Cybersecurity statistics for 2026: data breaches, cyber attack counts and costs

Prefer this source on Google

The numbers US and global cybersecurity, checked 1 October 2026

$20.877BCybercrime losses reported to the FBI in 2025, across 1,008,597 complaintsFBI IC3, 2025 Internet Crime Report
$4.99MAverage cost of data breaches worldwide, up 12% on 2025IBM and Ponemon Institute, July 2026
48%Share of confirmed breaches involving ransomware, up from 44%Verizon 2026 DBIR
3,322US data compromises in 2025, a new recordIdentity Theft Resource Center, January 2026
48,244CVE vulnerability records published in 2025CVE Program metrics
29 minAverage eCrime breakout time, with the fastest at 27 secondsCrowdStrike 2026 Global Threat Report
$240BWorldwide end-user spending on information security forecast for 2026Gartner, July 2025

Reported cybercrime losses grew 26% while complaints grew 17%, so the average complaint now carries a $20,699 loss.

Vulnerability exploitation is the way in for 31% of breaches in the 2026 DBIR, against 20% a year earlier.

Ransomware attacks targeted more organizations and collected less: Chainalysis traced $820 million in 2025 payments, down 8%, while claimed victims rose 50%.

Americans filed 1,008,597 cybercrime complaints with the Federal Bureau of Investigation in 2025 and reported $20.877 billion in losses, up 26% on 2024, according to the FBI Internet Crime Complaint Center's 2025 Internet Crime Report. The same year, the cost of data breaches rose 12% to a record $4.99 million on average in IBM's Cost of a Data Breach Report 2026.

This report gathers the cybersecurity statistics published between October 2025 and September 2026: how many cyberattacks occur, data breaches and their cost, ransomware attacks, vulnerabilities, AI-assisted cyber threats, security spending and the workforce.

It's written for cybersecurity leaders building a budget to protect their organizations from cyber threats & for analysts who need a number they can cite.

How many cyberattacks occur each year: 1,008,597 FBI complaints in 2025

The IC3 crossed one million complaints for the first time in 2025, up from 859,532 in 2024. That's almost 3,000 complaints about attacks and scams a day, and the Federal Bureau of Investigation's center has logged over 10 million since it opened in May 2000. The Federal Bureau of Investigation's 2024 release put the previous year's losses at over $16 billion.

The count covers victims who found the Federal Bureau of Investigation's IC3 form, so under-the-radar cyberattacks and cybercrime sit outside every FBI figure on this page.

Cybercrime complaints and reported losses by crime type

Phishing/spoofing leads the 2025 complaint count at 191,561 and investment fraud leads reported losses at $8.65 billion. In a nutshell, the gap between the two columns below is US cybercrime in one table.

IC3 category, 2025ComplaintsReported losses
Phishing/spoofing191,561$215.8M
Extortion89,129$122.5M
Investment fraud72,984$8.65B
Personal data breach67,456$1.31B
Tech/customer support47,794$2.13B
Business email compromise24,768$3.05B
Data breach3,963$435M

Investment fraud took the lion's share: $8.65 billion, 41% of everything reported. Across all categories, complaints involving cryptocurrency carried $11.366 billion in losses, up 21%, relevant to crypto market intelligence buyers.

Personal data breaches drew 67,456 complaints. Cybercriminals reuse the sensitive information from one breach to make the next scam targeted and believable, which is why phishing emails quote real account details.

Bar chart of 2025 losses reported to the FBI IC3 by crime type: investment fraud $8.65 billion, business email compromise $3.05 billion, tech and customer support scams $2.13 billion, breaches of personal data $1.31 billion and data breach $435 million, out of $20.877 billion across 1,008,597 complaints.
Investment fraud alone accounts for 41% of the $20.877 billion reported to the FBI in 2025.

DDoS attacks flood a network with junk traffic until normal operations stop. Cloudflare's 2025 DDoS threat report counted 47.1 million such attacks in 2025, up 121% on 2024, or 5,376 every hour. The largest hit 31.4 Tbps.

The Aisuru-Kimwolf botnet behind it runs on an estimated 1 to 4 million malware-infected hosts, primarily Android TVs, the kind of IoT devices that ship with malware-friendly defaults. Telecoms and information technology services were the most targeted.

Small businesses in the UK: 43% identified a breach

The UK's Cyber Security Breaches Survey 2025/2026 found 43% of businesses, an estimated 612,000, identified cyberattacks or breaches in the past year, unchanged on the previous year. Large firms reported 69%, medium firms 65%, small businesses 46% and micro businesses 42%.

Phishing attacks hit 38% of all businesses, by far the most common of the cyber threats in the cyber security survey, and among breached firms 51% saw phishing and no other attack, up from 45%. 19% of businesses (267,000) fell to a cyber crime. Under half of UK businesses protect accounts against these threats with multi-factor authentication: 47% use it.

Data breaches: 3,322 data compromises in 2025 set a new record

The Identity Theft Resource Center logged 3,322 US data compromises in 2025, beating the 3,202 record from 2023 and up 79% over five years. Data breach notices sent to individuals fell to 278,827,933. Financial companies topped the list with 739 compromises, ahead of 534 healthcare data breaches and 478 in professional services.

70% of 2025 notifications (2,324) gave no detail on how the attackers got in, up from 65% in 2024. Cybersecurity teams tracking state breach-notification rules use regulatory intelligence software to keep an eye on these filings.

Most data breaches start with a vulnerability or a person

Verizon's 2026 Data Breach Investigations Report analyzed more than 31,000 security incidents, over 22,000 of them confirmed data breaches in 145 countries. Exploitation of vulnerabilities was the initial access route in 31% of data breaches, up from 20%. The human element (errors, misuse by insiders and social engineering) appeared in 62% of data breaches, against 60% the year before.

The 2025 DBIR had credential abuse as the leading route at 22%. Initial access brokers sell stolen logins and network footholds on dark web forums; Chainalysis estimates they took $14 million in 2025. Insider threats need no exploit at all, and zero trust designs protect against both cybersecurity risks by checking identity on every request.

Third-party threats and supply chain attacks

Third-party involvement reached 48% of data breaches in the 2026 DBIR, a 60% rise on the previous dataset's 30%. Supply chain attacks reach a target through its vendors, so attacks on one software supplier expose the sensitive data of hundreds of customers. Buyers vetting vendors protect against third-party threats with third-party risk management tools, and physical suppliers sit in supply chain risk management software.

Cost of a data breach: $4.99 million on IBM's global average

IBM's 2026 edition, run by the Ponemon Institute across 602 data breaches from March 2025 to February 2026, puts the global average at $4.99 million, a 12% increase and a record high. Energy averaged $5.2 million, a cost that falls on the energy sector and its critical infrastructure.

Bar chart of IBM's average cost of a data breach worldwide: $4.45 million in 2023, $4.88 million in 2024, $4.44 million in 2025 and $4.99 million in 2026, with the breach lifecycle falling from 277 days to 258 days to 241 days.
The 2025 dip to $4.44 million lasted one edition; 2026 set a new high.

2023's report had $4.45 million, 2024's $4.88 million, and 2025's $4.44 million, the first decline in five years. The average lifecycle to identify and contain a breach fell from 277 days to 258 and then 241.

IBM's average bundles four cost centers: detection and escalation, notification, post-breach response such as legal costs, and lost business. Data breaches at US organizations cost far more: $10.22 million in the 2025 edition.

Healthcare industry and financial services industry costs

The healthcare industry had the costliest data breaches of any sector in IBM's 2024 edition at $9.77 million, down from nearly $11 million in 2023. The 2025 average fell to $7.42 million, and healthcare breaches still took 279 days to identify and contain. The healthcare market intelligence page covers the buyers who must protect those patient records.

The financial services industry averaged $6.3 million per breach in the 2026 study, a benchmark for banks and insurers across the finance industry. Teams in the financial sector that follow these numbers alongside markets can start at financial market intelligence.

AI-assisted attacks changed the bill too. One in four malicious breaches in the 2026 study was AI-enabled, a 56% increase led by deepfake impersonations and AI-enabled malware, and those cost about $6 million on average. Organizations using AI and automation extensively in security operations saved $1.93 million per breach, and more than 20% reported a breach targeted at AI models or applications.

Ransomware attacks: present in 48% of breaches while payments fall

Ransomware attacks sat in 48% of data breaches in the 2026 DBIR, up from 44%. More than two thirds of targets (69%) refused to pay, and the median payment fell to $139,875 from $150,000. Small businesses carry the heaviest share: ransomware appeared in 88% of breaches at small and midsize businesses in the 2025 DBIR.

Chainalysis traced $820 million in on-chain ransom payments in 2025, down 8% from $892 million, while claimed ransomware victims rose 50% to an all-time high. About 28% paid. When it rains it pours for defenders, though: more attacks at lower prices means more incidents to clean up.

Ransomware chart: median ransom paid was $139,875 in Verizon's 2026 DBIR and $59,556 in Chainalysis 2025 data; 31% of Verizon's victims and about 28% in Chainalysis data paid; total on-chain payments fell from $892 million in 2024 to $820 million in 2025 while claimed victims rose 50%.
Fewer than a third of targets pay on either count, and total payments fell 8% in 2025.

Encryption, recovery and critical infrastructure organizations

Sophos's State of Ransomware 2026, a survey of 2,158 IT and security leaders in 17 countries, found attackers encrypted data in 56% of attacks and the average recovery cost reached $1.7 million.

The IC3 received 3,611 complaints about ransomware attacks in 2025, up from 3,156, with losses above $32 million. Its top 10 variants, led by Akira and Qilin, hit critical manufacturing, healthcare and government facilities hardest. Those are critical infrastructure organizations, and cyberattacks that knock a hospital offline are a public sector problem as much as a private one.

Vulnerabilities: 48,244 CVE records in 2025, a new record

The CVE Program published 48,244 vulnerability records in 2025, up from 40,077 in 2024 and 2.4 times the 20,161 of 2021. The first half of 2026 added 35,872 more (15,163 in Q1 and 20,709 in Q2), already above the full-year 2023 count of 28,961.

Bar chart of published CVE records per year: 20,161 in 2021, 25,059 in 2022, 28,961 in 2023, 40,077 in 2024, 48,244 in 2025 and 35,872 in the first half of 2026.
Published CVE records more than doubled between 2021 and 2025.

Patching lags behind the threats, a race against time. Only 26% of the critical vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated in the DBIR dataset, down from 38%, and the median time to patch rose to 43 days from 32. Products past end-of-life support never receive the fix, so the only way to protect them is to replace them.

Mandiant's M-Trends 2026 puts exploits as the top initial infection vector for the sixth year running, at 32% of the attacks it investigated. Its mean time to exploit is minus seven days, so cybercriminals use the flaw before the patch exists. CrowdStrike found 40% of the vulnerabilities China-nexus adversaries exploited in their cyberattacks targeted edge devices such as VPN gateways that carry remote work traffic.

Cyber threats in 2026: AI, identity and speed

Cyberattacks move faster each year. CrowdStrike measured an average eCrime breakout time of 29 minutes, 65% faster than a year earlier, with the fastest at 27 seconds. Mandiant timed the hand-off from an initial access broker to a second group at 22 seconds in 2025, down from over 8 hours in 2022. Those numbers set how long defenders have to protect a network once cyberattacks begin.

AI-enabled cyberattacks rose 89%

CrowdStrike recorded an 89% increase in cyberattacks by AI-enabled adversaries. Malware attacks install malicious code to steal sensitive data; 82% of CrowdStrike's 2025 detections were malware-free, because the intruder logged in with valid credentials.

The 2026 DBIR found generative AI assisting 15 techniques used in attacks. ENISA reported that AI-supported phishing made up more than 80% of observed social engineering attacks by early 2025, and our AI statistics report tracks how fast the same tools spread among legitimate users.

The World Economic Forum's Global Cybersecurity Outlook 2026 found 87% of respondents named AI-related vulnerabilities as the fastest-growing cybersecurity threat of 2025, and 94% expect AI to drive the most change in the cybersecurity landscape in 2026.

Security assessments of AI tools rose from 37% of organizations to 64%, and 73% of respondents said they or someone in their network was hit by cyber-enabled fraud in the past year. CEOs rank that fraud as their top concern among threats, while CISOs focus on ransomware and supply chain resilience.

Identity, cloud and national security threats

State-nexus malicious actors ran 266% more cloud-conscious cyberattacks, per CrowdStrike. Mandiant's median dwell time, how long cyberattacks went unnoticed, rose to 14 days from 11; voice phishing became the second most common initial vector at 11%, and defenders found 52% of incidents themselves, up from 43%.

High tech was the most targeted industry in Mandiant's cases at 17%, ahead of financial services at 14.6%. Analysts who track each cybersecurity threat actor with open source intelligence tools stay a step ahead by watching the same login patterns.

64% of organizations in the WEF survey now factor geopolitically motivated cyberattacks into risk planning. Nation-state cyber threats against critical infrastructure are a national security matter: the Federal Bureau of Investigation attributed the theft of about $1.5 billion in virtual assets from the Bybit exchange in February 2025 to North Korea's TraderTraitor group.

Why the published cybersecurity statistics diverge

Eight publishers can describe the same year's attacks and land orders of magnitude apart, because each counts a different thing. The devil's in the details of each method.

MetricHouse and figureHouse and figureWhy they differ
Cost of cybercrimeCybersecurity Ventures: $10.5T (2025, global)FBI IC3: $20.877B (2025, US)Modelled global damage against losses US complainants reported
Security spending, 2026Cybersecurity Ventures: over $520BGartner: $240BRounded estimate against a segment-by-segment end-user forecast
Median ransom paidVerizon DBIR: $139,875Chainalysis: $59,556Breach casework against traced crypto wallets
Phishing as initial accessENISA: about 60%Mandiant: 6% email, 11% voiceEU incident reports against incident-response cases
Exploits as initial accessMandiant: 32%; Verizon: 31%ENISA: 21.3%DDoS-heavy EU dataset dilutes the share
Breaches countedVerizon: 22,000+ confirmed (145 countries)ITRC: 3,322 compromises (US)Global contributor data against public US notices

Cybercrime cost: $10.5 trillion or $20.9 billion

Cybersecurity Ventures estimates cybercrime will cost the world $10.5 trillion in 2025, up from $3 trillion in 2015. That's the publisher's own projection. The FBI's $20.877 billion counts only what US complainants reported, so the two numbers answer different questions.

Gartner forecasts $240 billion in end-user security spending for 2026, up 12.5%, with security software at $121.2 billion. Cybersecurity Ventures expects global spending on cybersecurity products and services to exceed $520 billion in 2026. The $280 billion gap is larger than Gartner's whole total.

Bar chart of security spending forecasts: Cybersecurity Ventures expects more than $520 billion in 2026; Gartner forecasts $240 billion in 2026, after $213 billion in 2025 and $193 billion in 2024, with $121.2 billion of the 2026 total in security software.
Gartner's 2026 forecast and Cybersecurity Ventures' estimate sit $280 billion apart.

Where incidents begin: 60% phishing or 6%

ENISA's 4,875 EU incidents from July 2024 to June 2025 put phishing at about 60% of initial intrusions, with vulnerability exploitation second at 21.3%. DDoS attacks made up 77% of ENISA's incidents and public administration was targeted in 38.2%.

Mandiant's response cases show email phishing at 6%. The denominators explain the gap: ENISA counts every reported EU incident, and Mandiant counts cyberattacks serious enough to call in a responder.

Two bar groups comparing initial access shares by publisher. Phishing: ENISA about 60%, Mandiant voice phishing 11% and email phishing 6%. Exploited vulnerabilities: Mandiant 32%, Sophos 32%, Verizon 31% and ENISA 21.3%.
Three of four datasets put exploited vulnerabilities between 31% and 32% of initial access.

On exploits the houses nearly agree: Mandiant 32%, Verizon 31%, and Sophos's 2025 survey of 3,400 organizations hit by ransomware attacks 32%.

Cybersecurity spending, cyber insurance and the workforce

Gartner tracks cybersecurity as its own slice of information technology spending: $193 billion in 2024, $213 billion in 2025 (up 10.4%) and $240 billion in 2026. Services make up $92.8 billion of the 2026 total and network security $25.8 billion. Gartner names AI and generative AI, used by staff and by attackers, as a growth driver.

Munich Re puts cyber insurance premiums, the price organizations pay to move cybersecurity risks off their books, at nearly $15 billion in 2025 and about $28 billion by 2030, an average annual growth rate of 15% from 2020; the CAGR calculator shows how that compounds. In the UK, 47% of businesses hold cyber cover to protect against losses from cyber threats.

The 2025 ISC2 Cybersecurity Workforce Study surveyed 16,029 cybersecurity professionals. 59% report critical or significant skills needs, up from 44% in 2024. 36% saw cuts, 39% hiring freezes and 24% layoffs, and 72% agree that cutting cybersecurity staff raises the risk of breach incidents. 48% feel exhausted keeping up with threats and technology.

The Bureau of Labor Statistics projects information security analyst jobs to rise 21% from 2025 to 2035, with about 14,100 openings a year and a median wage of $129,180 in May 2025.

Sources for every cybersecurity figure, and the two numbers no dataset holds

Cybercrime complaints and attacks: FBI IC3 2025 Internet Crime Report and the IC3 Bybit advisory of 26 February 2025 (ic3.gov), the FBI release of the 2024 report (fbi.gov), the Cyber Security Breaches Survey 2025/2026 (gov.uk) and the Cloudflare DDoS threat report for Q4 2025 (blog.cloudflare.com).

Breaches and their cost: the IBM Cost of a Data Breach Report 2026 (ibm.com, July 2026), IBM's releases of 24 July 2023, 30 July 2024 and 30 July 2025 (newsroom.ibm.com), the Verizon 2026 DBIR and the 2025 DBIR release (verizon.com), and the Identity Theft Resource Center 2025 annual report (idtheftcenter.org, January 2026).

Ransomware and vulnerabilities: Chainalysis (chainalysis.com, February 2026), Sophos's State of Ransomware 2026 and 2025 (sophos.com), CVE Program metrics (cve.org), Mandiant M-Trends 2026 (cloud.google.com) and the CrowdStrike 2026 Global Threat Report (crowdstrike.com).

Threats and spending: ENISA Threat Landscape 2025 (enisa.europa.eu, incidents from July 2024 to June 2025), the WEF Global Cybersecurity Outlook 2026 (weforum.org), Gartner (gartner.com, 29 July 2025), Cybersecurity Ventures (cybersecurityventures.com, November 2025) and Munich Re's Global Cyber Risk and Insurance Survey 2026 (munichre.com).

The workforce: the 2025 ISC2 Cybersecurity Workforce Study (isc2.org, December 2025) and the BLS Occupational Outlook Handbook (bls.gov, May 2025 wage data).

Every figure was checked against its source on 1 October 2026. Two numbers appear in no dataset above: a worldwide count of cyberattacks for 2025, and the losses from cybercrime that victims never report to the FBI or any other body.

Frequently asked questions

Is it true that cyber attacks are increasing?

Yes: on each count below that publishes a time series, cyberattacks and threats rose. FBI complaints rose from 859,532 to 1,008,597, ITRC data compromises set a new record at 3,322, Cloudflare's DDoS count more than doubled to 47.1 million, and Chainalysis saw claimed ransomware victims rise 50% in 2025.

Where do 90% of cyber incidents begin?

No 2025 or 2026 dataset puts any single starting point at 90% of incidents. The human element appears in 62% of Verizon's breaches, phishing in about 60% of ENISA's incidents, and exploited vulnerabilities in 31% to 32% of breaches across Verizon, Mandiant and Sophos. The 90% figure circulates as a claim about how cyberattacks start, usually blaming phishing or human error; 82% of CrowdStrike's detections were malware-free logins.

What is the biggest cyber attack in history?

By money stolen, the largest of the cyberattacks in this report is the February 2025 Bybit theft of about $1.5 billion in virtual assets, which the Federal Bureau of Investigation attributed to North Korea. By traffic, Cloudflare's record DDoS cyber attack peaked at 31.4 Tbps in 2025.

Is the US under a cyber attack right now?

Continuously: the Federal Bureau of Investigation receives almost 3,000 cybercrime complaints a day, and Cloudflare mitigates about 5,376 DDoS attacks every hour worldwide. CISA publishes current advisories for active cyberattacks against US organizations.

What is the #1 cybersecurity threat today?

No single cybersecurity threat leads on every yardstick: ransomware by breach share (48% in the 2026 DBIR), investment fraud by reported losses ($8.65 billion to the Federal Bureau of Investigation), and phishing by complaint count (191,561). Those are the biggest threats by three different yardsticks, and WEF respondents named AI-related vulnerabilities the fastest-growing at 87%.

Is cybersecurity still worth it in 2026?

As a career for cybersecurity professionals, the BLS projects 21% job growth to 2035 at a $129,180 median wage, though 24% of ISC2 respondents saw layoffs. As a business spend, Gartner forecasts 2026 security outlays up 12.5% while the average breach costs $4.99 million. For small businesses the answer runs through ransomware, present in 88% of SMB breaches in the 2025 DBIR.

Bottom line

Every series that counts cyberattacks went up: 1,008,597 FBI complaints, 3,322 US data compromises, 48,244 CVE records (35,872 more in the first half of 2026) and 47.1 million DDoS attacks. Costs followed, with the IBM average at $4.99 million and FBI-reported losses at $20.877 billion. Cyber threats got faster too, with a 29-minute average breakout, and small businesses face ransomware attacks in 88% of their breaches.

The most data breaches still start the same few ways: an unpatched flaw, a stolen login, a third party. For cybersecurity budgets, cite the exploit share (31% to 32%) with confidence. The threats with the most money behind them are investment fraud and ransomware. Treat the $10.5 trillion cybercrime cost and the $520 billion spending figure as one publisher's estimates, and name the publisher when you use them.