www.swif.ai/blog/cybersecurity-statistics
Help Center

150+ Cyber Security Statistics and Insights for 2026 (Updated August)

Human Written & Fact Checked

Cite this Webpage

Copy

Cybercrime cost the global economy an estimated $10.5 trillion in 2025 and is on track to reach $15.63 trillion by 2029, according to projections tracked by Statista. Victims in the United States alone reported $20.88 billion in losses to the FBI's Internet Crime Complaint Center in 2025, a 26% jump in a single year. And the average data breach now costs $4.44 million globally and a record $10.22 million in the US, per IBM's 2025 Cost of a Data Breach Report.

Behind those headline figures, the shape of the threat is changing fast. Third-party and supply chain compromise doubled its share of breaches in a single year. Shadow AI is quietly adding hundreds of thousands of dollars to breach costs. And ransomware crews have fragmented into more groups extorting more victims than ever.

This page collects the cyber security statistics that IT leaders, security teams, compliance officers, and the journalists who cover them are most likely to need in 2026, categorized by topic, with every number linked to its original source.

Methodology

We reviewed the major annual threat and breach reports published between mid-2025 and mid-2026, including IBM's Cost of a Data Breach Report, the Verizon Data Breach Investigations Report, the FBI IC3 Internet Crime Report, the World Economic Forum's Global Cybersecurity Outlook, Check Point's Cyber Security Report, Sonatype's State of the Software Supply Chain, and research from government bodies including the US GAO, CISA, and the Bureau of Labor Statistics. Every statistic below is attributed inline to the organization that originally published it, with the year the figure covers. Where a report is updated annually, we use the most recent edition available as of mid-2026; older figures are labeled with their year.

Key Cyber Security Statistics for 2026

  • Cybercrime cost the world an estimated $10.5 trillion in 2025, with projections reaching $13.82 trillion by 2028 and as high as $15.63 trillion by 2029. (Statista)
  • The average cost of a data breach is $4.44 million globally in 2025, the first decline in five years, while the US average hit a record $10.22 million. (IBM Cost of a Data Breach Report 2025)
  • Americans reported $20.877 billion in cybercrime losses across 1,008,597 complaints in 2025, up 26% from the $16.6 billion record set in 2024. (FBI IC3 2025 Internet Crime Report)
  • Third-party involvement in breaches doubled from 15% to 30% in a single year, the largest single-year shift the report has ever recorded, making supply chain compromise the defining intrusion pattern of 2025 and 2026. (Verizon 2025 Data Breach Investigations Report)
  • Organizations faced an average of 1,968 cyberattacks per week in 2025, an 18% increase year over year and a 70% increase since 2023. (Check Point Cyber Security Report 2026)
  • 44% of breaches now involve ransomware, up 37% from the prior year, and ransomware damage costs are forecast to reach $74 billion in 2026. (Verizon 2025 DBIR; Cybersecurity Ventures)
  • More than 454,600 new malicious open source packages were logged in 2025 alone, a 75% year-over-year increase, pushing the cumulative total past 1.23 million. (Sonatype 2026 State of the Software Supply Chain)
  • 94% of leaders say AI is the most significant driver of cybersecurity change in 2026, and 87% identify AI-related vulnerabilities as the fastest-growing cyber risk. (World Economic Forum Global Cybersecurity Outlook 2026)
  • Shadow AI added an average of $670,000 to breach costs at organizations with high levels of unsanctioned AI use, and 97% of AI-related breaches occurred at organizations lacking AI access controls. (IBM 2025)
  • 60% of breaches involve a human element, and 98% of cyberattacks involve some form of social engineering. (Verizon 2025 DBIR; Okta)
  • The cybersecurity workforce gap sits near 4.8 million unfilled roles globally, with roughly 515,000 open positions in the US alone. (Statista; CyberSeek)
  • Global information security spending is forecast to reach roughly $240 billion in 2026, up about 12.5% from 2025's estimated $183.9 billion to $212 billion range. (Fortune Business Insights; Gartner)

Show Image

The Cost of Cybercrime in 2026

The macro numbers keep setting records, and the gap between reported losses and true economic damage keeps widening.

  • Global cybercrime costs reached an estimated $10.5 trillion annually in 2025 and could climb to $15.63 trillion by 2029; an interim projection puts the figure at $13.82 trillion per year by 2028. (Statista)
  • The IMF has warned cybercrime could cost the world $23 trillion by 2027, a 175% increase from 2022, as attack frequency has doubled since the COVID-19 pandemic. (US State Department briefing on IMF estimates)
  • US cybercrime losses reported to the FBI hit $20.877 billion in 2025, up 26% year over year, with complaints crossing 1 million for the first time and averaging almost 3,000 per day. Cumulative reported losses since 2020 exceed $71.3 billion. (FBI IC3 2025)
  • The average reported loss per IC3 complaint in 2025 was $20,699. Cryptocurrency-linked complaints drove the highest losses at more than $11 billion across 181,565 complaints, and investment fraud accounted for nearly 49% of all scam-related losses at $8.6 billion. (FBI IC3 2025)
  • Americans over 60 reported approximately $7.7 billion in losses in 2025, up 37% from 2024. (FBI IC3 2025)
  • AI-related cybercrime made its official IC3 debut in 2025, with roughly 22,000 complaints and nearly $900 million in associated losses recorded for the first time. (FBI IC3 2025)
  • Business owners rank cyber incidents as the single biggest threat to their business at 34%, ahead of natural disasters and any other cause of loss. (Allianz Risk Barometer)
  • Firms lose up to 1.3% of their market value in the month following a cyberattack. (American Enterprise Institute)
  • Among businesses hit by attacks, 52% lost more than 5% of total revenue, and 15% lost more than 10% of annual revenue from a single incident, while roughly six in ten raised prices to recover cyberattack costs. (VikingCloud 2025 Cyber Threat Landscape Report; IBM)
  • Ransomware downtime costs businesses an average of $53,000 per hour, and DDoS downtime averages $6,130 per minute. (Pentest People; Security Magazine, citing Radware)
  • MKS Instruments, a semiconductor vendor, reported a $200 million revenue hit from a single ransomware attack, an example of how one incident can dwarf the ransom itself. (IMF)
  • California leads US states in cybercrime victim losses at roughly $2.16 billion per year, followed by Texas ($1.02 billion), Florida ($875 million), New York ($750 million), and New Jersey ($441 million). (FBI IC3)

Data Breach Statistics for 2026

The cost curve finally bent downward globally in 2025, but US costs, detection gaps, and record exposure counts all moved the wrong way.

  • The global average cost of a data breach fell 9% to $4.44 million in 2025, down from $4.88 million in 2024, the first decline in five years, driven largely by faster AI-assisted detection and containment. (IBM Cost of a Data Breach Report 2025)
  • The average US breach now costs a record $10.22 million, up 9% year over year and more than double the global average, with regulatory penalties and detection escalation costs the main drivers. The Middle East ($7.29 million) and Benelux ($6.24 million) follow. (IBM 2025)
  • The average breach lifecycle dropped to 241 days in 2025 (181 days to identify plus 60 to contain), the shortest in nine years, but breaches involving stolen credentials still take longest to resolve. Companies that contain breaches inside 200 days save more than $1 million versus those that do not. (IBM 2025)
  • Organizations using security AI and automation extensively saved $1.9 million per breach and detected incidents 80 days faster; earlier editions put the annual savings at $2.2 million. (IBM 2025)
  • Customer personally identifiable information was compromised in 53% of breaches, the most frequently stolen data type, while intellectual property carries the highest per-record cost at $178. (IBM 2025)
  • The use of stolen credentials appears in up to 31% of breaches over the past decade, and roughly 20% of breaches begin with vulnerability exploitation, a vector that grew 34% year over year. (Verizon DBIR)
  • 60% of breaches involve a human element, whether error, stolen credentials, or social engineering; older studies attributed as much as 88% to 95% of incidents to human error. (Verizon 2025 DBIR; Infosecurity Magazine)
  • US data compromises surged 72% between 2021 and 2023 to a record 3,205 incidents affecting over 353 million individuals, up from 614 annual incidents a decade earlier; more than 1.35 billion people worldwide were affected by data compromises in 2024. (Identity Theft Resource Center; Statista)
  • More than 2.6 billion personal records were compromised in data breaches between 2021 and 2023. (Apple)
  • 82% of detections in 2025 were malware-free, meaning attackers relied on stolen credentials and legitimate tools rather than detectable malicious software. (CrowdStrike 2026 Global Threat Report)
  • Mega-breaches remain routine: Ticketmaster saw 560 million customer records compromised, the MOVEit vulnerability exposed more than 93 million sensitive records across education, health, and finance, and the 2021 RockYou leak of 8.4 billion passwords remains the largest credential dump on record. (BBC; Cybersecurity Dive; Clear Insurance)
  • 9% of publicly traded US companies reported a breach in a single year, impacting 143 million people. (Security Intelligence)
  • Only 49% of organizations planned to increase security investment following a breach in 2025, down sharply from 63% in 2024, a sign of post-breach fatigue that worries insurers and regulators alike. (IBM 2025)

Ransomware Statistics for 2026

Ransomware is fragmenting, industrializing, and getting more expensive even as fewer victims pay.

  • 44% of breaches analyzed in the 2025 DBIR involved ransomware, up 37% from the prior year, and 62% of financially motivated incidents involved ransomware or extortion with a median loss of $46,000 per breach. (Verizon 2025 DBIR)
  • Global ransomware damage costs are forecast to reach $74 billion in 2026, with an attack on a business or consumer projected every 2 seconds by 2031. (Cybersecurity Ventures)
  • Extorted ransomware victims rose 53% year over year in 2025, and new ransomware-as-a-service groups grew 50%, with more than half of victims based in the United States. (Check Point Cyber Security Report 2026)
  • Ransomware attacks jumped 48% year over year in May 2026 alone, with 698 published attacks across 61 active groups; Qilin led with 14% of published attacks, and the market is now so fragmented that 58 additional groups shared the remaining volume. (Check Point Research)
  • The average extortion or ransomware breach disclosed by the attacker cost $5.08 million in 2025, and full recovery costs run roughly ten times the ransom demanded. (IBM 2025; Delphix, citing Sophos data)
  • Average ransom payments jumped 500% in a single year to about $2 million, according to survey data from 5,000 IT leaders. (Sophos State of Ransomware)
  • Ransomware attacks have risen 13% over five years with an average incident cost of $1.85 million, accounting for around 27% of all malware attacks and roughly 51% of cyberattack costs for small and mid-sized enterprises. (Astra)
  • Roughly 76% of organizations suffer at least one ransomware attack per year, and 96% of attacks specifically target backup repositories. (Veeam Data Protection Trends, 2024)
  • In 77% of ransomware incidents, the payload is deployed within 30 days of initial access, 54% within the first seven days, and the median time between access and launch is 6.11 days. (Google Cloud / Mandiant threat intelligence)
  • Ransomware payment rates collapsed from a peak of 85% in 2021 to roughly 28% to 31% in 2025, pushing operators toward data theft and public extortion; about half of attacks now skip pure encryption in favor of exfiltration-and-extort models. (Total Assure)
  • The FBI received more than 3,600 ransomware complaints in 2025, with Akira, Qilin, INC, BianLian, and Play the most reported variants, and every one of the 16 US critical infrastructure sectors reported ransomware attacks. Reported ransomware losses spiked 259% year over year to $32.3 million, a figure that excludes downtime, forensics, and legal costs. (FBI IC3 2025)
  • Ransomware affects roughly 72.7% of organizations, keeping it the most cited single cybersecurity threat worldwide. (Statista)
  • Transport for London's high-profile ransomware incident exposed traveler contact details, Oyster card data, and bank details of up to 5,000 people, one of a string of attacks on public infrastructure. (Healthcare Dive, citing IBM breach research)

Phishing, Social Engineering, and BEC Statistics

Email is still the front door, and AI has renovated it.

  • Phishing losses reported to the FBI grew 208% year over year to $215.8 million in 2025, even as complaint volume dipped slightly from 193,407 to 191,561, a sign attacks are getting more targeted and more lucrative. (FBI IC3 2025)
  • BEC losses hit $3.04 billion in 2025, and combined email-origin fraud (BEC, phishing, government impersonation) exceeded $4 billion, up 46% from 2024, roughly 19% of all reported cybercrime losses. Over a decade, BEC has cost businesses more than $55 billion. (FBI IC3 2025; Infosecurity Magazine)
  • Up to 98% of cyberattacks involve some form of social engineering, and phishing remains the most common initial vector, with an estimated 3.4 billion spam emails sent daily. (Okta; AAG IT Services)
  • An estimated 80% of phishing attacks are now AI-generated, GenAI use in phishing grew at least 17% year over year, and 60% of recipients fall for GenAI-driven phishing at rates comparable to human-written lures. Free tools can generate up to 30 phishing templates per hour. (Abnormal AI; KnowBe4, citing Perception Point; Harvard Business Review; Heimdal)
  • Vishing operations grew 442% between the first and second half of 2024, and AI-powered phishing made up over 80% of observed social engineering activity by early 2025. (CrowdStrike Global Threat Report; Xceedance)
  • Up to 74% of attacks involve spear phishing, companies with more than 1,000 employees face an 83% to 97% weekly chance of receiving BEC attempts, and BEC accounts for more than half of all social engineering incidents. (Proofpoint State of the Phish; Abnormal AI; Verizon DBIR)
  • Only 13% of targeted employees report phishing attempts to their organization, sharply limiting response time. (CISA)
  • Smishing now makes up more than two-thirds of mobile-targeted phishing, and mobile users are roughly three times more likely to click malicious links than desktop users. (Zimperium 2025 Global Mobile Threat Report)
  • ClickFix-style social engineering techniques surged 500% in 2025 as attackers coordinated campaigns across email, web, phone, and collaboration platforms rather than relying on email alone. (Check Point Cyber Security Report 2026)
  • 82% of malicious file attacks are delivered via email, and over 75% of targeted attacks start with an email; 94% of organizations reported email security incidents. (Check Point Security Report; Norton; Egress Email Risk Report)
  • 74% of companies say insider threats are becoming more frequent, 53% now actively train staff on minimizing internal risk, and 42% of security leaders attribute up to a quarter of incidents to insiders, with another 23% attributing between 25% and 49%. (Cybersecurity Insiders / Gurucul Insider Threat Report; Securonix; VikingCloud)

Supply Chain and Third-Party Attack Statistics

This is the category journalists will cite most in 2026. Supply chain compromise has moved from an emerging risk to the dominant intrusion pattern, and the numbers moved faster than almost any other metric in security. For a deeper cut of this data, see our full supply chain attack statistics roundup.

  • Third-party involvement in breaches doubled from 15% to 30% in a single year, the largest single-year shift ever recorded by the report. (Verizon 2025 Data Breach Investigations Report)
  • A supply chain compromise costs $4.91 million on average and takes 267 days to identify and contain, the longest lifecycle of any breach vector tracked. (IBM 2025 Cost of a Data Breach Report)
  • Sonatype cataloged more than 454,600 new malicious open source packages in 2025, a 75% year-over-year increase, pushing the cumulative count of known and blocked malicious packages above 1.23 million. More than 99% of open source malware now lives on npm. (Sonatype 2026 State of the Software Supply Chain)
  • ReversingLabs independently measured a 73% year-over-year increase in malicious open source packages from 2024 to 2025, corroborating the trendline. (ReversingLabs 2026 Software Supply Chain Security Report)
  • 63% of organizations fell victim to a supply chain attack in the past two years, and supply chain attacks cost roughly 17 times more to remediate than direct breaches. (Checkmarx; AppSec Santa research compilation of IBM and Verizon data)
  • 26% of businesses suffered a cyber incident originating from their supply chain in the past year, yet 48% of IT decision-makers admit to working with suppliers despite known security concerns. (Databarracks Data Health Check 2026)
  • 65% of large companies by revenue name third-party and supply chain vulnerabilities as their greatest cyber resilience challenge in 2026, up from 54% in 2025. Supply chain exposure ranks as the number one cyber risk concern among high-resilience organizations. (World Economic Forum Global Cybersecurity Outlook 2026)
  • CEOs of highly resilient organizations integrate security into procurement (70%) and prioritize supplier maturity assessments (59%) to manage supply chain risk. (WEF Global Cybersecurity Outlook 2026)
  • Group-IB's 2026 threat analysis names supply chain attacks the dominant force reshaping the global threat landscape, with attackers exploiting trusted vendors, open source software, SaaS platforms, browser extensions, and MSPs to gain inherited access to hundreds of downstream organizations from a single upstream breach. (Group-IB High-Tech Crime Trends Report 2026)
  • 97% of top US retailers experienced a third-party data breach in the past year, and at least 29% of all data breaches involve third-party attack paths. (SecurityScorecard)
  • 97% of commercial codebases contain open source components, and package registries served 9.8 trillion downloads in 2025, making the dependency graph itself the largest attack surface most companies own. (Sonatype 2026)
  • Supply chain attacks were flagged in 54 million US victim records in a single year. (Identity Theft Resource Center)
  • 60% of companies in supply chains now use cybersecurity risk as a buying consideration when choosing partners, and Gartner has predicted cybersecurity risk will be a primary buying criterion for chief supply chain officers. (Gartner)
  • 36% of security leaders say they are unprepared for ransomware targeting third parties in their supply chain, one of the top four threats leaders admit they cannot yet handle. (VikingCloud 2025 Cyber Threat Landscape Report)
  • 55% of SMBs experienced a third-party or vendor outage in the past year, and roughly 1 in 5 assume vendors are secure simply because of a contract or a trusted brand name. (VikingCloud 2026 SMB Threat Landscape Report)
  • 62% of restaurant chains work with six or more third-party vendors per location, and 14% rely on 11 or more, widening the attack surface with every integration; 45% of retailers hit by attacks reported supply chain disruption, and 52% of retailers name supply chain attacks as the most common attack method they face. (VikingCloud 2026 Quick Service Restaurant Report; VikingCloud retail research)

AI, Shadow AI, and Deepfake Statistics

2026 is the year AI risk stopped being hypothetical and started showing up in breach cost data.

  • 94% of surveyed leaders say AI is the most significant driver of cybersecurity change in the year ahead, and 87% identify AI-related vulnerabilities as the fastest-growing cyber risk of 2025. (World Economic Forum Global Cybersecurity Outlook 2026)
  • The share of organizations assessing the security of AI tools nearly doubled in a year, from 37% in 2025 to 64% in 2026, and 40% now conduct periodic reviews of AI tools rather than one-time assessments (24%). (WEF Global Cybersecurity Outlook 2026)
  • High levels of shadow AI added an average of $670,000 to breach costs ($4.63 million versus $3.96 million), and shadow AI factored into 20% of breaches. Shadow AI incidents compromised customer PII at a 65% rate versus a 53% global average, and IP at 40% versus 33%. (IBM 2025 Cost of a Data Breach Report)
  • 97% of organizations that suffered AI-related breaches lacked proper AI access controls, and 63% had no formal AI governance policy. 13% of organizations reported breaches of AI models or applications, and another 8% did not know whether they had been compromised that way. (IBM 2025)
  • 1 in 6 breaches (16%) involved attackers using AI tools, most commonly for phishing (37%) and deepfake impersonation (35%). (IBM 2025)
  • 89% to 90% of organizations encountered risky AI prompts within a three-month window, and roughly 1 in every 41 to 48 prompts submitted to enterprise AI tools is classified as high risk. A review of 10,000 MCP servers found security weaknesses in 40%. (Check Point Cyber Security Report 2026)
  • Gartner expects more than 40% of organizations to experience a security or compliance incident tied to unauthorized shadow AI by 2030, and predicts that by 2027, 40% of enterprises will demote or decommission autonomous AI agents after governance gaps surface in production. (Gartner)
  • 97% of companies report GenAI-related security issues and breaches, while 24% believe GenAI will make incident response more efficient. (Capgemini)
  • 53% of security leaders say AI-powered attacks are their biggest challenge, and 53% admit AI is creating attack points they are unprepared for. Their top AI-driven concerns: generative AI phishing (51%), prompt hacking (45%), AI voice deepfakes (43%), and deepfakes generally (41%). Unpreparedness for deepfake attacks jumped from 3% of managers in 2024 to 21% in 2025, and from 6% to 28% among C-suite leaders. (VikingCloud 2025 Cyber Threat Landscape Report)
  • Google Cloud's Cybersecurity Forecast 2026 predicts attackers will use AI across the full attack lifecycle, including prompt injection, AI-generated phishing, and deepfakes, while flagging shadow AI and attacks on virtualization infrastructure as fast-rising threats. (Google Cloud Cybersecurity Forecast 2026)
  • On the defensive side, 45% of leaders use AI for automated incident detection and hunting, 41% already use GenAI to close the skills gap, 56% plan to use AI to train security professionals, and 83% of organizations have trained staff on generative or agentic AI risk. GenAI-driven hyper-personalized training could cut employee-caused incidents 40% by 2026. (VikingCloud; CompTIA; Gartner)
  • The AI cybersecurity market is projected to exceed $133 billion by 2030. (Security Magazine, citing Techopedia)

Cloud, IoT, Device, and DDoS Statistics

Hybrid infrastructure keeps expanding faster than the controls that protect it.

  • Up to 61% of companies experience at least one cloud attack per year, and 21% of cloud incidents result in data breaches. 27% of operators report public cloud security issues, with misconfigurations behind 23% of those, and over half of all cloud breaches involve human error. (Thales Cloud Security Study; Infosecurity Magazine, citing Thales)
  • An estimated 70% of cloud breaches in 2026 originate from compromised identities rather than software flaws, and 88% of companies now operate multi-cloud or hybrid environments, with 81% depending on two or more providers for critical workloads. (Fortinet 2026 Cloud Security Report)
  • Up to 70% of IoT and internet-connected devices remain vulnerable to attack, IoT malware attacks surged 124% globally, and early 2026 data shows an average of more than 820,000 IoT attacks per day, with routers the gateway for roughly 75% of IoT-related intrusions. (CybelAngel, citing HP research; Dexpose IoT threat data)
  • In the UK's NHS, 46% of IoT devices carry at least one known but unaddressed risk, and 83% of medical imaging devices run on unsupported operating systems. (Cynerio NHS IoT security report)
  • DDoS attacks are increasing roughly 20% year over year, and law enforcement shut down 48 DDoS-for-hire platforms in a single year. Criminals now launch an estimated 44,000 DDoS attacks daily, botnet attacks have peaked at 29.7 Tbps, and finance and telecom absorb roughly 60% of targeted DDoS volume. (Cloudflare DDoS Threat Report; ENISA Threat Landscape; StationX)
  • Cyberattacks on Android devices in critical infrastructure surged over the past year: energy up 387%, healthcare up 224%, manufacturing up 111%. (The HIPAA Journal)
  • The AV-TEST Institute registers over 450,000 new malware samples and potentially unwanted applications every day. (AV-TEST)
  • Hundreds of millions of devices became more exposed when Microsoft ended Windows 10 support in October 2025, one of the largest single expansions of unpatched attack surface on record. (BeyondTrust)
  • An average of 1.4 billion social media accounts are hacked every month. (StationX)

Vulnerability and Patching Statistics

CVE volume is growing faster than most teams can triage.

  • The National Vulnerability Database recorded over 30,000 new CVEs in a year, half rated high or critical severity, and 2026 forecasts suggest disclosure volumes could plausibly reach 70,000 to 100,000 this year. A new vulnerability is now published roughly every 17 minutes, and half of all CVEs ever published appeared in the last five years. (FIRST 2026 Vulnerability Forecast; Computer Weekly)
  • Roughly 29% of exploited vulnerabilities show evidence of exploitation on or before the day the CVE is published, while only about 1.1% of CVEs have been exploited historically and roughly 2% weaponized. (FIRST; VulnCheck)
  • Monthly critical CVEs jumped 13% in a year, with overall CVE counts rising about 25% annually, and researchers logged 612 new unique CVEs in a single quarter at one point. (Coalition vulnerability forecasts, via CSO; Help Net Security; Statista)
  • Operating systems with the most recorded CVEs include Debian Linux (8,809), Android (7,245), the Linux kernel (6,010), and Fedora (5,122). (CVEdetails)
  • More than 40% of Log4j downloads were still vulnerable versions three months after the flaw was patched, and 38% of Log4j users kept running vulnerable versions long after disclosure, a case study in patch inertia. (Dark Reading; Veracode)
  • In attacks on critical infrastructure, 85% of incidents could have been mitigated with patching, MFA, or least-privilege access. (IndustryWeek, citing IBM X-Force)
  • There are at least 23,900 known cybersecurity vulnerabilities feeding the more than 2,300 unique cyberattacks that occur every day. (Astra)

Small and Medium Business Cyber Security Statistics

SMBs are now targeted deliberately, not incidentally.

  • 75% of SMB owners rank cyberattacks, data breaches, and ransomware as the number one threat most likely to hurt operations this year, ahead of inflation and recession for the first time. (VikingCloud 2026 SMB Threat Landscape Report)
  • 40% of SMBs say a cyberattack costing $100,000 or less could put them out of business, and the average small business pays about $120,000 to recover from an attack. (VikingCloud 2026 SMB Report; PurpleSec, citing IBM)
  • 60% of small businesses close within six months of a breach or cyberattack, and SMEs absorb roughly 50% of all cyberattacks. (Inc.; Cybersecurity Ventures)
  • Small businesses are three times more likely to be targeted than larger companies, 70% of attackers deliberately target them, and total SMB cybercrime costs run $2.4 billion per year. (CISA; Cisco)
  • 61% of small businesses experienced a breach in the last year, and 70% of ransomware attacks in 2021 hit businesses with fewer than 500 employees. 46% of all breaches impact companies with fewer than 1,000 employees. (CrowdStrike small business research; StrongDM)
  • More than a quarter of SMBs report experiencing a deepfake scheme (29%), customer data breach (27%), ransomware (26%), or DoS attack (26%) in the past year, and 25% found their credentials leaked on the dark web. 46% faced AI-generated phishing or phishing-as-a-service schemes. (VikingCloud 2026 SMB Report)
  • 84% of SMB owners self-manage cybersecurity, 54% of those with a dedicated cyber expert still run the program solo, and 28% admit the person managing security lacks sufficient training. Top self-identified weaknesses: password reuse (43%), inability to keep up with patching (38%), and outdated security technology (34%). (VikingCloud 2026 SMB Report)
  • SMB security spending priorities for 2026: real-time threat monitoring (49%), antivirus (42%), vulnerability scanning (40%), AI-driven threat detection (39%), AI-assisted incident response (34%), and AI fraud detection (34%), while penetration testing (30%), dark web monitoring (27%), and password managers (24%) lag. (VikingCloud 2026 SMB Report)
  • On average, SMBs spend between $826 and $653,587 per cybersecurity incident. (Astra)

Industry-Specific Cyber Security Statistics

Healthcare

  • Healthcare has posted the highest breach costs of any industry for 14 to 15 consecutive years, at $7.42 million per breach in 2025, down from $9.77 million in 2024 as overall costs fell, though some incident-level estimates for 2026 run as high as $12.6 million. (IBM 2025 Cost of a Data Breach Report)
  • 546 US healthcare entities reported breaches in 2025, including 409 providers, 100 business associates, and 35 health plans, with 2025 producing some of the biggest healthcare breaches on record. (The HIPAA Journal)
  • Healthcare is the third-most attacked industry worldwide, ransomware against healthcare grew at least 25%, and more than 630 ransomware attacks hit healthcare bodies in a single year. 68% of healthcare officials witnessed an average of two attacks per year. (HHS ransomware analysis; Security Magazine, citing Proofpoint)
  • Healthcare breaches take longest to resolve: about 213 to 255 days to detect, versus a 194-day cross-industry detection average, and 88% of healthcare workers have opened phishing emails. Data theft is now the primary goal in 56% of healthcare attacks. (IBM healthcare breach analysis; Astra)
  • More than 70% of US hospitals surveyed by HHS follow NIST cybersecurity protocols, and healthcare breach costs have risen 53% since the start of the pandemic even as year-over-year costs recently fell about 10.6%. (Industrial Cyber, citing HHS; Healthcare Dive, citing IBM)

Finance and Insurance

  • The average financial services breach costs $5.56 million to $6.4 million, roughly 22% above the global average, and credential theft dominates: 78% of finance incidents involve stolen customer logins. (IBM 2025; IBM financial industry analysis)
  • The financial sector suffered more than 20,000 cyberattacks between 2004 and 2023, causing $12 billion in losses, and US financial data compromises jumped from 138 in 2020 to 744 in 2023. (International Monetary Fund; Statista)
  • API and web application attacks on financial services rose 65% in a year, malicious bot requests spiked 69%, and finance faces the highest web application attack volume of any industry while ranking third-most-attacked for phishing. Financial-sector ransomware is growing about 9% year over year. (Akamai financial services threat research; Sophos)
  • Financial firms take an average of 177 days to identify breaches and 56 days to contain them. (Security Intelligence)

Manufacturing and Industrial

  • Manufacturing remains the most-attacked sector, accounting for 34.7% of all incidents in the past year, with ransomware used in 31% of manufacturing cases, often to halt production lines and force payment. (IBM X-Force, via IndustryWeek)
  • The average manufacturing breach costs $5.56 million (2024), and the industrial sector saw the steepest cost increase of any industry, up $830,000 year over year. (IBM; Security Intelligence)
  • Up to 44% of manufacturing computers are affected by ransomware, and about 62% of manufacturing ransomware victims pay the ransom. Manufacturing represented 29% of published ransomware victims globally, a 56% year-over-year increase, and backdoor attacks account for 28% of malicious actions against the sector. (Sophos State of Ransomware in Manufacturing; Check Point Research)

Retail

  • 80% of retailers were hit with at least one successful cyberattack in the past 12 months, and 22% experienced 7 to 15 attacks. Retail breach costs rose 18% year over year to an average of $3.48 million, and retail accounts for 6% of global breaches. (VikingCloud retail research; IBM)
  • The fallout: 68% of retailers reported downtime, 45% supply chain disruption, 45% lost sales, 33% regulatory fines, and 23% stock price declines after attacks. (VikingCloud retail cybersecurity research)

Education

  • K-12 ransomware attacks spiked 92% in a year, education saw 265 attacks (up 70%), and the US accounted for 80% of known education ransomware. Attacks against schools and universities rose another 23% in the first half of 2025, with an average ransom demand of $556,000. (ThreatDown; Comparitech, via Higher Ed Dive)
  • Each day of ransomware downtime costs schools up to $550,000, higher-ed breaches average $3.65 million, 95% of higher-ed ransomware attackers target backups, and education ransomware downtime cost more than $53 billion over five years. Education is also the single most-attacked industry by raw volume, absorbing 4,641 weekly attacks per organization in May 2026. (Comparitech; Varonis, citing Sophos; Check Point Research)

Government and Nation-State Activity

  • Federal agencies reported 32,211 information security incidents to DHS in FY 2023, and GAO has made over 4,400 cybersecurity recommendations since 2010, more than 730 of which remained unimplemented as of February 2026, including 48 designated priority items. (US Government Accountability Office)
  • Russian cyberattacks on Ukraine surged nearly 70% in 2024, reaching 4,315 recorded incidents, part of the running CSIS timeline of significant state-linked cyber operations since 2006. (CSIS Significant Cyber Incidents)
  • The fall 2025 US federal government shutdown coincided with an 85% increase in attacks on US government targets, with the VA and DOJ most targeted, and US government data breaches nearly tripled from 47 in 2020 to 128 in 2024. (Dark Reading; SOAX)
  • Nearly 80% of security leaders are concerned about being targeted by a nation-state attack within the next year, and CISA continues to track and publish active threats across all 16 critical infrastructure sectors. (VikingCloud; CISA)

Defense Industrial Base

  • The aerospace and defense sector has seen a 300% increase in cyberattacks since 2018, over 80% of A&D organizations experienced a breach in the past 12 months, and 61% faced ransomware in the past year amid roughly 1,250 incidents per week industry-wide. The average defense-sector breach costs $5.46 million. (Fortune Business Insights; WifiTalents defense industry data)
  • Over 50% of defense contractors struggle to implement CMMC compliance requirements, which have been mandatory in defense contracts since November 2025, and at least 70% of the defense industrial base consists of small businesses facing standard SMB threats with defense-grade stakes. (Radicl DIB Cybersecurity Maturity Report; Axios)

Hospitality, Restaurants, Travel, and Auto Services

  • 90% of North American hotel IT and security leaders experienced at least one attempted attack during peak season, 82% reported a successful breach, 44% suffered 12+ hours of downtime, and 58% faced five or more attacks. Hotels working with an MSSP resolved incidents within 12 hours 80% of the time. (VikingCloud 2025 State of Hospitality Cyber Report)
  • 80% of quick service and fast casual restaurant leaders experienced a cyberattack in the past 12 months, 80% were hit by social engineering, 76% had data exposed, and 10% temporarily or permanently closed a location afterward. 78% delayed a security patch to avoid disrupting operations, and 68% would lose over $1,000 per hour of peak-rush downtime. (VikingCloud 2026 Quick Service Restaurant Report)
  • 92% of travel agencies experienced cyber threats in the past 12 months, 66% had sensitive customer data compromised, and 68% of owners rank cyberattacks as the single greatest threat to their business in 2026, ahead of inflation (60%) and recession (54%). 44% manage cybersecurity entirely on their own. (SecureTrust 2026 Travel Agency Resilience Report)
  • Among auto service, repair, and parts businesses, 54% saw attack frequency or severity rise in the past year, POS terminals are the most attacked system (66%), and 64% of leaders said incidents went unreported to executive leadership. (VikingCloud 2025 Auto Services Survey)

Cybersecurity Spending, Insurance, and Zero Trust Statistics

Budgets keep climbing, but so does what they have to cover.

  • Global information security spending was forecast at roughly $183.9 billion to $212 billion for 2025, growing about 15%, and is projected to reach approximately $240 billion in 2026, a 12.5% year-over-year increase, with security services growing faster than software or network security. (Gartner; Fortune Business Insights)
  • Companies spend an average of 12% of IT budgets on cybersecurity, budgets are growing about 8% per year, and allocations have risen roughly 8.6% over the past half-decade. The broader market compounds at about 7.92% annually through 2030. (Statista; IANS Security Budget Benchmark)
  • Companies using security automation and AI spend $1.8 million to $1.9 million less per breach, and having a tested incident response plan saves an average of $2.66 million per breach. (IBM)
  • More than 86% of firms are adopting zero trust models, at least 41% of businesses already run zero trust architecture, and the zero trust market is projected at nearly $133 billion by 2032. Identity and access management alone was set to exceed $24.1 billion in 2025, 83% of SME IT professionals mandate MFA, and 47.1% of business owners back passwordless access. (Cisco Zero Trust Outcomes Report; JumpCloud, citing IBM; Statista; MarketsandMarkets; KuppingerCole)
  • Cyber insurance claims are rising about 13% year over year with average carrier losses near $100,000 per claim, and ransomware drives 19% of all claims. Policy counts are growing 11.7% annually with claims topping 33,500 per year, written premiums were expected to reach roughly $23 billion in 2025, and the market is set to top $20 billion. Only 74% of companies carry specific cybercrime coverage. (Coalition Cyber Claims Report; NAIC; Insurance Information Institute; NetworkAssured)
  • 75% of large organizations with revenues above $5.5 billion carry cyber insurance, versus only 25% of organizations under $250 million in revenue. (International Monetary Fund)
  • What buyers want from security partners: 41% prioritize cost-effective, easy-to-use AI solutions, 40% want predictive attack prevention, and 39% want vendors that ease the talent shortage. (VikingCloud 2025 Cyber Threat Landscape Report)

Cybersecurity Workforce and Jobs Statistics

The people problem is not getting solved by 2026.

  • The global cybersecurity workforce gap sits near 4 million to 4.8 million unfilled roles, with the active workforce around 5.5 million professionals; Asia-Pacific carries the largest gap at 3.4 million unfilled positions. (Statista)
  • The US has approximately 515,000 open cybersecurity positions against about 1.34 million employed professionals, meaning the workforce fills only around three-quarters of demand; earlier counts put unfilled US roles as high as 570,000. Texas, Florida, California, Colorado, Illinois, Virginia, Maryland, and New York post the most openings. (CyberSeek; National Science Foundation)
  • US information security analyst jobs are projected to grow 33% by 2033, about 29 points above the all-occupation average, with roughly 17,300 openings per year. For comparison, computer occupations overall are projected to grow 12%. (US Bureau of Labor Statistics)
  • 45% of professionals say skills shortages are the biggest challenge facing cybersecurity teams, 63% of companies are considering GenAI to offset hiring gaps, and about 40% of C-level executives intend to use GenAI to cover critical skills shortages. Gartner predicts GenAI will remove the need for specialized education in up to half of entry-level cybersecurity roles by 2028. (Statista; Gartner; Computerworld, citing Kaspersky)
  • 2026 salary bands: entry-level roles pay roughly $74,000 to $110,000, mid-level $115,000 to $212,000, senior specialists up to $280,000, and CISOs up to $420,000, with AI security specialist, cloud security engineer, zero trust architect, and DFIR among the most in-demand roles. (KnowledgeHut salary data; US Bureau of Labor Statistics)

Emerging Trends and What's New in 2026

These are the storylines journalists covering security should watch this year, backed by the freshest data available.

  • Attack tempo keeps compounding. Organizations averaged 1,968 weekly attacks in 2025 (up 18% year over year and 70% since 2023) and roughly 2,055 to 2,086 weekly attacks in early-to-mid 2026, while Cloudflare-scale networks now block on the order of 230 billion threats daily. (Check Point Cyber Security Report 2026; Cloudflare 2026 Threat Report, via VARINDIA)
  • Attackers log in rather than break in. 82% of detections are malware-free, phishing and social engineering opened 40% of incident response cases, and identity, APIs, and service accounts are the fastest-growing target class. (CrowdStrike 2026 Global Threat Report; Cybereason)
  • Supply chain risk went mainstream in the boardroom. With third-party breach share doubling to 30% and 65% of large firms calling supply chain vulnerabilities their top resilience challenge, expect SBOM mandates, supplier maturity assessments, and procurement-embedded security to accelerate through 2026. (Verizon 2025 DBIR; WEF Global Cybersecurity Outlook 2026)
  • The C-suite and the front line see different wars. 79% of managers say a successful attack hit their organization in the past year versus 65% of C-suite leaders; 81% of managers say at least one material incident went unreported to leadership versus 55% of executives; and 8% of leaders admit they or a teammate hid an incident for fear of job loss. Top reasons for silence: reputational or regulatory fallout (44%), belief the incident could be contained internally (41%), and no safe reporting protocol (37%). (VikingCloud 2025 Cyber Threat Landscape Report)
  • Attack frequency and severity are climbing in tandem. 71% of organizations report more frequent attacks, 61% report more severe ones, 90% of frontline managers say attacks are more frequent than last year, and 59% of businesses experienced a successful attack in the past 12 months, with a third believing AI was involved. Only 26% of leaders could recognize and respond to a major attack in under a day, while most (54%) said it would take 1 to 7 days. (VikingCloud)
  • Post-quantum planning is now real budget line-item territory. 37% of leaders believe quantum technologies will affect cybersecurity within 12 months, and Gartner lists post-quantum cryptography migration among its top 2026 trends as "harvest now, decrypt later" attacks push crypto-agility planning forward. (WEF Global Cybersecurity Outlook 2026; Gartner)
  • Cybercrime is regionally uneven. Organizations in India faced 3,195 weekly attacks in early 2026, 62% above the global average, and IC3 received complaints from more than 200 countries accounting for nearly $1.6 billion in losses. (Check Point Research; FBI IC3 2025)
  • Leaders remain least prepared for: ransomware on their own business (46%), phishing and social engineering (39%), ransomware targeting supply chain third parties (36%), and deepfake attacks (31%). In response, 51% increased employee security awareness training, 47% improved network security, and 31% increased penetration testing in the past year. (VikingCloud 2025 Cyber Threat Landscape Report)

How swif.ai Helps

Most of the numbers above trace back to the same root causes: unmanaged devices, unsanctioned SaaS and AI tools, and third-party blind spots. swif.ai helps IT and security teams close those gaps with unified device management across macOS, Windows, Linux, iOS, Android and Chromebooks coming soon. With real-time Shadow IT and AI discovery, and pre-built compliance policies mapped to SOC 2, ISO 27001, and HIPAA in the compliance dashboard. Contact us today to learn how we can secure your endpoints.

Journalists and researchers are welcome to cite any statistic on this page with attribution. This page is reviewed and updated as new editions of the major annual reports are released.