The Hacker in a
Hoodie Index
Last close S&P 5007,411.98▾0.61% DOW51,947.25▾0.38% NASDAQ24,975.82▾2.13% 24 JUL 2026 · CLOSE
158 incidents on the public record most recent disclosed Jul 31, 2026 updated Aug 5, 2026
The index
What $100 became · 2014 → 2024

Measured as a return, cybercrime loss has outpaced the S&P 500 by more than six to one.

Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.

Hackers in hoodies
$100
S&P 500, dividends reinvested
$100

Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.

Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100

The gap is still widening

6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
50010001500200025003000 '14'15'16'17'18'19'20'21'22'23'24'25 reporting change first reading, 6.05x IC3 lossS&P 500
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Coming Soon · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Sign Up Now!
The Losses, Side By Side
What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.
The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 2% a year and then fell 9% in 2025.

If the per-event price is roughly flat while the total keeps climbing, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is per breach, shown for shape only, never added to the aggregate lines.

$3M$4M$5M 2014201820222025
The biggest verified lossesGraded · Verified

Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size and never summed. Sort by any column.

The 10 largest of 14 Verified losses · each stated by the company’s own filing · one figure each, never summed · click a heading to sort
1UNITEDHEALTH GROUP INC $2.2BFeb 2024Healthcare and Life Sciences
2AUTONATION, INC. $43MJul 2024Retail and Consumer
3HALLIBURTON CO $35MAug 2024Energy and Utilities
4CONDUENT Inc $25MApr 2025Professional and Business Services
5DAVITA INC. $25MApr 2025Healthcare and Life Sciences
6loanDepot, Inc. $24.6MJan 2024Financial Services
7WEST PHARMACEUTICAL SERVICES INC $7MMay 2026Healthcare and Life Sciences
8GROUP 1 AUTOMOTIVE INC $5.9MJun 2024Retail and Consumer
9The University of Phoenix, Inc. $5.1MDec 2025Public Sector and Education
10ARTIVION, INC. $4.6MDec 2024Healthcare and Life Sciences
On the Government Record · live
30government-record disclosures logged · 2026 year to date
All Verified · SEC 8-K filings and state-regulator breach and enforcement records
This is a count of cyber incidents on the public government record, whether disclosed through an SEC 8-K filing or a state-regulator breach or enforcement notification, not a measure of total losses for the year. Most incidents never reach a public filing or notice, and many records report the event before any dollar figure exists. It counts disclosed events and never sums their figures.
AMGEN INCJul 2026
Filing excerpt“Amgen disclosed that threat actors compromised third-party cloud storage environments containing company information, stealing files that may include patient health information, confidential business data, intellectual property, and research materials. The company has activated its incident response plan, engaged independent forensic experts, and is assessing the full scope of the exposure.”
Not yet quantified
VVerifiedHealthcare and Life Sciences
River Financial CorpJun 2026
Filing excerpt“Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment.”
Not yet quantified
VVerifiedFinancial Services
HEALTHSTREAM INCJul 2026
Filing excerpt“HealthStream disclosed that it detected unauthorized activity on its network on July 23, 2026, prompting the company to activate its incident response plan, engage external cybersecurity experts, and notify law enforcement. The investigation determined that a threat actor exfiltrated certain company data, but the company says its cloud-based platforms remain operational and it does not currently expect a material impact to its business or financial results.”
Not yet quantified
VVerifiedTechnology and Software
ANALOG DEVICES INCJun 2026
Filing excerpt“Analog Devices disclosed that it identified unauthorized access to certain company systems on June 23, 2026, prompting the company to activate its incident response plan, engage external cybersecurity experts, and notify law enforcement. The investigation determined that certain files were exfiltrated, although the company said it had no evidence the data had been publicly released or misused at the time of filing. Importantly, Analog Devices reported no operational disruption and stated it does not believe the incident is reasonably likely to materially impact its business, operations, or financial condition. The company also revealed it is separately assessing an unrelated cybersecurity matter that surfaced in public reporting on July 26, 2026.”
Not yet quantified
VVerifiedTechnology and Software
SPay Inc dba Stack SportsMay 2026
Stack Sports discovered unauthorized code inside its Sports Affinity payment platform that captured payment-card information entered during checkout. The company operates registration and payment systems used by youth and amateur sports leagues, meaning affected transactions may involve parents paying participation fees for children. The malicious code was reportedly present from May 8 until June 8, 2026, creating a month-long payment-card skimming window. The number of affected customers remains undisclosed, but the platform’s role across youth sports organizations gives the incident a potentially broad consumer impact.
California AG breach notification
Not yet quantified
VVerifiedTechnology and Software
Showing the 5 most recent. View the complete ledger of 131 government-record incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →
Beyond the FilingsGraded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. They are logged individually, with their source and grade, and like everything on this page they are never summed.

Minnesota State Officials2026-07
Minnesota officials disclosed a coordinated cyberattack targeting more than 30 community water systems between July 26 and July 27, 2026. Several communities, including Braham, Plymouth, South St. Paul and Maple Plain, reported disruptions to operational technology supporting water treatment, although officials stated there was no impact to drinking water quality or public safety. In Braham, the attack temporarily shut down the city's water treatment plant until operators restored service using manual processes. The incident is one of the largest coordinated cyberattacks against U.S. municipal water systems publicly disclosed to date and underscores the continued targeting of critical infrastructure.
Authorities investigating a coordinated cyberattack against Minnesota water systems
Not yet quantified
AAttested
Unitel2026-07
Angola's largest telecommunications provider suffered a cyberattack that disrupted nationwide voice, mobile data, and internet services just one day before its planned stock market listing. The incident affected more than 21 million subscribers, forcing the company to activate incident response and recovery efforts while services remained degraded. Unitel has not disclosed the attack vector, threat actor, or whether customer data was compromised, but did proceed with their public offering.
Angola's Unitel hit by cyberattack ahead of stock market debut
Not yet quantified
AAttestedTelecommunications
Bank of BarodaJul 2026
State-owned Bank of Baroda (BoB) on Monday, July 27, confirmed a security incident that led to unauthorised access to “certain data” by threat actors. The incident involved comprise of an employee’s email account, Bank of Baroda said. Reports suggest that the exfiltrator dumped 1TB on the internet, for free.
Bank of Baroda confirms data breach, says employee email account compromised in hack
Not yet quantified
AAttestedFinancial Services
Triple-AJul 2026
Triple- A, a Singapore-based company said it unauthorized access on July 25th, 2026 and temporarily placed certain services into maintenance mode for about three hours while it secured the affected infrastructure. Triple-A did not disclose the amount lost or explain how the wallets were compromised. Onchain investigator Specter previously estimated the losses at about $11.8 million.
Triple-A Confirms Treasury Wallet Breach After Reported $11.8M Loss
Not yet quantified
AAttestedFinancial Services
Chick-Fil-AJun 19
According to the notification letter sent to affected customers, hackers launched an automated attack against Chick-fil-A's website and mobile application between June 17 and June 19 using credentials obtained from a third-party source. Chik-Fil-A has not disclosed the number of customers impacted and has filed incident notifications with several State AG offices around the US.
Newsweek
Not yet quantified
AAttestedRetail and Consumer
Showing the 5 most recent. View the complete ledger of 27 media-reported incidents →
The Verifiable Sources
FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.44MLATEST · 2025
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~2%/yr since 2014, and it fell 9% in 2025.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.