236 incidents latest Aug 26 updated Aug 27
Coming Fall of 2026 · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Not yet published

Reported cybercrime losses have outgrown the stock market by more than six to one.

The Hacker in a Hoodie Index is the record behind that claim: what individual cyber incidents actually cost, each figure read from the document that reported it.

The index

What $100 became · 2014 → 2024

One hundred dollars, tracked two ways since 2014. The gap is the story.

Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.

Hackers in hoodies
$100
S&P 500, dividends reinvested
$100

Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.

Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100

The gap is still widening

6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
50010001500200025003000 '14'15'16'17'18'19'20'21'22'23'24'25 reporting change first reading, 6.05x IC3 lossS&P 500
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Follow the record

New figures as they clear verification, and word when Built Wrong lands. No more email than the work warrants.

The Losses, Side By Side

What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.

The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 3% a year, from $3.5M in 2014 to a record $4.99M in 2026.

If the per-event price is growing in the low single digits while the total keeps compounding at double digits, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is the cost of one breach, shown here for shape, not added to the totals above.

$0$2M$4M$6M$8M$10M 2014201820222026 $4.99M

The biggest verified losses

Graded · Verified

Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size, never rolled into a single total. Sort by any column.

The 10 largest of 23 Verified losses · each stated by the company’s own filing · one figure each, never added together · click a heading to sort
1UNITEDHEALTH GROUP INC $3.09BFeb 2024Healthcare and Life Sciences
2Coupang, Inc. $410MDec 2025Retail and Consumer
3AUTONATION, INC. $43MJul 2024Retail and Consumer
4Sinqia S.A. $37.7MAug 2025Technology and Software
5HALLIBURTON CO $35MAug 2024Energy and Utilities
6F5, INC. $26.5MOct 2025Technology and Software
7CONDUENT Inc $25MApr 2025Professional and Business Services
8DAVITA INC. $25MApr 2025Healthcare and Life Sciences
9loanDepot, Inc. $24.6MJan 2024Financial Services
10UPBOUND GROUP, INC. $13MJul 2026Professional and Business Services
How each figure is graded VVerifiedthe linked primary document states it AAttesteda published report credits a named source IInferredno direct confirmation; a lead, not a figure The full standard →

On the Government Record · live

35SEC 8-K cyber-incident disclosures logged · 2026 year to date
All Verified · SEC 8-K material cyber-incident filings, Item 1.05 and Item 8.01
This counts the cyber incidents companies disclosed to the SEC on Form 8-K this year — the material-incident filings under Item 1.05 and the cyber events reported under Item 8.01. It is a count of disclosures, not a measure of total losses: most incidents never reach a public filing, and many are reported before any dollar figure exists. The ledger below also carries state-regulator breach and enforcement records, shown for context but not included in this count. It counts disclosed filings and never sums their figures.
A cybersecurity incident on August 25, 2026, knocked out Boston Scientific's order processing and shipping worldwide. The filing names no entry point, no actor, no data type, because the investigation hasn't reached that far yet. When core operations can't survive one unnamed intrusion, the systemic fragility was built in long before the attacker showed up. Global disruption isn't the sign of a sophisticated adversary; it's the sign of a single point of failure wearing a lot of hats.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life Sciences
AestoDec 2025
disclosed by Together Women's Health LLC - Aesto
Together Women's Health filed its breach notice under Aesto, the same vendor whose AWS environment has already surfaced in other patients' notifications this year. The letter names Social Security numbers and two dates in December 2025, and stops there: no stated entry point, no actor, no count of people affected. A filing this thin is its own kind of disclosure. When a vendor keeps reappearing as the common thread across unrelated clinics, the failure isn't in any one exam room; it's in the shared filing cabinet everyone quietly outsourced to.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences
Nutex Health's servers were accessed and drained by an unnamed third party sometime before the August 24, 2026 filing. The entry point unstated, the count unstated, the haul spanning patient, employee, provider, and financial records in one undifferentiated pull. A vague reference to "unauthorized activity involving data stored" on their network. Data didn't steal your data, the adversary did.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business Services
LACMAJul 2025
disclosed by Museum Associates d/b/a Los Angeles Museum of Art
Los Angeles County Museum of Art (LACMA) discovered a breach on Monday, July 7, 2025. Then it took them until February of 2026 to figure out what go stolen (LACMA, Louvre much?). Then it took them until August 24, 2026 to post the incident with the California AG and on their on website. What's missing in the AG report? All the sensitive data types that were stolen.
California AG breach notification
Not yet quantified
VVerified
ZeroStack Corp. disclosed a material cybersecurity incident under Item 8.01 (other events), not as a 1.05 (material incident), and the filing states nothing further: no entry point, no actor, no data type, no scope. That silence is itself the finding, since a disclosure obligation triggered by materiality has been met while the architecture that produced the exposure remains hidden. A filing can satisfy the law without telling anyone what actually failed.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedWholesale and Distribution
Showing the 5 most recent. View the complete ledger of 175 government-record incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →

Beyond the Filings

Graded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. Each is logged on its own, with its source and grade, and like every figure here it stands alone, never combined into a total.

Sotheby's International, a luxury real estate firm, reported it is investigating a cyber security incident involving unauthorized access to data held in a third-party software platform used to store marketing contact information. The company said the person who accessed the data claimed to have obtained 1.6 million contacts but it refuted that claim because it did not have that many on its database. Regardless of the number, given Sotheby's clientele, even marketing data seems to be a valuable haul from a valuable brand.
Luxury real estate firm hit by cyber security attack
Not yet quantified
AAttestedRetail and Consumer
disclosed by Conwy Mind
A North Wales mental health charity confirms sensitive data was accessed, informing their clients that their trusted provider Beacon CRM had experienced a breach on 7/29/2026 that affected many of Beacon's non-profit clients.
Cyber attack on North Wales mental health charity sees sensitive data accessed
Not yet quantified
AAttestedPublic Sector and Education
The notice attached to this incident reads "to review," which means the source confirms nothing beyond a name and a date: not the vector, not the actor, not what was reached, not how many were affected. Apollo Global sits in the Index with a placeholder where an accounting should be. An institution's disclosure obligation is itself a control point, and a statement that has not yet been given is not transperancy, especially for customers. .
Apollo Global reveals data breach after hackers target financial firms
Not yet quantified
AAttestedFinancial Services
AlationAug 2026
AI data giant Alation confirmed a cyberattack, and the headline confirms nothing else: no entry point, no actor, no data type, no count of records or systems touched. That leaves a data-governance vendor built to sit inside other companies' data stacks, cataloging and connecting sensitive information as its core function, now acknowledging compromise without saying what that position exposed.
Alation Confirms Cyberattack: What Security Teams Need to Know
Not yet quantified
AAttestedTechnology and Software
A state Medicaid portal exposed data on 41,000 members. Per usual, the state and their auditor declared that "no social security numbers were taken" but the laundry list of other data elements stolen suggest a ready-made-cookbook for use in other forms of targeted consumer attacks such as social engineering and financial scams.
State says data from 41,000 Medicaid members exposed in portal breach
Not yet quantified
AAttestedPublic Sector and Education
Showing the 5 most recent. View the complete ledger of 61 media-reported incidents →

The record by sector

From the ledger
FROM THE LEDGER · INCIDENT COUNT · n = 232 incidents
Which sectors the tracked incidents fall in: a count of incidents, not a total of dollars. Each bar is that sector’s share of the 232 on the record, ranked; a floor, not a census.

Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.

See all 13 sectors and the full method →

The Verifiable Sources

FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.99MLATEST · 2026
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~3%/yr since 2014, to a record $4.99M in 2026.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.