Form: Cost-of-Breach DisclosureSource: IBM Cost of a Data BreachFiled: 28 Apr 2026
DataBreachCost.comOpen calc
Independent breach-cost research, read by security and risk leaders.Sponsor this site →
Schedule 03 / By IndustryIBM 2026, 17 sectors classified

Sector ranking

Healthcare costs $1.33x the global average.

Sector cost differences are not noise: they reflect data sensitivity, regulatory regime, and the speed at which an incident becomes a regulator's problem. IBM's 2026 figures, ranked by total average cost, with the 2025 figure alongside each.

Direct answer / IBM 2026 average breach cost by industry

The IBM Cost of a Data Breach Report 2026 puts the global average breach at a record $4.99M. By industry, healthcare is the most expensive for the 13th consecutive year at $6.64M, followed by financial services $6.29M, then industrial and technology tied at $5.5M, energy $5.24M, and pharmaceuticals $5.25M. Retail sits well below average at $3.8M, education at $4.15M, and the public sector lowest at $3.5M, though it still climbed 22% year over year. Only healthcare fell in 2026; every other sector rose.

Healthcare$6.64M
Financial Services$6.29M
Technology$5.5M
Retail$3.8M
Education$4.15M
Public Sector$3.5M

Source: IBM Cost of a Data Breach Report 2026 (Figure 3, all 17 sectors below). Last verified August 2026.

Section 03.1 / Sector ranking

Average breach cost by industry, IBM 2026

Healthcare / HIPAA$6.64M (-11%)
Financial Services / PCI DSS / GLBA$6.29M (+13%)
Industrial / NIST / ICS$5.5M (+10%)
Technology / SOX / GDPR$5.5M (+15%)
Entertainment / Varies$5.38M (+21%)
Pharmaceuticals / FDA / GxP$5.25M (+14%)
Energy / NERC CIP$5.24M (+8%)
Services / Varies$5.08M (+11%)
Communications / FCC / GDPR$4.71M (+26%)
Transportation / TSA / CISA$4.5M (+13%)
Media / Varies$4.49M (+6%)
Hospitality / PCI DSS$4.33M (+7%)
Consumer / CCPA / GDPR$4.31M (+16%)
Education / FERPA$4.15M (+9%)
Research / Varies$3.99M (+5%)
Retail / PCI DSS$3.8M (+7%)
Public Sector / FISMA / FedRAMP$3.5M (+22%)

Primary source:IBM Cost of a Data Breach Report 2026 (Figure 3). Each bar shows the 2026 average with its year-over-year change vs 2025.

Section 03.2 / Sector deep-dive

Why each sector pays what it does

Rank #01

Healthcare

2025: $7.42M / Regulation: HIPAA / YoY: -11%

$6.64M

avg total cost

A full medical record sells for hundreds of dollars on the dark market versus $5 for a credit card. HIPAA mandates extensive notification and remediation, and patient-care disruption creates massive operational liability. Healthcare has been #1 for 13 consecutive years.

Key regulations

HIPAAHITECH ActState breach notification laws

Notable breaches

  • Change Healthcare (UnitedHealth) / 2024 / $2.45B
    Primary source: UnitedHealth Group 10-Q filings, 2024-2025
  • Anthem / 2015 / $260M
    Primary source: OCR settlement, multistate AG settlement, SEC 10-K filings
  • Premera Blue Cross / 2014 / $74M
    Primary source: OCR settlement, public regulator filing

Rank #02

Financial Services

2025: $5.56M / Regulation: PCI DSS / GLBA / YoY: +13%

$6.29M

avg total cost

Financial data triggers immediate fraud risk and rapid regulatory response. PCI DSS compliance failures trigger steep fines. Customer churn is severe (account closures), and card reissuance costs banks $5-$15 per card. Regulators pursue penalties more aggressively than in most sectors.

Key regulations

PCI DSSGramm-Leach-BlileySOXGDPR / state laws

Notable breaches

  • Equifax / 2017 / $1.4B+
    Primary source: FTC settlement order, 2019; SEC 10-K filings
  • Capital One / 2019 / $300M+
    Primary source: OCC consent order; SEC 10-K filings
  • JPMorgan Chase / 2014 / $1B+ (program)
    Primary source: DOJ securities fraud indictment

Rank #03

Industrial

2025: $5M / Regulation: NIST / ICS / YoY: +10%

$5.5M

avg total cost

Manufacturing breaches increasingly target OT/ICS systems. IP theft of product designs, processes, and formulas is the primary risk. Supply-chain disruption costs multiply quickly. Ransomware impact on production lines can cost millions per day.

Key regulations

NIST CSFIEC 62443GDPR / CCPA

Notable breaches

  • Honda (EKANS ransomware) / 2020 / Undisclosed
    Primary source: Honda official disclosure to media

Rank #04

Technology

2025: $4.79M / Regulation: SOX / GDPR / YoY: +15%

$5.5M

avg total cost

Tech firms hold massive volumes of third-party customer data, creating supply-chain liability. High-value IP (source code, AI model weights) amplifies damage beyond PII. Sophisticated attackers target tech firms as stepping stones to their customers.

Key regulations

GDPRCCPASOX (public companies)

Notable breaches

  • SolarWinds / 2020 / $100M+
    Primary source: SEC enforcement action; SolarWinds 10-K
  • Yahoo / 2013 / $470M+
    Primary source: Verizon acquisition price reduction; SEC filings
  • Facebook / Meta / 2019 / $5B FTC fine
    Primary source: FTC consent order, 2019

Rank #05

Entertainment

2025: $4.43M / Regulation: Varies / YoY: +21%

$5.38M

avg total cost

Rank #06

Pharmaceuticals

2025: $4.61M / Regulation: FDA / GxP / YoY: +14%

$5.25M

avg total cost

Pharma breaches often involve proprietary drug formulas and clinical-trial data. IP loss adds value far beyond PII. Regulatory scrutiny is high, and patient-safety implications elevate severity.

Key regulations

FDA 21 CFR Part 11GxPGDPRHIPAA (clinical)

Notable breaches

  • Merck (NotPetya) / 2017 / $1.35B
    Primary source: Merck SEC 10-K, 2017-2019
  • Pfizer employee data leak / 2020 / Undisclosed
    Primary source: California AG complaint

Rank #07

Energy

2025: $4.83M / Regulation: NERC CIP / YoY: +8%

$5.24M

avg total cost

Critical-infrastructure status means breaches can trigger national-security responses. Operational technology (OT/SCADA) intertwines with IT, extending blast radius. Physical-safety implications raise regulatory scrutiny dramatically.

Key regulations

NERC CIPTSA Pipeline directivesGDPR

Notable breaches

  • Colonial Pipeline / 2021 / $15M+
    Primary source: DOJ FBI press release; Colonial board statements
  • Norsk Hydro / 2019 / $71M
    Primary source: Norsk Hydro Q1 2019 earnings disclosure

Rank #08

Services

2025: $4.56M / Regulation: Varies / YoY: +11%

$5.08M

avg total cost

Professional and managed-service firms hold client data subject to that client's regulations. Contract penalty clauses and the loss of enterprise relationships drive cost. Reputation damage compounds because trust is the product.

Key regulations

Varies by client industryGDPRCCPA

Notable breaches

  • Accenture / 2021 / Undisclosed
    Primary source: LockBit ransomware leak site, public confirmation

Rank #09

Communications

2025: $3.75M / Regulation: FCC / GDPR / YoY: +26%

$4.71M

avg total cost

Rank #10

Transportation

2025: $3.98M / Regulation: TSA / CISA / YoY: +13%

$4.5M

avg total cost

Rank #11

Media

2025: $4.22M / Regulation: Varies / YoY: +6%

$4.49M

avg total cost

Rank #12

Hospitality

2025: $4.03M / Regulation: PCI DSS / YoY: +7%

$4.33M

avg total cost

Rank #13

Consumer

2025: $3.72M / Regulation: CCPA / GDPR / YoY: +16%

$4.31M

avg total cost

Rank #14

Education

2025: $3.8M / Regulation: FERPA / YoY: +9%

$4.15M

avg total cost

Education records contain long-lived sensitive data, SSNs, financial aid, mental health records, that persists for decades. Under-resourced IT departments create vulnerability. FERPA compliance adds notification requirements.

Key regulations

FERPACOPPAHIPAA (campus health)State laws

Notable breaches

  • Los Angeles Unified School District / 2022 / Undisclosed
    Primary source: Public LAUSD board statements
  • Lincoln College (forced closure) / 2022 / Closure
    Primary source: Lincoln College official closure announcement

Rank #15

Research

2025: $3.79M / Regulation: Varies / YoY: +5%

$3.99M

avg total cost

Rank #16

Retail

2025: $3.54M / Regulation: PCI DSS / YoY: +7%

$3.8M

avg total cost

Retail typically holds payment card data with lower per-record value than healthcare. High volume partially offsets lower per-record cost. PCI DSS provides a clear compliance framework. Customer churn is moderate as loyalty is often price-driven.

Key regulations

PCI DSSGDPR / CCPAState breach laws

Notable breaches

  • Target / 2013 / $292M
    Primary source: Target SEC 10-K filings 2013-2017
  • Home Depot / 2014 / $198M
    Primary source: Home Depot SEC 10-K 2014; AG settlements
  • TJX / 2007 / $256M
    Primary source: TJX SEC filings; FTC settlement

Rank #17

Public Sector

2025: $2.86M / Regulation: FISMA / FedRAMP / YoY: +22%

$3.5M

avg total cost

Lower per-record cost but enormous volumes and political consequences. Government breaches can compromise national security. Remediation is slow due to procurement processes.

Key regulations

FISMAFedRAMPOMB guidance

Notable breaches

  • OPM / 2015 / $133M+
    Primary source: OPM IG report; House Oversight hearings
  • SolarWinds (federal agencies) / 2020 / Undisclosed
    Primary source: CISA Emergency Directive 21-01

Primary source:IBM Cost of a Data Breach Report 2026 (Figure 3), with each sector's 2025 figure shown for comparison. Notable breach cost figures sourced from public SEC filings, regulator orders, AG settlements, and OCR enforcement actions. Last verified August 2026.

Index / Companion schedules

Mean time to identify + contain

247 days

IBM 2026, up 2.5%, reversing a five-year decline

Schedule F / Reference Q&A

Frequently Asked Questions