India’s data breach costs soar to a record ₹25.5 crore in 2026 as AI-driven attacks accelerate

India’s data breach bill has reached a new high, with costs climbing 15.9% in 2026 amid rising AI-enabled cyber threats, highlighting a shift towards cyber resilience as a crucial financial and strategic concern.

India’s data breach bill has surged to a record ₹25.5 crore in 2026, underlining how cyber incidents have become a material financial risk rather than a narrow technology problem. The figure, reported by WhalesBook, is up 15.9% from ₹22 crore in 2025 and reflects the growing cost of incident response, disruption and recovery as companies expand their digital operations.

The escalation comes as attackers increasingly use artificial intelligence to sharpen their methods. IBM said in a July study that 25% of malicious breaches were AI-enabled, up 56% from the previous year, with deepfake impersonation and AI-driven malware among the most common tactics. In India, the scale of the threat is also rising: the average breach now affects about 39,500 records, slightly more than a year earlier.

The gap between companies that have automated security and those that have not is becoming more pronounced. WhalesBook reported that organisations without extensive AI security automation faced average breach costs of ₹31.6 crore, versus ₹21.3 crore for firms with stronger automated defences. IBM found a similar pattern globally, saying companies using AI and automation in security operations reduced breach costs by nearly $2 million, while a quarter of firms had still not adopted these tools.

Warnings from Indian authorities and industry reports suggest the pressure is broadening across sectors. The Ministry of Home Affairs has cautioned banks, fintech groups and consumers about deepfake fraud aimed at bypassing facial authentication and video-based know your customer checks. Thales, in a 2026 data threat report, said 65% of Indian organisations had experienced deepfake-related incidents and 64% ranked AI-enabled attacks as their top security risk, yet only 30% had set aside dedicated funding for AI-related protection.

That spending gap may become harder to ignore as compliance deadlines approach. WhalesBook said the Digital Personal Data Protection Act is due to come into force in May 2027, with penalties of up to ₹250 crore for data leaks. For investors, the message is clear: cyber resilience is increasingly linked to margins, capital allocation and long-term competitiveness.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.