3 Sources
[1]
Average data breach cost hits record high of Rs 25.5 crore in India: IBM report
By 2026, the financial impact of data breaches in India surged to Rs 25.5 crore, marking a notable increase of sixteen percent from the previous year. The scope of these breaches also widened, with more records being compromised. Companies that did not implement AI in their security operations endured higher costs, emphasizing the necessity for organizations to adopt AI as a cornerstone of their security frameworks. Mumbai, The average organisational cost of a data breach in India reached an all-time high of Rs 25.5 crore in 2026, up 16 per cent compared to Rs 22 crore last year, a report said on Monday. The data breach in India also grew in scale, with 39,500 records compromised on average in 2026, as against 38,200 in 2025, IBM said in its report. The Rs 25.5 crore is the "highest average cost of a data breach", the global IT firm said. Gaurav Agarwal, vice president, technology, IBM India and South Asia, said the artificial intelligence (AI) adoption is enabling cyber threats to evolve rapidly. "AI with agentic capabilities must be embedded across the full security lifecycle, from detection and analysis to prioritisation and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage," he said. Organisations with no AI and automation in security operations paid an average of Rs 31.6 crore per breach, compared to Rs 21.3 crore for organisations with extensive use and Rs 23.1 crore for those with limited deployment, the report said.
[2]
India Records Highest-Ever Data Breach Cost at ₹25.5 Crore: IBM Study
IBM released its 2026 Cost of a Data Breach Report, which found that the average total organizational cost of a data breach in India reached an all-time high of INR 255 million (INR 25.5 crore) in 2026, a 15.9% increase over last year's INR 220 million (INR 22 crore). The average breach in India also grew in scale, with 39,500 records compromised on average, up from 38,200 in 2025. The report found that 26% of malicious breaches in India were AI-generated, highlighting how artificial intelligence is reshaping the cyber threat landscape by enabling attacks to become faster, more sophisticated and increasingly scalable. The findings show that while AI is transforming the nature of cyberattacks, it is also helping organizations strengthen cyber resilience. Organizations that extensively deployed AI and security automation experienced significantly lower breach costs and faster breach response, while nearly 73% of organizations also indicated plans to further strengthen investments in security tools and governance following a breach.
[3]
Cost of Org-level Data Breach Touches its Highest Level in India at Rs.25.5 Crore: IBM
The average total of organisational costs of a data breach in India has reached an all-time high of Rs.25.5 crore in 2026, which represents a 15.9% jump over last year's levels of Rs.22 crore, says a research report. The scale of the average breach also went up to 39,500 records on average from 38,200 in 2025, says IBM's Cost of a Data Breach Report, 2026. In a statement announcing the launch of the report, IBM also noted that phishing, including voice and SMS phishing, was the most common initial attack vector in India, while 68% of Indian organisations surveyed still have limited or no use of AI and security automation. The report noted that 26% of malicious breaches in India were AI-generated, highlighting how artificial intelligence is reshaping the cyber threat landscape by enabling attacks to become faster, more sophisticated and increasingly scalable. The findings show that while AI is transforming the nature of cyberattacks, it is also helping organizations strengthen cyber resilience. Organizations that extensively deployed AI and security automation experienced significantly lower breach costs and faster breach response, while nearly 73% of organizations also indicated plans to further strengthen investments in security tools and governance following a breach. "India's accelerating AI adoption is creating immense opportunities for innovation, but it is also enabling cyber threats to evolve rapidly. The findings underscore that organizations using AI and strong governance, were significantly better positioned to fend off cyberattacks," says Gaurav Agarwal, Vice President, Technology, IBM India & South Asia. "Today, most organizations apply AI in limited ways, often focused on detection. To keep pace, AI with agentic capabilities must be embedded across the full security lifecycle -- from detection and analysis to prioritization and remediation. That should be the strategic imperative for businesses to build resilience and a competitive advantage," he added. The 2026 report, based on surveys conducted by Ponemon Institute and sponsored and analysed by IBM, is based on breaches experienced by 602 organizations globally between March 2025 and February 2026. The follow-on study was conducted in May 2026, where 456 organizations of the 602 from the CODB research responded. Of these organizations, 78% or 356 of organizations were aware of recent reports about highly advanced frontier models such as Mythos. The report (download it here) also noted that only 32% of organisations reported extensive of AI and security automation, while 36% had a limited adoption while another 32% reported no use of AI in their enterprises. Organizations with no AI and automation in security operations paid an average of Rs. 31.6 crore per breach, compared to Rs. 21.3 crore for organizations with extensive use, and Rs. 23.1 crore for those with limited deployment. On the topic of slower responses without automation, the report said breaches at enterprises with no AI and security automation took an average of 236 days to identify and 75 days to contain, longer than those with extensive automation where the timeframe was around 175 days to identify and 81 days to contain. Referring to how shadow AI continued to pose a significant risk, the report noted that Shadow AI added an average of Rs. 1.79 crore to the cost of a breach where present, making it one of the top three cost-increasing factors in India, alongside non-compliance with regulations and cloud migration. The report detailed out how the financial services faced the highest costs by noting that the sector the highest average breach cost in India at Rs. INR 40.9 crore), followed by technology at Rs. INR 35.7 crore) and communications at Rs.34.5 crore. Phishing, including voice and SMS phishing, was the most common initial attack vector in India (19%), followed by drive-by compromise (16%) and supply chain compromise (15%). Offensive security testing, such as red teaming and penetration testing, was the largest cost-reducing factor in India, saving organizations an average of Rs. 2.47 crore, followed by proactive threat hunting and AI governance technology. The report also listed out the top-5 areas where organizations are planning additional security investments are - incident response plans and testing (67%), threat detection and response technologies such as SIEM, SOAR and EDR (51%), identity and access management (49%), AI security and governance tools (39%), and employee awareness and training (36%).
Share
Copy Link
India recorded its highest-ever data breach cost at ₹25.5 crore in 2026, marking a 16% jump from ₹22 crore in 2025, according to IBM's latest report. The study reveals that 26% of malicious breaches were AI-generated, while organizations without AI in security operations paid ₹31.6 crore per breach compared to ₹21.3 crore for those with extensive automation.
The average cost of data breaches in India reached an unprecedented ₹25.5 crore in 2026, representing a 16% increase from ₹22 crore in 2025, according to IBM's Cost of a Data Breach Report
1
2
. This marks the highest average cost of a data breach ever recorded in the country. The scale of breaches also expanded significantly, with 39,500 records compromised on average in 2026, up from 38,200 in 20253
. The IBM report, based on surveys conducted by Ponemon Institute analyzing breaches experienced by 602 organizations globally between March 2025 and February 2026, paints a concerning picture of India's evolving cyber threat landscape.Artificial intelligence is fundamentally transforming how cyberattacks unfold in India. The IBM report found that 26% of malicious breaches in India were AI-generated, highlighting how AI is enabling attacks to become faster, more sophisticated, and increasingly scalable
2
3
. Phishing, including voice and SMS phishing, emerged as the most common initial attack vector in India, accounting for 19% of breaches, followed by drive-by compromise at 16% and supply chain compromise at 15%3
. Gaurav Agarwal, Vice President of Technology at IBM India and South Asia, emphasized that India's accelerating AI adoption is creating immense opportunities for innovation while simultaneously enabling cyber threats to evolve rapidly3
.The stark cost differential between organizations with and without AI and security automation underscores the critical importance of technology adoption. Organizations with no AI and automation in security operations paid an average of ₹31.6 crore per breach, compared to ₹21.3 crore for organizations with extensive use and ₹23.1 crore for those with limited deployment
1
3
. Despite these compelling numbers, 68% of Indian organizations surveyed still have limited or no use of AI and security automation3
. Only 32% of organizations reported extensive use of AI in their security operations, while 36% had limited adoption and another 32% reported no use of AI in their enterprises3
.Speed of response directly impacts the financial damage from breaches. Breaches at enterprises with no AI and security automation took an average of 236 days to identify and 75 days to contain, significantly longer than those with extensive automation where the timeframe was around 175 days to identify and 81 days to contain
3
. Agarwal stressed that most organizations currently apply AI in limited ways, often focused only on detection. He emphasized that AI with agentic capabilities must be embedded across the full security lifecycle, from detection and analysis to prioritization and remediation, as a strategic imperative for businesses to build cyber resilience and competitive advantage1
3
.Related Stories
Shadow AI emerged as a significant risk factor, adding an average of ₹1.79 crore to the cost of a breach where present, making it one of the top three cost-increasing factors in India alongside non-compliance with regulations and cloud migration
3
. The financial services sector faced the highest average breach cost in India at ₹40.9 crore, followed by technology at ₹35.7 crore and communications at ₹34.5 crore3
. These sector-specific vulnerabilities highlight how different industries face varying levels of exposure based on the sensitivity of data they handle and their digital infrastructure complexity.The record high data breach cost is driving organizations to reassess their security posture. Nearly 73% of organizations indicated plans to strengthen investments in security tools and governance following a breach
2
3
. The top five areas where organizations are planning additional security investments include incident response plans and testing at 67%, threat detection and response technologies such as SIEM, SOAR and EDR at 51%, identity and access management at 49%, AI security and governance tools at 39%, and employee awareness and training at 36%3
. Offensive security testing, such as red teaming and penetration testing, was identified as the largest cost-reducing factor in India, saving organizations an average of ₹2.47 crore, followed by proactive threat hunting and AI governance technology3
.Summarized by
Navi
1
Technology

2
Science and Research

3
Technology
