IBM says one in four malicious breaches is now AI-enabled. The IDB and the OAS, assessing thirty countries, name critical infrastructure protection as one of the region's weakest areas. In the Dutch Caribbean, tax and government services have already gone down.
BY LCN NEWSROOM
Quick summary: IBM's 2026 breach report finds one in four malicious breaches are now AI-enabled, up 56 per cent in a year and costing about $6 million each. A separate IDB and OAS assessment of thirty Latin American and Caribbean countries names critical infrastructure protection as a persistent low-maturity area across the region.
What IBM actually found
The attacker's tooling changed faster than the defender's budget.
IBM reported on 29 July that one in four malicious breaches were AI-enabled, a 56 per cent increase over the previous year, and that those breaches cost an average of $6 million, which IBM puts at roughly a million dollars above what other breaches cost. More than 20 per cent of organisations reported a breach targeting AI models or applications directly. The global average cost of a breach rose 12 per cent to a record, driven by detection, escalation and lost business.
The mechanism matters more than the total. IBM attributes the growth to AI deepfake impersonation and AI-enabled malware, which are not new categories of attack so much as old ones made cheap. Impersonating a finance director convincingly used to require skill and time. It now requires a model and a voice sample.
Regional press carrying the study's Latin American cut, including Gestión in Peru and Fast Company México, put the regional figures lower than the global ones: close to 19 per cent of malicious attacks AI-generated, and an average breach cost of about $4.65 million with roughly 40,300 records exposed per incident. Those reports also record a wide gap by defensive posture, with organisations using AI and automation in security operations averaging $4.04 million against $5.64 million for those without.
A lower regional cost is not good news. It substantially reflects smaller organisations holding less data, not stronger defences.
The region is not incapable of moving first on this class of problem. When generative AI began flooding courts with fabricated filings, Chile's system buckled under 38,477 of them while Caribbean jurisdictions already had a practice direction in place. Anticipation is possible here. It is simply not the default.
Why the enterprise number is the wrong one to watch
Because in the Caribbean the exposed asset is the state.
Breach-cost studies measure companies. They price stolen records, downtime and remediation for firms that carry cyber insurance and legal counsel. That framing travels badly to small island states, where the consequential systems are not corporate customer databases but tax collection, customs, ports, utilities, health records and civil registries, run by ministries with thin budgets and thinner specialist staffing.
When those fail, the loss is not measured in average cost per record. It is measured in a country that cannot collect revenue or clear a container.
The consumer end of the same shift is already visible locally, in contactless card fraud reaching Guyana's digital payments. What changes with AI-enabled attacks is not the existence of the threat but the cost of running it at scale.
It has already happened here
In the Dutch Caribbean, and it took services down.
In July 2025 the Curaçao Tax Office was hit by ransomware. Its Finance Ministry said the incident affected the Dutch Tax and Customs Administration from 24 July and predicted days of service outages, and The Record reported that the disruption extended across Aruba and Curaçao, affecting crucial government services in islands with close to half a million residents between them. NL Times reported that the attacks crippled government institutions across the islands.
That is the scenario a regional plan exists to prevent, executed against Caribbean territories with closer administrative ties to a European state than most CARICOM members enjoy. It is a reasonable proxy for what an attack on a small Caribbean revenue authority looks like.
What the region's own assessment says
Progress overall. Infrastructure is where it stops.
The Inter-American Development Bank and the Organization of American States published the 2025 Cybersecurity Report: Vulnerability and Maturity Challenges to Bridging the Gaps in Latin America and the Caribbean, the third edition of a joint assessment developed with the Global Cyber Security Capacity Centre at the University of Oxford. It benchmarks thirty countries against the Cybersecurity Capacity Maturity Model for Nations, allowing comparison over time and between states from 2020 to 2025.
The headline is genuine improvement. Maturity rose across all five dimensions of the model, and the gap between the region's strongest and weakest countries narrowed.
The exceptions are the point. The Capacity Centre's own summary of the findings records that critical infrastructure protection, software quality and cybersecurity market development remain at lower maturity levels, that investment in research and innovation is still limited, and that adoption of cyber insurance remains low. It also notes that rapid AI adoption is reshaping the threat landscape, amplifying existing risks and creating new ones.
Read against IBM, those two findings meet badly. The threat side is being automated and cheapened. The defensive side has its weakest scores exactly where a state's essential services sit.
What CARICOM is doing about it
There is a plan, and it is recent.
CARICOM launched an updated Cyber Security and Cybercrime Action Plan on 31 October 2025 in Port of Spain. It was led by the CARICOM Implementation Agency for Crime and Security, working with the European Union and Latin America and Caribbean Digital Alliance policy dialogue on cybersecurity, implemented by Expertise France, and EL PAcCTO 2.0, implemented by the Fundación para la Internacionalización de las Administraciones Públicas.
IMPACS describes the update as a shift from traditional cyber security measures toward cyber resilience, and positions the plan as the roadmap for member states to build national and regional frameworks, harmonise cybercrime legislation and protect vital infrastructure.
The framing from the launch was notably unromantic about technology. Natasha George, Deputy Commissioner of Police for Intelligence and Investigation in the Trinidad and Tobago Police Service, told the room that cybercrime "is often portrayed as a technological battle, firewalls versus malware," but that "at its core, cybercrime is profoundly human."
That is the right instinct in a region where the binding constraint is people rather than licences. A resilience plan needs analysts, incident responders and procurement officers who understand what they are buying.
Where the training actually happens
Through a forum most of the region has never heard of.
The Caribbean Telecommunications Union has run the Caribbean Internet Governance Forum for two decades, reaching its twenty-first edition in August 2025 alongside the fourth Caribbean Youth Internet Governance Forum. Recent editions have opened with a dedicated capacity-building day, and the twentieth forum's programme put an introduction to internet governance and its national, regional and global contexts at the front of the agenda.
A youth track running four editions deep is the part worth noticing. The workforce gap the IDB and OAS identify is not closed by procurement. It is closed by people who entered the field a decade earlier, which is what a youth forum is for.
The question that is not answered
Whether the plan is matched by capability, state by state.
A regional action plan, a maturity assessment and a governance forum are three real instruments. None of them establishes what any individual CARICOM government can do at two o'clock in the morning when a revenue system stops responding. That depends on national incident response capacity, on whether critical infrastructure operators are regulated and audited, and on whether anyone has rehearsed.
La Caribeña News was not able to establish the current operational status of national incident response arrangements across CARICOM member states from published sources, and does not assert a finding here. That is the reporting this story needs next, and it is a question member governments can answer directly.
The region has already seen the alternative. It happened in Curaçao, it took the tax office offline, and the report card published by its own development bank says infrastructure protection is where the region scores worst.
Frequently Asked Questions
What did the IBM 2026 report find?
That one in four malicious breaches are AI-enabled, a 56 per cent increase over the previous year, costing an average of $6 million each. More than 20 per cent of organisations reported a breach targeting AI models or applications, and the global average breach cost rose 12 per cent to a record.
What are the Latin American figures?
Regional press carrying the study's regional cut report close to 19 per cent of malicious attacks as AI-generated and an average breach cost of about $4.65 million, with roughly 40,300 records exposed per incident.
What did the IDB and OAS assessment cover?
Thirty countries in Latin America and the Caribbean, benchmarked against the Cybersecurity Capacity Maturity Model for Nations, comparing 2020 with 2025. It was produced with the Global Cyber Security Capacity Centre at the University of Oxford.
What are the region's weakest areas?
Critical infrastructure protection, software quality and cybersecurity market development remain at lower maturity, with limited research and innovation investment and low adoption of cyber insurance.
Has a Caribbean government actually been attacked?
Yes. In July 2025 ransomware hit the Curaçao Tax Office, and reporting described disruption to government services across Aruba and Curaçao.
What is CARICOM's response?
An updated Cyber Security and Cybercrime Action Plan launched on 31 October 2025 in Port of Spain, led by CARICOM IMPACS with European partners, shifting emphasis from cyber security to cyber resilience and aiming to harmonise cybercrime legislation across member states.
Where can Caribbean professionals get involved?
The Caribbean Telecommunications Union runs the Caribbean Internet Governance Forum, which reached its twenty-first edition in August 2025 alongside the fourth Caribbean Youth Internet Governance Forum, with capacity-building sessions built into the programme.