Adversarial AI finally arrived with a price tag, and the cost curve reversed.
AI-driven attacks rose 56% and add an average of USD 1 million per breach. The global average cost climbed 12% to nearly USD 5 million, undoing the first decline in five years. And 88% of observed exploitation now occurs within 48 hours of a public proof of concept.
- Published
- September 15, 2026
- Period covered
- July 1, 2026 – September 30, 2026
- Documentary cut-off
- September 15, 2026
Executive perspective
Six conclusions that matter for the year ahead
Adversarial AI is now measurable, and it is priced
A 56% increase in AI-driven attacks, adding a million dollars per breach through velocity and scale. Attackers are, in IBM's phrase, abandoning human speed for machine speed. We held this line at emerging for six editions because the evidence described assistance rather than capability. A category with a measured price is no longer emerging.
Last year's cost improvement did not hold
Nearly USD 5 million, up 12%, reversing the first decline in five years. We described the 2025 drop as evidence that defensive investment produces a financial return. That reading was correct for that year's data and wrong as a trend, and we took more comfort from one data point than one data point supports.
The exploitation window is now 48 hours
Between January and June 2026, 88% of observed exploitation of vulnerabilities with a public proof of concept occurred within 48 hours of its release. Our own June 2025 recommendation of a two-week patch ceiling is obsolete by a factor of seven. No mid-market remediation process runs in 48 hours, and pretending otherwise helps nobody.
Intrusion volume plateaued, and that is the quarter's genuinely new fact
Overall intrusion activity rose approximately 4%, against a 27% surge the previous year. After eighteen months of compounding growth in nearly everything we track, a headline volume stopped climbing. Cost per breach, cloud eCrime and fraud losses all rose over the same window, which looks like a market that stopped adding customers and started raising revenue per customer.
AI defence works, and almost nobody points it at vulnerabilities
Organisations using AI security tools shortened breach lifecycles by 65 days and lowered costs by USD 1.93 million. Half of breached organisations deployed agents in threat hunting, response and containment. Only 18% applied them to vulnerability scanning and management, which is precisely where the 48-hour window bites.
One group accounts for 55% of all state-aligned intrusions
FAMOUS CHOLLIMA represents 55% of all nation-state intrusions and 44% of all technology-sector intrusions, operating primarily through fraudulent employment. The control that addresses it is identity verification at hiring, not a security product, and very few organisations treat recruitment as a security process.
The quarter in numbers
+56%
Increase in AI-driven attacks
Adding an average of USD 1 million per breach. The first quarter in six in which adversarial AI carries a measured financial consequence.
$5 M
Global average cost of a data breach
Nearly five million, up 12%, reversing the first decline in five years. The improvement we reported in September 2025 did not persist.
88%
Exploitation within 48 hours of a public proof of concept
January to June 2026. The patch window is two days, and our own two-week recommendation is obsolete.
+4%
Overall intrusion activity growth
Against +27% the previous year. A genuine plateau after eighteen months of compounding growth.
+171%
eCrime cloud-conscious activity
Financially motivated actors moving into cloud, where trusted access converts directly to money.
$1.93 M
Cost saved by organisations using AI security tools
Alongside 65 days off the breach lifecycle. Defensive AI outperforms offensive AI on the measured numbers, roughly two to one.
18%
Breached organisations applying AI agents to vulnerability management
Against 50% applying them to threat hunting and response. The gap sits exactly where the 48-hour window does.
55%
Share of nation-state intrusions attributable to a single group
FAMOUS CHOLLIMA, also 44% of technology-sector intrusions, operating mainly through fraudulent employment.
The board agenda
Five questions your board should be able to answer this quarter
They follow directly from the findings above. The full edition carries, for each one, the evidence behind it and the prioritised action that answers it.
What is our plan for a vulnerability that is exploited 48 hours after the proof of concept appears, given we cannot patch in 48 hours?
88% within two days.
Where have we deployed AI agents, and why not in vulnerability management?
50% in response, 18% in vulnerability work.
Who verifies the identity of a remote technical hire before they receive credentials?
One group at 55% of nation-state intrusions.
Is our build pipeline inside the security programme or inside engineering?
Adversaries now target CI/CD, container and package registries.
Who owns payment fraud, eighteen months after we first asked?
USD 20.9 billion reported, up 26%.
Want to see what changed this quarter, the trend radar, the FortaRisks point of view and what we are watching next?
The executive perspective above is the opening of the report. The complete edition carries the analysis and the recommendations that follow from it.
What the full edition adds
- What changed this quarter, and what only looks new
- Trend radar: direction, maturity and business impact
- The FortaRisks point of view, four convictions
- Looking ahead, next 3 to 6 months, with confidence levels
- The threat landscape, developments in detail
- Sector exposure, with OT and manufacturing broken out
- Prioritised recommendations, by theme and by risk addressed
- The prioritised action answering each question above, plus the source base and method
16 pages · 28 sources · immediate download, no wait
How this edition was built
This edition draws on the executive and annual reports published by leading consulting, research and cybersecurity firms up to the cut-off date, read against FortaRisks Research analysis and our own cyber threat intelligence. It scores the five forecasts made in June: one partial, four unresolved, our weakest scorecard of the series. It announces a change to how we forecast, tying each one to a named publication and release window. And it states plainly that the cost improvement we reported a year ago did not hold.
Every figure on this page appears in the full edition with its source, its data period and its methodological limits. A source is admitted only when its publication date precedes the documentary cut-off, so a historical edition never draws on research that did not yet exist. Where two independent datasets disagree, we report both rather than selecting one. The reading, the cross-source synthesis and the conclusions are FortaRisks Research's own, informed by the threat intelligence we operate.
See where your organisation sits on these numbers
The report says what is happening across the market. A 30-minute demo says what is happening on your attack surface.