158 incidents on the public record·most recent disclosed Jul 31, 2026·updated Aug 5, 2026
The index
What $100 became · 2014 → 2024
Measured as a return, cybercrime loss has outpaced the S&P 500 by more than six to one.
Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.
Hackers in hoodies2014
$100
S&P 500, dividends reinvested
$100
6.05×
Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.
Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr10-year window · 2014–2024
34.2%/yrfull record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100
The gap is still widening
6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Coming Soon · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It
This index is one number from a larger argument: that cybersecurity’s failure is
structural, not technical. The foundations were wrong from the start, but we can rebuild.
Sign Up Now!
The Losses, Side By Side
What we’ve lost, by the numbers
Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous
annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation.
These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a
forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not
disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger,
and noted only here. The trillion-dollar figure is constantly referred to in public messaging and
presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures
has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B
while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the
point out rather than choose.
The consequences that barely moved
Cost per breach barely moved.
Across more than a decade, while aggregate reported losses compounded at double digits, the modeled
cost of a single breach grew about 2% a year and then fell 9% in 2025.
If the per-event price is roughly flat while the total keeps climbing, the growth is in volume and
attack surface, not in severity. That is a finding the headline trillion-dollar number hides.
IBM’s figure is per breach, shown for shape only, never added to the aggregate lines.
The biggest verified lossesGraded · Verified
Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size and never summed. Sort by any column.
The 10 largest of 14 Verified losses · each stated by the company’s own filing · one figure each, never summed · click a heading to sort
30government-record disclosures logged · 2026 year to date
All Verified · SEC 8-K filings and state-regulator breach and enforcement records
This is a count of cyber incidents on the public government record, whether disclosed through an SEC 8-K filing or a state-regulator breach or enforcement notification, not a measure of total losses for the year. Most incidents never reach a public filing or notice, and many records report the event before any dollar figure exists. It counts disclosed events and never sums their figures.
AMGEN INCJul 2026
Filing excerpt“Amgen disclosed that threat actors compromised third-party cloud storage environments containing company information, stealing files that may include patient health information, confidential business data, intellectual property, and research materials. The company has activated its incident response plan, engaged independent forensic experts, and is assessing the full scope of the exposure.”
Filing excerpt“Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment.”
Filing excerpt“HealthStream disclosed that it detected unauthorized activity on its network on July 23, 2026, prompting the company to activate its incident response plan, engage external cybersecurity experts, and notify law enforcement. The investigation determined that a threat actor exfiltrated certain company data, but the company says its cloud-based platforms remain operational and it does not currently expect a material impact to its business or financial results.”
Filing excerpt“Analog Devices disclosed that it identified unauthorized access to certain company systems on June 23, 2026, prompting the company to activate its incident response plan, engage external cybersecurity experts, and notify law enforcement. The investigation determined that certain files were exfiltrated, although the company said it had no evidence the data had been publicly released or misused at the time of filing. Importantly, Analog Devices reported no operational disruption and stated it does not believe the incident is reasonably likely to materially impact its business, operations, or financial condition. The company also revealed it is separately assessing an unrelated cybersecurity matter that surfaced in public reporting on July 26, 2026.”
Stack Sports discovered unauthorized code inside its Sports Affinity payment platform that captured payment-card information entered during checkout. The company operates registration and payment systems used by youth and amateur sports leagues, meaning affected transactions may involve parents paying participation fees for children. The malicious code was reportedly present from May 8 until June 8, 2026, creating a month-long payment-card skimming window. The number of affected customers remains undisclosed, but the platform’s role across youth sports organizations gives the incident a potentially broad consumer impact.
Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. They are logged individually, with their source and grade, and like everything on this page they are never summed.
Minnesota State Officials2026-07
Minnesota officials disclosed a coordinated cyberattack targeting more than 30 community water systems between July 26 and July 27, 2026. Several communities, including Braham, Plymouth, South St. Paul and Maple Plain, reported disruptions to operational technology supporting water treatment, although officials stated there was no impact to drinking water quality or public safety. In Braham, the attack temporarily shut down the city's water treatment plant until operators restored service using manual processes. The incident is one of the largest coordinated cyberattacks against U.S. municipal water systems publicly disclosed to date and underscores the continued targeting of critical infrastructure.
Authorities investigating a coordinated cyberattack against Minnesota water systems
Not yet quantified
AAttested
Unitel2026-07
Angola's largest telecommunications provider suffered a cyberattack that disrupted nationwide voice, mobile data, and internet services just one day before its planned stock market listing. The incident affected more than 21 million subscribers, forcing the company to activate incident response and recovery efforts while services remained degraded. Unitel has not disclosed the attack vector, threat actor, or whether customer data was compromised, but did proceed with their public offering.
Angola's Unitel hit by cyberattack ahead of stock market debut
Not yet quantified
AAttestedTelecommunications
Bank of BarodaJul 2026
State-owned Bank of Baroda (BoB) on Monday, July 27, confirmed a security incident that led to unauthorised access to “certain data” by threat actors. The incident involved comprise of an employee’s email account, Bank of Baroda said. Reports suggest that the exfiltrator dumped 1TB on the internet, for free.
Bank of Baroda confirms data breach, says employee email account compromised in hack
Not yet quantified
AAttestedFinancial Services
Triple-AJul 2026
Triple- A, a Singapore-based company said it unauthorized access on July 25th, 2026 and temporarily placed certain services into maintenance mode for about three hours while it secured the affected infrastructure. Triple-A did not disclose the amount lost or explain how the wallets were compromised. Onchain investigator Specter previously estimated the losses at about $11.8 million.
Triple-A Confirms Treasury Wallet Breach After Reported $11.8M Loss
Not yet quantified
AAttestedFinancial Services
Chick-Fil-AJun 19
According to the notification letter sent to affected customers, hackers launched an automated attack against Chick-fil-A's website and mobile application between June 17 and June 19 using credentials obtained from a third-party source. Chik-Fil-A has not disclosed the number of customers impacted and has filed incident notifications with several State AG offices around the US.
THE RULE
It would be tempting to add these numbers up and put one big total at the top of the page. We do not,
and we never will. Each line measures something different: different victims, different crimes,
different units, overlapping in some places and blind to each other in others. Add them together and
you get a number that means nothing, the kind of headline figure this index was built to refuse. So
the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR
The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.