350+ Cybercrime Statistics for 2026
Updated:
September 22, 2026
Global cybercrime damage is projected to hit $10.5 trillion annually in 2025, which would make it the third largest economy on earth behind the United States and China. The FBI’s IC3 logged 859,532 complaints in 2024 and $16.6 billion in reported losses, a 33% jump in a single year.
Those totals only capture what gets reported. Ransomware, phishing, credential theft and state-sponsored intrusion hit every sector and every region, and the gap between attacker speed and defender readiness keeps widening. A single intrusion now takes 48 minutes to spread laterally, while the average breach still runs 258 days before containment.
The team at Bright Defense has compiled a comprehensive list of up-to-date 200+ valid cybercrime statistics for 2026. In this article, you’ll find hand-picked statistics about:
- Global financial impact and projected damages
- Frequency and scope of cyber attacks
- Ransomware and malware trends
- Phishing and social engineering
- Data breaches and exposure
- Geopolitical and regional insights
- Emerging threats and future projections
- Workforce shortages and defense gaps
- Cybercrime across Asia
- Cyber attacks across Europe
Without further ado, let’s check out the stats!
1. Global Financial Impact of Cybercrimes

- US cybercrime losses reached $20,877,000,000 in 2025, a 26% increase over 2024 and the highest total the FBI has recorded. (Source: FBI IC3)
- IC3 received 1,008,597 complaints in 2025, the first year above one million in the center’s 25-year history, at an average loss of $20,699 per complaint. (Source: FBI IC3)
- Cyber-enabled fraud accounted for roughly 453,000 complaints and more than $17.7 billion in losses. (Source: FBI IC3)
- The costliest crime types in 2025, with 2024 figures for comparison:
- Investment fraud: $8,648,617,756, up from $6,570,639,864
- Business email compromise: $3,046,598,558, up from $2,770,151,146
- Personal data breach: $1,314,923,988, down from $1,453,296,303
- Confidence and romance fraud: $929,287,469, up from $672,009,052
- Government impersonation: $797,943,193, up from $405,624,084
(Source: FBI IC3)
- Phishing and spoofing losses tripled to $215,843,126 from $70,013,036. Malware losses rose to $19,370,572 from $1,365,945. (Source: FBI IC3)
- Data breach losses reported to IC3 reached $435,240,992, up from $364,855,818. (Source: FBI IC3)
- Victims aged 60 and over filed 201,266 complaints and lost $7,748,000,000 in 2025, a 37% rise in complaints and a 59% rise in losses. Average loss in that group was $38,500, and 12,444 complainants lost more than $100,000 each. (Source: FBI IC3)
- Victims aged 60 and over accounted for 24.2% of cyber-enabled fraud complaints, the largest single age band. (Source: FBI IC3)
- AI-related crime generated 22,364 complaints and $893,346,472 in losses in its first year as a tracked category. (Source: FBI IC3)
- The IC3 Recovery Asset Team initiated 3,900 Financial Fraud Kill Chain incidents covering $1,163,919,846 in attempted theft and froze $679,013,183, a 58% success rate. (Source: FBI IC3)
- Of 655 kill chain incidents involving critical infrastructure organizations, the team froze $146,561,094 of $261,451,001 in reported losses, a 56% success rate. (Source: FBI IC3)
- Call center fraud, covering tech support and government impersonation, produced more than 80,000 complaints and over $2.9 billion in losses. (Source: FBI IC3)
- On-chain ransomware payments fell to roughly $820 million in 2025, an 8% decline from the revised $892 million in 2024 and the lowest full-year total since 2021. (Source: Chainalysis)
- Only 28% of ransomware victims paid in 2025, an all-time low, against 62.8% in 2024 and 78.9% in 2022. (Source: Chainalysis)
- The global average cost of a data breach reached $4.99 million in the 2026 reporting period, a 12% increase and a record, working out to $1,100 per hour. (Source: IBM)
- AI-driven attacks added an average of $1 million per breach, with malicious AI-driven incidents averaging $6.04 million against $5.03 million for those without AI. (Source: IBM)
- Organizations using security AI and automation extensively averaged $4.00 million per breach against $5.93 million for those using none, a $1.93 million saving. (Source: IBM)
- 85% of breached organizations said they would increase security spending in response to frontier AI model threats, up from 64% before learning of those threats. (Source: IBM)
- Worldwide end-user spending on information security is projected to reach $240 billion in 2026, a 12.5% increase over the $213 billion spent in 2025. (Source: Gartner)
- Global cybercrime costs are projected to plateau near $12.2 trillion by 2031, implying 2.5% annual growth from 2026 onward. The estimate folds in stolen funds, fraud, productivity loss, intellectual property theft, remediation, fines, and reputational harm, which makes it a damages model rather than a measure of economic output. (Source: Cybersecurity Ventures)
2. Frequency & Scope of Cyber Attacks

- Organizations faced an average of 1,968 cyberattacks per week in 2025, an 18% year-over-year increase and nearly 70% above 2023. (Source: Check Point)
- Weekly attack volume by region in 2025:
- Africa: 3,092, up 5%
- APAC: 2,909, up 10%
- Latin America: 2,795, up 13%
- Europe: 1,642, up 20%
- North America: 1,422, up 23%
(Source: Check Point)
- Education remained the most targeted sector at 4,352 weekly attacks per organization, a 22% increase. Within APAC, India recorded the highest volume at 7,684 weekly attacks. (Source: Check Point)
- Hardware and semiconductors saw a 34% global increase in weekly attacks, rising 75% in Europe and 24% in North America. Taiwan and China were the most targeted at 7,393 and 5,631 weekly attacks. (Source: Check Point)
- The 2026 DBIR analyzed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries, the largest dataset Verizon has published. (Source: Verizon)
- Vulnerability exploitation became the most common initial access vector for the first time in the report’s 19-year history, reaching 31% from 20%, a 55% increase in that vector. Credential abuse fell to 13% from 22%. (Source: Verizon)
- Only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38% the prior year. Median time to full resolution rose to 43 days from 32. (Source: Verizon)
- Organizations carried 50% more critical vulnerabilities to patch in the median case than the previous year. (Source: Verizon)
- Breaches involving third parties rose 60% year over year and now account for 48% of all breaches. (Source: Verizon)
- Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts, with 50% of findings resolved within a month. Weak passwords and permission misconfigurations took almost eight months to reach the same 50% mark. (Source: Verizon)
- System intrusion accounts for 60% of all breaches, up from 53%. (Source: Verizon)
- Average eCrime breakout time fell to 29 minutes in 2025 from 48 minutes, a 65% gain in speed. The fastest observed breakout took 27 seconds. (Source: CrowdStrike)
- 82% of detections in 2025 were malware-free, with attackers using stolen credentials and native admin tools rather than malicious code. (Source: CrowdStrike)
- Attacks from AI-enabled adversaries increased 89% year over year, and adversaries injected malicious prompts into legitimate generative AI tools at more than 90 organizations. (Source: CrowdStrike)
- Incidents using fake CAPTCHA lures rose 563% in 2025 as attackers shifted away from fake browser update lures. (Source: CrowdStrike)
- 42% of exploited vulnerabilities were weaponized before public disclosure. (Source: CrowdStrike)
- China-nexus activity increased 38% in 2025, with logistics the most heavily targeted vertical at an 85% increase. Among vulnerabilities those actors exploited, 67% delivered immediate system access and 40% targeted internet-facing edge devices. (Source: CrowdStrike)
- Cloud-conscious intrusions rose 37% overall, with a 266% increase from state-nexus actors. (Source: CrowdStrike)
- DPRK-linked incidents rose more than 130%, and PRESSURE CHOLLIMA’s $1.46 billion cryptocurrency theft was the largest single financial heist recorded. (Source: CrowdStrike)
- PUNK SPIDER was the most active big game hunting adversary of 2025 with 198 observed intrusions, a 134% increase. (Source: CrowdStrike)
- CrowdStrike tracks more than 280 named adversaries. (Source: CrowdStrike)
- CVE submissions grew 263% between 2020 and 2025. NIST enriched nearly 42,000 CVEs in 2025, 45% more than any prior year, and still could not keep pace. (Source: NIST)
- NIST moved the NVD to a triage model on April 15, 2026, enriching only CVEs that meet set criteria and listing the rest as lowest priority. (Source: NIST)
- Zero-day attacks rose to 14 events in H1 2026, up from 7 in H1 2025 and on pace to double the full-year 2025 count of 17. (Source: ITRC)
- Supply chain attacks produced 280,644,600 victim notices in H1 2026 from just 38 initial breach events affecting 206 entities. (Source: ITRC)
- Healthcare and public health recorded the highest number of cyber threats among critical infrastructure sectors in 2025, with 182 data breaches and 460 ransomware attacks. (Source: FBI IC3)
3. Ransomware & Malware Trends

- Data leak sites listed 2,122 new victims in Q1 2026 across more than 70 active sites, the second-highest Q1 on record and 117% above Q1 2024. (Source: Check Point)
- Q2 2026 recorded 2,139 victims, flat against Q1 but 33% higher year over year. (Source: Check Point)
- Active ransomware groups reached a record 93 in Q2 2026, up from 71 in Q1. The top ten groups’ share of victims fell to 57.6% from 71%. (Source: Check Point)
- Qilin held first place for the third consecutive quarter with 338 victims in Q1 2026, outposting the combined total of the bottom 50 groups. (Source: Check Point)
- The Gentlemen jumped from 40 victims in Q4 2025 to 166 in Q1 2026, then 279 in Q2, built on a pre-staged stockpile of roughly 14,700 compromised FortiGate devices. (Source: Check Point)
- LockBit 5.0 posted 163 victims in Q1 2026 and shifted its target mix away from the United States, from a historic share above 50% down to 21.2%. (Source: Check Point)
- Monthly Q1 2026 volume held steady at 732 victims in January, 684 in February and 706 in March. (Source: Check Point)
- Fourteen groups active in Q4 2025 disappeared during Q1 2026 while 21 new names appeared, most posting fewer than ten victims. (Source: Check Point)
- 97% of publicly disclosed ransomware incidents in Q2 2026 involved data exfiltration, the highest rate recorded. (Source: BlackFog)
- Undisclosed ransomware attacks reached 2,027 in Q2 2026, a 40% year-over-year rise from 1,446 in Q2 2025, against 306 publicly disclosed attacks in the same quarter. (Source: BlackFog)
- 57 distinct ransomware variants appeared in disclosed Q2 2026 attacks, a 21% increase over Q1. Attribution failed entirely for 30% of disclosed incidents. (Source: BlackFog)
- The highest single ransom demand recorded in Q2 2026 was $25 million. (Source: BlackFog)
- The ITRC logged 76 ransomware events in H1 2026, up from 73 in H1 2025, reversing the prior year’s decline. (Source: ITRC)
- On-chain ransomware payments fell to roughly $820 million in 2025, an 8% decline from the revised $892 million in 2024 and the lowest full-year total since 2021. (Source: Chainalysis)
- Only 28% of victims paid in 2025, an all-time low, against 62.8% in 2024 and 78.9% in 2022. (Source: Chainalysis)
- The median on-chain ransom payment rose 368% to $59,556 in 2025 from $12,738 in 2024, driven by a small number of high outlier payments. (Source: Chainalysis)
- Exposed applications and systems were the most common ransomware entry point at 38%, followed by user devices at 30% and firewalls at 21%. (Source: Sophos)
- 97% of organizations where compromised credentials were the root cause had multi-factor authentication enabled in some capacity at the time of the incident, with an average of 2.5 methods deployed. (Source: Sophos)
- 56% of attacks succeeded in encrypting data, up from the 50% low a year earlier. That splits into 40% encrypted only and 16% encrypted and stolen. (Source: Sophos)
- 61% of victims said their firewall detected the attack before the payload detonated. Where the firewall detected nothing, 71% had data encrypted, against 50% where it caught the attack early. (Source: Sophos)
- Organizations with 3,001 to 5,000 employees stopped 46% of attacks before encryption or extortion, against 34% for those with 100 to 250 employees. (Source: Sophos)
- Backup-based recovery surged to 66% of attacks where data was encrypted, up from 54%. Only 2% of organizations recovered no data at all. (Source: Sophos)
- The median ransom demand fell to $698,000, a 65% drop over two years. The mean demand fell to $3,126,372, a 28% reduction since the 2024 report. (Source: Sophos)
- Demands scale with revenue. Organizations under $50 million faced median demands near $140,000, while those above $5 billion faced $5.7 million. (Source: Sophos)
- The median payment among 530 paying organizations was $769,000, and the median payment came to 90% of the original demand, with 51% paying less and 18% paying more. (Source: Sophos)
- 59% of demands from attacks that began with an exploited firewall vulnerability were for $1 million or more, against 48% of all demands. (Source: Sophos)
- Payment rates by sector ran from 72% for local and state government and 64% for media, leisure and entertainment down to 32% for retail. (Source: Sophos)
- The mean recovery cost excluding ransom reached $1,700,200, an 11% increase but still 38% below the $2,730,684 peak in the 2024 report. The median held at $375,000. (Source: Sophos)
- 55% of organizations recovered within one week and 83% within one month. Only 3% took longer than three months. (Source: Sophos)
- 99% of victims that had data encrypted reported lasting repercussions on their IT and security teams, and 21% saw their leadership team replaced. (Source: Sophos)
- Cross-referencing actor-disclosed attacks against known crypto-wallet payments put the median share of publicized victims who actually paid at roughly 9% per ransomware group. (Source: Verizon)
- 27% of ransomware victims had no associated infostealer or credential leak in the year before the attack. Of those that did, 50% experienced that event within 95 days. (Source: Verizon)
- Initial access brokers priced non-privileged accounts at a median of roughly $700 and administrative accounts at roughly $1,300. VPN access made up 44% of connection types offered. (Source: Verizon)
- AI-assisted malware development mapped almost entirely to known techniques, with a median of 55 existing malware examples performing the same function. Under 2.5% of observations involved techniques with one or fewer known examples. (Source: Verizon)
- Lumma dominated infostealer logs at 43%, down from 51%, while Redline rose to 22% from 8%. Over 76% of infected machines were likely non-corporate devices, up from 70%. (Source: Check Point)
4. Phishing & Social Engineering Cybercrime Statistics

- Social engineering was the third most common breach pattern in the 2026 DBIR, appearing in 16% of all breaches. (Source: Verizon)
- The human element appeared in 62% of breaches, up slightly from 60% the previous year. (Source: Verizon)
- Phishing held steady at 16% of all breaches while pretexting reached 6%, becoming a more common initial access vector for ransomware and extortion. (Source: Verizon)
- 41% of social engineering breaches involved vectors other than email, with roughly a quarter of social action vectors coming from social media or phones. (Source: Verizon)
- The median click rate in email phishing simulations was 1.4%, against roughly 2% for phone-centric simulations, a 40% higher success rate on the non-email vectors. (Source: Verizon)
- Across 3,709,045,972 emails analyzed at security gateways, attacks blocked broke down as:
- Plain phishing: 80%
- Emails carrying malware: 10%
- Callback attempts: 5%
- Business email compromise: 3%
(Source: Verizon)
- Large organizations faced a median of 48 SMS-based phishing campaigns against managed mobile devices per year, against 12 for smaller organizations. (Source: Verizon)
- Phishing and spoofing generated 191,561 complaints to IC3 in 2025, the highest complaint volume of any crime type, down slightly from 193,407 in 2024. (Source: FBI IC3)
- Phishing and spoofing losses reported to IC3 tripled to $215,843,126 in 2025 from $70,013,036 in 2024. (Source: FBI IC3)
- Business email compromise produced $3,046,598,558 in losses in 2025, second only to investment fraud. (Source: FBI IC3)
- Tech and customer support scams generated 47,794 complaints in 2025, up from 36,002 in 2024. Combined with government impersonation, call center fraud produced more than 80,000 complaints and over $2.9 billion in losses. (Source: FBI IC3)
- AI-related crime generated 22,364 complaints and $893,346,472 in losses in 2025, its first year as a tracked category. Within that, businesses reported over $30 million lost to AI-enabled BEC, victims lost over $19 million to AI-assisted confidence and romance scams, and nearly $13 million to AI-involved employment scams. (Source: FBI IC3)
- AI-automated phishing emails achieved 54% click-through rates against 12% for standard attempts, a 4.5 times increase. (Source: Microsoft)
- AI automation has the potential to raise phishing profitability by up to 50 times through scaling targeted attacks at minimal cost. (Source: Microsoft)
- Phishing was the top initial attack vector into breached organizations for the fourth consecutive year. Voice and SMS phishing appeared in 17% of attacks and produced the highest average breach cost of any vector at $5.29 million. (Source: IBM)
- Social engineering such as help desk impersonation and MFA fatigue appeared in 13% of attacks at an average cost of $5.23 million, and took 254 days to identify and contain. (Source: IBM)
- Deepfake and impersonation attacks drove 45% of AI-driven incidents, ahead of AI-enabled malware at 19% and AI-generated phishing at 17%. (Source: IBM)
- Malicious email at 26% and phishing at 24% became the top two root causes of ransomware attacks, together accounting for half of all incidents. Exploited vulnerabilities fell 14 percentage points to 18%. (Source: Sophos)
- 79% of ransomware attacks started with an identity-based approach, and 67% of victims confirmed the ransomware incident was the same event as their most significant identity attack. (Source: Sophos)
- SCATTERED SPIDER relied almost exclusively on social engineering to persuade help desk staff to perform self-service password resets, gaining access to cloud and single sign-on accounts. (Source: CrowdStrike)
- Microsoft detected approximately 8.3 billion email-based phishing threats in Q1 2026, with monthly volume falling from 2.9 billion in January to 2.6 billion in March. (Source: Microsoft)
- QR code phishing grew 146% across Q1 2026, from 7.6 million attacks in January to 18.7 million in March. (Source: Microsoft)
- Microsoft tracked 10.7 million BEC attacks in Q1 2026, and 82% to 84% of opening messages were generic conversational bait with no explicit payment request. (Source: Microsoft)
- Phishing attacks rose 13.8% in Q1 2026 from the 853,244 recorded in Q4 2025, with 766 unique brands targeted. (Source: APWG)
- Telecom became the most-attacked category in Q1 2026, climbing from 5.9% of all attacks in Q3 2025 to 33%. (Source: APWG)
- The average amount requested in wire transfer BEC attacks fell 15% to $42,663 in Q1 2026, and total wire transfer BEC attacks observed dropped 25% quarter over quarter. (Source: APWG)
Our article featuring 200+ verified phishing statistics offers the most current data on phishing trends. Check it out for a clear breakdown of the latest figures and insights.
5. Data Breaches & Exposure

- The ITRC tracked 1,803 data compromises in the first half of 2026, a 3.3% increase over H1 2025 and 14.8% over H1 2024. (Source: ITRC)
- Q2 2026 produced 1,029 compromises against 774 in Q1, the second-highest single-quarter total in ITRC tracking history. The annualized pace of roughly 3,606 events would surpass 2025’s record of 3,321. (Source: ITRC)
- Victim notices reached 471,206,085 in H1 2026, exceeding the 297,539,178 issued across all of 2025. (Source: ITRC)
- The Instructure Holdings Canvas breach alone generated an estimated 275 million victim notices, 58% of the H1 total. Canvas and Under Armour together produced 347.7 million notices, more than the entire 2025 calendar year. (Source: ITRC)
- H1 2026 events break down as 1,394 data breaches (77% of the total), 4 exposures, 1 leak, 2 previously compromised data releases, and 402 unclassified compromises. (Source: ITRC)
- Cyberattacks caused 1,256 compromises (69.7%) and 434,845,000 victim notices (92.3%). System and human errors caused 125 events, physical attacks 17. (Source: ITRC)
- Only 425 H1 2026 breach notices (24%) disclosed how the breach happened, while 1,378 (76%) withheld it. In 2020, nearly 100% of notices disclosed root cause. (Source: ITRC)
- Of the 1,256 cyberattacks recorded, 972 (77.4%) list the attack vector as Not Specified. (Source: ITRC)
- Named cyberattack vectors in H1 2026:
- Phishing, smishing and BEC: 157 events, down 37.9% from 253 in H1 2025
- Ransomware: 76 events, up from 73
- Zero-day attacks: 14 events, double the 7 recorded in H1 2025
- Stolen or compromised credentials: 11
- Malware: 10
- Credential stuffing: 9
(Source: ITRC)
- Insider wrongdoing produced 21 confirmed events in H1 2026, more than seven times the 3 recorded across all of 2025. (Source: ITRC)
- Supply chain attacks generated 280,644,600 victim notices from just 38 initial breach events affecting 206 entities. (Source: ITRC)
- Publicly traded companies accounted for 185 of 1,803 compromises (10.3%) but 392,871,662 victim notices (83.4%). (Source: ITRC)
- Compromises by sector in H1 2026:
- Financial services: 387 compromises, 13.0 million notices
- Healthcare: 281 compromises, 11.7 million notices
- Professional services: 269 compromises, 906,960 notices
- Manufacturing: 189 compromises, 74.0 million notices
- Technology: 99 compromises, 314.4 million notices
(Source: ITRC)
- Manufacturing victim notices reached 74 million in six months, roughly 37.6 times the full-year 2025 total of 1.97 million. (Source: ITRC)
- A previously compromised data release discovered June 12, 2026 involved an unsecured Elasticsearch cluster exposing approximately 24 billion records. (Source: ITRC)
- The global average cost of a data breach reached $4.99 million, a 12% increase and a record. That works out to $1,100 per hour. (Source: IBM)
- US average breach costs hit $11.5 million, up 11% and nearly double the global average. Benelux ranked third at $7.37 million behind the Middle East at $8.00 million. (Source: IBM)
- Detection and escalation plus lost business each rose 11.5% and together accounted for $3.18 million of the $4.99 million average, or 63% of total cost. Post-breach response rose fastest at 15%. (Source: IBM)
- Healthcare remained the costliest industry for the thirteenth consecutive year at $6.64 million, though that figure fell 10.5% from $7.42 million. Financial followed at $6.29 million. (Source: IBM)
- Customer PII was compromised in 52% of breaches at $192 per record. Intellectual property was the costliest data type at $196 per record, compromised in 32% of breaches. (Source: IBM)
- 53% of breached organizations had not encrypted sensitive data at rest and in motion at the time of the breach. Another 10% did not know. (Source: IBM)
- Phishing was the top initial attack vector for the fourth consecutive year. Voice and SMS phishing appeared in 17% of attacks and produced the highest average cost at $5.29 million. (Source: IBM)
- Malicious or criminal attacks caused 55% of breaches, ahead of human error at 23% and IT failure at 22%. (Source: IBM)
- Mean time to identify and contain rose to 247 days, split 183 days to identify and 64 to contain, reversing a five-year decline. Removable media and supply chain compromises took longest at 258 days each. (Source: IBM)
- Breaches disclosed by the attacker cost the most at $5.12 million. Those found by an MSSP cost least at $4.86 million. Internal teams identified 38% of breaches and closed them in 209 days against 281 days for third-party discovery. (Source: IBM)
- Breaches running longer than 200 days cost $5.65 million against $4.32 million for shorter ones. (Source: IBM)
- 42% of organizations fully recovered from their breach, up from 35% and quadruple the 12% recorded in 2024. The share needing more than 150 days to recover fell to 19% from 26%. (Source: IBM)
- Supply chain compromise was the single most expensive cost factor, adding $227,250 above the global average, followed by security system complexity at $208,265 and shadow IT at $201,165. (Source: IBM)
- A DevSecOps approach was the largest cost reducer at $253,805 below average, followed by identity and access management at $225,622. (Source: IBM)
Our compliance statistics report covers the full scope of how regulatory gaps translate into financial and legal consequences.
6. Geopolitical & Regional Insights

- North America became the most-attacked region for the first time in six years, accounting for 29% of cases observed by X-Force, up from 24% in 2024. Asia-Pacific ranked second. (Source: IBM X-Force)
- Vulnerability exploitation became the leading cause of attacks at 40% of incidents observed in 2025, and attacks beginning with exploitation of public-facing applications rose 44%. (Source: IBM X-Force)
- In Asia-Pacific, exploitation of public-facing applications at 50% and valid accounts at 30% led initial access vectors. Manufacturing absorbed 65% of regional attacks, followed by finance and insurance at 17% and transportation at 7%. (Source: IBM X-Force)
- Active ransomware and extortion groups surged 49% year over year while publicly disclosed victim counts rose roughly 12%. Large supply chain and third-party compromises nearly quadrupled since 2020. (Source: IBM X-Force)
- Nation-state activity observed by Microsoft concentrated on three countries: the United States at 623 events, Israel at 603 and Ukraine at 277. (Source: Microsoft)
- Next-highest observed activity counts by country:
- United Arab Emirates: 166
- United Kingdom: 144
- Taiwan: 143
- Korea: 126
- India: 100
- Poland: 97
(Source: Microsoft)
- Nation-state actors targeted IT most heavily at 26% of total activity, followed by research and academia at 14% and government at 12%. (Source: Microsoft)
- The NCSC handled 204 nationally significant cyber incidents against the UK in the 12 months to August 2025, up from 89 the previous year. (Source: NCSC)
- Of 429 total incidents the NCSC handled, 18 were classed as highly significant, a near 50% rise and the third consecutive annual increase. (Source: NCSC)
- The NCSC received 1,727 incident tips over the period. Three vulnerabilities accounted for 29 of the incidents it worked: CVE-2025-0282 in Ivanti Connect Secure, CVE-2024-47575 in Fortinet FortiManager and CVE-2025-53770 in Microsoft SharePoint Server. (Source: NCSC)
- North America absorbed 55% of interactive intrusions observed in 2025, followed by Europe and East Asia at 9% each. (Source: CrowdStrike)
- Technology was the most targeted industry for interactive intrusions at 23%, followed by manufacturing at 15%, retail at 12% and financial services at 11%. (Source: CrowdStrike)
- PRESSURE CHOLLIMA’s $1.46 billion cryptocurrency theft was the largest single financial heist ever recorded. (Source: CrowdStrike)
- ENISA analysed 4,875 incidents affecting EU member states and EU-based organizations between July 1, 2024 and June 30, 2025. (Source: ENISA)
- DDoS was the dominant EU incident type at 77% of reported incidents, deployed mostly by hacktivists. Hacktivism accounted for almost 80% of total EU incidents, though only 2% produced service disruption. (Source: ENISA)
- Public administration was the most frequently targeted EU sector at 38.2% of reported cases, with over 94% of those attacks being low-impact DDoS. (Source: ENISA)
- Ransomware accounted for 81.1% of cybercriminal incidents against EU organizations, with data breaches at 15.2%. Entities classified as essential under NIS2 accounted for 53.7% of all recorded EU incidents. (Source: ENISA)
- The United States accounted for approximately 52% of ransomware victims disclosed on leak sites in 2025, followed by the United Kingdom at 5%, with Canada and Germany each at 4%. (Source: Check Point)
- LockBit 5.0 shifted its target mix away from the United States in Q1 2026, from a historic share above 50% down to 21.2%. (Source: Check Point)
- IC3 received complaints from more than 200 countries in 2025, accounting for almost $1.6 billion of total losses. The top foreign filers were Canada at 7,479, India at 5,879, Mexico at 1,654 and South Africa at 1,532. (Source: FBI IC3)
- North Korean operatives infiltrated US employers as remote IT workers at scale. Okta Threat Intelligence documented more than 6,500 interviews across 500 companies by over 130 DPRK-linked actors, and Amazon blocked 1,800 suspected North Korean applications between April 2024 and December 2025. (Source: ITRC)
- Breach costs by country in the 2026 reporting period:
- Middle East: $8.00 million, up from $7.29 million
- Canada: $5.20 million, up from $4.84 million
- Germany: $4.93 million, up 18% from $4.03 million
- United Kingdom: $4.17 million, up from $4.14 million
- India: $2.79 million, up from $2.51 million
- Brazil: $1.41 million, up from $1.22 million
(Source: IBM)
- South Africa recorded the largest percentage increase in average breach costs at 22%, reaching $3.04 million. (Source: IBM)
Cybersecurity never stands still. Take a look at 200+ cybersecurity stats that capture the latest trends, risks, and defenses shaping today’s digital world.
7. Emerging Threats & Future Projections

- 94% of surveyed leaders expect AI to be the most significant driver of change in cybersecurity in 2026, and 87% identified AI-related vulnerabilities as the fastest-growing cyber risk over 2025. (Source: World Economic Forum)
- The share of organizations assessing the security of AI tools before deployment nearly doubled to 64% in 2026 from 37% in 2025. (Source: World Economic Forum)
- 77% of organizations already use AI for cybersecurity, mainly for phishing detection, intrusion response and user behavior analytics. (Source: World Economic Forum)
- The main barriers to deploying AI for cybersecurity are insufficient knowledge or skills at 54%, the need for human oversight at 41% and uncertainty about risk at 39%. (Source: World Economic Forum)
- 64% of organizations now account for geopolitically motivated cyberattacks in their risk planning, making geopolitics the top factor influencing mitigation strategy. (Source: World Economic Forum)
- 77% of leaders reported an increase in cyber-enabled fraud and phishing, and 73% said they or a leader they know had been personally targeted. (Source: World Economic Forum)
- Among organizations rating themselves insufficiently resilient, 85% also report lacking key people and skills, against 22% among highly resilient organizations. (Source: World Economic Forum)
- AI-related breaches grew to 21% of organizations in 2026 from 13%, a 61% increase. (Source: IBM)
- Breach costs by AI incident type:
- Model inversion: $6.07 million
- Prompt injection: $5.89 million
- Cloud security misconfiguration affecting AI workloads: $5.25 million
- Malicious model: $4.94 million
- Model evasion: $4.72 million
(Source: IBM)
- Security incidents involving shadow AI more than doubled to 43% from 20%, and those incidents averaged $5.39 million against $4.63 million the prior year. Roughly one in five resulted in a regulatory fine. (Source: IBM)
- 67% of users accessing unauthorized generative AI services did so through non-corporate accounts. (Source: Verizon)
- 68% of breached organizations lacked AI governance to manage AI or detect shadow AI, up from 63%. Only 19% reported coordination between governance and security teams. (Source: IBM)
- 51% of organizations reported financial loss from AI-related breaches, followed by operational disruption and unauthorized access to sensitive data at 44% each. (Source: IBM)
- Breaches involving open-source models averaged $5.63 million against $4.98 million for models trained in-house. (Source: IBM)
- 50% of organizations have deployed AI agents in their SOC. Among them, 56% use agents for threat hunting and 54% for automated response, while only 18% apply them to vulnerability scanning and management. (Source: IBM)
- 74% of organizations rethought if and where they deploy agents in their SOCs after learning of frontier AI model threats. Planned deployment rose to 60% for alert triage from 34%, 52% for penetration testing from 33%, and 37% for vulnerability scanning from 18%. (Source: IBM)
- Less than half of organizations, 46%, secure non-human identities in AI workflows. Among those that do, 55% use machine identity and lifecycle management and 30% apply role-based access controls to service accounts. (Source: IBM)
- Only 26% of organizations have a post-quantum cryptography project underway, 69% have none, and 61% lack controls to monitor and secure cryptographic assets such as keys and certificates. (Source: IBM)
- Within two years, experts expect AI to favor attackers over defenders by 31.7%. (Source: UC Berkeley, cited in IBM)
- 62% of organizations surveyed experienced at least one deepfake attack in the preceding 12 months, and 37% of security leaders personally encountered a deepfake incident during a video call. (Source: Gartner)
- Deepfakes accounted for one in five biometric fraud attempts across more than one billion identity verification events in 195 countries. Deepfaked selfie attempts rose 58% in 2025 and injection attacks rose 40%. (Source: Entrust)
- Resemble AI verified 821 deepfake attacks in H1 2026 from 1,760 news reports, documenting at least 15,736 victims and linking the cases to 3.46 million synthetic files. Its full-year 2025 report recorded 1,567 verified incidents and more than $1.28 billion in documented losses. (Source: Resemble AI)
- Generative AI-enabled fraud losses in the US are projected to reach $40 billion by 2027 from $12.3 billion in 2023, a 32% compound annual growth rate. (Source: Deloitte)
- 85% of breached organizations plan to increase security spending in response to frontier AI model threats, up from 64% before learning of those threats. Planned investment areas lead with hiring skilled specialists at 45%, incident response plans and testing at 43%, and identity and access management at 41%. (Source: IBM)
- Global cybercrime costs are projected to plateau near $12.2 trillion by 2031, implying 2.5% annual growth from 2026 onward. (Source: Cybersecurity Ventures)
8. Workforce & Defense Gaps

- ISC2 declined to publish a workforce gap estimate for the first time in the study’s history, because respondents in both 2024 and 2025 prioritized critical skills over headcount. The 2025 study surveyed a record 16,029 practitioners. (Source: ISC2)
- 95% of respondents reported at least one cybersecurity skills need, 59% described the deficiency as critical or significant, and only 5% believed they were fully resourced on skills. (Source: ISC2)
- 88% of respondents experienced at least one significant cybersecurity event in the past 12 months attributable to a skills shortage. (Source: ISC2)
- 33% of organizations lack the resources to adequately staff their teams, and 29% cannot afford to hire staff with the skills they need. Only 34% agreed their organization has the right number of cybersecurity people. (Source: ISC2)
- Budget cuts affected 36% of organizations and layoffs 24%, each down one percentage point from 2024 after the prior year’s surge. (Source: ISC2)
- 75% of professionals said they were likely to stay with their current organization for the next year, dropping to 66% over two years. (Source: ISC2)
- Among organizations rating themselves insufficiently resilient, 85% also report lacking key people and skills, against 22% among highly resilient organizations. The largest global shortages are in threat intelligence analysts, DevSecOps engineers and identity and access management specialists. (Source: World Economic Forum)
- A security skills shortage added $179,635 to the average breach cost, ranking seventh among 30 cost factors analyzed. (Source: IBM)
- Employee training reduced average breach costs by $196,259, and a DevSecOps approach was the single largest reducer at $253,805. (Source: IBM)
- Hiring skilled specialists became the top planned post-breach investment at 45%, up from 27% the prior year, followed by incident response plans and testing at 43%. (Source: IBM)
- Organizations using AI and automation extensively identified and contained breaches in 215 days against 280 days for those using none, a 65 day difference, and spent $4.00 million per breach against $5.93 million. (Source: IBM)
- Only 36% of breached organizations used security AI and automation extensively, up from 32%. Use in threat prevention lagged at a combined 69% against 77% for investigation. (Source: IBM)
- Internal IT or security teams identified 38% of breaches and closed them in 209 days, 15% faster than the global average of 247 days. Third-party discovery stretched that timeline to 281 days. (Source: IBM)
- Managed security service providers closed breaches in 230 days and produced the lowest average cost of any discovery route at $4.86 million, 2.6% below the global average. (Source: IBM)
- Lack of people or skills was the second most cited operational root cause of ransomware attacks at 58%, behind security gaps at 62%. Human error at 35.3% was the only factor that rose year over year. (Source: Sophos)
- Lack of capacity was cited by 43% of organizations with 100 to 250 employees and still 40% of those with 3,001 to 5,000, showing resourcing pressure does not resolve with scale. (Source: Sophos)
- 99% of ransomware victims that had data encrypted reported lasting repercussions on their IT and security teams. Staff absence due to stress or mental health issues affected 29%, and 21% saw their leadership team replaced. (Source: Sophos)
- 68% of breached organizations lacked AI governance to manage AI or detect shadow AI, and only 19% reported coordination between governance and security teams. (Source: IBM)
- 53% of breached organizations had not encrypted sensitive data at rest and in motion at the time of the breach, and another 10% did not know whether it was encrypted. (Source: IBM)
- 61% of organizations lack controls to monitor and secure cryptographic assets such as keys and certificates across their environment. (Source: IBM)
- In healthcare, 47% cited insufficient budget and 42% insufficient staffing as barriers to preventing attacks. (Source: Ponemon Institute and Proofpoint)
- 76% of healthcare organizations take steps to address employee security awareness, up from 71%. Of those, 63% run regular training programs, 51% monitor employee actions and 41% run phishing simulations. (Source: Ponemon Institute and Proofpoint)
- 97% had MFA enabled in some capacity where compromised credentials caused the ransomware attack, showing deployment gaps rather than absence of the control. (Source: Sophos)
- Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts, and weak passwords and permission misconfigurations took almost eight months to reach 50% resolution. (Source: Verizon)
- Only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38%. (Source: Verizon)
For a deeper look at how often companies test and what they find, see our breakdown of 120+ penetration testing statistics.
9. Cybercrime in Asia
Let’s check out some cybercrime statistics that occurred in different countries in Asia
Cybercrime Statistics for Japan

- Ransomware cases confirmed in Japan reached 123 in the first half of 2026, up 7 year over year and the highest six-month reading since the NPA began half-year tracking in 2020. (Source: Japan Times)
- Small and medium-sized enterprises accounted for 79 of those 123 cases, with large companies making up 31. (Source: Japan Times)
- Restoration took more than a month in over half of H1 2026 cases, 9 cases led to complete business suspension, and damages topped ¥10 million in 60% of cases. (Source: Japan Times)
- The NPA detected about 13,700 cases of suspicious access per day in the first half of 2026, up roughly 50% year over year. (Source: Japan Times)
- Financial losses from online fraud reached ¥175.5 billion in the first half of 2026, up 45%. (Source: Japan Times)
- Japan confirmed 226 ransomware cases across all of 2025, up 4 from 2024 and the second-highest annual total on record. Roughly 60% of victims were small and midsize companies. (Source: Japan Times)
- Among the 149 2025 cases where the ransomware family was identified, Qilin led with 32 cases, followed by LockBit with 19. 8Base appeared in just 1 case after the NPA released a recovery tool and international operations disrupted the group. (Source: Japan Times)
- Phishing reports to the Council of Anti-Phishing Japan grew roughly 1.4 times to a record 2,454,297 in 2025, an increase of about 730,000 over the previous year. (Source: Japan Times)
- Reported fake websites rose by about 300,000 to over 1 million in 2025. (Source: Xinhua)
- Phishing accounted for 90% of illicit money transfer cases, the most common method used. (Source: Xinhua)
- Online banking fraud losses split 55% to individuals and 45% to companies in 2025. Corporate losses surged to roughly ¥4.7 billion, more than quadruple the previous year. (Source: Xinhua)
- Total fraud losses in Japan hit a record ¥324.1 billion in 2025, combining special fraud with social media investment and romance scams. (Source: Japan National Police Agency)
- Special fraud cases rose 31.9% to 27,758 in 2025, producing ¥141.4 billion in losses. Social media investment fraud reached 9,538 cases and ¥127.4 billion, while romance scams totaled 5,604 cases and ¥55.2 billion. (Source: Japan National Police Agency)
- Cryptocurrency featured in 40.2% of social media-related fraud cases and accounted for nearly 48% of total losses. International calls made up about 75% of fraud-related phone activity. (Source: Japan National Police Agency)
- Independent leak-site tracking recorded 134 ransomware incidents affecting Japanese organizations in 2025, a 17.5% increase over 2024, averaging roughly 11 per month. (Source: Cisco Talos)
- Manufacturing accounted for 28% of affected Japanese organizations, followed by automotive at 8%, trading companies at 7%, IT at 6% and education at 5%. (Source: Cisco Talos)
- Qilin was responsible for 22 of those incidents, 16.4% of the Japanese total. (Source: Cisco Talos)
- Asahi Group Holdings took its distribution system offline and reverted to phone orders after a Qilin ransomware attack, while Askul customers lost access to e-commerce platforms. (Source: Insurance Journal)
- The average cost of a data breach in Japan reached $4.01 million in the 2026 reporting period, up from $3.65 million. (Source: IBM)
Cybercrime Stats for India

- Indians reported losses of ₹22,495 crore to cyber fraud in 2025, with cybercrime complaints up 24% year over year. (Source: Ministry of Home Affairs)
- Investment scams accounted for 76% of financial fraud losses in 2025 despite making up only 35% of complaints, indicating a high value per case. (Source: Ministry of Home Affairs)
- 1,03,488 senior citizens filed financial cyber fraud complaints totaling ₹4,005.12 crore in 2025, while 4,63,114 women filed complaints totaling ₹3,764.51 crore, a combined ₹7,769.63 crore. (Source: Ministry of Home Affairs)
- Cybercrime complaints grew from roughly 4.5 lakh in 2021 to over 22 lakh by 2024, and parliamentary data shows 900% growth in complaints between 2021 and 2025. (Source: Ministry of Home Affairs)
- The NCRP portal recorded 3.8 million cyber fraud incidents with total reported losses of ₹36,448 crore from inception through February 28, 2025. Of that, ₹4,381 crore was placed under lien but only ₹60.52 crore was returned to victims. (Source: IndiaSpend)
- Victims recover approximately 2.18% of the losses they report. (Source: CyberPeace Foundation)
- The Citizen Financial Cyber Fraud Reporting and Management System saved more than ₹7,130 crore across more than 23.02 lakh complaints since its 2021 launch. (Source: Ministry of Home Affairs)
- Banks shared over 18.43 lakh suspect identifiers and 24.67 lakh mule bank accounts with I4C, which helped block fraudulent transactions worth ₹8,031.56 crore. (Source: Ministry of Home Affairs)
- Digital arrest scam incidents rose from 39,925 in 2022 to 1,23,672 in 2024, with reported losses climbing from about ₹91 crore to ₹1,935 crore over the same period. (Source: IndiaSpend)
- CERT-In handled over 29.44 lakh cyber incidents in 2025, issuing 1,530 alerts, 390 vulnerability notes and 65 advisories, and publishing 29 CVEs. (Source: Press Information Bureau)
- More than 9.7 lakh cybersecurity incidents were recorded across India’s banking and healthcare sectors during 2025 and the first half of 2026. (Source: Ministry of Electronics and Information Technology)
- CERT-In empanelled 231 certified cybersecurity audit organisations in 2025, with most audits focused on banking, finance, power, energy and transport. (Source: Press Information Bureau)
- Cyber Swachhta Kendra now covers 98% of India’s digital population, has onboarded 1,427 organisations and recorded 89.55 lakh downloads of its free botnet removal tools. (Source: Press Information Bureau)
- CERT-In ran 122 cybersecurity drills and exercises in 2025, plus 32 technical training programmes and 95 awareness sessions, training 20,799 officers and professionals. (Source: Press Information Bureau)
- India’s internet connections reached 100.29 crore in 2025, up from 25.15 crore in March 2014, with average monthly data use per user at 24.01 GB. (Source: Press Information Bureau)
- India’s cybersecurity industry is valued at roughly $20 billion with more than 400 startups and a workforce of 6.5 lakh professionals. (Source: Press Information Bureau)
- The average cost of a data breach in India reached $2.79 million in the 2026 reporting period, up from $2.51 million. (Source: IBM)
- India ranked second among foreign countries filing IC3 complaints in 2025, with 5,879 complaints. (Source: FBI IC3)
- India recorded the highest average weekly attack volume within APAC at 7,684 attacks per organization in 2025. (Source: Check Point)
Cybercrime in Singapore

- Scam and cybercrime cases fell 24.8% to 41,974 in 2025 from 55,810 in 2024. (Source: Singapore Police Force)
- Scams accounted for 88.9% of those cases at 37,308, down 27.6% from 51,501 in 2024. (Source: Singapore Police Force)
- Total scam losses fell 17.9% to S$913.1 million in 2025 from S$1.11 billion in 2024. (Source: Singapore Police Force)
- The median loss per case rose to S$1,644 in 2025 from S$1,389 in 2024, so fewer victims lost more each. (Source: Singapore Police Force)
- The top five scam types by case volume in 2025 were e-commerce scams, phishing scams, job scams, investment scams and government officials impersonation scams. (Source: Singapore Police Force)
- The top five scam types by amount lost were investment scams, government officials impersonation scams, job scams, phishing scams and business email compromise scams. (Source: Singapore Police Force)
- Government officials impersonation scams more than doubled to 3,363 cases in 2025 from 1,504 in 2024, running against the overall decline. (Source: Singapore Police Force)
- E-commerce scams fell 42.5% to 6,703 cases from 11,665, yet losses dropped only 4.6% to S$16.7 million from S$17.5 million. (Source: Singapore Police Force)
- Phishing scams fell to 6,264 cases from 8,552, with losses dropping to S$39.9 million from S$59.4 million. (Source: Singapore Police Force)
- Business email compromise losses fell 60.1% to S$35.3 million from S$88.5 million. (Source: Singapore Police Force)
- Cryptocurrency accounted for about S$182.2 million, or 20.0%, of total scam losses. (Source: Singapore Police Force)
- Self-effected transfers featured in 81.8% of scam cases, down marginally from 82.4%, meaning victims themselves moved the money under manipulation rather than losing account control. (Source: Singapore Police Force)
- 85.2% of scam victims were aged under 65, with adults aged 30 to 49 the most affected group at about 36.1%. Victims over 65 made up about 15% but lost the most per person. (Source: Singapore Police Force)
- Most cases involved losses under S$5,000, and only about 5% of cases involved losses of S$100,000 or more. (Source: Singapore Police Force)
- The Anti-Scam Command recovered about S$140.5 million in 2025, split between S$117.7 million in fiat currency and S$22.8 million in cryptocurrency. (Source: Singapore Police Force)
- Anti-Scam Command and its partners helped victims avert at least S$348 million in further losses, including S$339.7 million in fiat currency and S$8.8 million in cryptocurrency. (Source: Singapore Police Force)
- The Mule Facility Restriction Framework, operational from October 1, 2025, had placed 550 money mules, 801 telco mules and 51 corporate entities under restrictions as of February 9, 2026. (Source: Singapore Police Force)
- Coordinated operations against overseas syndicates led to the arrest of over 47 overseas-based suspects and 194 subjects arrested or traced in Singapore, involving losses of over S$52 million. (Source: Singapore Police Force)
- As of December 31, 2025, at least 479,000 customers had locked close to S$4.4 billion of savings using Money Lock. (Source: Singapore Police Force)
- Insurance services scams emerged as a new scam type in 2025, with 791 cases reported in the first half of the year alone. (Source: Singapore Police Force)
Cyber Attacks in China

- Chinese police cracked 258,000 telecom and online fraud cases nationwide in 2025. (Source: Ministry of Public Security)
- Authorities intercepted 21.707 billion yuan, roughly $3.2 billion, in fraud-linked funds through emergency payment suspension in 2025. (Source: Global Times)
- Police arrested 542 sponsors, heads and key members of fraud syndicates in 2025. (Source: Ministry of Public Security)
- More than 7,600 Chinese nationals suspected of telecom fraud were repatriated from Myawaddy in Myanmar through cooperation with Myanmar, Thailand and Cambodia. (Source: Ministry of Public Security)
- Telecom and online fraud cases in China declined year over year for eight consecutive months from October 2025 through May 2026. (Source: Global Times)
- Ten scam categories account for 85% of all telecom and online fraud cases. Fake order-boosting and rebate schemes are the most prevalent at 25% of cases, while fake online investment products cause roughly 40% of total losses. (Source: Global Times)
- Police cracked approximately 1.74 million telecom and online fraud cases across the 14th Five-Year Plan period from 2021 to 2025. (Source: Ministry of Public Security)
- Joint operations with Myanmar, Thailand and Cambodia dismantled more than 2,000 overseas fraud compounds and captured more than 80,000 suspects over that period. (Source: Ministry of Public Security)
- Campaigns targeting organizations providing support services to fraud groups, including advertising, technology development and money laundering, captured 366,000 suspects including over 3,400 ringleaders. (Source: Ministry of Public Security)
- A crackdown on fraud operations in northern Myanmar’s Kokang region led to the arrest of more than 57,000 Chinese nationals. (Source: Ministry of Public Security)
- The Bai syndicate alone was linked to over 31,000 telecom fraud cases and amassed more than 10.6 billion yuan, about $1.46 billion, in illicit gains while operating 41 large-scale gambling and fraud parks since 2015. (Source: Ministry of Public Security)
- China’s national anti-fraud centre issued 1.8 million early warnings, intercepted nearly 4.7 billion scam calls and 3.4 billion fraudulent text messages, and blocked 315 billion yuan in suspected illicit funds from the start of 2024. (Source: Ministry of Public Security)
- A joint operation with five Southeast Asian nations resolved more than 160 cases, most linked to telecom fraud, and led to the arrest of over 70,000 suspects. (Source: Supreme People’s Procuratorate)
- Microsoft observed 49 nation-state threat events targeting China, placing it below Germany at 74 and well below the United States at 623. (Source: Microsoft)
- HKCERT handled 15,877 security incidents in Hong Kong during 2025, a 27% increase over the prior year. (Source: HKCERT)
Cybercrime Stats for Pakistan

- The NCCIA received 150,542 cybercrime complaints in 2025, of which 81,996 related to financial fraud and 2,974 to WhatsApp account hacking. (Source: Ministry of Interior, National Assembly reply)
- Of the complaints received in 2025, 26,036 were converted into formal inquiries and 1,955 were registered as cases. (Source: Ministry of Interior)
- 2,445 suspects were arrested in 2025, while courts delivered 32 convictions and 122 acquittals. (Source: Ministry of Interior)
- Across four years, the NCCIA logged 523,000 complaints, conducted 414,852 verifications, initiated 80,090 inquiries, registered 5,755 cases and arrested 7,600 suspects. (Source: NCCIA)
- Convictions fell each year over that period: 92 in 2023, 60 in 2024 and 39 in 2025, against 877 acquittals recorded between 2023 and 2026. (Source: NCCIA)
- The NCCIA received 94,552 complaints nationwide over the nine-month period from April to December 2025, according to data obtained under a right to information request. (Source: Dawn)
- Kaspersky detected more than 5.3 million on-device attacks in Pakistan between January and September 2025, roughly one million per month. (Source: Kaspersky)
- 27% of Pakistani users and 24% of corporate networks encountered malware spread through infected USB drives, CDs, DVDs and hidden installers during that period. (Source: Kaspersky)
- Kaspersky blocked over 2.5 million web-based attacks in the same nine months, with 16% of users and 13% of organizations exposed to phishing, exploits, botnets, RDP intrusions and spoofed Wi-Fi networks. (Source: Kaspersky)
- Malware detections in Pakistan broke down as:
- Exploitation attempts stopped: 354,000
- Banking malware detections: 166,000
- Spyware attacks prevented: 126,000
- Backdoors blocked: 113,000
- Password stealers stopped: 107,000
- Ransomware incidents: 42,000
(Source: Kaspersky)
- Seven advanced persistent threat groups were identified targeting Pakistan’s government, intelligence agencies, oil and gas industry and corporate sector. (Source: Kaspersky)
- Pakistan recorded the second lowest share of users attacked by web-borne threats across the Middle East, Turkey and Africa region in Q1 2025. (Source: Kaspersky)
- Exploited flaws in Pakistan included newly disclosed issues in 7-Zip alongside older weaknesses in Microsoft Office, HTML, WinRAR and VLC. (Source: Kaspersky)
- Pakistan’s first national Artificial Intelligence Policy is in the process of being finalised, with deepfake and voice-cloning scams named as a rapidly evolving danger. (Source: Ministry of Interior)
- The NCCIA operates a public reporting portal at nccia.gov.pk and a dedicated cybercrime helpline on 1799. (Source: NCCIA)
10. Cyber Attacks in Europe
As one of the wealthiest and most digitally interconnected regions globally, Europe has become a prime target for cybercriminals seeking financial gain and influence.
With its vast digital infrastructure and economic power, the region faces a growing number of cyber threats.
Let us examine the current landscape of cyberattacks across Europe and evaluate how effectively it is positioned to confront these evolving challenges:
The State of Cybercrime in the UK

- The CSEW estimated 4.5 million incidents of fraud in the year ending March 2026, no statistically significant change from 4.2 million the previous year. (Source: ONS)
- Fraud victims rose 10% to 3.8 million from 3.4 million, and fraud prevalence rose 0.7 percentage points to 7.8% of people aged 16 and over. (Source: ONS)
- Bank and credit account fraud rose 15% to around 2.8 million incidents, while other fraud fell 37% to around 151,000 incidents. (Source: ONS)
- Fraud levels are 32% higher than the earliest comparable year, the year ending March 2017, when the CSEW estimated around 3.4 million incidents. (Source: ONS)
- The CSEW estimated 798,000 incidents of computer misuse in the year ending March 2026, no statistically significant change from the previous year. (Source: ONS)
- Computer misuse is around 55% below the year ending March 2017 estimate of roughly 1.8 million incidents. (Source: ONS)
- Headline CSEW crime totalled 9.6 million incidents, remaining 14% below the 11.2 million recorded in the year ending March 2017, when fraud and computer misuse were first included. (Source: ONS)
- 19% of businesses and 14% of charities were victims of at least one cybercrime in the past year, similar to the previous survey. (Source: Cyber Security Breaches Survey 2025 to 2026)
- The City of London Police launched Report Fraud on 4 December 2025, replacing Action Fraud and the National Fraud Intelligence Bureau as the national reporting point for fraud and cybercrime in England, Wales and Northern Ireland. (Source: ONS)
- Police recorded fraud and computer misuse data were suspended from the year ending March 2026 bulletin while the City of London Police transitions to the new system, so no recorded cybercrime figures exist for that period. (Source: ONS)
- Under the new system, Cifas reports are classified as crimes when they meet Home Office Counting Rules, a change from the previous arrangement where only direct public reports to Action Fraud counted as crimes. (Source: ONS)
- The NCSC handled 204 nationally significant cyber incidents against the UK in the 12 months to August 2025, up from 89 the previous year, with 18 of 429 total incidents classed as highly significant. (Source: NCSC)
- Three vulnerabilities accounted for 29 of the incidents the NCSC worked: CVE-2025-0282 in Ivanti Connect Secure, CVE-2024-47575 in Fortinet FortiManager and CVE-2025-53770 in Microsoft SharePoint Server. (Source: NCSC)
- The average cost of a data breach in the UK reached $4.17 million in the 2026 reporting period, up marginally from $4.14 million. (Source: IBM)
- Microsoft observed 144 nation-state threat events targeting the UK, the second-highest count in Europe after Ukraine at 277. (Source: Microsoft)
- The CSEW year ending March 2026 estimates are based on face-to-face interviews with 31,350 people aged 16 and over. (Source: ONS)
Cybercrime in Germany
- Cybercrime cost the German economy an estimated €202.4 billion in 2025, roughly 4.5% of GDP. (Source: BKA Bundeslagebild Cybercrime 2025)
- The BKA registered 333,922 cybercrime offences in 2025, split into 126,034 domestic cases and 207,888 committed from abroad or from unknown locations. (Source: BKA)
- Foreign-origin offences exceeded domestic offences for the first time, rising 65.1% while domestic cases fell 7.3%. (Source: BKA)
- 1,041 ransomware attacks were reported in 2025, a 10% increase. About 96% targeted companies, organisations and institutions, and roughly 90% hit small and medium-sized enterprises. (Source: BKA)
- Around 76% of ransomware attacks used the double extortion model, combining encryption with the threat of publishing stolen data. (Source: BKA)
- DDoS attacks rose 25% to 36,706 cases in 2025. (Source: BKA)
- Card and payment fraud offences rose 4.8% to 96,383 cases in 2025. (Source: Polizeiliche Kriminalstatistik 2025)
- German police registered around 5.5 million offences of all types in 2025, down 5.6%, with an overall clearance rate of 57.9%. The cybercrime clearance rate sits near 32%, far below that average. (Source: Polizeiliche Kriminalstatistik 2025)
- Total damage from theft, industrial espionage and sabotage reached €289.2 billion in 2025, up €22.6 billion or about 8% from €266.6 billion the prior year, the highest figure Bitkom has recorded. (Source: Bitkom)
- Roughly 70% of that total, about €202.4 billion, is attributed directly to cyberattacks. (Source: Bitkom)
- 87% of German companies were affected by data theft, espionage or sabotage in the past twelve months, with a further 10% suspecting attacks. (Source: Bitkom)
- Ransomware caused damage at 34% of surveyed companies, followed by DDoS at 25% and malware at 24%. 15% of companies have paid a ransom at some point. (Source: Bitkom)
- 73% of affected companies reported that information and production systems were attacked directly, rather than peripheral systems such as websites or individual devices. (Source: Bitkom)
- 46% of companies with a confirmed or suspected attack traced at least one to Russia, and 46% to China. (Source: Bitkom)
- 28% of companies named foreign intelligence services as perpetrators, up from 7% in 2023, a fourfold increase in two years. (Source: Bitkom)
- More than 35% of companies now receive information about their attackers from government authorities, reflecting closer cooperation between security agencies and industry. (Source: Bundesamt für Verfassungsschutz)
- The BSI recorded 950 reported ransomware cases between July 2024 and June 2025, with around 80% affecting small and medium-sized enterprises. (Source: BSI)
- The average cost of a data breach in Germany reached $4.93 million in the 2026 reporting period, an 18% rise from $4.03 million. (Source: IBM)
- Microsoft observed 74 nation-state threat events targeting Germany. (Source: Microsoft)
- The Bitkom study surveyed 1,002 German companies with at least ten employees and annual revenue of €1 million or more, between mid-April and mid-June 2025. (Source: Bitkom)
Cybercrime in France
- ANSSI handled 3,586 security events in 2025, an 18% decrease from 2024, which had been inflated by reporting spikes around the Paris Olympic and Paralympic Games. (Source: ANSSI)
- 1,366 of those were confirmed incidents, meaning ANSSI verified that a malicious actor successfully acted on the victim’s information system. That figure was stable against 2024. (Source: ANSSI)
- 128 ransomware compromises were reported to ANSSI in 2025, down from 141 in 2024, a decline of roughly 9%. (Source: ANSSI)
- Data exfiltration incidents rose more than 50% to 196 from 130, whether or not tied to ransomware. (Source: ANSSI)
- Of 460 events reported as possible data leaks, only 42% could be confirmed. ANSSI’s director general described the remainder as bluff, covering opportunistic claims and recycled data from earlier breaches. (Source: ANSSI)
- Four sectors accounted for 76% of incidents ANSSI handled:
- Education and research: 34%
- Ministries and local authorities: 24%
- Health: 10%
- Telecommunications: 9%
(Source: ANSSI)
- Small, medium and mid-sized companies made up 48% of ransomware victims, followed by local authorities at 11%. (Source: ANSSI)
- Qilin accounted for 21% of identified ransomware strains with more than 700 claimed victims across the year, followed by Akira at 9% and LockBit 3.0 at 5%. More than ten new strains appeared. (Source: ANSSI)
- State-linked groups deployed ransomware for revenue, blurring the line with cybercrime. North Korea-linked Moonstone Sleet used Qilin in targeted attacks, while China-associated operators deployed NailaoLocker and RA World alongside espionage activity. (Source: ANSSI)
- ANSSI recorded a resurgence in malicious repurposing of legitimate tools and services by actors linked mainly to Russia and China, alongside cloud service compromises that encrypted resources and caused temporary outages for French business and consumer services. (Source: ANSSI)
- Cybermalveillance.gouv.fr assisted more than 504,810 victims in 2025, a 20% increase and the highest total since the platform launched, against 28,855 requests in 2018. (Source: Cybermalveillance.gouv.fr)
- Account hijacking became the leading threat for businesses and associations at 21% of assistance journeys, growing 52%. (Source: Cybermalveillance.gouv.fr)
- Wire transfer fraud entered the top three threats for businesses and associations for the first time. (Source: Cybermalveillance.gouv.fr)
- Hacking incidents overall rose 112% year over year, and cyber harassment targeting businesses rose 205%. (Source: Cybermalveillance.gouv.fr)
- Personal data breaches roughly doubled, rising 107%, feeding waves of phishing that impersonated parcel deliveries, orders and bank advisors. (Source: Cybermalveillance.gouv.fr)
- 5,078 local authorities used the 17Cyber assistance service in 2025. Account hijacking displaced phishing as their leading reason for seeking help, at 20.1% of assistance journeys. (Source: Cybermalveillance.gouv.fr)
- A breach of the ANTS public vehicle registration agency exposed 11.7 million accounts, illustrating French public sector exposure. (Source: ANSSI)
- The average cost of a data breach in France reached $4.05 million in the 2026 reporting period, up from $3.73 million. (Source: IBM)
- Microsoft observed 72 nation-state threat events targeting France. (Source: Microsoft)
Check Out Our Other Statistical Research Articles:
- 100+ Compliance Statistics for 2026
- Zero Day Exploit Stats for 2026
- Healthcare Data Breach Stats
- 120+ Penetration Testing Statistics
- 150 Deepfake Stats for 2026
What is Cyber Crime?
Cyber crime, also known as cybercrime, refers to any type of criminal activity that involves the use of computers, computer networks, or other digital technologies to commit or facilitate illicit activities. These crimes can range from the theft of personal and financial data to sophisticated attacks on critical infrastructure, such as power grids or financial systems.
Cyber crimes can be perpetrated by individuals, groups, or even state-sponsored organizations, and they can have severe consequences for individuals, businesses, and society as a whole. The theft of financial data, identity theft, and various forms of online fraud are common examples of cyber crime, highlighting the need for robust cyber security measures to protect sensitive information.
Recent Notable Cyber Attacks
The incidents below define the current threat landscape. What connects most of them is not a novel exploit but a person: a help desk agent talked out of a credential, an employee phished into surrendering a token, or a vendor whose access was simply inherited.
1. Instructure Canvas
The largest breach of the period. ShinyHunters compromised the Canvas education platform operated by Instructure Holdings, generating an estimated 275 million victim notices.
That single event accounted for 58 percent of all US victim notices issued in the first half of 2026 and drove the technology sector to 314.4 million notices, nearly triple its entire 2025 total.
The breach illustrates the multiplier effect of platform compromises: one intrusion cascades across every institution using the software. For the wider volume picture across sectors and years, see our data breach statistics.
2. AT&T
Two separate incidents that get conflated constantly. In January 2024, a dataset surfaced on a hacking forum containing Social Security numbers and account passcodes for roughly 7.6 million current and 65.4 million former account holders, data dating to 2019 or earlier that AT&T initially could not attribute to itself or a vendor.
Separately, in July 2024, a Snowflake-linked intrusion exposed call and text metadata for nearly all AT&T wireless customers covering May through October 2022, an incident for which a hacker was reportedly paid roughly $370,000.
AT&T later paid $13 million to settle an FCC probe over a third-party cloud vendor’s handling of customer data. A threat actor recombined and re-released both datasets in 2025, which is why the incidents resurfaced in coverage as though new.
3. Match Group
ShinyHunters claimed the breach in January 2026, and the reported entry point was not Match Group itself but AppsFlyer, a third-party marketing analytics partner serving Tinder, Hinge and OkCupid.
Our full write-up of the Match Group data breach covers what was exposed and how the vendor relationship created the exposure.
4. Asahi Group Holdings
Qilin ransomware forced Japan’s largest beverage company to take its distribution system offline and revert to processing beer and beverage orders by telephone. The attack landed alongside a separate compromise at office supplier Askul, which cut off e-commerce access for retailers depending on its platform.
Japanese police recorded 226 ransomware cases in 2025 and 123 more in the first half of 2026, the highest six-month figure since half-year tracking began.
5. Jaguar Land Rover
Described as the costliest cyber incident in UK history, the attack caused prolonged production disruption. It arrived alongside ransomware-linked breaches at Marks & Spencer and the Co-op Group, incidents the NCSC cited when reporting 204 nationally significant cyber incidents in the year to August 2025, more than double the previous year’s 89.
6. The FBI Surveillance Network Intrusion
In March 2026, the FBI formally classified a China-linked intrusion into one of its internal surveillance networks as a major incident under federal law. The compromised system held pen register and trap-and-trace data, meaning call patterns, phone numbers and browsing records of people the bureau was actively monitoring.
7. Stryker Wiper Attack
An Iran-aligned hacktivist group hit the medical technology company in March 2026 with destructive malware rather than ransomware. Employees reportedly watched company computers being wiped in real time, forcing offices to close. The attack marks a shift from extortion toward pure disruption in hacktivist operations.
8. PRESSURE CHOLLIMA Cryptocurrency Theft
The North Korea-linked group executed a $1.46 billion cryptocurrency theft, the largest single financial heist ever recorded. DPRK-linked incidents rose more than 130 percent across 2025, with FAMOUS CHOLLIMA activity more than doubling.
9. The Gentlemen
Founded in late 2025 by a former Qilin affiliate, the group jumped from 40 victims in Q4 2025 to 166 in Q1 2026 and 279 in Q2, reaching third place globally. Its scale came from a pre-staged stockpile of roughly 14,700 compromised FortiGate devices. Edge appliances remain the softest target in most environments, and 42 percent of exploited vulnerabilities in 2025 were weaponized before public disclosure, a pattern our zero-day exploit statistics tracks in detail.
10. Under Armour
A breach affecting 72.7 million accounts, the second largest of the first half of 2026. Combined with Canvas, the two incidents alone produced more victim notices than the entire 2025 calendar year.
11. Voice Phishing Against Identity Providers
In April 2026, ShinyHunters used a voice phishing call to persuade an employee at one of the largest US broadband providers to hand over credentials for a Microsoft Entra account. The same technique drove SCATTERED SPIDER’s campaigns, which relied almost exclusively on persuading help desk staff to perform self-service password resets.
Telecom and broadband providers have been repeat targets, as the Brightspeed breach affecting one million customers showed. Voice and SMS phishing now produce the highest average breach cost of any attack vector at $5.29 million.
12. Healthcare Data Breaches
DentaQuest lost health data belonging to 15 million people, the largest known US breach of 2026. CareCloud, which hosts electronic patient records, lost the medical information of at least 3.7 million people, while a breach at billing provider Aesto Health was confirmed to affect at least 9.5 million patients across dozens of practices using its software.
13. 700Credit
The automotive credit reporting provider exposed 5.6 million Social Security numbers, a case that shows how much identity data sits inside specialist vendors most consumers have never heard of. The details are in our coverage of the 700Credit breach.
14. Hasbro
Weeks after discovering intruders in late March 2026, the 103-year-old toymaker remained largely offline with its website unavailable and no ability to serve customers. The case illustrates the gap between detecting an incident and being able to recover from one.
15. Instagram Account Hijacking Via AI Chatbot
Tens of thousands of accounts were taken over in early 2026 by abusing Meta’s AI chatbot. Attackers opened a chat impersonating the target, claimed to be locked out, and asked the chatbot to send a password reset code to an attacker-controlled email address. The hijackings ran for months before anyone noticed.
16. Cl0p and the Oracle E-Business Suite Campaign
Cl0p’s mass exploitation of Oracle E-Business Suite drove much of the Q1 2026 ransomware spike before the group nearly disappeared in Q2. The pattern repeats its earlier MOVEit campaign: find one widely deployed enterprise application, exploit it at scale, and harvest victims in a single burst.
These incidents underscore the evolving nature of cyber threats and the critical importance for organizations to bolster their cybersecurity measures to protect against such sophisticated attacks.
Cyber Crime in the US and UK
Cyber crime is a significant problem in both the US and the UK, with both countries experiencing high levels of cyber attacks and data breaches. According to cyber crime statistics, the US is one of the most targeted countries for cyber attacks, with an estimated 53.35 million US citizens affected by cyber crime in the first half of 2022 alone. The UK is also a major target, with an estimated 32% of UK businesses reporting a cyber attack or data breach in 2023. These statistics highlight the pervasive nature of cyber crime and the urgent need for robust cyber security measures to protect personal and financial data in both countries.
How to Prevent Cyber Crime
Cybercrime can hit anyone, but most threats are preventable. With a few smart habits and tools, you can stay protected. Here’s what to do:
1. Use Strong Passwords and Multi-Factor Authentication (MFA)
Creating complex passwords is your first line of defense. Avoid using common phrases, birthdays, or easily guessable sequences like “123456.” Instead, use a combination of uppercase and lowercase letters, numbers, and symbols.
Don’t reuse passwords across different sites. If one gets exposed, the rest are at risk. Password managers like Bitwarden or 1Password can help you store and generate secure passwords.
Multi-Factor Authentication (MFA) adds a second step, like a text code or app notification, making it much harder for hackers to gain access, even if they know your password.
2. Regularly Update Software and Systems
Cybercriminals often exploit known software bugs. That’s why software companies constantly release patches to close those gaps.
Make sure your operating system, antivirus programs, browsers, and even mobile apps are up to date. Enable auto-updates when possible, and don’t ignore those system restart reminders. They’re usually triggered by important patches.
In a business setting, IT teams should maintain a patch management schedule to ensure all devices are updated consistently.
3. Be Cautious with Emails and Links
Phishing emails remain one of the most common cyberattack methods. These emails often look legitimate and may even appear to come from trusted brands or coworkers.
Always double-check the sender’s email address and look for spelling errors or urgent calls to action like “Click now to avoid suspension.” If it feels off, it probably is.
Hover over links to see where they really lead. If you’re unsure, contact the sender directly through a different channel before clicking anything.
4. Watch for AI Generated Scams and Deepfakes
Fraudsters now use AI to mimic voices, faces, and writing styles. These tools can create fake emails, clone voices in phone calls, or generate realistic videos to impersonate trusted individuals.

Always verify unexpected requests for money, credentials, or sensitive information, especially if they claim urgency. Use a separate and known method to confirm. In workplaces, train employees to recognize AI generated phishing and set up verification steps for wire transfers or password resets.
5. Use Security Software
Install and regularly update antivirus and anti-malware programs. These tools scan your system for known threats, block malicious websites, and even warn you about risky downloads.
Some advanced security suites also offer ransomware protection, a secure VPN, and firewall management. For business use, endpoint protection platforms (EPPs) like CrowdStrike or SentinelOne can help monitor and protect multiple devices at once.
6. Back Up Important Data
If ransomware locks you out of your files, having a recent backup can save you. Backups should be stored in at least two locations: one offline, like an external hard drive, and one online, such as a cloud service.
Schedule regular automatic backups to avoid relying on manual reminders. Make sure you test your backups too. They’re useless if they’re corrupted or incomplete when you need them.
For businesses, using solutions like Veeam or Acronis can help automate and secure backups across your entire network.
7. Secure Your Network
Start with a strong password on your Wi-Fi and ditch the default login credentials. Use WPA3 encryption if your router supports it. Set up a guest network for visitors, and keep smart home devices separate from your work or personal devices.
For businesses, invest in firewalls and virtual private networks (VPNs) to secure remote access. Regularly scan the network for unknown devices or open ports that could serve as entry points.
8. Educate and Train Users
Human error is one of the weakest links in cybersecurity. That’s why regular training is so important. Teach staff and family members how to spot phishing, why they shouldn’t use personal devices for sensitive tasks, and how to report suspicious activity.
Interactive training sessions, phishing simulations, and clear cybersecurity guidelines go a long way in reducing accidental security breaches.
For parents, talk to your kids about safe internet habits. Don’t just install parental controls without explaining why. They need to understand the risks, not just follow rules.
9. Develop and Enforce Security Policies
If you’re running a business, have clear rules about device usage, data access, password protocols, and how to handle sensitive information.
Make sure your employees know what to do if they suspect a breach. Incident response plans should be documented, rehearsed, and updated regularly.
Even for personal use, having your own rules, like never logging into bank accounts on public Wi-Fi, can make a big difference.
10. Monitor and Analyze Network Activity
Use tools like intrusion detection systems (IDS) or intrusion prevention systems (IPS) to monitor real-time traffic and catch threats before they escalate.
For small businesses and tech-savvy individuals, tools like Wireshark, Splunk, or Security Onion can help you track unusual behavior. Look for unexplained spikes in data usage, failed login attempts, or unauthorized access requests.
The sooner you detect suspicious activity, the quicker you can contain it.
11. Collaborate with Authorities and Organizations
If you do get attacked, report it to local authorities or cybersecurity agencies. In the U.S., that’s the FBI’s Internet Crime Complaint Center (IC3). Many other countries have similar bodies.
Businesses should stay connected with cybersecurity organizations and information-sharing groups like ISACs (Information Sharing and Analysis Centers). Being part of these communities can give you early warnings and help you respond more effectively.
The pattern in this data is clear. Attackers are not breaking down doors. They are calling help desks, exploiting gaps nobody patched, and walking in through vendors nobody vetted.
Bright Defense Prevents Cybercrimes
We build continuous compliance programs that keep your controls under watch year-round, so problems surface when they appear rather than when an auditor finds them. We take companies through SOC 2, ISO 27001, HIPAA, CMMC and PCI DSS from first gap assessment to audit, then keep them compliant afterward. Our penetration testing covers network, cloud, API, web application and social engineering surfaces, with findings your engineers can act on and your auditors will accept. And our fractional CISO service gives mid-market companies senior security leadership without the full-time headcount.
We are a boutique firm, not a compliance mill. You work with senior practitioners who learn your environment, not a rotating bench working from a checklist. And we do not disappear once the report is delivered, because compliance that lapses between audits protects nobody.
Book a free consultation and we will show you where you stand against the frameworks your customers are asking about.
FAQ
1. How Much Money Did Victims Report Losing To Cybercrime In The United States Most Recently?
The FBI’s IC3 recorded $20.877 billion in losses from 1,008,597 complaints in 2025, a 26% increase over 2024 and the first year complaint volume passed one million in the center’s 25-year history. The average loss per complaint was $20,699.
2. Which Cybercrime Categories Caused The Biggest Reported Losses In The IC3 Data?
Investment fraud led at $8.65 billion in 2025, followed by business email compromise at $3.05 billion, tech support scams at $2.1 billion, personal data breach at $1.31 billion and confidence or romance fraud at $929 million.
3. Was Ransomware Present In A Large Share Of Data Breaches In Recent Breach Research?
Yes. Verizon’s 2026 DBIR found ransomware in 48% of reviewed breaches, up from 44%. The median ransom paid fell to $139,875 from $150,000, and 69% of victim organizations did not pay, up from 65%.
4. Is Vulnerability Exploitation A Major Initial Access Path In Breaches Right Now?
Yes, and it is now the leading one. Verizon’s 2026 DBIR reports vulnerability exploitation reached 31% of breaches, up from 20%, overtaking credential abuse for the first time in the report’s 19-year history. Credential abuse fell to 13%. Only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38%, with a median time to full resolution of 43 days.
5. What Do UK Government Figures Estimate About Cybercrime Volume For Businesses?
The Cyber Security Breaches Survey 2025/2026 estimates UK businesses experienced approximately 5.19 million cybercrimes of all types in the last 12 months, including roughly 70,000 non-phishing cybercrimes. 19% of businesses were victims of at least one cybercrime, and 43% identified a breach or attack, equating to around 612,000 organisations.
6. I Got An Email Asking To Change Bank Details For An Invoice. What Is The Safest Next Step?
Call the vendor on a number you already hold on file, never one supplied in the email, and confirm the change verbally. Business email compromise cost victims $3.05 billion in 2025, and Microsoft found that 82% to 84% of opening BEC messages are generic conversational bait containing no payment request at all, which is why filters tuned to financial language miss the first contact.
7. I Clicked A Phishing Link And Entered My Password. What Should I Do First?
Change the password immediately on that account and on every account sharing it, prioritising email and banking. Then contact the fraud department for any affected financial account, follow your internal incident process, and set fraud alerts with the credit bureaus if personal accounts are involved. Expect follow-on attempts: unexpected password reset emails, new account alerts, or contact claiming to be from the breached organisation.
8. I Sent Money To A Scammer. What Actions Give The Best Chance Of Stopping Or Reversing It?
Contact your bank or payment provider immediately, report the transfer as fraudulent and request a recall along with any indemnification documents. Then file at ic3.gov with full transaction details. Speed is the deciding factor: the IC3 Recovery Asset Team froze $679 million of $1.16 billion in attempted theft during 2025, a 58% success rate, but that process only works when complaints are filed quickly.
9. What Are The Top 10 Most Common Cybercrimes?
By complaint count in the FBI IC3 2025 report: phishing and spoofing, extortion, investment fraud, personal data breach, non-payment and non-delivery, tech and customer support, business email compromise, identity theft, employment fraud, and confidence or romance fraud.
10. Where Do Most Cyber Incidents Begin?
The commonly cited “more than 90% of attacks start with phishing” figure traces to older awareness material and is not supported by current breach data. Verizon’s 2026 DBIR puts the human element in 62% of breaches and social engineering in 16%, while vulnerability exploitation is the single largest initial access vector at 31%. IBM has found phishing to be the top attack vector for four consecutive years and the costliest at $5.29 million per breach, but “top” is not the same as “90% of everything.”
11. Which Country Is Number 1 In Cyber Security?
Albania leads the National Cyber Security Index with 98.33 out of 100, followed by Canada and Estonia tied at 96.67. The index scores 155 countries and territories across 49 indicators. Germany ranks 13th, the United States 31st and the United Kingdom 42nd. The NCSI measures governmental readiness to prevent and respond to incidents, not how secure a country actually is.
12. What Causes 95% Of All Cybersecurity Breaches?
No credible dataset supports a 95% figure. Verizon’s 2026 DBIR puts the human element, covering error, misuse, stolen credentials and social engineering, at 62% of breaches. IBM attributes 23% of breaches to human error as a root cause, against 55% for malicious or criminal attacks and 22% for IT failure. The 95% number circulates widely but traces back to a single consultancy claim with no published methodology.
13. What Is The Most Commonly Reported Cyber-Enabled Crime Type In The IC3 Complaint Totals?
Phishing and spoofing, with 191,561 complaints in 2025. Complaint volume fell slightly from 193,407 in 2024, but reported losses tripled from $70 million to $215.8 million.
14. How Much Phishing Volume Was Observed In The Most Recent APWG Data?
APWG recorded a 13.8% rise in Q1 2026 from the 853,244 attacks logged in Q4 2025, and identified 766 unique targeted brands during the quarter. For scale on blocked volume rather than unique sites, Microsoft detected approximately 8.3 billion email-based phishing threats in Q1 2026 alone. The two figures measure different things and should not be combined.
15. Which Industries Do Phishers Target Most In Recent APWG Reporting?
Telecom became the most-attacked category in Q1 2026, climbing from 5.9% of all attacks in Q3 2025 to 33%, with URL phishing against the sector up 75% since Q4 2025. Social media and SaaS or webmail remained significant targets.
Add Bright Defense as a Preferred Source on Google


