Costs of Data Breach in 2025: The IBM Report
IBM’s Cost of a Data Breach Report 2025 gives boards and executives a data-driven view of what breaches actually cost, and what changes that cost most. In a year increasingly shaped by artificial intelligence, the findings reach well beyond the security function.
Global Costs Fall, US Costs Rise
The global average cost of a data breach fell for the first time in five years, down 9% to USD 4.44 million. Faster detection and response, driven largely by AI and automation, explains most of the improvement.
The United States moved in the opposite direction. Average breach costs there reached a record USD 10.22 million, driven by regulatory fines and rising detection costs. Boards operating across jurisdictions should read this divergence as a warning against treating breach cost as a single global figure.
AI Cuts Both Ways
AI now defends and attacks. AI-powered defences shorten detection and response times. At the same time, roughly 16% of breaches now involve attackers using AI, typically for advanced phishing and deepfakes.
A newer risk sits between these two poles: shadow AI. Unauthorised or unmonitored AI applications now add roughly USD 670,000 to the average breach cost. This is not a future risk. It is already showing up in the numbers.
How Breaches Happen
Phishing remains the most common initial attack vector, at 16% of breaches, closely followed by supply chain compromise. Malicious insider incidents cost the most per case, at USD 4.92 million on average.
Breaches spanning multiple environments, such as hybrid cloud combined with on-premises infrastructure, are the most expensive and the slowest to contain: USD 5.05 million on average, and up to 276 days to full containment. Environment complexity is a cost driver in its own right, independent of how the breach started.
The AI Governance Gap
IBM’s data points to a specific gap. 63% of breached organisations had no comprehensive AI governance policy in place. Shadow AI incidents are hard to detect, tend to compromise more personal data, and take longer to contain. Attackers already use generative AI at scale to produce convincing phishing content and deepfakes.
What Moves the Cost
IBM identifies four practices that consistently reduce breach cost: integrating security into software development through DevSecOps, extensive use of AI and automation for detection and response, mature SIEM platforms, and documented AI governance.
Four factors consistently raise it: fragmented security architecture, third-party and supply chain exposure, unmanaged shadow AI, and a shortage of skilled security staff.
What Boards Should Do
Four actions follow directly from the data.
- Extend identity and access governance to non-human identities, including AI agents, not only human users.
- Close the AI governance gap: adopt a policy for AI use, with regular audits and cross-functional oversight.
- Invest in AI-driven detection and response tools. They reduce both breach duration and cost.
- Build response capability. Breaches happen. Recovery speed determines the financial outcome.
Source: IBM, Cost of a Data Breach Report 2025.