India's Data Breach Costs Reach ₹25.5 Crore
India's data breach costs surge 15.9% to ₹25.5 crore. AI-generated cyberattacks rise.

The average total organisational cost of a data breach in India has reached an all-time high of ₹25.5 crore in 2026, marking a 15.9% increase over last year. This significant rise is attributed to the growing number of cyberattacks, with India witnessing 15 lakh cyberattack attempts during Operation Sindoor, resulting in 150 compromised systems.
According to a report by IBM, breaches in India have grown in scale, with 39,500 records compromised on average, up from 38,200 in 2025. The report highlights that nearly 26% of malicious breaches were AI-generated, indicating that artificial intelligence is transforming the cyber threat landscape by making attacks faster, more sophisticated, and increasingly scalable.
The IBM report found that organisations that extensively deployed AI and security automation experienced significantly lower breach costs and faster breach response. In contrast, those with no AI paid the highest average cost of ₹31.6 crore per breach. Organisations with extensive AI deployment paid an average of ₹21.3 crore per breach, while those with limited deployment paid ₹23.1 crore.
Gaurav Agarwal, Vice President of Technology at IBM India and South Asia, noted that India's accelerating AI adoption is creating immense opportunities for innovation but also enabling cyber threats to evolve rapidly. He emphasized that organisations using AI and strong governance were significantly better positioned to fend off cyberattacks.
The report revealed that only 32% of organisations reported extensive use of AI and security automation, while 36% reported limited use and 32% reported no use at all. Organisations with no AI and automation in security operations took an average of 236 days to identify and 75 days to contain breaches, longer than those with extensive automation.
Phishing, including voice and SMS phishing, was the most common initial attack vector in India, accounting for 19% of breaches, followed by drive-by compromise (16%) and supply chain compromise (15%). The top five areas where organisations are planning additional security investments include incident response plans and testing, threat detection and response technologies, identity and access management, and AI security.
In light of these findings, it is essential for organisations to strengthen their investments in security tools and governance. Nearly 73% of organisations indicated plans to further invest in security measures following a breach. By leveraging AI and security automation, organisations can build resilience and gain a competitive advantage in the face of evolving cyber threats.
The surge in data breach costs and AI-generated cyberattacks serves as a reminder of the importance of robust cybersecurity measures in India. As the country continues to adopt AI and other emerging technologies, it is crucial for organisations to prioritize cybersecurity and invest in the necessary tools and governance to protect themselves against increasingly sophisticated threats.
In conclusion, the rising cost of data breaches in India highlights the need for organisations to adopt a proactive approach to cybersecurity. By investing in AI and security automation, organisations can reduce the risk and cost of breaches, ultimately protecting their customers, employees, and reputation. As India's digital landscape continues to evolve, it is essential for organisations to stay ahead of the curve and prioritize cybersecurity to ensure a safe and secure digital environment.
Frequently asked questions
What is the average total organisational cost of a data breach in India in 2026?
The average total organisational cost of a data breach in India in 2026 is ₹25.5 crore.
What percentage of malicious breaches were AI-generated in India?
Nearly 26% of malicious breaches were AI-generated in India.