation, the human element, and breach patterns that are not necessarily AI-specific, use our current cybersecurity statistics reference rather than merging all cyber-risk figures into an AI total.

How to Read AI Cyber Attack Statistics Without Being Misled

“AI cyber attack” is not yet a standardized reporting category. One organization may count a phishing message drafted with a model; another may require AI to materially shape intrusion activity; a third may count attacks against an AI application. Combining those categories produces dramatic but meaningless totals.

Use this five-level evidence hierarchy before quoting a number.

AI Cyber Attack Evidence Types Compared

Evidence typeWhat it measuresBest useWhat it cannot prove alone
Confirmed incident or breach studyInvestigated security events, affected organizations, and sometimes financial impactEstimating business impact and comparing breach outcomes inside the stated sampleThe percentage of all organizations or all global attacks involving AI
Security telemetry and threat intelligenceActivity visible to a provider’s sensors, customers, investigations, or intelligence collectionTracking direction, techniques, and changes within that provider’s visibilityA complete census outside the provider’s coverage and detection methods
AI-provider misuse datasetMalicious behavior detected on a specific model, account set, or platformUnderstanding how actors request and apply AI assistanceBehavior on other hosted services, local models, or attacks that never touch the provider
Complaint or law-enforcement dataVictim reports, alleged losses, and reported criminal methods within a jurisdictionMeasuring reported harm and identifying fraud patternsConfirmed incident totals, unreported losses, or worldwide prevalence
Exposure scan, survey, or forecastReachable systems, respondent experience, expectations, or modeled scenariosFinding attack surface, sentiment, preparedness gaps, and plausible future pressureSuccessful compromise; a survey or forecast is not observed attack telemetry

The comparison prevents a common error: treating an exposure count as a breach count or a provider trend as a global prevalence rate. Always keep the source population, observation window, geography, and attribution method beside the number.

AI Attack Labels Compared

LabelWorking definitionEvidence requiredCommon reporting error
AI-assistedA human operator leads the activity and uses a model for one or more discrete tasksEvidence that a model contributed to a task plus evidence of human directionCalling any generated message or script an autonomous attack
AI-enabledAI materially expands the speed, scale, reach, or capability of the malicious activityIncident, telemetry, or provider evidence showing a meaningful operational contributionCounting every attack in which AI appeared, regardless of material effect
AI-orchestratedAn agent chains multiple actions, uses tools, interprets results, and continues with intermittent supervisionTool-call records, case reconstruction, or provider investigation showing multi-step agencyAssuming “agentic” means fully unsupervised from target selection to impact
Attack on an AI systemThe model, data, agent, plug-in, API, vector store, or surrounding infrastructure is the targetEvidence of unauthorized access, manipulation, exposure, or service abuseMixing attacks against AI systems with attackers’ malicious use of AI

These labels are a practical editorial taxonomy, not an industry reporting standard. They make the article’s comparisons explicit and keep early agentic cases separate from more common human-led use.

This page owns malicious-use and attack evidence. Our separate AI in cybersecurity statistics guide covers defensive adoption, SOC automation, and how security teams use AI.

Where Attackers Are Using AI Now

Social engineering and impersonation

AI can reduce the time and language skill needed to produce tailored messages, synthetic profiles, voice clones, and convincing video. Modern AI video creation has also made realistic synthetic media more accessible, reinforcing the need to verify identity through trusted channels rather than visual appearance alone. The practical risk is not that every message becomes perfect; it is that attackers can test more variants and maintain credible conversations across email, messaging, phone, and video. The practical risk is not that every message becomes perfect; it is that attackers can test more variants and maintain credible conversations across email, messaging, phone, and video.

The FBI’s complaint data specifically references fake social profiles, voice clones, identification documents, and believable videos. Organizations should treat a familiar voice or face as a presentation layer, not proof of identity. Review our social engineering attack statistics for the wider human-targeting context.

Payment and account-change workflows need a second channel that attackers cannot satisfy with the same message. A callback to a known number, dual approval, and a cooling-off rule for unusual requests are stronger than asking the sender another question in the compromised channel. Our business email compromise statistics page covers the financial-fraud pattern in more detail.

Capability development, scripting, and evasion

In Anthropic’s selected sample, capability development was the most common technique family: 574 of 832 accounts, or 69%. Obfuscated files or information appeared for 64.7% of actors, data from local systems for 55.9%, and impairment of defenses for 54.9%. These are observations of model misuse, not proof that the model independently completed a successful breach.

The defensive implication is to measure outcomes rather than guess authorship. Endpoint, identity, email, cloud, and network telemetry should still detect suspicious behavior whether code or content was written by a person, a model, or both. Regular penetration testing services can validate whether exposed paths produce real business impact.

Vulnerability discovery and exploitation

Google Threat Intelligence Group reported the first threat actor it believes used an AI-developed zero-day exploit. Google said the criminal actor planned mass exploitation, while proactive discovery may have prevented the exploit’s use. That is a vendor assessment of a specific case not evidence that AI-generated zero-days are routine.

AI may compress research and development time, but exploitable exposure still depends on ordinary weaknesses: reachable services, vulnerable software, weak identity controls, excessive privileges, and slow remediation. Internet-facing applications need an owner, an inventory record, a patch target, logging, and a tested containment path. Web application penetration testing services help validate those controls against realistic abuse cases.

Agentic and AI-orchestrated operations

Agentic tools can plan subtasks, invoke tools, interpret results, and continue with limited supervision. That creates a genuine speed and scale concern, yet current evidence does not support calling most attacks autonomous. Anthropic observed AI use for lateral movement in 54 of 832 sampled malicious accounts, or 6.5%, and for privilege escalation and impact stages in 22.5%.

High-risk testing should focus on what an agent can reach and authorize: identities, secrets, tools, data stores, network destinations, and approval gates. A scoped LLM and AI penetration test should evaluate the whole application and tool chain, not just prompt behavior.

Attacks against AI applications and infrastructure

IBM found that more than one in five breached organizations in its study reported an attack targeting AI models or applications. The two most common surrounding causes were compromised APIs, applications, or plug-ins and cloud misconfigurations, each reported by 27%. This shifts security attention from the model alone to the identity, integration, application, and cloud layers around it.

Trend Micro’s 2026 AI security research identified more than 113,000 confirmed internet-exposed Ollama instances and 2,500 exposed Chroma servers in its 2025 observation window. These are exposures, not confirmed attacks, but they demonstrate why discovery, authentication, network restriction, and timely upgrades must precede production use.

Cloud configuration reviews should cover model endpoints, vector stores, object storage, service accounts, API gateways, logging, secrets, and egress. Cloud penetration testing services can test whether a configuration weakness can be chained into unauthorized access without relying on speculative model behavior.

Documented AI-Enabled Cyber Attack Cases

The three cases below show different roles for AI and different levels of public evidence. They should not be added together as one incident total.

Documented caseAI roleReported scopeWhat it demonstratesKey limitation
Anthropic espionage campaign, detected September 2025AI-orchestrated activity with periodic human decisionsRoughly 30 global targets; successful in a small number of casesA provider-documented chain in which AI reportedly performed most campaign workProvider-authored assessment based on visibility into its own service; limited independent public validation
Google suspected AI-developed zero-day, reported May 2026AI-assisted vulnerability and exploit developmentPlanned mass exploitation that Google said may have been preventedAI may contribute to development of a previously unknown exploitGoogle stated a belief about one investigated case; no confirmed mass-exploitation outcome was reported
FBI warning on senior-official impersonationAI-assisted social engineering using synthetic voice and messagingPublic warning without a campaign-wide incident countSynthetic media can strengthen identity and trust abuse across channelsThe warning describes a pattern and victim risk, not a quantified breach dataset

AI-orchestrated espionage attempt against roughly 30 targets

In September 2025, Anthropic detected activity it assessed with high confidence as a Chinese state-sponsored operation. The company said the actor attempted infiltration of roughly 30 technology, financial, chemical, and government targets and succeeded in a small number of cases.

Anthropic described the event as the first documented large-scale cyberattack executed without substantial human intervention. It estimated that AI performed 80%–90% of campaign work, with human decisions at a small number of critical points. This is a provider-authored incident assessment based on visibility into its own service; independent public validation is limited.

The case matters because it connects planning, tool use, interpretation, and repeated action. It does not prove that fully autonomous compromise is now dominant. Defenders should respond by constraining agent permissions, monitoring tool calls, isolating sensitive environments, and rehearsing the decisions that require a human stop.

Suspected AI-developed zero-day prepared for mass exploitation

Google’s May 2026 report said its team identified a criminal actor using a zero-day exploit it believes was developed with AI. The planned mass-exploitation event may not have occurred because of Google’s counter-discovery. The careful wording matters: this is evidence of AI-assisted exploit development in one investigated case, not a count of successful AI-generated zero-day attacks.

The control lesson is familiar but urgent: reduce public exposure, shorten remediation time, require strong identity controls, detect unusual process and account behavior, and maintain an emergency path for containment. Continuous penetration testing can help verify whether newly introduced exposure becomes exploitable between annual assessments.

Senior-official impersonation using AI-generated voice

The FBI warned that malicious actors had impersonated senior U.S. officials through text messages and AI-generated voice messages. The objective was to establish trust and move targets into another communication channel where further access or information could be requested.

This pattern is best understood as identity and process abuse. Controls should verify the request, not the media. Known-directory callbacks, approval separation, protected contact lists, and reporting channels can interrupt the attack even when the synthetic content is convincing.

Business Cost and Sector Exposure

IBM’s 2026 breach study reported a $6 million average cost for AI-enabled breaches, about $1 million above its $4.99 million global average. The report says those AI-enabled events consisted mainly of deepfake impersonation and AI-enabled malware. Because the study includes 602 organizations that experienced breaches, use the figure for planning and comparison not as a prediction of what any single event will cost.

The same study says 62% of reported AI-driven attacks targeted critical-infrastructure sectors. Financial-services breaches averaged $6.3 million and energy breaches averaged $5.2 million. Sector labels, reporting practices, company size, and incident mix all affect those averages, but the concentration supports prioritizing high-consequence workflows and essential services.

The cost mechanism is broader than model usage. Faster preparation and scalable impersonation increase the volume of attempts; weak identity and application controls allow access; delayed detection extends dwell time; and uncertain ownership slows containment. A security program should therefore connect AI-specific controls to established identity, cloud, application, data, and incident-response capabilities.

A 90-Day Defense Plan for AI-Enabled Attacks

The table gives leaders a quick comparison of the three phases. The detailed steps that follow provide the implementation sequence.

PhasePrimary objectiveHighest-priority actionsExit evidence
Days 0–30Establish ownership and remove obvious exposureInventory AI assets and privileged identities; assign owners; restrict public endpoints; strengthen MFA and transaction verificationEvery production AI asset and privileged identity has an owner, exposure classification, and remediation date
Days 31–60Harden the surrounding system and improve telemetryApply least privilege; protect secrets; centralize model, tool, identity, data, and egress logs; patch critical exposureSecurity operations can reconstruct who invoked the system, what it called, and which resources it reached
Days 61–90Validate controls under realistic pressureTest impersonation workflows and AI applications; run table-top exercises; retest fixes; assign residual riskHigh-consequence paths are prevented, detected, contained, or formally accepted by an accountable owner

Days 0–30: Establish ownership and remove obvious exposure

  1. Inventory approved AI applications, agents, model endpoints, vector stores, plug-ins, service accounts, secrets, and external data connections.
  2. Assign a business owner and technical owner to each production AI system. Record the data it can access and actions it can perform.
  3. Find public AI endpoints and administrative interfaces. Restrict them through authentication, network controls, and API gateways.
  4. Require phishing-resistant MFA for administrators, remote access, cloud control planes, and high-risk business workflows.
  5. Add independent verification for payments, payroll changes, new beneficiaries, password resets, and executive requests.

Exit criterion: Every production AI asset and privileged identity has an owner, exposure classification, and remediation date for critical gaps.

Days 31–60: Harden the surrounding system and improve telemetry

  1. Apply least privilege to agents, tools, plug-ins, APIs, and service accounts. Remove permissions that are convenient but not required.
  2. Store secrets outside prompts and code. Rotate exposed or long-lived credentials and restrict where they can be used.
  3. Log model access, tool calls, permission changes, sensitive data retrieval, unusual egress, and identity events in a central detection workflow.
  4. Patch internet-facing software and AI infrastructure against risk-based service levels. Add emergency procedures for actively exploited flaws.
  5. Define incident tags for AI-assisted social engineering, malicious model use, agent abuse, prompt injection, model or data theft, and AI infrastructure compromise.

Exit criterion: Security operations can reconstruct who invoked an AI system, which tools it called, what sensitive resources it reached, and which controls acted.

Days 61–90: Validate controls under realistic pressure

  1. Test impersonation and transaction-verification workflows with legal, HR, finance, and executive teams.
  2. Assess AI applications for authorization failures, unsafe tool use, cross-tenant exposure, sensitive-data leakage, indirect prompt injection, and excessive agency.
  3. Run tabletop exercises covering a compromised AI service account, malicious plug-in, exposed vector store, synthetic executive request, and model-provider disruption.
  4. Retest remediated findings and record residual risk with an accountable owner and deadline.
  5. Use threat-informed exercises to measure prevention, detection, escalation, containment, and recovery rather than relying on policy review alone.

A scoped red teaming as a service engagement can connect identity, application, cloud, and human-control failures into a realistic exercise while keeping objectives and safety boundaries explicit.

Exit criterion: The organization has evidence that its highest-consequence attack paths are prevented, detected, contained, or accepted by an accountable risk owner.

Metrics Security Leaders Should Track

Avoid a vanity metric such as “AI attacks blocked.” Detection rules and classifications change too quickly for that total to stand alone. Track control coverage and operational outcomes instead:

Review these measures quarterly and after material model, agent, plug-in, identity, or data-flow changes. The aim is not to prove that the organization is “AI secure,” but to show that high-consequence paths are owned, observable, and tested.

Frequently Asked Questions

What percentage of cyber attacks use AI?

There is no reliable global percentage. IBM found that one in four malicious breaches in its 2026 sample were AI-enabled, while other sources measure vendor-observed attacks, banned platform accounts, complaints, or exposed systems. Those denominators cannot be combined into one worldwide share. Quote the source, sample, time window, and definition with any percentage.

Are AI cyber attacks increasing in 2026?

Several scoped datasets point upward. IBM reported a 56% year-over-year increase in AI-enabled malicious breaches within its study, CrowdStrike reported an 89% increase in attacks by AI-enabled adversaries in its visibility, and Anthropic’s medium-or-higher risk share rose between halves of its selected sample. These are consistent directional signals, not a universal growth rate.

What is the most common malicious use of AI in cyber attacks?

It depends on the dataset. Provider observations emphasize capability development, scripting, obfuscation, and data collection. Complaint data highlights synthetic profiles, voice, video, and impersonation. Across sources, preparation and social engineering appear more common than fully autonomous, end-to-end intrusion activity.

How much does an AI-enabled data breach cost?

IBM’s 2026 study reported an average of $6 million for AI-enabled breaches, roughly $1 million above the study’s $4.99 million global breach average. That is an average across a defined breached-organization sample, not a guaranteed cost for an individual company or incident.

Are autonomous AI cyber attacks real?

Yes, but they are early and should be described precisely. Anthropic reported a large-scale espionage campaign in which AI performed most campaign work with occasional human decisions. Its broader 832-account study still found much lower observed use for lateral movement than for preparation, so autonomous operations are documented without being the dominant pattern in that sample.

How can organizations defend against AI-powered attacks?

Start with controls that remain effective regardless of who or what produced the attack: phishing-resistant MFA, independent transaction verification, least privilege, asset and exposure management, rapid patching, centralized identity and tool-call logs, tested incident response, and regular adversarial validation. Add AI-specific controls around agent permissions, plug-ins, model endpoints, vector stores, and sensitive data access.

Conclusion

The credible 2026 evidence does not support one sensational global AI-attack number. It supports a more useful conclusion: attackers are applying AI across preparation, impersonation, development, evasion, exploitation, and selected in-network operations, while AI applications themselves create additional targets. Organizations should classify the evidence correctly, secure the surrounding system, and test whether their highest-consequence paths can be abused at machine speed.

DeepStrike can help scope and validate an evidence-led testing program across AI applications, cloud, identity, web applications, and human workflows.

About The Author

Khaled Hassan is the CEO of DeepStrike, an elite cybersecurity firm specializing in advanced penetration testing and offensive security operations. A veteran red team leader, Khaled holds prestigious industry certifications including CISSP, OSCP, and OSWE. He has successfully directed complex adversary emulation engagements for Fortune 500 companies across the finance, healthcare, and technology sectors. Throughout his career, Khaled has focused on dissecting complex attack chains and neutralizing critical cloud and application vulnerabilities to build resilient defense strategies for global enterprises.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us