One in Four Breaches Now Involves AI. Cybersecurity Is the Job It’s Creating.

A person studying a video on a phone in dim light, checking whether what they are watching is real

ℹ️ Quick Answer: One in four data breaches between March 2025 and February 2026 involved AI, according to IBM, up 56% in a single year. That surge is why AI cybersecurity jobs are one of the few areas where the technology creates work instead of removing it, though budget cuts have kept hiring behind the demand.

📋 WHAT’S INSIDE

  1. What the New Breach Numbers Actually Say
  2. AI Fakes Got Better, and Some Got Worse on Purpose
  3. The Scam I Keep Thinking About
  4. Why AI Cybersecurity Jobs Are Growing, Not Shrinking
  5. What to Do This Week
  6. The Honest Limitations

Last updated August 14, 2026

I’ve started doing something I never used to do, which is pausing videos to work out whether they’re real. Just the regular stuff, the kind that shows up between two posts from people I actually know.

What tipped me off was the quality. A lot of the fakes look rough on purpose, like somebody shot them on a phone from 2014. Think grainy, washed out, slightly shaky. My first instinct was that bad footage meant real footage, because who bothers faking something badly. That instinct turned out to be exactly backwards.

So when the new breach numbers landed this week, the part that stuck with me wasn’t that attacks are up. It’s what that means for work. We spend most of our time talking about AI erasing jobs. This is the corner of the economy where it’s going to do the opposite.

What the New Breach Numbers Actually Say

A server room lit in blue, the kind of system behind the 2026 breach numbers

One in four breaches between March 2025 and February 2026 involved AI, up 56% from the year before, and the total number of breaches is on pace to beat last year.

That one-in-four figure comes from IBM’s Cost of a Data Breach Report 2026, which also put the global average cost of a breach at $4.99 million, a 12% jump and a record high. IBM attributes the 56% rise in AI-driven attacks mostly to deepfake impersonations and AI-enabled malware. The growth is in fooling people rather than picking locks.

The volume numbers come from the Identity Theft Resource Center, reported by CNBC this week. There were 1,803 reported data compromises in the first half of 2026, against 1,732 in the same stretch of 2025. If the back half keeps pace, 2026 clears the 3,321 incidents recorded for all of last year. “We continue to see this ever-increasing number of data breaches,” ITRC president James Lee told CNBC. “That does not appear to be slowing down.”

Malicious insider incidents hit 21 in six months, and the ITRC had never recorded more than three in a full year. Part of that is laid-off employees taking data on the way out. The rest is a scheme the FBI has flagged, where North Korea places remote IT workers inside US companies using stolen identities. The ITRC adds that the operation leans on AI-generated resumes and deepfake video during the job interview, and calls it “arguably the most significant structural driver of malicious insider attacks.” People are faking their own faces through hiring calls now.

AI Fakes Got Better, and Some Got Worse on Purpose

Jeremy Tree pic 2

Deliberately degraded video is a known technique. Grain and blur hide the mistakes a model still makes, so a rough clip can be harder to catch than a clean one.

Reader’s Digest walked through why so much AI video looks like it came off a potato. Lower quality hides the physics errors. When the whole clip is a mess, no single detail stands out as wrong. That’s also why so many fakes claim to be porch security camera footage, since nobody expects a doorbell cam to look good. The “bunnies on a trampoline” clip that fooled millions of viewers last year was exactly that, fake security footage.

Everyone has an HD camera in their pocket. A modern phone doesn’t produce a blurry, washed-out video. When you see one, slow down and look again.

AI still handles text badly, so watch for letters bleeding into each other, fonts that change halfway through a sign, and typos that don’t make sense. Clocks are worse. Check whether the numbers run in order and whether the hands move at a believable speed.

The Scam I Keep Thinking About

An older woman reacting with alarm to something on her phone

Voice cloning already works. Video is close behind, and the people with the most to lose are the ones least prepared for it.

Picture getting a video from a family member saying they’ve been arrested and need bail money right now. Not a text. Not a voice call. A video, with their face and their voice and the panic you’d expect from someone in that situation.

I don’t think that lands on many people under 40. They grew up assuming media can be faked, so the reflex to verify is already there. I think it lands on a lot of people over 70, and the loss figures suggest the damage is far worse when it does.

The FBI’s 2025 Internet Crime Report put total reported losses at $20.9 billion, up 26% from 2024, across more than a million complaints. Adults 60 and older accounted for $7.7 billion of that, roughly a 60% increase in a single year. People in their 30s and 40s reported $4.6 billion.

The per-person numbers tell it better than the totals do. FTC data shows adults in their 70s report a median loss of about $1,000, and for people 80 and over it runs past $1,600. For people in their 20s the median is around $417. Younger people get targeted constantly and report fraud plenty. The money that walks out the door climbs steeply with age.

Why AI Cybersecurity Jobs Are Growing, Not Shrinking

A security officer watching multiple screens in a dim control room, one of the AI cybersecurity jobs in demand

Every one of those attacks needs a person on the other side of it, which is why AI cybersecurity jobs are expanding while the technology trims headcount elsewhere.

We talk about AI as a thing that removes work. Here it manufactures it. Somebody has to build the detection, run the response, train the staff who click the links, and sit down with a family to explain that the video of their son was not their son. AI is getting good enough at fooling people that the fooling has become its own industry, and industries need workers.

The spending signals are already showing up. PwC surveyed 3,887 business and technology executives across 72 countries and territories, and 78% said they would increase cybersecurity budgets over the following year. Deloitte’s Center for Board Effectiveness and the Center for Audit Quality found cybersecurity sitting in the top three priorities for 93% of audit committees at public companies, and half of the 237 respondents ranked it first outright.

The gap between what employers need and who exists to do it is enormous. ISC2’s 2024 workforce study put the global shortfall at 4.8 million unfilled cybersecurity positions against an active workforce of about 5.5 million, meaning the field would need to roughly double to cover what employers said they needed. ISC2 dropped that estimate from its 2025 study, so treat 4.8 million as the last published figure rather than a live one.

The tools help, and they don’t remove the person. IBM found organizations using AI and automation extensively in their security work saved an average of $1.93 million per breach compared with organizations using none. Somebody still has to run them.

What to Do This Week

A diverse group of adults attentively listening in an indoor business meeting setting.

Two conversations and one afternoon of paperwork cover most of the risk for a normal household.

  • Agree on a family code word. Any request for money that arrives by video, voice or text has to include it. It costs one dinner conversation, and a cloned voice can’t produce a word it never heard.
  • Hang up and call back on the number you already have, never the number that just contacted you. This single habit stops most impersonation attempts cold.
  • Freeze your credit at Equifax, Experian and TransUnion. It’s free, and it stops a stolen identity from turning into a loan in your name.
  • Pull your credit reports at AnnualCreditReport.com. You can do it weekly at no cost now, and checking doesn’t affect your score.
  • Have the conversation with your parents instead of sending them a link. The people most at risk are the least likely to read a security article on their own.

I went deeper on how these scams actually run in an earlier post, including what three seconds of recorded voice is enough to do.

The Honest Limitations

The jobs argument has a hole in it, and I would rather name it than sell around it.

Demand for AI cybersecurity jobs is not the same as hiring for them. ISC2’s own research found 25% of cybersecurity professionals reported layoffs in their departments in 2024, up three points from the year before, and 37% faced budget cuts, up seven points. Budget pressure rather than a shortage of qualified people became the main driver of understaffing, and two-thirds of respondents said those cuts would make the skills gap harder to close in the years ahead. The need is real and getting worse. The paychecks have lagged behind it.

The other honest note is about my own read on the generational split. I think a deepfake bail video works better on older targets, and the loss data supports that direction. It’s still my read rather than a study of that specific scam. Younger people fall for plenty, and confidence about spotting fakes is its own kind of vulnerability.

Are AI cyberattacks actually increasing?

Yes. IBM found one in four data breaches involved AI between March 2025 and February 2026, a 56% rise year over year, driven mostly by deepfake impersonation and AI-enabled malware. The Identity Theft Resource Center counted 1,803 reported breaches in the first half of 2026, putting the year on pace to pass the 3,321 recorded for all of 2025.

Will AI take cybersecurity jobs?

The evidence points the other way for now. Two-thirds of security professionals in ISC2’s workforce study expect their expertise to work alongside AI rather than be replaced by it, and fewer than half had put generative AI into their tools at all. A third do worry about their roles being eliminated. The near-term pressure on security headcount has come from budget cuts rather than automation.

How can I tell if a video is AI-generated?

Treat low quality as a warning sign rather than reassurance, because blur and grain hide the errors a model still makes, and “security camera footage” is a common cover story. Check any text in the frame for letters bleeding together and fonts that change mid-sign, and check clocks for numbers running out of order. For anything involving money, verify through a second channel.

What is the single best protection against a deepfake scam?

A family code word, agreed in advance, required for any request involving money. It costs nothing, and a cloned voice cannot produce a word it has never heard. Pair it with a simple habit of hanging up and calling back on a number you already had rather than the one that contacted you.


The gap between how good the fakes are getting and how ready most people are is the part that actually worries me. The jobs will follow the damage, and there is going to be plenty of damage.

Related reading: How AI scams actually work | AI jobs that didn’t exist five years ago | AI deception is getting harder to catch | AI fraud detection for your accounts | New to AI? Start here

Want AI tips that actually work? 💡

Join readers learning to use AI in everyday life. One email when something good drops. No spam, ever.

We don’t spam! Read our privacy policy for more info.

WHO WROTE THIS

Moses Smith. I write Everyday AI for people who aren’t engineers. I go try the tools, then tell you honestly whether they were worth it. Sometimes the answer is no, and that’s kind of the point.

This blog is free and has no ads. If it saved you some time, you can buy me a coffee.

Leave a Reply

Your email address will not be published. Required fields are marked *