A Rare Piece of Good News, With a Catch

For the first time in five years, the global average cost of a data breach actually fell - down to $4.44 million in 2025 from $4.88 million the year before, according to IBM's closely watched annual Cost of a Data Breach report. The reason was largely faster detection: organisations using AI-powered security tools identified and contained breaches in a mean of 241 days, the shortest window in nine years. That is the good news. The catch is that 241 days is still eight months - plenty of time for stolen data to be sold, combined with other leaked datasets, and used against the people it belongs to, long before the affected company even sends out a notification email.

The Numbers Get Worse Depending on Where You Are

That global average hides sharp regional differences. In the United States, the average breach cost climbed to an all-time high of $10.22 million - more than double the global figure - driven by heavier regulatory fines and steeper litigation exposure. Healthcare remains the single most expensive sector to suffer a breach, averaging $7.42 million, a position it has now held for over a decade, largely because medical records combine financial, personal, and health information in a single, highly valuable package for criminals.

AI Is Making Both Sides Smarter

Security teams are using AI to spot anomalies and contain incidents faster, which explains part of the recent cost decline. But attackers are using the same technology. AI is now involved in roughly one in six breaches, primarily to power more convincing phishing emails and deepfake-based social engineering. A newer and more concerning trend is "shadow AI" - employees using unauthorised AI tools without company oversight - which has been linked to roughly one in five breaches, almost always at organisations with no access controls in place for those tools at all.

What "Your Data Is Out There" Actually Means

Most people picture a data breach as a single dramatic hack. In practice, it is usually quieter and more cumulative: your email and an old password from one leaked service, your phone number from another, your date of birth from a third. None of these individually feels catastrophic. Combined, they give a scammer enough to convincingly impersonate you, reset your accounts, or build a targeted phishing message that references real details about your life. This is why so many scam attempts feel unnervingly specific - the information genuinely did come from somewhere real.

What You Can Actually Do About It

You cannot prevent a company from being breached, but you can limit the damage when it happens. Use a password manager and a genuinely unique password for every account, so one leaked password doesn't unlock the rest of your digital life. Turn on two-factor authentication wherever it's offered, ideally using an authenticator app rather than SMS. Check whether your email has appeared in known breaches using a reputable breach-checking service, and treat any hit as a prompt to change that specific password immediately. Be wary of unexpected emails or calls that reference real personal details - that specificity is often meant to earn your trust, not prove the sender is legitimate. None of this makes you unhackable. It makes you a meaningfully harder and less rewarding target, which for most opportunistic criminals is enough to make them move on to someone else.