IBM: ASEAN data breach costs hit record US$4.12 million as AI attacks rise
ASEAN organizations faced an average data breach cost of US$4.12 million in 2026, up from US$3.67 million a year earlier.
The average cost of a data breach for organizations across ASEAN reached US$4.12 million in 2026, the highest level recorded in the region, according to IBM's 2026 Cost of a Data Breach Report.
The study found that 29% of ASEAN organizations that experienced malicious breaches reported that the attacks were generated using AI. The report was produced by the Ponemon Institute and sponsored and analyzed by IBM.
ASEAN recorded the ninth-highest average breach cost among the 16 country and regional samples covered by the study. The regional average increased from US$3.67 million in 2025 to US$4.12 million in 2026, compared with US$4.01 million in Japan, US$3.03 million in South Korea, US$2.79 million in India, and US$2.96 million in Australia.
The ASEAN findings are based on 26 organizations in Singapore, Indonesia, the Philippines, Malaysia, Thailand, and Vietnam. ASEAN accounted for 4% of the 602 organizations included in the overall study, which covered 16 countries and geographic regions and 17 industries.
Organizations using AI and security automation extensively recorded an average breach cost of US$3.66 million, compared with US$4.86 million among organizations that did not use the technologies. These organizations also identified and contained breaches 123 days faster.
"As AI continues to lower the cost and increase the speed of cyberattacks, organizations across ASEAN are facing longer breach investigations and growing financial consequences," Catherine Lian, general manager of IBM ASEAN, said.
Globally, organizations that extensively used AI and automation for security recorded an average breach cost of US$4 million, compared with US$5.93 million among organizations with no use of the technologies. Their average time to identify and contain a breach was 215 days, compared with 280 days for organizations that did not use them.
Financial and infrastructure sectors carry higher breach costs
Financial services recorded the highest average breach cost among the sectors covered in the ASEAN findings, at US$6.53 million. Industrial organizations followed at US$5.99 million, while communications organizations recorded an average cost of US$4.28 million.
Globally, critical infrastructure sectors accounted for 62% of AI-driven attacks studied, with financial services and energy recording the highest concentrations.
The report also identified valid-account abuse as one of the most expensive initial attack vectors in ASEAN, with associated breach costs averaging more than US$4.5 million.
Globally, abusing valid accounts had an average breach cost of US$5.07 million. Phishing delivered through voice or SMS averaged US$5.29 million, while social engineering involving helpdesk impersonation or MFA fatigue averaged US$5.23 million.
Only 29% of ASEAN organizations surveyed said sensitive data was encrypted both at rest and in transit when the breach occurred. Globally, 37% of breached organizations said they had encrypted sensitive data at the time of the breach, while 34% reported having controls to monitor and secure cryptographic assets such as keys and certificates.
Organizations that invested in offensive security testing, security orchestration and automation, and key lifecycle management reported some of the largest reductions in breach-related costs.
Supply-chain compromise was also among the longer-running breach types in the global findings, with breaches taking an average of 258 days to identify and contain. It was also the second most common initial attack vector, behind phishing.
AI expands both the attack surface and security response
Following a breach, 71% of ASEAN organizations said they planned to increase spending on security tools and governance. In the global follow-on research, 85% of organizations that were aware of advanced frontier AI threats said they planned to increase security spending because of those capabilities.
The report separates AI-driven attacks from incidents involving an organization's own AI models or applications. Globally, 21% of organizations experienced a security incident involving an AI model or application, up from 13% the previous year.
Among organizations that experienced an AI-related breach, 92% lacked proper AI access controls, while only 40% of organizations overall reported using access controls on AI models and data.
The most expensive AI-related incidents in the global study involved model inversion and prompt injection, with average breach costs of US$6.07 million and US$5.89 million, respectively. Other incidents included cloud security misconfigurations affecting AI workloads, malicious models, model evasion, insecure deployment, and data poisoning.
Globally, more than one in four organizations that experienced a malicious attack reported that it was AI-driven, representing a 56% increase from the previous year. Deepfake impersonation accounted for 45% of AI-driven attacks, followed by AI-enabled malware at 19% and AI-generated phishing or other communications at 17%.
Use of AI and automation also varied across security operations. Among breached organizations globally, 77% reported either limited or extensive use of the technologies for threat investigation, compared with 69% for threat prevention.
A follow-on study conducted in May 2026 received responses from 456 of the 602 organizations in the Cost of a Data Breach research. Of those respondents, 356, or 78%, said they were aware of recent reports concerning highly advanced frontier models such as Mythos.