Skip to content

Invest1 publisher3 min readPublished

IBM prices the AI-assisted breach at a million dollars more than the rest

A quarter of 602 hacked companies told IBM their attacker used AI, and those breaches cost about a million dollars more each. Anthropic's own misuse report shows the throughput behind that number.

The Investor · Invest desk

Illustration accompanying IBM prices the AI-assisted breach at a million dollars more than the rest

What happened

  • Anthropic's report on Claude misuse describes attackers taking more than 2,100 bundles of Azure AD authentication tokens in roughly 34 hours after breaching a software-as-a-service provider.
  • The Google Threat Intelligence Group found an attacker already inside a cloud environment that used agentic AI to plan, build and execute a large-scale credential theft operation in under six hours.
  • Anthropic, OpenAI and Google are discussing a joint standards body for the AI industry, The Information reported on the 13th.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • decision A measured per-breach premium gives a security budget a figure to argue against, and the choice it forces is between spending to cut how often breaches happen and spending to shorten how long each one runs.
  • constraint Attack timelines now fit inside a single shift. A change-approval queue measured in days sits outside that window, so the binding limit on defence is staffed response hours.
  • exposure The compromise travelled from a supplier to its client list. That leaves companies liable for authentication tokens sitting inside a system they do not operate and cannot instrument.
  • precedent If the model vendors write the industry's standards, the misuse counts offered to a procurement team will come from the members' own detection systems.

Divide 2,100 token bundles by 34 hours and the attackers were lifting roughly 62 an hour, overnight, with no shift change [1] [5]. Spread the same haul across the roughly 200 customer companies reached through one compromised software-as-a-service provider and it comes to about ten bundles each [2] [4]. Anthropic said AI agents performed nearly all of that work [6].

IBM asked 602 companies that had been hacked in the year to February, and about 150 of them said they had been targeted in an attack that used AI [14] [3]. A quarter of the sample, up 56% on the previous year, implies roughly 16% a year earlier [15] [4]. IBM put the added damage at an average of $1 million per breach [16]. Weight that by the 25% incidence and the expected extra cost on any one breach is about $250,000 [5].

The three-hour case is the one that sets staffing. Anthropic's report describes a single stolen developer token becoming administrator control of a victim's cloud environment in about three hours [7]. The Google Threat Intelligence Group came at it from the other side, concluding that defenders' response times are shrinking as attackers move beyond piecemeal questions to automating multiple stages of an attack [13]. "Sophisticated attacks no longer require sophisticated human attackers," Anthropic said [10].

Seoul Economic Daily says the government is rewriting security standards for next-generation AI [1], and Anthropic, OpenAI and Google are discussing a joint standards body for the industry, The Information reported on the 13th [2]. Two of those three supplied the incident evidence above. Anthropic's material is its own telemetry on misuse of Claude between December and August [3]. In the swarm case, one agent parcelled tasks out to sub-agents and ran attacks in parallel against about 50 organisations in education, health care, finance, manufacturing and government. That case was detected and described by the vendor whose model was used [8] [9].

I would expect the spending to follow the vendor chain before the perimeter. The compromise of one provider reached about 200 of its clients [4], and every one of those clients now has to inventory access it granted and does not run.

Two readings cut against that. The IBM figure is what breached companies said about their own attackers, and attribution follows salience, so part of the 56% rise may be a change in reporting [14] [15]. And if defensive automation shortens response as fast as offensive automation shortens attack, the $1 million premium is a transitional cost [16]. Korea's ministry is careful on this point. Reported breach incidents there totalled 1,236 in the first half, up 19.5% and about 202 more than a year earlier [17] [6]. "With the spread of generative AI, not every attack is fully automated yet, but when the time and cost of preparing an attack fall, attackers can analyze more targets in less time than before," the ministry said [18].

What would show the pricing wrong: a survey next year with AI incidence above 25% and the per-breach premium flat or falling [14] [16]. That would mean AI is making attacks cheaper to run without making the losses larger.

What to watch

  • Next year's IBM survey: whether AI incidence passes 25% while the $1 million per-breach premium holds.
  • Whether the Anthropic, OpenAI and Google standards body publishes misuse counts drawn from something other than members' own telemetry.
  • Korea's second-half breach tally against the 1,236 incidents reported in the first half.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories