Phishing has topped the list of initial attack vectors for the fourth year running, according to the latest edition of IBM’s annual Cost of Data Breach report.
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence.
Voice and SMS phishing has led to the highest average breach costs of any attack vector studied this year, according to IBM’s research, reaching at US $5.29 million per incident.
Social engineering attacks – which include help desk impersonation and MFA fatigue tactics – were not far behind at an average cost of US $5.23 million.
To put those figures in context, the global average cost of a data breach across all types of attack came to US $4.99 million. In short, phishing and social engineering attacks cause above an average financial cost for victim organizations.
But, of course, that doesn’t tell the whole story. A successful phishing attack will often lead to a valid business account being accessed and abused – at an average cost, according to the report, of $5.07 million per breach.
It’s easy to see just how quickly a single convincing email or phone call can set off a chain of events that could cost an organization millions of dollars.
It’s impossible in 2026 not to recognize the difference that artificial intelligence is making to cybersecurity, and how criminals have adopted AI to their benefit.
Generative AI has dramatically lowered the cost, time, and expertise required to launch convincing phishing campaigns. Poorly worded emails with suspicious links are increasingly a thing of the past, as AI can easily generate highly-targeted, convincing communications at a scale that unheard of in the past.
The report found that AI-generated phishing and other communications accounted for some 17% of the malicious AI attacks studied. Meanwhile, the highest volume of AI-driven attacks overall involves deepfake impersonation. 45% of AI-driven attacks saw deepfake techniques used to make convincing voice and video messages, designed to trip up unsuspecting users.
All of this use of AI means that the barrier to launching sophisticated phishing campaigns has effectively collapsed. Where once cybercriminals would have required skilled cohorts and significant resources, they now can use AI to automate, personalize and deploy attacks at scale.
What is particularly disappointing is that despite breaches which start with a phishing attack being one of the most well-understood types of threat, they still take an average of 251 days to identify and contain. according to the research.
251 days is an awfully long time for a cybercriminal to explore a hacked network, escalate their privileges, and steal sensitive data.
Part of the problem is that criminals are abusing legitimate credentials and established channels to access information. Once an attacker is operating through a valid account, businesses may find it difficult to distinguish a normal user’s behavior from that of a hacker – unless the right visibility tools are put in place.
It is clear that awareness training on its own is not enough. If it were, then phishing would have been removed from the top of the attack charts long ago.
That’s not to say that awareness training has no value – it remains a valuable layer of defense – but it should not be your company’s primary way of dealing with the problem.
Businesses should deploy layered technical defenses which can pick up what humans miss. Incoming messages – via email and other routes – should be filtered and analyzed for suspicious content before they reach a user’s desktop or smartphone. Anomalous behavior should be highlighted after an account has been compromised. Controls should be put in place to limit the blast radius of a breach after a user clicks on the wrong link.
Without stronger controls, phishing is likely to keep on being a winning tactic for cybercriminals, especially when augmented with AI.
Source: Fortra