One in four malicious data breaches is now AI-enabled, and 86% of phishing attacks are AI-driven. Attackers use artificial intelligence to write flawless phishing emails, clone voices from seconds of audio, and scan for exposed network infrastructure faster than defenders can patch it. The AI cyber threat statistics below are global unless a narrower population is noted, drawn from current primary research, and each one is attributed to its original source.
The numbers point where defenses are weakest: the network layer, where AI-driven attacks exploit misconfigured cloud connections, exposed AI servers, and flat networks with no segmentation. That foundation is what we design and build at The Network Installers.
Key Takeaways
- 1 in 4 malicious data breaches is now AI-enabled, up 56% year over year (IBM Cost of a Data Breach, 2026).
- 86% of phishing attacks are AI-driven as of early 2026 (KnowBe4 phishing threat research).
- AI-enabled breaches cost $6 million on average, roughly $1 million more than the $4.99 million global average breach (IBM, 2026).
- Deepfakes now make up about 6.5% of fraud attempts, roughly 1 in 15, up from about 1 in 1,000 three years earlier (Signicat fraud research, 2024 survey).
- Only 0.1% of people can reliably identify a high-quality deepfake (iProov consumer study, 2025).
- The FBI logged $893 million in AI-related fraud losses across 22,364 complaints in 2025 (FBI Internet Crime Report).
- The AI-in-cybersecurity market reached $29.64 billion in 2025 and is projected to hit $167.77 billion by 2035 (Precedence Research).
- 62% of AI-driven attacks target critical-infrastructure sectors such as energy, manufacturing, and government (IBM, 2026).
Citation Policy: These statistics are free to reuse, including for commercial work. If a figure here helps your article, report, or presentation, a link back to The Network Installers is all we ask in return.
How Many Cyberattacks Use AI in 2026?
AI is now embedded in the majority of attacks rather than a fringe technique. The clearest measure comes from breach forensics: one in four malicious breaches involves attacker use of AI, and the share is climbing fast.
| Metric | Figure | Source (data year) |
|---|---|---|
| Malicious breaches that are AI-enabled | 1 in 4 (25%), up 56% year over year | IBM Cost of a Data Breach (2026) |
| Phishing attacks that are AI-driven | 86% | KnowBe4 (Q1 2026) |
| Organizations hit by an AI-powered attack in the past year | 87% | SoSafe (2025) |
| Increase in activity from AI-enabled adversaries | 89% | CrowdStrike Global Threat Report (2025) |
These figures are measured, not modeled. IBM’s Cost of a Data Breach research put AI-enabled breaches at one in four in 2026, KnowBe4 measured 86% of phishing as AI-driven in early 2026, and CrowdStrike logged an 89% rise in AI-adversary activity over 2025.

AI Phishing Statistics
AI-generated phishing beats human-written phishing and costs almost nothing to produce. A Harvard Business Review study recorded a 54% click-through rate for AI-automated spear-phishing against 12% for a control group, and testing by SoSafe plus a 2024 phishing intelligence report tracked how far AI has pushed both success rates and volume.

| Phishing metric | Figure | Source (data year) |
|---|---|---|
| AI spear-phishing click-through rate | 54%, vs 12% for a control group | Harvard Business Review (2024) |
| Cost reduction from AI-automating a campaign | Over 95% | Harvard Business Review (2024) |
| People who clicked a link in an AI-generated phishing email | 21% (1 in 5) | SoSafe (2025) |
| Rise in phishing email volume, second half of 2024 | 202% | Infosecurity Magazine (2024) |
| Rise in credential-phishing attacks, second half of 2024 | 703% | Infosecurity Magazine (2024) |
AI phishing is the single largest driver of AI-enabled breaches, because email is the entry point for most network intrusions and AI removes the cost and quality limits that once capped attack volume.
AI Deepfake Statistics
Deepfake incidents are accelerating, and human detection has collapsed. Resemble AI’s deepfake incident database tracks publicly reported synthetic-media incidents over time.

| Period | Verified deepfake incidents | Change |
|---|---|---|
| Full-year 2024 | 150 | baseline |
| Q1 2025 | 179 | surpassed all of 2024 in one quarter |
| Q2 2025 | 487 | +312% year over year |
| Q3 2025 | 2,031 | largest quarter on record |
Source: compiled from Resemble AI’s successive quarterly deepfake threat reports, 2024 to 2025.
- Deepfakes rose from 0.1% of all fraud attempts to roughly 6.5% in three years, now about 1 in 15 cases (Signicat and Censuswide survey of 1,206 fraud decision-makers across seven European countries, 2024).
- Only 0.1% of people can reliably tell a high-quality deepfake from real footage (iProov study of 2,000 UK and US consumers, 2025).
- Deepfake-enabled fraud losses exceeded $200 million in North America in the first quarter of 2025 alone (Resemble AI, 2025).
- US losses from generative-AI-enabled fraud are projected to reach $40 billion by 2027, up from $12.3 billion in 2023 (Deloitte Center for Financial Services).
The marquee case remains the engineering firm Arup, which lost $25.6 million when an employee joined a video call with deepfaked versions of the company’s CFO and colleagues and authorized the transfers.
AI Voice Cloning and Vishing Statistics
Voice cloning turns seconds of recorded audio into a weapon, and 2025 was the first year the US FBI broke AI-enabled fraud out as its own category. A seven-country McAfee consumer survey and a peer-reviewed Nature study on human voice perception show how often it works.
| Voice-cloning metric | Figure | Source (data year) |
|---|---|---|
| AI-related fraud losses logged by the FBI in 2025 | $893 million across 22,364 complaints | FBI Internet Crime Report (2025) |
| AI voice-scam victims who lost money | 77% | McAfee (2023) |
| Adults who experienced or know someone hit by a voice scam | About 1 in 4 | McAfee (2023) |
| Accuracy when people try to identify an AI-generated voice | About 60% | Nature Scientific Reports (2025) |
The FBI total is a floor, not a ceiling. It counts only fraud that victims recognized and reported as AI-driven, so the real figure is almost certainly higher.

AI Password Cracking Statistics
AI-trained models guess passwords by learning human habits instead of brute-forcing every combination, which makes weak and reused passwords collapse quickly.
- An AI password-cracking tool cracked 51% of 15.68 million common passwords in under a minute, and 81% within a month (ISACA analysis, 2023).
- 94% of leaked passwords are reused or duplicated across accounts (Cybernews study of 19 billion exposed credentials, 2025).
Password reuse is the multiplier: one cracked credential unlocks several accounts.
AI in Cybersecurity Market Size
Spending on defensive AI is rising as fast as the threats.

| Year | AI-in-cybersecurity market size | Note |
|---|---|---|
| 2025 | $29.64 billion | current |
| 2026 | $35.40 billion | projected |
| 2035 | $167.77 billion | projected, 18.93% CAGR |
Source: Precedence Research, figures for 2026.
Network security is consistently this market’s largest segment, reflecting how much of the attack surface now lives at the infrastructure layer.
The Cost of AI-enabled Data Breaches
AI raises both the frequency and the price of a breach. IBM’s forensic dataset shows AI-enabled breaches cost about $1 million more than the global average.
| Breach type or sector | Average cost | Source (data year) |
|---|---|---|
| AI-enabled breach | $6.0 million | IBM (2026) |
| Global average breach | $4.99 million | IBM (2026) |
| Healthcare | $6.64 million | IBM (2026) |
| Financial services | $6.3 million | IBM (2026) |
| Energy | $5.2 million | IBM (2026) |
According to IBM’s Cost of a Data Breach research, an AI-enabled breach cost $6 million on average in 2026, against a $4.99 million global average. Healthcare remained the most expensive sector to breach for the thirteenth straight year at $6.64 million. The gap between an AI-enabled breach and a standard one is the clearest dollar case for hardening the infrastructure attackers use to get in.

Which Industries are Most Targeted By AI Attacks
AI-driven attacks concentrate on critical infrastructure, the sectors where downtime causes the most damage and stolen records sell for the most.
- 62% of reported AI-driven attacks targeted critical-infrastructure sectors (IBM, 2026), including energy, manufacturing, government, and healthcare.
- Healthcare carries the highest breach cost of any sector at $6.64 million (IBM, 2026), the result of sensitive patient records and urgent uptime needs.
- Financial services breaches averaged $6.3 million and energy breaches $5.2 million under AI-driven attack (IBM, 2026).
These are the same sectors that depend on dense, reliable cabling and segmented networks: hospitals, manufacturing plants, school districts, and government facilities.
How AI Attacks Exploit Network Infrastructure
The fastest-growing AI attack surface is not software. It is exposed, misconfigured, and unsegmented network infrastructure. This is the cut most statistics roundups skip, and it is where the numbers point hardest.
| Weakness | Figure | Source (data year) |
|---|---|---|
| Breaches involving compromised APIs or applications | 27% | IBM (2026) |
| Breaches involving cloud misconfiguration | 27% | IBM (2026) |
| Breaches targeting AI models or applications directly | Over 20% | IBM (2026) |
| Ollama AI servers confirmed exposed to the internet | 113,000+ (of 313,000+ scanned) | Trend Micro (2025) |
| Exposed Ollama servers running with no authentication | 10,000+ | Trend Micro (2025) |
| Exposed ChromaDB servers running with no authentication | 200+ | Trend Micro (2025) |
According to IBM’s Cost of a Data Breach research, 27% of breaches in 2026 involved compromised APIs or applications and another 27% involved cloud misconfiguration, while more than 20% targeted AI models or applications directly. On the exposure side, Trend Micro scanned more than 313,000 internet-facing servers between September and December 2025 and confirmed over 113,000 as exposed Ollama AI instances, more than 10,000 of them running with no authentication at all, alongside 200-plus ChromaDB servers reachable online without authentication.
Exposure is not the same as compromise, but an AI server on the open internet with no authentication is an entry point waiting to be used. Ollama ships with no built-in authentication, which means it is meant to sit behind a properly configured web server on a segmented network, not on a public IP. Cloud misconfiguration, flat networks, and unmanaged devices are the failures AI tooling now finds and exploits at machine speed. That is a network-design problem before it is a software problem.

Defensive AI: Adoption and Effectiveness
Defensive AI measurably lowers breach cost, though it does not close the gap on its own. IBM’s Cost of a Data Breach research quantifies the payoff.
- Organizations using AI and automation in security operations cut breach costs by about $2 million on average (IBM, 2026).
- Roughly two-thirds of organizations now deploy security AI or automation across their operations, up year over year (IBM, 2026).
Even with AI defenses in place, a large share of organizations still get breached, because attackers adopt the same tools. AI defense works best on a sound foundation: segmented networks, patched and inventoried infrastructure, and monitored traffic. Without that, AI tooling monitors a network it cannot actually see.
AI Cyber Threats to Small Businesses
Small and mid-sized businesses face AI-driven attacks without the security staff to match, a mismatch attackers exploit deliberately. A VikingCloud survey of North American SMBs shows how exposed they are and where they plan to respond.
| Small-business metric | Figure | Source (data year) |
|---|---|---|
| SMBs hit by AI-generated or advanced phishing in the past year | 46% | VikingCloud (2026) |
| SMBs that experienced a deepfake scheme | 29% | VikingCloud (2026) |
| SMBs whose security manager lacks sufficient AI-threat training | 28% | VikingCloud (2026) |
| SMBs planning to add AI threat detection in 2026 | 39% | VikingCloud (2026) |
| SMBs planning to add AI incident response in 2026 | 34% | VikingCloud (2026) |
Smaller organizations rarely have a dedicated security team, so the network itself has to carry more of the defensive load through segmentation, access control, and clean configuration.

About this Data
These statistics come from primary research: breach forensics (IBM Cost of a Data Breach), law-enforcement reporting (FBI Internet Crime Report), vendor threat telemetry (CrowdStrike, Trend Micro, KnowBe4), academic studies (Nature, Harvard Business Review), and independent surveys (Signicat, iProov, McAfee, VikingCloud). Each figure is attributed inline with the year the data describes and, where a source’s population is narrower than global, the country or region. Single-vendor telemetry reflects that vendor’s visibility, not a global census, and is labeled that way.
Frequently Asked Questions
What is the number one cybersecurity threat today?
AI-driven phishing and social engineering is the leading cybersecurity threat in 2026. 86% of phishing attacks are now AI-driven (KnowBe4), and email-based social engineering remains the most common entry point for network breaches. AI makes these attacks cheaper to run and harder to spot, which is why they scaled faster than any other attack type.
How much of cybercrime now uses AI?
One in four malicious data breaches is AI-enabled as of 2026, a 56% increase year over year (IBM Cost of a Data Breach). In specific attack categories the share is far higher: 86% of phishing attacks use AI (KnowBe4). AI is now embedded across the attack lifecycle, from writing lures to scanning for exposed infrastructure.
Is cybersecurity in danger from AI?
AI raises risk on both sides. Attackers use it to run cheaper, faster, more convincing attacks, and AI-enabled breaches cost about $6 million on average, roughly $1 million more than a standard breach (IBM, 2026). Defenders use the same technology to cut breach costs by about $2 million and detect threats faster. The outcome depends on the foundation: a segmented, well-configured, monitored network gives AI defenses something to protect.
Where do most AI-driven attacks begin?
Most AI-driven breaches begin at the network and application layer. 27% of breaches involve compromised APIs or applications and another 27% involve cloud misconfiguration (IBM, 2026), while attackers scan continuously for exposed infrastructure such as the 113,000-plus internet-exposed AI servers Trend Micro found in 2025. Email phishing is the leading human entry point; misconfigured infrastructure is the leading technical one.
Conclusion
AI has changed the economics of attack. It makes phishing 95% cheaper to run, turns seconds of audio into a convincing voice clone, and scans the internet for exposed infrastructure faster than any human team. The data through 2026 shows the pressure landing hardest at the network layer, where misconfiguration, flat network design, and unmanaged devices give AI tooling its openings.
That layer is our work. The Network Installers has spent 19-plus years building network infrastructure across more than 20,000 commercial and government locations, designing the structured cabling and segmentation that decide whether AI-driven attacks find an open door or a hardened one. If you are planning a network build, upgrade, or segmentation project, talk to our team about building it to hold up.
Sources
- IBM: Cost of a Data Breach
- KnowBe4: Phishing Threat Research
- CrowdStrike: Global Threat Report
- Harvard Business Review: AI and the Quality of Phishing Scams
- SoSafe: AI-Generated Phishing Data
- Infosecurity Magazine: 2024 Phishing Attacks Report
- Resemble AI: Deepfake Incident Database
- Signicat: Deepfake Fraud Research
- iProov: Deepfake Detection Study
- Deloitte: Deepfake Banking Fraud
- CNN: Arup Deepfake Scam
- FBI: Internet Crime Report
- McAfee: Beware the Artificial Imposter
- Nature Scientific Reports: Human Detection of AI-Generated Voices
- ISACA: Credential Hacking and AI
- Cybernews: Password Leak Study
- Precedence Research: AI in Cybersecurity Market
- Trend Micro: Exposed AI Servers
- VikingCloud: Cybersecurity Statistics



