The global average cost of a data breach was USD 4.44 million in 2025, according to IBM's Cost of a Data Breach Report, based on research across 600 breached organizations conducted by the Ponemon Institute. The United States remains by far the most expensive place to have a breach, at USD 10.22 million on average, a record high that is roughly 2.3 times the global figure. Both numbers cover the study window of March 2024 through February 2025.

Average cost of a data breach by country/region, 2025 (USD millions) United States10.22MMiddle East7.29MBenelux6.24MCanada4.84MUnited Kingdom4.14MGermany4.03MJapan3.65MAustralia2.55M

Figure 1: Top 8 countries and regions ranked by average breach cost. Source: IBM Cost of a Data Breach Report 2025.

What is the average cost of a data breach in 2026?

The most recent published figure, from IBM's Cost of a Data Breach Report 2025, puts the global average at USD 4.44 million, down 9 percent from USD 4.88 million a year earlier. That is the first year-over-year decline in five years, and IBM credits faster detection, much of it aided by AI and automation in security operations, rather than fewer breaches overall.

The study behind that number is not a survey of headlines. Ponemon Institute researchers interviewed staff at 600 organizations across 16 countries and regions and 17 industries that had experienced a real breach in the prior 12 months, then modeled the total cost using more than a hundred cost factors: detection, notification, lost business, and post-breach response. Cost per compromised record varies by data type rather than a single blended figure: customer personal data averaged USD 160 per record, employee personal data USD 168, and intellectual property USD 178, the most expensive category because IP theft tends to trigger the longest and most expensive investigations.

The decline is a global average, not a universal trend. The United States moved in the opposite direction, and several large economies, covered in the next section, still sit well above the world figure. A single average also hides a wide underlying spread: a breach at a small business with weak logging and no incident response plan routinely costs multiples of the mean, which is one reason data breach statistics for smaller companies tend to look worse in relative terms even when the absolute dollar figure is lower.

Takeaway: the headline cost fell for the first time in five years, but "average" conceals a country-by-country and sector-by-sector spread wide enough that the global number alone tells you little about your own risk.

Which country has the highest data breach costs?

The United States, at USD 10.22 million per breach on average in 2025, a record high and the most expensive country IBM has measured in the 15 years it has published this metric. That is up 9 percent from 2024 and now stands 2.3 times above the global average.

IBM attributes the US premium to a specific combination of factors rather than a single cause: all 50 states carry mandatory breach-notification laws, class-action litigation following a breach is common and expensive, and federal and state regulatory fines have escalated. Detection and escalation costs, the expense of hiring forensics teams, outside counsel, and crisis communications, also run higher in the US than anywhere else IBM tracks.

The rest of the top tier is a large step down but still well above the global mean. The Middle East is second at USD 7.29 million, followed by the Benelux region (Belgium, Netherlands, Luxembourg) at USD 6.24 million, Canada at USD 4.84 million, the United Kingdom at USD 4.14 million, and Germany at USD 4.03 million, which fell about 24 percent from the prior year. Japan sits close to the global average at USD 3.65 million, while Brazil is the least expensive country IBM measures, at USD 1.22 million.

Country or regionAverage breach cost (2025)vs. global average
United StatesUSD 10.22 million2.30x
Middle EastUSD 7.29 million1.64x
BeneluxUSD 6.24 million1.41x
CanadaUSD 4.84 million1.09x
United KingdomUSD 4.14 million0.93x
GermanyUSD 4.03 million0.91x
JapanUSD 3.65 million0.82x
BrazilUSD 1.22 million0.27x

Takeaway: breach cost is not just a function of attack severity; it tracks a country's regulatory exposure and litigation environment as much as the technical scale of the incident, which is why the US sits so far above every other market IBM studies.

Which industries have the most expensive breaches?

Healthcare, at USD 7.42 million on average, the most expensive industry for the 14th consecutive year even though the figure fell USD 2.35 million from 2024. Financial services follows at USD 5.56 million, then industrial at USD 5 million, energy at USD 4.83 million, and technology at USD 4.79 million.

Healthcare's persistent lead comes down to two things: the sensitivity of the records involved (medical histories carry a long shelf life for fraud and cannot be reissued the way a credit card number can) and slow detection. Healthcare breaches took an average of 279 days to identify and contain, more than five weeks longer than the global average of 241 days, giving attackers more time inside a network before anyone notices.

Retail, education, and the public sector sit at the other end of the range. Retail averaged USD 3.54 million, education USD 3.8 million, and the public sector was lowest of all industries IBM measured at USD 2.86 million, likely reflecting lower average breach severity and different regulatory cost structures rather than better security in absolute terms.

Average cost of a data breach by industry, 2025 (USD millions) Healthcare7.42MFinancial5.56MIndustrial5MEnergy4.83MTechnology4.79MEducation3.8MRetail3.54MPublic sector2.86M

Figure 2: Top and bottom industries by average breach cost. Source: IBM Cost of a Data Breach Report 2025.

IndustryAverage breach cost (2025)Change vs. 2024
HealthcareUSD 7.42 milliondown USD 2.35 million
Financial servicesUSD 5.56 millionroughly flat
IndustrialUSD 5.00 millionroughly flat
EnergyUSD 4.83 millionroughly flat
TechnologyUSD 4.79 millionroughly flat
EducationUSD 3.80 millionroughly flat
RetailUSD 3.54 millionroughly flat
Public sectorUSD 2.86 millionlowest of all sectors

Takeaway: healthcare's lead is not new and is not closing; if you handle health records, budget for a cost profile closer to double the cross-industry average, not the headline USD 4.44 million figure.

What factors raise or lower breach costs?

Security posture moves the bill by millions in either direction, and IBM's 2025 report isolates the individual factors with the largest swing. Extensive use of security AI and automation cut the average cost by USD 1.9 million and shortened the breach lifecycle by 80 days compared to organizations with little or no AI use in their security operations. A capable incident response team, tested regularly, and a mature DevSecOps approach were the next-largest cost reducers; the 2023 edition of the same report measured the DevSecOps gap alone at nearly USD 1.7 million.

Working against that progress is a new category of risk: AI systems themselves. 13 percent of breached organizations in the 2025 study reported an AI model or application was involved in the breach, and another 8 percent were not sure whether AI was a factor at all. Among organizations that did have an AI-related incident, 97 percent said they lacked proper access controls on those AI systems, and 63 percent had no AI governance policy in place or were still building one. Shadow AI, meaning AI tools employees adopt without security team knowledge or approval, was present in 20 percent of breaches and added USD 670,000 to the average cost when it was a high-level factor.

Ransomware and extortion breaches carry their own premium. When an attacker disclosed the breach themselves, typically to pressure the victim during an extortion attempt, the average cost reached USD 5.08 million, and 63 percent of victim organizations refused to pay the ransom demand.

Figure 3: Factors that push the average breach bill up versus down. Source: IBM Cost of a Data Breach Report 2025.

Share of breached organizations reporting an AI-related security incident (2025) 13%8%79%AI model/app breach confirmed13%Unsure if AI was involved8%No AI involvement reported79%

Figure 4: How many breached organizations identified AI as a factor. Source: IBM Cost of a Data Breach Report 2025.

Takeaway: the biggest cost swings are now security-operations choices an organization controls directly, security AI and automation on one side, unmanaged shadow AI on the other, rather than the nature of the attack itself.

How much does breach detection time affect cost?

Every extra day a breach goes undetected adds to the final bill, and IBM's 2025 data quantifies the gap directly: organizations that detected their own breach internally paid about USD 900,000 less on average than organizations that only learned about the breach when the attacker disclosed it.

The global mean time to identify and contain a breach was 241 days in 2025, a 17-day improvement over 2024 and the fastest pace in nine years, largely credited to wider use of AI-assisted detection tools. Healthcare again lagged the rest of the field, averaging 279 days, more than five weeks slower than the cross-industry mean, which compounds the sector's already-high per-incident cost.

Global average cost of a data breach, 2020 to 2025 (USD millions) 01.534.56M2020202120222023202420254.44M

Figure 5: Six years of the global average, including 2025's first decline in five years. Source: IBM Cost of a Data Breach Report, 2020 through 2025 editions.

The direction of that six-year line matters as much as any single year's figure. Costs rose every year from 2020 through 2024, then fell in 2025 for the first time, which is the clearest evidence yet that detection speed, not breach volume, is the lever currently moving the global average. If your organization has never mapped how long it would take your own team to notice unauthorized access, that gap is worth closing before it shows up as a cost statistic in next year's report; you can also generate a compliant privacy policy that spells out your breach-notification commitments so a slow internal response is not compounded by an unclear public one.

Takeaway: speed of detection is now the single most controllable lever on breach cost, worth roughly USD 900,000 per incident based on 2025's data.

The Bottom Line

Every cut of IBM's 2025 data points the same direction: cost is driven less by the fact that a breach happened and more by how fast it was caught and how prepared the organization was beforehand. The USD 4.44 million global average fell for the first time in five years because more breaches are being caught by internal teams using AI-assisted tools, yet the United States, healthcare, and organizations running unmanaged shadow AI all moved against that trend and now carry a meaningfully larger bill than the global figure suggests. For a full picture of how breaches happen in the first place, see the companion data breach statistics roundup, and for how these cost figures compare across history, the biggest data breaches of all time shows what the largest incidents on record actually cost at scale. The practical read for any organization handling personal data: detection speed and AI governance are no longer optional line items, they are now the two factors with the clearest, largest, and most quantified effect on the final bill.

Frequently Asked Questions

What is the average cost of a data breach in 2026? The most recent published figure is USD 4.44 million globally, per IBM's Cost of a Data Breach Report 2025, based on research across 600 breached organizations conducted by the Ponemon Institute between March 2024 and February 2025. That figure is down 9 percent from USD 4.88 million the year before, the first decline in five years.

Which country has the highest data breach costs? The United States, at USD 10.22 million on average per breach in 2025, roughly 2.3 times the global average and a record high for any country in the 15 years IBM has tracked the metric. The Middle East is second at USD 7.29 million, followed by the Benelux region at USD 6.24 million.

Which industry has the most expensive data breaches? Healthcare, at USD 7.42 million on average, the most expensive sector for the 14th consecutive year despite falling USD 2.35 million from 2024. Financial services is second at USD 5.56 million, followed by industrial at USD 5 million.

How much does breach detection time affect the cost? Breaches identified and contained by internal teams cost about USD 900,000 less than ones an attacker discloses first, per IBM's 2025 report. The global mean time to identify and contain a breach was 241 days in 2025, the fastest in nine years, while healthcare breaches took 279 days, more than five weeks longer.

Where the Numbers Come From

  1. IBM. (2025). "Cost of a Data Breach Report 2025." Global average USD 4.44 million, 600 organizations studied across 16 countries/regions and 17 industries, research conducted by Ponemon Institute, study window March 2024 to February 2025.
  2. Help Net Security. (2025). "Average global data breach cost now $4.44 million." Confirms the 9 percent year-over-year decline, 241-day mean time to identify and contain, and the USD 900,000 internal-detection savings figure.
  3. IBM Think. (2025). "2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security." Source for the AI and shadow AI findings: 13 percent AI-related breaches, 97 percent lacking AI access controls, USD 670,000 shadow AI cost premium.
  4. HIPAA Journal. (2025). "Average Cost of a Healthcare Data Breach Falls to $7.42 Million." Confirms healthcare's 14th consecutive year as the most expensive industry and the 279-day detection window.
  5. IBM Think. (2025). "Cost of a data breach: The healthcare industry." Sector-level detail supporting the industry cost ranking.
  6. The Record from Recorded Future News. (2025). "IBM: Average cost of a data breach in US shoots to record $10 million." Independent confirmation of the USD 10.22 million US figure and the 15-year US cost leadership streak.
  7. IBM Security. (2023). "Cost of a Data Breach Report 2023." Source for the 2020 to 2023 global average figures used in the six-year trend line (USD 3.86 million, USD 4.24 million, USD 4.35 million, USD 4.45 million) and the 553-organization sample size for that edition.

Note: All figures verified as of July 2026 against IBM's Cost of a Data Breach Report 2025 and independent secondary reporting. IBM's report is published annually each summer; figures in this post reflect the 2025 edition and will be refreshed when the next edition is released.