The Hacker in a
Hoodie Index
Live S&P 500742.09▾0.16% DOW517.94▾0.55% NASDAQ696.06▴0.10% 20 JUL 2026 · CLOSE
Market levels are tracked via ETF proxies: SPY for the S&P 500, DIA for the Dow, QQQ for the Nasdaq. Figures are delayed.
The index
What $100 became · 2014 → 2024

Measured as a return, cybercrime loss has outpaced the S&P 500 by more than five to one.

$100$2,074
in cybercrime loss (IC3) · compounding 35.4% a year
$100$389
in the S&P 500 · total return, $293 after inflation
5.3× Cybercrime loss outgrew the market over the decade. The ratio holds on either basis: $2,074 against $389 in nominal dollars, or $1,563 against $293 once both are adjusted for inflation.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 5.3x multiple does not depend on how inflation is handled: it is the same whether both sides are measured in nominal dollars or both in real ones.
Coming Soon · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Sign Up Now!
The Losses, Side By Side
What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.
The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 2% a year and then fell 9% in 2025.

If the per-event price is roughly flat while the total keeps climbing, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is per breach, shown for shape only, never added to the aggregate lines.

$3M$4M$5M 2014201820222025
The Verifiable Sources
FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.44MLATEST · 2025
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~2%/yr since 2014, and it fell 9% in 2025.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
The SEC’s 8-K Scoreboard · live
28material 8-K disclosures logged · 2026 year to date
All Verified · Item 1.05 and cyber-flagged Item 8.01 filings
This is a count of material cyber incidents disclosed to the SEC, not a measure of total losses for the year. Most incidents never trigger an 8-K, many filings report the event before any dollar figure exists, and private and non-US companies do not file 8-Ks at all. The scoreboard counts disclosed events and never sums their figures.
CLOVER HEALTH INVESTMENTS, CORP. /DEJul 2026
Filing excerpt“Based on preliminary findings from the Company’s investigation, those accounts were assigned to employees who had member visit-scheduling and broker-facing sales functions. The employee accounts had access to certain personally identifiable information and protected health information, but had no access to corporate financial or claims systems. While the investigation is ongoing into the precise nature, scope, and extent of data that was subject to unauthorized access and acquisition, the Company believes that its rapid response successfully contained and terminated the unauthorized access.”
Not yet quantified
VVerifiedFinancial Services
Coca Cola CompanyJul 2026
Filing excerpt“On July 16, 2026, The Coca-Cola Company announced that Fairlife, a $4bn dairy company owned by the Company was hit by a ransomware event. Coca-Cola does not disclose the actual date that the event occurred or the scale of the potential loss but filed an 8k to acknowledge the possibility that this was a material event. This event can only be measured against the disclosure date of 7/16/2026 due to the limited information Coca-Cola shares in their filing. https://techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/”
Not yet quantified
VVerifiedManufacturing
River Financial CorpJun 2026
Since the date of the original filing, River's investigation has progressed. River has determined that an unauthorized threat actor accessed portions of its network and removed certain data from its environment.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedFinancial Services
SR Bancorp, Inc.Jul 2026
Other Events Mercadien, P.C. CPAs ("Mercadien"), which provides internal audit-related services to SR Bancorp, Inc (the "Company") and Somerset Regal Bank (the "Bank"), has discovered a data security incident in which an unauthorized actor accessed and acquired certain files on Mercadien's computer servers.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedFinancial Services
AdaptHealth Corp.Jun 2026
AdaptHealth Corp. (the "Company") is investigating a security incident whereby a threat actor gained unauthorized access to Company systems and exfiltrated certain data therefrom.
SEC 8-K, Item 1.05
Not yet quantified
VVerifiedHealthcare and Life Sciences
Showing the 5 most recent. View the complete ledger of 118 disclosed 8-K incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →
Media Reported Incidents · primary-sourced and attributedGraded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. They are logged individually, with their source and grade, and like everything on this page they are never summed.

Ecopetrol2026-07
The Colombian state-controlled ‌energy company Ecopetrol announced on Friday that a cyberattack resulted in the theft of data tied to about 3,300 user accounts ​and that it could not "guarantee" the breach would ​not have a "material adverse" financial impact.
News: Reuters
Not yet quantified
IInferredEnergy and Utilities
Coca-Cola2026-07
The Coca-Cola Co. said a cyberattack has forced it to temporarily halt its Fairlife milk operations in the U.S. "The full scope, nature, and impacts of the incident are not yet known," Coca-Cola said in a statement. It added that the breach has not affected product quality or safety.
News: CBS News
Not yet quantified
IInferredRetail and Consumer
Abbott2026-07
Abbott did not disclose what kind of information was accessed. The company declined to respond further to MedTech Dive’s request for comment regarding when the attack was discovered and what kind of information was accessed.
News: MedTech Dive
Not yet quantified
IInferredHealthcare and Life Sciences
Centers Lab NJ LLC2026-07
Healthcare diagnostics company Centers Laboratory (Centers Lab NJ LLC) has informed the US government that a data breach discovered nearly one year ago affects more than 540,000 individuals.
News: SecurityWeek
Not yet quantified
IInferredHealthcare and Life Sciences
Mount Royal University2026-07
Mount Royal University Confirms Data Stolen in Ransomware Attack.
News: SecurityWeek
Not yet quantified
IInferredPublic Sector and Education
Showing the 5 most recent. View the complete ledger of 13 media-reported incidents →
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.