Managed ITServices
Statistics

Cyber Crime Statistics for 2026: Losses, Attack Trends, and What the Latest Data Shows

Cyber crime statistics for 2026 point in one direction: losses keep climbing even as some attack economics shift. According to the FBI's 2025 Internet Crime Report, published in April 2026, the…

Cyber crime statistics for 2026 point in one direction: losses keep climbing even as some attack economics shift. According to the FBI's 2025 Internet Crime Report, published in April 2026, the Internet Crime Complaint Center (IC3) received 1,008,597 complaints in 2025 with reported losses of $20.9 billion, a 26% increase over 2024. Separately, the Federal Trade Commission reports that consumers lost about $16 billion to fraud in 2025, the highest total on record and roughly 25% more than the year before. On the enterprise side, IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million, a 12% jump and a new record high, while the US average sits at $11.5 million.

This page collects the freshest cybercrime statistics available as of September 2026, drawn from government complaint data, breach-cost research, blockchain analysis, and large-scale incident datasets. Every figure links to the original source.

Key cybercrime statistics at a glance

  • $20.9 billion in reported losses across 1,008,597 complaints to the FBI's IC3 in 2025, up 26% year over year (FBI IC3 2025 Internet Crime Report, published 2026).

  • $16 billion lost by US consumers to fraud in 2025, the highest figure on record, with imposter scams accounting for $3.5 billion (FTC, 2026).

  • $4.99 million global average cost of a data breach, a 12% increase and a record high; the US average is $11.5 million (IBM Cost of a Data Breach 2026).

  • 48% of breaches now involve ransomware, and 31% begin with vulnerability exploitation, which has overtaken stolen credentials as the top entry point (Verizon 2026 DBIR).

  • 62% of breaches involve a human element, and third-party involvement doubled to 48% (Verizon 2026 DBIR).

  • $8.6 billion lost to investment fraud in 2025, the costliest IC3 crime category, with $7.2 billion of that tied to cryptocurrency (FBI IC3, 2026).

  • $7.7 billion lost by victims aged 60 and older, up 59% in a single year (FBI IC3, 2026).

  • 3,322 publicly reported data compromises in the US in 2025, an all-time high, affecting 278.8 million victim notices (ITRC 2025 Annual Data Breach Report, published January 2026).

  • $820 million in ransomware payments tracked on-chain in 2025, down 8%, while claimed attacks rose 50% (Chainalysis, 2026).

  • $1.7 million average ransomware recovery cost, up 11% year over year (Sophos State of Ransomware 2026).

  • 81% of small businesses reported a security breach, a data breach, or both in the past year (ITRC 2025 Business Impact Report).

  • 56% increase in AI-driven attacks, with one in four organizations experiencing an AI-driven breach (IBM, 2026).

Cyber Crime Statistics for 2026: Losses, Attack Trends, and What the Latest Data Shows infographic

How much cybercrime costs in 2026

The two most-cited numbers in any cyber crime statistics roundup come from the FBI and the FTC, and both set records for 2025.

The FBI's 2025 Internet Crime Report is the first IC3 annual report to cross one million complaints. Reported losses reached $20.877 billion, up 26% from the $16.6 billion reported for 2024. Because IC3 only counts crimes that victims voluntarily report, the FBI has consistently described its totals as a floor rather than a ceiling.

The FTC's figures cover a broader universe of fraud, not only internet-enabled crime. Per the FTC's June 2026 release, consumers reported losing about $16 billion in 2025, about 25% more than in 2024. Imposter scams were the most reported fraud type, appearing in nearly one in three fraud reports and generating $3.5 billion in losses. Bank impersonators alone took nearly $1 billion, and government impersonators about $920 million. Imposter scam losses have nearly tripled since 2020.

For organizations, the benchmark is IBM's annual study. The 2026 Cost of a Data Breach Report puts the global average at $4.99 million, a 12% increase over the 2025 edition and the highest figure in the study's history. The United States remains the most expensive country to be breached in, at $11.5 million per incident. Healthcare, long the costliest industry, fell 10.5% to $6.64 million per breach in the 2026 edition, down from $7.42 million in 2025. Phishing was the initial vector in 17% of breaches and carried an average cost of $5.9 million. Breaches that began through supply chain compromise or removable media took 258 days to identify and contain, versus a 247-day average across all attack types.

The most common types of cybercrime

IC3 data gives the clearest picture of what cybercrime looks like from the victim's side. By complaint volume, the FBI's 2025 report ranks phishing and spoofing first with 191,561 complaints, followed by extortion (89,129) and investment fraud (72,984).

By dollar loss, the ranking changes completely:

  • Investment fraud: $8.65 billion across 72,984 complaints, the costliest category by a wide margin. Cryptocurrency investment fraud alone accounted for $7.2 billion.

  • Business email compromise (BEC): $3.05 billion across 24,768 complaints. BEC remains the most expensive threat per incident for businesses, averaging roughly $123,000 per complaint.

  • Tech and customer support scams: $2.13 billion across 47,794 complaints.

  • Ransomware: 3,611 complaints and $32.3 million in direct reported losses, with 63 new variants identified. The FBI's ransomware loss figure covers only ransom amounts reported to IC3 and excludes downtime, recovery, and lost business, which is why ransomware looks small in IC3 data and enormous everywhere else.

Cryptocurrency runs through much of this. IC3 logged 181,565 complaints with a cryptocurrency nexus in 2025 (up 21%) totaling $11.37 billion in losses (up 22%). That means more than half of all reported IC3 losses in 2025 involved crypto in some form, and 18,589 complainants each lost more than $100,000.

Who cybercrime hits hardest

Older Americans. Victims aged 60 and older filed 201,266 complaints with IC3 in 2025, a 37% increase, and reported $7.75 billion in losses, a 59% increase. That is 37% of all reported losses from one age group. The average loss for a senior victim was $38,500, and 12,444 seniors lost more than $100,000 each, according to the FBI IC3 2025 report.

Small businesses. The Identity Theft Resource Center's 2025 Business Impact Report found that 81% of small businesses suffered a security breach, a data breach, or both in the past year. Among those breached, 62.5% faced total costs above $250,000 and 36.7% lost more than $500,000. For the first time, 38.3% of small business leaders said they raised prices to offset incident costs, effectively passing cybercrime losses to consumers. Readiness is moving the wrong way: only 38.4% felt "very prepared" in 2025, down from 56.5% in 2024, and multi-factor authentication adoption fell from 33.6% to 27.2%.

Industries with the most breaches. The ITRC's 2025 Annual Data Breach Report, released in January 2026, counted 3,322 publicly reported compromises in the US in 2025, up 5% from 3,152 in 2024 and 79% over five years. That is the highest annual total in the ITRC's 20-year history. Financial services led with 739 compromises, followed by healthcare (534), professional services (478), manufacturing (299), and education (188). Victim notices fell sharply to 278.8 million from 1.37 billion in 2024, largely because 2024 included a handful of mega-breaches. Transparency is also declining: 70% of breach notices in 2025 contained no information about the attack vector, up from 65% the year before.

How attackers get in: data breach statistics for 2026

The Verizon 2026 Data Breach Investigations Report analyzed more than 31,000 incidents and 22,000 confirmed breaches across 145 countries, the largest dataset in the report's history. Its headline findings reshape several long-standing assumptions:

  • Vulnerability exploitation is now the top initial access vector at 31% of breaches, up from 20% the previous year (a 55% increase). Credential abuse as an initial vector dropped to 13% from 22%, although stolen credentials still appear somewhere in 39% of breaches.

  • Phishing held steady at 16% of initial access, and pretexting, now tracked separately, accounted for 6%.

  • The human element was involved in 62% of breaches, up slightly from 60%.

  • Third-party involvement jumped to 48% of breaches, up from 30%, a 60% year-over-year increase driven by supply chain and vendor compromises.

  • Patching is falling behind. Only 26% of critical vulnerabilities in CISA's Known Exploited Vulnerabilities catalog were fully remediated in 2025 (down from 38%), and median remediation time stretched to 43 days from 32, while organizations faced 50% more critical vulnerabilities to patch.

  • Mobile is a growing target, with 40% higher click rates on malicious links compared to desktop.

The DBIR also documents how generative AI is being folded into attacks: threat actors used AI assistance across a median of 15 different attack techniques, mostly to accelerate well-documented methods rather than invent new ones. On the defender side, 67% of users accessed unauthorized GenAI services on corporate devices, and 45% of employees are now regular AI users at work, up from 15%.

Ransomware statistics: fewer payments, more attacks, higher costs

Ransomware is the category where 2026 data diverges most sharply depending on what you measure.

Measured by breaches, ransomware is expanding. The Verizon 2026 DBIR found ransomware in 48% of all breaches, up from 44%. But 69% of victims did not pay, and the median payment fell to $139,875 from $150,000.

Measured by money flowing to criminals, ransomware is stagnating. Blockchain analysis by Chainalysis tracked $820 million in ransomware payments in 2025, down 8% from a revised $892 million in 2024, even as claimed attacks on data leak sites rose 50% to an all-time high. Chainalysis estimates that only about 28% of victims paid, potentially a record low. The median payment, however, jumped 368% to $59,556, which suggests attackers are concentrating on fewer, larger targets. Initial access brokers received at least $14 million in on-chain payments.

Measured by victim cost, ransomware is getting more expensive. The Sophos State of Ransomware 2026 survey of 2,158 IT and security leaders in 17 countries found the average recovery cost reached $1.7 million per incident, up 11%. Encryption rates rose to 56% of attacks from 50%. Among victims whose data was encrypted, 48% paid, and 51% of those negotiated a lower amount than demanded; the median demand was $698,000 and the median payment $769,000. Sophos also reports that 79% of ransomware attacks started with an identity-based approach, and the leading root causes were malicious email (26%), phishing (24%), compromised credentials (23%), and exploited vulnerabilities (18%). Smaller firms with 100 to 250 employees stopped attacks before encryption only 34% of the time, compared with 46% for organizations of 3,001 to 5,000 employees.

IBM's data reinforces the trend. In the 2026 Cost of a Data Breach Report, 39% of breached organizations experienced a ransomware attack, up from 24% in 2023, a 62.5% increase over four years. In 41% of ransomware cases, attackers threatened the victim's brand reputation as leverage.

AI-driven attacks are now measurable, not theoretical. IBM's 2026 report recorded a 56% year-over-year increase in AI-driven attacks, led by deepfake impersonation (45% of AI-driven attacks) and AI-enabled malware. One in four organizations experienced an AI-driven breach, adding roughly $1 million to average breach costs. The ITRC found AI-powered attacks were a root cause in more than 40% of small business cyber events.

Shadow AI has become a breach vector. Per IBM, security incidents involving shadow AI more than doubled to 43% from 20%, with an average breach cost of $5.39 million and regulatory fines in one in five cases. The average cost of an AI model inversion attack, where attackers reconstruct training data, reached $6 million. Verizon's finding that 67% of users access GenAI through non-corporate accounts explains why.

AI defense pays for itself. Organizations using AI and automation extensively in security operations saved an average of $1.93 million per breach versus those using none, according to IBM's 2026 study.

Vulnerability exploitation has overtaken credentials. The DBIR's finding that 31% of breaches now start with a software vulnerability, combined with only 26% of KEV-listed flaws being fully remediated, makes patch management the single biggest gap in 2026.

Third-party risk doubled. With 48% of DBIR breaches involving a third party and professional services showing the fastest growth in ITRC compromises, vendor and MSP security is now central to any cybercrime risk assessment.

Fraud is aging. The 59% surge in losses among victims 60 and older, to $7.75 billion, is the fastest-growing segment in IC3 data. Combined with the FTC's record $16 billion in consumer fraud, elder fraud is on track to become the largest single cybercrime loss category by victim group.

Crypto is the payment rail for most losses. With $11.37 billion of IC3 losses tied to cryptocurrency, and $7.2 billion in crypto investment fraud alone, more than half of all reported US internet crime losses in 2025 moved through digital assets.

How managed IT services can help

Most of the entry points documented above (unpatched vulnerabilities, phishing, weak identity controls, unmanaged AI tools, and third-party exposure) are exactly the areas that managed security service providers are built to cover. For small businesses, where 81% report a breach and MFA adoption is falling, outsourcing monitoring and patching is often the fastest way to close the gap.

Looking for a managed security service provider that can help your organization reduce breach risk and meet compliance requirements? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options and get a free assessment.

Need Help With Your Security Strategy?

Get a free assessment from our team of cybersecurity experts.

Related Articles

HM

Hadley McIntosh

Updated Oct 1, 2026 · 11 min read