There were 1,803 reported data compromises in the first half of this year, up from 1,732 over the same period last year, affecting more than 471 million victim notices combined. The more telling statistic sits underneath that headline count: roughly one in four breaches between March last year and February this year was AI-enabled, a share that's up 56% from the year before. Attackers are adopting AI tooling faster than most defenses are adapting to counter it.
This isn't an abstract trend confined to obscure incidents. The Department of Homeland Security confirmed hackers breached the Homeland Security Information Network, an unclassified platform used to coordinate security around the 2026 FIFA World Cup, a target chosen specifically because of the high-profile event it supports. Craneware, an Edinburgh-based healthcare financial software firm, disclosed unauthorized access to a subset of its data environment to the London Stock Exchange in July. Healthcare, government, consumer brands, insurance, and software development have all shown up among the sectors hit this year.
Why AI changes the economics of an attack
AI tooling lowers the cost and skill threshold required to run a convincing attack. Credential theft and vishing, voice-based phishing that impersonates a trusted caller, both benefit enormously from AI-generated content that's harder for a target to distinguish from a genuine communication than older, more obviously scripted attempts. Ransomware operators are using AI to accelerate reconnaissance and identify high-value targets faster than manual research would allow. None of these techniques are new in concept. What's new is how much faster and cheaper AI makes each one to execute at scale.
'Malicious insider' incidents rising alongside these external, AI-enabled attacks adds a second dimension to the same trend. An organization now has to defend against both an external attacker armed with better tools and an internal actor who may be using those same tools to exfiltrate data more efficiently than in past years. Both trends point toward the same conclusion: the volume and sophistication of the threat landscape are both climbing simultaneously, not just one or the other.
Traditional security training programs were largely built around teaching employees to spot the telltale signs of a scripted phishing email: awkward phrasing, obvious spelling errors, a mismatched sender address. AI-generated attacks increasingly lack those tells entirely, which means a meaningful share of existing employee training material is becoming less effective at exactly the moment attack volume is climbing, a gap that organizations are still working through operationally.
Boards are responding, which is itself a signal
Cybersecurity now ranks among the top three priorities for 93% of audit committees at public companies, with half of respondents ranking it their single leading priority. That level of board-level attention typically translates into sustained budget allocation, since audit committees are directly responsible for the risk oversight function that cybersecurity spending falls under. A priority this concentrated at the governance level tends to show up in vendor revenue with a reasonably short lag.
Whitmore's Watchlist:
CRWD (CrowdStrike Holdings): A leading endpoint security platform positioned to benefit directly from rising breach volume and AI-enabled attack sophistication.
PANW (Palo Alto Networks): A broad cybersecurity platform provider spanning network, cloud, and AI-driven threat detection capabilities.
CIBR (First Trust Nasdaq Cybersecurity ETF): Diversified exposure across the cybersecurity sector for investors who want the theme without picking individual vendors.
The critical infrastructure angle is the one to watch
Attacks tied to a major global event like the World Cup point toward a broader pattern worth tracking: threat actors increasingly targeting infrastructure that supports high-visibility events or essential services, rather than only pursuing direct financial theft. That shift raises the stakes beyond typical data breach economics, since disruption to critical infrastructure carries consequences well beyond the immediate financial cost of a stolen dataset.
Government and healthcare targets in particular tend to carry outsized downstream consequences relative to a typical consumer data breach, since disruption to either can affect public safety or patient care directly rather than just exposing personal information. That distinction is part of why regulatory and compliance spending in those specific sectors has continued climbing even in years when overall corporate technology budgets have tightened elsewhere.
Whitmore's Take: The rise of AI-enabled attacks is a structural shift in how cheap and scalable breaches have become, not a temporary spike likely to fade on its own. Worth treating cybersecurity spending as a durable, multi-year theme rather than a reactive response to any single headline incident.

Written by Daniel Whitmore
Millionaire Insiders