Skip to content

AI NewsPublished 5 min read

IBM: AI-Enabled Breaches Push Average Costs

a lattice of neural pathways radiating from a bright core
Listen to this article · 9:49 · AI-generated narration
0:00 / 9:49
Chapters

The short version

Businessday NG reported that IBM's findings put the average damage from AI-enabled breaches at $6.04 million as Digital Encode launched DEPAS AI. For SMB IT leaders, the news supplies updated breach-cost evidence and a new autonomous security-testing option to evaluate.

  • Gazettengr said DEPAS AI shifts penetration testing from periodic checks to continuous assessment.
  • Businessday NG reported that specialized agents can test applications, APIs, cloud environments, and network infrastructure.
  • Insurance Portal said deepfake impersonation and AI-enabled malware predominated among attacks reported to IBM.
  • Digital Encode said a verification agent retests reported vulnerabilities to reduce false positives.

Businessday NG reported on August 18, 2026, that Digital Encode launched DEPAS AI as surveyed organizations faced average AI-enabled breach damage of $6.04 million. The Nigerian cybersecurity professional services firm positioned the platform as a defensive response to attackers using artificial intelligence to automate and accelerate cybercrime, Businessday NG reported.

Gazettengr reported on August 18, 2026, that DEPAS AI provides continuous, autonomous cybersecurity testing. Adewale Obadare, CEO of Digital Encode, said the Digital Encode Penetration Autonomous System was designed to move organizations from periodic manual checks to continuous testing across systems and networks, Gazettengr reported.

Peter Obadare, chief visionary officer at Digital Encode, said attackers were weaponizing AI to move faster than human teams could respond, while the platform combined artificial intelligence with human intelligence, Businessday NG reported. Digital Encode unveiled the platform as attackers increasingly used AI to launch faster and more sophisticated attacks, Gazettengr said.

IBM measures a widening attack imbalance

Insurance Portal reported on August 12, 2026, that IBM surveyed 3,558 security and C-suite executives at 602 organizations affected by breaches between March 2025 and February 2026. The survey covered organizations that had experienced data breaches, Insurance Portal said.

Among malicious breaches affecting that surveyed population, 25% were AI-enabled, a 56% increase over the prior year's findings, according to Insurance Portal's August 12, 2026 article. Insurance Portal identified deepfake impersonation and AI-enabled malware as the predominant AI-assisted attack types reported globally to IBM.

Companies reporting extensive use of AI and automation in security operations reduced breach costs by almost $2 million on average, Insurance Portal reported in its August 12, 2026 article. The same dated article said one in four organizations had not adopted those tools in security operations.

IBM researchers said attacks could cost thousands to launch while resulting breaches inflicted millions in damage, Insurance Portal reported. The publication also said organizations using AI and security automation extensively experienced lower breach costs and faster response times.

DEPAS AI automates continuous testing

DEPAS AI uses multiple specialized agents to test enterprise applications, web applications, APIs, mobile applications, backend systems, cloud environments, and network infrastructure around the clock, Businessday NG reported. An agentic coordinator tracks the systems under examination and deploys additional agents when an issue requires deeper investigation, according to Businessday NG.

Gazettengr said every identified vulnerability is independently tested by another agent before it is reported. Digital Encode designed that verification process to reduce false positives and limit time spent investigating weaknesses that cannot be exploited, Businessday NG reported.

A chain builder connects separate vulnerabilities to show how an attacker could combine multiple weaknesses into a successful attack path, Gazettengr reported. Digital Encode said isolated vulnerabilities do not always reveal the full extent of cyber risk, Businessday NG reported.

The platform's coordinator manages testing, tracks systems, analyzes results, and deploys additional agents for deeper checks, Gazettengr said. Businessday NG described DEPAS AI as Digital Encode's effort to bring automation to the defensive side of cybersecurity.

Breach volume adds pressure beyond AI

Yahoo reported on August 15, 2026, that data-compromise activity was putting the year on pace to surpass the prior annual incident record. The Identity Theft Resource Center tracked 1,803 data compromises in the first half of 2026, compared with 3,321 incidents during all of 2025, Yahoo reported in its August 15, 2026 article.

A breach involving Instructure Holdings' Canvas education platform accounted for an estimated 275 million victim notices, or roughly 58% of the first-half total, according to Yahoo's August 15, 2026 report. Yahoo said the Identity Theft Resource Center recorded 21 insider wrongdoing events in the opening six months of 2026, up from three during all of 2025.

Only 24% of breach notifications in the first half of 2026 explained how an incident happened, the lowest share on record, Yahoo reported on August 15, 2026. The article separately said AI was making attacks easier to execute.

XL.net previously covered related findings about AI-enabled ransomware and breach costs. Yahoo's newer article documented breach notices, data compromises, insider wrongdoing, and notification transparency alongside the rise in AI-assisted attacks.

Tron's take

My take is that a US small or mid-sized business should treat the cost finding as a reason to validate its exposure, not as a reason to purchase an autonomous platform immediately. Digital Encode announced a specific testing approach, but the available sources do not provide independent performance results or details about US availability.

I would first confirm whether existing penetration tests cover internet-facing applications, APIs, cloud configurations, mobile software, and attack chains across systems. Continuous testing could be useful where applications change frequently, while periodic testing may remain proportionate for a stable and limited environment. That is my reading of the news, not a reported result.

A security assessment can determine whether continuous testing addresses a documented gap before a company adds another security tool. XL.net sells security assessments and managed IT services. Deliberate adoption means applying proven controls well while monitoring autonomous testing products as their results, integration requirements, and operating costs become clearer.

Questions I'd expect

What was the reported average cost of an AI-enabled breach?

AI-enabled breaches averaged $6.04 million among organizations covered by IBM's breach research, Businessday NG reported on August 18, 2026. The figure describes the organizations studied rather than a forecast for every business.

How common were AI-enabled malicious breaches?

AI-enabled attacks represented 25% of malicious breaches among 602 breached organizations surveyed by IBM, a 56% increase from the prior year's findings, Insurance Portal reported on August 12, 2026.

What does DEPAS AI test?

DEPAS AI tests enterprise and web applications, APIs, mobile applications, backend systems, cloud environments, and network infrastructure, Businessday NG reported. Its agents also verify vulnerabilities and connect separate weaknesses into potential attack chains.

Does DEPAS AI replace a security team?

Digital Encode presented DEPAS AI as combining artificial intelligence with human intelligence, Businessday NG reported. The company described automated testing, coordination, verification, and attack-chain analysis while retaining a role for human security work.

All AI news