3 in 10 Asean organizations have experienced AI-driven malicious attacks – 2026 study

TechnologyBusiness & Finance
16 Aug 2026 • 12:04 AM MYT
The Manila Times
The Manila Times

One of the longest-running English broadsheets in the Philippines

3 in 10 Asean organizations have experienced AI-driven malicious attacks – 2026 study

ACCORDING to IBM’s 2026 Cost of a Data Breach Report, organizations across Asean faced an average data breach cost of $4.12 million in 2026, the highest level recorded so far. Furthermore, nearly three in 10 Asean organizations reported experiencing AI-generated malicious breaches. These findings highlight the growing operational and financial pressure as attackers increasingly use AI-enabled tactics to exploit complex digital environments.

In contrast, organizations that use AI and security automation extensively cited lower average breach costs of $3.66 million, compared to $4.86 million among those with no such tools. They were also able to identify and contain breaches 123 days faster.

Catherine Lian, general manager, IBM Asean, said, “The report findings underscore the value of AI and automation in cybersecurity. Organizations that have integrated these technologies into their security operations are containing breaches faster and reducing associated costs at a time of unprecedented levels of cyber challenges and pressure.”

Key takeaways

– Critical infrastructure faces higher AI-driven risk. Financial services organizations reported the region’s highest average breach costs at $6.53 million, followed by industrial organizations at $5.99 million and communications organizations at $4.28 million, reflecting heightened cyber risk across critical infrastructure sectors.

– Frontier AI threats drive earlier action. In Asean, 71 percent of organizations said they planned to increase investments in security tools and governance following a breach. Globally, 85 percent of organizations plan to increase spending in advanced frontier AI cyber capabilities, arguing that they’d rather act on future risk than wait for an incident.

Other major findings

– Identity-based attacks remain costly. Abusing valid accounts was one of the costliest initial attack vectors in Asean, with breach costs averaging more than $4.5 million.

– Encryption gaps persist. Core weaknesses in encryption and cryptographic management continue. Only 29 percent of organizations said sensitive data was encrypted both at rest and in transit at the time of the breach.

– Security testing and automation help reduce costs. Organizations that invested in offensive security testing, security orchestration and automation reported some of the largest reductions in breach-related costs.

– Breaches involving AI models grew substantially. Breaches involving the compromise of AI systems, training data or infrastructure represented 21 percent of all breaches, up from 13 percent just a year ago. Among the costliest attacks were data poisoning, prompt injections and cloud misconfigurations affecting AI workloads, signifying that such tools are at the crosshairs of threat actors.

– Organizations still lack AI governance. Continuing a theme from last year, most organizations are still wanting in proper AI governance and controls against cyber threats. Of the organizations that experienced an AI-related incident, 92 percent lacked proper AI access controls and 68 percent lacked AI governance policies. Only 19 percent of organizations reported coordination between governance and security teams. These findings underscore the notion that AI adoption is outpacing oversight and that organizations deploying AI must treat AI security as a core element of their risk management framework.

– Majority of organizations failed to encrypt sensitive data. A striking 53 percent of breached organizations reported that they did not encrypt sensitive data at rest and in transit at the time of the incident. On-premises data was involved in 30 percent of breaches, up from 20 percent just two years ago, suggesting that legacy infrastructure remains a significant vulnerability. These findings serve as a stark reminder that organizations must prioritize data-centric security measures, including encryption, data classification and access controls.

The 2026 Cost of a Data Breach Report is by Ponemon Institute and sponsored and analyzed by IBM. The Asean findings are based on data from 26 organizations studied between March 2025 and February 2026.

Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved