Skip to main content

Back to Blog

The Rising Cost of Trusted Access

IBM 2026 Cost of a Data Breach Report

The cost of a data breach continues to climb. According to the IBM Cost of a Data Breach Report 2026, the global average reached a record $4.99 million, up 12% from the previous year. In the United States, the average cost rose to $11.5 million, more than twice the global average. Detection and escalation costs combined with lost business accounted for 63% of the average breach cost.

AI understandably dominates much of the conversation around this year’s report. IBM found a significant increase in AI-driven attacks, including the use of AI for impersonation, phishing, and other forms of social engineering.

But the Cost of a Data Breach 2026 findings also highlight a more familiar security problem: attackers continue to target ways to obtain and abuse trusted access.

Phishing remained the leading initial attack vector, while social engineering and valid-account abuse were also among the most common. Together, these findings reinforce an important challenge for identity security. Attackers don’t always need to break through security controls if they can acquire credentials or otherwise gain access that the organization already trusts.

The Cost of a Data Breach Reaches a Record High

IBM’s $4.99 million global average represents an all-time high and reverses the decline in breach costs reported in 2025. The increase was driven largely by detection, escalation, and lost business costs, including disrupted operations and customer churn.

Breaches also aren’t getting resolved particularly quickly. The average time required to identify and contain a breach increased to 247 days, reversing a five-year downward trend. Organizations took an average of 183 days to identify a breach and another 64 days to contain it.

That combination, higher costs and lengthy detection times, makes the way attackers initially gain access especially important.

For the fourth consecutive year, phishing was the leading initial attack vector among breached organizations in IBM’s research. Supply chain compromise ranked second, followed by abusing valid accounts, drive-by compromise, and social engineering.

Trusted Access Remains a Valuable Attack Path

The financial impact of attacks involving identity and access was substantial.

Voice and SMS phishing, which accounted for 17% of attacks, resulted in an average breach cost of $5.29 million. Social engineering attacks, including IT or help desk impersonation and MFA fatigue, averaged $5.23 million. Breaches involving the abuse of valid accounts averaged $5.07 million.

Trusted Access by the Numbers
$5.07M
Average cost of breaches involving valid-account abuse
243 days
Average time to identify and contain breaches involving valid-account abuse
$225,622
Lower average breach cost associated with identity and access management (IAM)
Source: IBM Cost of a Data Breach Report 2026

These attack vectors aren’t interchangeable, but they can share an important objective: gaining access that appears legitimate. IBM notes that the results suggest phishing and social engineering attacks are targeting credentials with access to valuable data.

This distinction matters. When attackers exploit a vulnerability or introduce malware, security teams can look for indicators of malicious activity. But when an attacker obtains working credentials, malicious activity can begin with successful authentication.

The organization may see access through a valid account even though that access is being abused by an attacker.

That makes credential security an important part of determining whether trusted access should remain trusted.

AI Is Accelerating Attacks Against Identity

The methods attackers use to obtain access are also evolving.

More than one in four organizations that experienced a malicious attack reported an AI-driven attack, representing a 56% increase from the previous year. AI deepfake and impersonation attacks accounted for 45% of malicious AI-driven attacks, while AI-generated phishing and other communications represented another 17%.

IBM points specifically to generative AI’s ability to make social engineering attacks cheaper to create and harder to detect, helping attackers trick users and bypass identity controls.

The financial consequences are significant as well. Malicious AI-driven breaches averaged $6.04 million, compared with $5.03 million for malicious attacks that weren’t AI-driven—approximately $1 million more per breach.

For identity teams, the takeaway isn’t simply that AI introduces a new category of cyberattack. AI can also make existing attack techniques more convincing and scalable.

Phishing and impersonation can become more convincing and harder to recognize. And when those techniques result in compromised credentials or other trusted access, attackers may be able to operate without immediately appearing unauthorized..

The technologies are changing. The value of a valid credential isn’t.

Valid Account Abuse Can Remain Undetected for Months

IBM’s findings around breach timelines make valid-account abuse particularly notable.

Breaches involving valid-account abuse took an average of 243 days to identify and contain: 179 days to identify the breach and another 64 days to contain it. Social engineering incidents averaged 254 days, while phishing incidents averaged 251 days.

The longer an incident persists, the financial consequences can increase.

IBM found that breaches with a lifecycle exceeding 200 days averaged $5.65 million, compared with $4.32 million for breaches identified and contained in fewer than 200 days.

These findings underscore the importance of identifying account compromise as quickly as possible, particularly when attackers are operating through access that may initially appear legitimate.

Identity Security Requires Ongoing Visibility

IBM’s analysis provides additional evidence for the value of identity security. Among 30 factors evaluated for their impact on breach costs, identity and access management (IAM) was the second-largest cost-reducing factor, associated with $225,622 lower costs compared with the global average. Only a DevSecOps approach ranked higher.

IAM provides essential controls over who should have access and what they should be allowed to do. But organizations also need to consider whether the credentials providing that access remain secure.

That distinction matters because credential risk can change over time. A credential that was secure when it was created can become compromised later.

Password screening at creation and reset can help prevent known compromised credentials from entering an environment. Continuous monitoring extends that visibility throughout the credential lifecycle, allowing organizations to identify credentials that become compromised later.

This shifts credential security away from a point-in-time decision. Instead of assuming a credential remains trustworthy until there is evidence of account misuse, organizations can reassess that trust as new exposure data becomes available.

Keeping Trusted Access Trustworthy

IBM’s 2026 findings show that breach costs are rising while attackers gain new ways to make phishing, impersonation, and other attacks more convincing and scalable. At the same time, valid-account abuse remains a costly attack path that can persist for months before it is identified and contained.

For identity security teams, the challenge is increasingly about determining whether access that appears legitimate should still be trusted.

Successful authentication confirms that the presented credentials satisfy the authentication requirements. It doesn’t necessarily mean those credentials haven’t been compromised or that the resulting access should be trusted.

As credential risk changes over time, security controls need to account for that change. Continuous credential monitoring provides a way to identify when previously trusted credentials become compromised so organizations can respond to that change in risk.