Cybersecurity threat reports from IBM and Zscaler paint a stark picture of the escalating financial impacts of data breaches and ransomware attacks, with IBM finding the global average cost of a data breach reached $4.9 million in 2024, while Zscaler reported a record-breaking single ransom payment of $75 million and ransomware payments in total exceeding $1 billion in 2023.

IBM's annual “Cost of a Data Breach Report” found the average cost of data breaches worldwide increased 10% year over year, representing the largest annual jump since the pandemic, with 70% of breached organizations reporting significant or very significant disruptions.

The surge was driven by the combined costs of lost business such as operational downtime and lost customers, and post-breach responses including operational downtime, customer service staffing, and regulatory fines. These costs reached $2.8 million on average, the highest combined amount in six years.

Malicious insider attacks topped the list of the most expensive attack vectors, averaging nearly $5 million per breach. Other costly methods included business email compromise, phishing, social engineering, and compromised credentials.

“Businesses are caught in a continuous cycle of breaches, containment, and fallout response,” Kevin Skapinetz, VP of strategy and product design at IBM Security, noted. “This cycle now often includes investments in strengthening security defenses and passing breach expenses on to consumers – making security the new cost of doing business.”

IBM’s reported analyzed breaches in 604 organizations across 17 industries and 16 countries regions that ranged from 2,100 to 113,000 compromised records.

The roles of AI and talent shortage in data breach costs IBM’s report also showed that 26% more organizations faced severe staffing shortages compared to the previous year, while more than half of the breached organizations suffer from high talent-gap levels. The issue led to an average of $1.76 million more in data breach costs than organizations with low level or no security staffing issues.

However, one in five of the surveyed organizations said they used some form of generative artificial intelligence (genAI) security tools to boost productivity and efficiency.

AI-powered security strategies also have shown promise in mitigating the financial impact of breaches. According to IBM's report, two-thirds of organizations studied stated they are deploying AI and automation across their security operations centers (SOCs), which is a 10% year-over-year increase.

Extensive use of these technologies in prevention workflows – such as attack surface management and red teaming and posture management – resulted in an average $2.2 million reduction in breach costs compared to those with no AI use in prevention workflows. IBM pointed out this was the largest cost savings revealed in the 2024 report.

“As generative AI rapidly permeates businesses [and] expanding the attack surface, these expenses will soon become unsustainable, compelling businesses to reassess security measures and response strategies,” Skapinetz wrote. “To get ahead, businesses should invest in new AI-driven defenses and develop the skills needed to address the emerging risks and opportunities presented by generative AI.”

The escalating cost of ransomware attacks Zscaler's “ThreatLabz 2024 Ransomware Report” found a troubling 18% year-over-year increase in ransomware attacks, alongside an unprecedented ransom payout of $75 million to the Dark Angels ransomware group, which was the largest ever paid by one company. This single payment nearly doubled the highest publicly known ransomware payout.

The Zscaler research analyzed the ransomware threat landscape from April 2023 through April 2024. These ransomware attacks often cause extended downtime, substantial data loss, and high recovery costs. Zscaler noted the total ransomware payments exceeded $1 billion in 2023.

Meanwhile, ransomware extortion attacks have consistently surged, with the number of victim companies listed on data leak sites increasing nearly 58% since last year’s report. The manufacturing industry was the most targeted industry with 653 attacks – more than double any other industry.

“Ransomware defense remains a top priority for CISOs in 2024,” Zscaler Chief Security Officer Deepen Desai stated. “The increasing use of ransomware-as-a-service models, along with numerous zero-day attacks on legacy systems, a rise in vishing attacks, and the emergence of AI-powered attacks, has led to record-breaking ransom payments.”