Sector ranking
Healthcare costs $1.33x the global average.
Sector cost differences are not noise: they reflect data sensitivity, regulatory regime, and the speed at which an incident becomes a regulator's problem. IBM's 2026 figures, ranked by total average cost, with the 2025 figure alongside each.
Direct answer / IBM 2026 average breach cost by industry
The IBM Cost of a Data Breach Report 2026 puts the global average breach at a record $4.99M. By industry, healthcare is the most expensive for the 13th consecutive year at $6.64M, followed by financial services $6.29M, then industrial and technology tied at $5.5M, energy $5.24M, and pharmaceuticals $5.25M. Retail sits well below average at $3.8M, education at $4.15M, and the public sector lowest at $3.5M, though it still climbed 22% year over year. Only healthcare fell in 2026; every other sector rose.
Source: IBM Cost of a Data Breach Report 2026 (Figure 3, all 17 sectors below). Last verified August 2026.
Section 03.1 / Sector ranking
Average breach cost by industry, IBM 2026
Primary source:IBM Cost of a Data Breach Report 2026 (Figure 3). Each bar shows the 2026 average with its year-over-year change vs 2025.
Section 03.2 / Sector deep-dive
Why each sector pays what it does
Rank #01
Healthcare
2025: $7.42M / Regulation: HIPAA / YoY: -11%
$6.64M
avg total cost
A full medical record sells for hundreds of dollars on the dark market versus $5 for a credit card. HIPAA mandates extensive notification and remediation, and patient-care disruption creates massive operational liability. Healthcare has been #1 for 13 consecutive years.
Key regulations
Notable breaches
- Change Healthcare (UnitedHealth) / 2024 / $2.45B
Primary source: UnitedHealth Group 10-Q filings, 2024-2025 - Anthem / 2015 / $260M
Primary source: OCR settlement, multistate AG settlement, SEC 10-K filings - Premera Blue Cross / 2014 / $74M
Primary source: OCR settlement, public regulator filing
Rank #02
Financial Services
2025: $5.56M / Regulation: PCI DSS / GLBA / YoY: +13%
$6.29M
avg total cost
Financial data triggers immediate fraud risk and rapid regulatory response. PCI DSS compliance failures trigger steep fines. Customer churn is severe (account closures), and card reissuance costs banks $5-$15 per card. Regulators pursue penalties more aggressively than in most sectors.
Key regulations
Notable breaches
- Equifax / 2017 / $1.4B+
Primary source: FTC settlement order, 2019; SEC 10-K filings - Capital One / 2019 / $300M+
Primary source: OCC consent order; SEC 10-K filings - JPMorgan Chase / 2014 / $1B+ (program)
Primary source: DOJ securities fraud indictment
Rank #03
Industrial
2025: $5M / Regulation: NIST / ICS / YoY: +10%
$5.5M
avg total cost
Manufacturing breaches increasingly target OT/ICS systems. IP theft of product designs, processes, and formulas is the primary risk. Supply-chain disruption costs multiply quickly. Ransomware impact on production lines can cost millions per day.
Key regulations
Notable breaches
- Honda (EKANS ransomware) / 2020 / Undisclosed
Primary source: Honda official disclosure to media
Rank #04
Technology
2025: $4.79M / Regulation: SOX / GDPR / YoY: +15%
$5.5M
avg total cost
Tech firms hold massive volumes of third-party customer data, creating supply-chain liability. High-value IP (source code, AI model weights) amplifies damage beyond PII. Sophisticated attackers target tech firms as stepping stones to their customers.
Key regulations
Notable breaches
- SolarWinds / 2020 / $100M+
Primary source: SEC enforcement action; SolarWinds 10-K - Yahoo / 2013 / $470M+
Primary source: Verizon acquisition price reduction; SEC filings - Facebook / Meta / 2019 / $5B FTC fine
Primary source: FTC consent order, 2019
Rank #05
Entertainment
2025: $4.43M / Regulation: Varies / YoY: +21%
$5.38M
avg total cost
Rank #06
Pharmaceuticals
2025: $4.61M / Regulation: FDA / GxP / YoY: +14%
$5.25M
avg total cost
Pharma breaches often involve proprietary drug formulas and clinical-trial data. IP loss adds value far beyond PII. Regulatory scrutiny is high, and patient-safety implications elevate severity.
Key regulations
Notable breaches
- Merck (NotPetya) / 2017 / $1.35B
Primary source: Merck SEC 10-K, 2017-2019 - Pfizer employee data leak / 2020 / Undisclosed
Primary source: California AG complaint
Rank #07
Energy
2025: $4.83M / Regulation: NERC CIP / YoY: +8%
$5.24M
avg total cost
Critical-infrastructure status means breaches can trigger national-security responses. Operational technology (OT/SCADA) intertwines with IT, extending blast radius. Physical-safety implications raise regulatory scrutiny dramatically.
Key regulations
Notable breaches
- Colonial Pipeline / 2021 / $15M+
Primary source: DOJ FBI press release; Colonial board statements - Norsk Hydro / 2019 / $71M
Primary source: Norsk Hydro Q1 2019 earnings disclosure
Rank #08
Services
2025: $4.56M / Regulation: Varies / YoY: +11%
$5.08M
avg total cost
Professional and managed-service firms hold client data subject to that client's regulations. Contract penalty clauses and the loss of enterprise relationships drive cost. Reputation damage compounds because trust is the product.
Key regulations
Notable breaches
- Accenture / 2021 / Undisclosed
Primary source: LockBit ransomware leak site, public confirmation
Rank #09
Communications
2025: $3.75M / Regulation: FCC / GDPR / YoY: +26%
$4.71M
avg total cost
Rank #10
Transportation
2025: $3.98M / Regulation: TSA / CISA / YoY: +13%
$4.5M
avg total cost
Rank #11
Media
2025: $4.22M / Regulation: Varies / YoY: +6%
$4.49M
avg total cost
Rank #12
Hospitality
2025: $4.03M / Regulation: PCI DSS / YoY: +7%
$4.33M
avg total cost
Rank #13
Consumer
2025: $3.72M / Regulation: CCPA / GDPR / YoY: +16%
$4.31M
avg total cost
Rank #14
Education
2025: $3.8M / Regulation: FERPA / YoY: +9%
$4.15M
avg total cost
Education records contain long-lived sensitive data, SSNs, financial aid, mental health records, that persists for decades. Under-resourced IT departments create vulnerability. FERPA compliance adds notification requirements.
Key regulations
Notable breaches
- Los Angeles Unified School District / 2022 / Undisclosed
Primary source: Public LAUSD board statements - Lincoln College (forced closure) / 2022 / Closure
Primary source: Lincoln College official closure announcement
Rank #15
Research
2025: $3.79M / Regulation: Varies / YoY: +5%
$3.99M
avg total cost
Rank #16
Retail
2025: $3.54M / Regulation: PCI DSS / YoY: +7%
$3.8M
avg total cost
Retail typically holds payment card data with lower per-record value than healthcare. High volume partially offsets lower per-record cost. PCI DSS provides a clear compliance framework. Customer churn is moderate as loyalty is often price-driven.
Key regulations
Notable breaches
- Target / 2013 / $292M
Primary source: Target SEC 10-K filings 2013-2017 - Home Depot / 2014 / $198M
Primary source: Home Depot SEC 10-K 2014; AG settlements - TJX / 2007 / $256M
Primary source: TJX SEC filings; FTC settlement
Rank #17
Public Sector
2025: $2.86M / Regulation: FISMA / FedRAMP / YoY: +22%
$3.5M
avg total cost
Lower per-record cost but enormous volumes and political consequences. Government breaches can compromise national security. Remediation is slow due to procurement processes.
Key regulations
Notable breaches
- OPM / 2015 / $133M+
Primary source: OPM IG report; House Oversight hearings - SolarWinds (federal agencies) / 2020 / Undisclosed
Primary source: CISA Emergency Directive 21-01
Primary source:IBM Cost of a Data Breach Report 2026 (Figure 3), with each sector's 2025 figure shown for comparison. Notable breach cost figures sourced from public SEC filings, regulator orders, AG settlements, and OCR enforcement actions. Last verified August 2026.
Index / Companion schedules
01 Calculator
→Estimate a specific industry & size combination.
02 Statistics
→Global averages and methodology context.
04 Biggest breaches
→Verified cost figures for 17 mega-breaches.
09 Notification laws
→Regulation-specific reporting timelines.
10 Cost breakdown
→The IBM four-category framework.
08 By country
→Same industry can cost very differently across regions.
Mean time to identify + contain
247 days
IBM 2026, up 2.5%, reversing a five-year decline
Schedule F / Reference Q&A