295 incidents latest Sep 18 updated Sep 19
Coming Fall of 2026 · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Not yet published

Reported cybercrime losses have outgrown the stock market by more than six to one.

The Hacker in a Hoodie Index is the record behind that claim: what individual cyber incidents actually cost, each figure read from the document that reported it.

The index

What $100 became · 2014 → 2024

One hundred dollars, tracked two ways since 2014. The gap is the story.

Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.

Hackers in hoodies
$100
S&P 500, dividends reinvested
$100

Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.

Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100

The gap is still widening

6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
50010001500200025003000 '14'15'16'17'18'19'20'21'22'23'24'25 reporting change first reading, 6.05x IC3 lossS&P 500
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Follow the record

New figures as they clear verification, and word when Built Wrong lands. No more email than the work warrants.

The Losses, Side By Side

What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.

The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 3% a year, from $3.5M in 2014 to a record $4.99M in 2026.

If the per-event price is growing in the low single digits while the total keeps compounding at double digits, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is the cost of one breach, shown here for shape, not added to the totals above.

$0$2M$4M$6M$8M$10M 2014201820222026 $4.99M

Featured

From the ledger

The biggest verified losses

Graded · Verified

Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size, never rolled into a single total. Sort by any column.

The 10 largest of 28 Verified losses · each stated by the company’s own filing · one figure each, never added together · click a heading to sort
1UNITEDHEALTH GROUP INC $3.09BFeb 2024Healthcare and Life Sciences
2Coupang, Inc. $410MDec 2025Retail and Consumer
3UNITED NATURAL FOODS INC $400M est.Jun 2025Wholesale and Distribution
4AUTONATION, INC. $43MJul 2024Retail and Consumer
5EVERTEC, Inc. $37.7MAug 2025Technology and Software
6HALLIBURTON CO $35M est.Aug 2024Energy and Utilities
7F5, INC. $26.5MOct 2025Technology and Software
8CONDUENT Inc $25MApr 2025Professional and Business Services
9DAVITA INC. $25MApr 2025Healthcare and Life Sciences
10loanDepot, Inc. $24.6MJan 2024Financial Services
How each figure is graded VVerifiedthe linked primary document states it AAttesteda published report credits a named source IInferredno direct confirmation; a lead, not a figure The full standard →

On the Government Record · live

39SEC 8-K cyber-incident disclosures logged · 2026 year to date
All Verified · SEC 8-K cyber-incident filings, Item 1.05, Item 8.01, and Item 7.01
This counts the cyber incidents companies disclosed to the SEC on Form 8-K this year — the material-incident filings under Item 1.05, the cyber events reported under Item 8.01, and cyber disclosures made under Item 7.01 (Regulation FD). It is a count of disclosures, not a measure of total losses: most incidents never reach a public filing, and many are reported before any dollar figure exists. The ledger below also carries state-regulator breach and enforcement records, shown for context but not included in this count. It counts disclosed filings and never sums their figures.
Not yet quantified
VVerified
Opportune LLP's attorney general filing states that a breach occurred and stops there: no vector, no record count, no data type, no incident date. The only detailed account comes from the bad guy. Chaos, the ransomware group that claims to hold the firm's entire internal data environment, is using it as leverage. A filing that outsources its own facts to the extortionist has already lost the room. The control point here was disclosure itself, and Opportune ceded it to the attacker's press release.
Energy and Utilities
California AG breach notification
Initial attack type not disclosed · Impact ransomware inferred + data extortion · Actor Chaos
Not yet quantified
VVerified
CallOnDoc's entire explanation to California regulators for over 1.1 million exposed patient records was one sentence: unauthorized access, discovered December 28, 2025. No attack vector named, no control point identified, just a date and a headcount. What leaked was not card numbers but diagnoses, prescriptions, and contact details, the full shape of a patient's medical life. A database of that size sitting reachable enough for a dark web seller called iProfessor to resell it is not a misfortune; it is a filing cabinet with no lock and no protections open for anyone who could get to it.
Healthcare and Life Sciences
California AG breach notification
Initial attack type not disclosed · Impact data theft confirmed · Actor iProfessor
Not yet quantified
VVerified
Leggett & Platt's benefit plan data was exposed sometime in October 2025, filed with California regulators nearly a year later. As with almost all filings about data being stolen, no details are provided: only a courtesy notice that a breach happened and someone eventually wrote it down. A filing that omits its own mechanism is still an admission that no one was watching closely enough to describe it.
Professional and Business Services
California AG breach notification
Initial attack type not disclosed · Impact data theft inferred
Not yet quantified
VVerified
Tarter Krinsky & Drogin's filing with the California Attorney General names a two-day window in September 2025 and stops there. No vector, no actor, no count, no data type: the notice confirms a breach happened without saying what happened. Yet another regulatory required disclosure that discloses absolutely nothing. Feels like the transparency we need, right?
Professional and Business Services
California AG breach notification
Initial attack type not disclosed · Impact data theft inferred
Not yet quantified
VVerified
Alliance Environmental Group's April 2026 incident reached the California Attorney General five months later, with the filing still marked draft pending operator summary. With zero details other than informing customers that their data had been stolen, the notice describes a reporting obligation met, not a breach explained.
Professional and Business Services
California AG breach notification
Initial attack type not disclosed · Impact data theft confirmed
Showing the 5 most recent. View the complete ledger of 210 government-record incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →

Beyond the Filings

Graded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. Each is logged on its own, with its source and grade, and like every figure here it stands alone, never combined into a total.

GyazoSep 2026
Not yet quantified
AAttested
An unpatched flaw in Gyazo's own image upload server let an attacker run arbitrary commands and walk into the database behind it: 23.62 million accounts, their password hashes, and roughly 490 million image metadata records, most from links minted in 2019 or earlier. The upload server was never meant to be the database's front door, but nothing stood between the two to prevent it. The attacker also lifted the list marking which images were private, and Helpfeel cannot say those images went unseen. Calling an image link 'private' was a label, not an actual lock.
Technology and Software
Gyazo breach exposes 23.62 million user records and 490 million image records - PII and metadata exposed in huge attack
Initial attack type software vulnerability inferred
Not yet quantified
AAttested
Premier Medical Group's notice never names an entry point: only that systems were disrupted in June, and files were pulled on June 14, exposing over 280,000 patients' names, diagnoses, medications, and insurance details. The attack vector is absent from the story, and that absence says everything about the brokenness of cybersecurity. PMG's fix is to have patients audit their own insurance statements for services they never received. Reviewing bills is not incident response; it's handing the actual victims a homework job and transferring the damage accountability to the very people PMG let down.
Healthcare and Life Sciences
280,000 Impacted by Premier Medical Group Data Breach
Initial attack type not disclosed · Impact data theft confirmed + operational outage
MEOSep 2026
Not yet quantified
AAttested
MEO called it a 'mass attack' and left it there: no vector named, no actor named, just service disruption and international congestion that also hit Vodafone, NOS, and Digi on the same day. That spread points at shared network infrastructure as the actual failure domain, not a single company's bad luck. 'No customer data breach' is the easiest claim to make when the statement never says what kind of attack this was.
Telecommunications
MEO hit by cyberattack
Initial attack type not disclosed · Impact operational outage confirmed
TelusSep 2026
Not yet quantified
AAttested
Telus Digital's systems suffered another unauthorized access after disclosing a massive breach in March of this year. What data was taken and how many people it touched remain unstated by anyone with the authority to say. The March attack involved stolen Google Cloud Platform tokens via a third-party vendor. The September event was facilitated through compromised user/account credentials. Telus seems to have some serious identity issues.
Telecommunications
Telus confirms 'unauthorized access' to customers' information | Daily Hive
Initial attack type compromised credentials confirmed · Impact data theft inferred
Not yet quantified
AAttested
FLHSMV blames one compromised credential: a Plant City Police Department login stored on an employee's personal device. ShinyHunters tells a different story. They claim it was an exploited password reset flaw run across multiple DMV and FBI accounts since September 3. Tomato, Tomatoh. The DAVID database's security perimeter turned out to be one officer's personal device. The record count, over 200,000 by the hackers' claim, remains unconfirmed. The breach was also confirmed by the bad guys days before Florida admitted it.
Public Sector and Education
Florida confirms DMV database breached via stolen police account
Initial attack type compromised credentials confirmed · Impact data theft inferred · Actor ShinyHunters
Showing the 5 most recent. View the complete ledger of 85 media-reported incidents →

The record by sector

From the ledger
FROM THE LEDGER · INCIDENT COUNT · n = 295 incidents
Which sectors the tracked incidents fall in: a count of incidents, not a total of dollars. Each bar is that sector’s share of the 295 on the record, ranked; a floor, not a census.

Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.

See all 14 sectors and the full method →

The Verifiable Sources

FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.99MLATEST · 2026
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~3%/yr since 2014, to a record $4.99M in 2026.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.