Cybersecurity Statistics: Latest Data and Trends

Written by Nick Galov • Edited by Branko Krstic
• 15 min read

Cybersecurity and online safety rarely are things that come to mind. We casually surf the internet with no concern for the dangers that lurk in the digital realms of the 21st century.

Even those among us cautious of their online safety can be affected by cybercrime. Numerous instances of data leaks and security breaches in companies widely considered safe are proof of that. Yahoo, Imgur, and many health companies had sensitive data stolen. Some others, like Facebook, even allegedly sell data for profit.

Yet, many of us keep ignoring the issue as if it doesn’t matter in the slightest.

So let me show you the seriousness of the problem with some numbers

Some Scary Cybersecurity Statistics For 2022 (Editor’s Choice):

  • By 2021, the cybersecurity damage is expected to reach $6 trillion.
  • Not so surprising, given that 50% of users would click on a link from an unknown sender…
  • …and that the majority of IoT devices reduce overall security.
  • 43% of cyber attacks are aimed at small businesses.
  • 58% of malware attacks are directed at small businesses.
  • Still, financial companies pay the most – on average, $18.3 million per surveyed company.
  • 90% of the CIOs state their cybersecurity budget is spent inefficiently.

We at Web Tribunal want to raise awareness about online safety and help you understand how much of a threat some innocent browsing can pose. Here is a sizeable list of cybersecurity statistics:

General Cybersecurity Facts and Stats

Sadly, cybercrime happens way more often than we’d like to think.

1. Cybercrime damages were projected to reach $10.5 trillion in 2025.

(Source: Cybersecurity Ventures)

Cybersecurity Ventures projected global cybercrime costs would reach $10.5 trillion annually by 2025, up from an estimated $3 trillion in 2015.

Read that as a projection rather than a measured outcome. It was published ahead of 2025 and no audited global total exists to confirm it, which is true of essentially every headline cybercrime cost figure. The useful part is the scale and direction, not the precision.

2. A hacker attack occurs every 39 seconds in the US.

(Source: Cybint)

A hacking attack is happening every 39 seconds in the US. On a yearly basis, every third person in the country is affected by hacker attacks.

3. 24% of US adults reuse the same password across multiple accounts.

(Source: CNET)

A 2025 CNET survey found 24% of US adults using the same password across multiple accounts.

Other research frames the question differently and arrives at a complementary answer: Consumer Reports found 65% using unique passwords, which implies roughly a third do not. Either way, password reuse remains the single easiest way to turn one breach into several.

4. The most common password in 2025 was still 123456.

(Source: NordPass)

NordPass has analysed leaked credential databases every year since 2019, and 123456 keeps coming out on top. It did so again in 2025.

The rest of the list rarely changes either: simple number runs, "password", "admin" and keyboard patterns. These appear in breach dumps, so they reflect what people actually set rather than what they say they set.

NordPass also broke the 2025 data down by age and found almost no difference between generations, with an 18-year-old choosing much the same password as an 80-year-old. Our password statistics cover that breakdown along with current NIST requirements and passkey adoption.

5. 18 million Americans were victims of traditional identity fraud in 2025.

(Source: Javelin Strategy & Research)

Javelin’s 2026 Identity Fraud Study reports 18 million US victims of traditional identity fraud in 2025.

The study now separates traditional identity fraud, where criminals take over or open accounts using stolen details, from scams in which victims are manipulated into handing money over themselves. The older 16.7 million figure for 2017 used a broader definition, so the two are not directly comparable.

Cybersecurity and Business Organizations

Companies, large and small, are one of the main targets for hacking because of the earning potential they present

6. 66% of organizations reported that cybersecurity incidents increased in 2025.

(Source: Ponemon-Sullivan)

Current Ponemon-Sullivan research finds 66% of organizations reporting that cybersecurity incidents increased in 2025.

Note this is a question about measured incidents rather than perceived risk, which is what this page previously reported. Organizations saying incidents rose is a stronger claim than organizations feeling more exposed.

7. 93% of organizations use cloud services.

(Source: McAfee)

Cloud storage services helped companies around the world to cut costs of data storage. Despite the convenience that cloud services offer – great cost, scalability, and accessibility – they present a major security threat, as they are prime targets for attempts at information technology security breaches. Our cloud adoption statistics show how far that migration has gone across enterprises, SMBs and government.

93% of all organizations in the world have decided to use cloud solutions as their main data storage points.

8. 72% of business owners are very or extremely concerned about cyber attacks.

(Source: Gallagher)

Gallagher’s 2025 survey found 72% of business owners very or extremely concerned about cyber attacks.

The population is business owners generally rather than the small-business owners this page used to cite, so the jump from 58% is partly a change in who was asked. The direction is consistent across surveys regardless.

9. 70% of IT professionals say their company can’t respond properly to a cyber threat.

(Source: Ponemon Institute)

Even though most IT professionals are aware of the threat the lack of cybersecurity presents, 70% believe that their organizations are unfit to respond to a cyber attack due to the lack of a cybersecurity response plan.

Out of 2,600 IT professionals surveyed, 26% said that their company has an informal process of dealing with this type of event, while 27% of those who actually have a response plan said that their incident response plan isn’t followed consistently.

10. 65% of the top 100 banks in the US failed web security testing.

(Source: Slashdot)

Here’s an interesting bit of cybersecurity statistics for all of those who use online banking in the US:

More than 1,000 websites were audited anonymously by the Online Trust Alliance; the sites of the top 100 banks in America were included. The report from the audit says that 65% of the banks failed the web security testing, scoring the lowest out of all tested websites.

In order to pass the screening, websites had to score more than 80% in 3 categories: consumer protection, security, and privacy. Failing in one of the categories brought a failing mark. As it turns out, just 27% of the top 100 banks were able to meet the criteria.

17% of the banks that failed had moderately adequate website security; 45% didn’t have the necessary email security. 34% of those who failed had poor privacy protection.

11. The global cybersecurity workforce gap was about 4.76 million in 2024.

(Source: ISC2)

ISC2’s 2024 workforce study estimated a global shortfall of about 4.76 million cybersecurity professionals.

Two caveats. This is the 2024 estimate, not a current one: ISC2 stopped publishing a workforce-gap headcount in its 2025 study, so there is no newer like-for-like number. And a modelled gap is an estimate of unmet demand, not a count of posted vacancies.

Data Breach Statistics

Data breaches happen on larger scales because information becomes more and more valuable.

12. There were 3,322 data compromises in the US in 2025.

(Source: Identity Theft Resource Center)

The ITRC recorded 3,322 data compromises in the United States in 2025.

ITRC counts compromises, which covers breaches, exposures and leaks, so the figure is not interchangeable with older counts of “data breaches”. It is US-only, which matters when comparing it with the global Verizon figures below.

13. Verizon confirmed more than 22,000 data breaches in its 2026 report.

(Source: Verizon DBIR)

Verizon’s 2026 Data Breach Investigations Report confirmed more than 22,000 data breaches, drawn from victims in 145 countries. It is the largest dataset in the report’s 19-year history, covering October 2024 to November 2025.

This is a global figure drawn from Verizon’s own contributor dataset rather than a count of every breach worldwide, so it measures what that dataset saw. It is not comparable with the US compromise count above.

14. US data compromises have more than doubled since 2021.

(Source: Identity Theft Resource Center)

The 3,322 US data compromises recorded in 2025 are more than double the 1,291 publicly disclosed breaches reported for 2021.

Some of that rise is better reporting rather than more incidents. Disclosure requirements have broadened considerably over the period, so a growing count partly reflects more being counted.

15. The average breach lifecycle reached 247 days in 2026.

(Source: IBM)

IBM’s 2026 Cost of a Data Breach Report puts the mean time to identify and contain a breach at 247 days.

That is a combined figure. This page used to carry identification and containment separately, at 191 and 66 days, and the new number cannot be matched against either on its own. What it says is that organizations still spend roughly eight months between an intrusion starting and it being shut down.

16. The average breach now costs $4.99 million globally.

(Source: IBM)

IBM puts the global average cost of a data breach at $4.99 million in 2026, up 12% year over year and a record for the report.

Healthcare remains the costliest sector at $6.64 million, its thirteenth consecutive year at the top, followed by financial services at $6.29 million. IBM also found that one breach in four involved AI, and those averaged about $6 million.

17. US breaches cost more than twice the global average.

(Source: IBM)

The average breach in the United States cost $11.5 million in 2026, against the $4.99 million global average.

Regulatory exposure, litigation and notification requirements all push the US figure up. It is the clearest reminder that a global average hides enormous variation by jurisdiction.

18. $141 is the average cost per lost or stolen record.

(Source: IBM)

On average, every lost or stolen record from the companies featured in the IBM research cost 141 dollars in 2017. During 2016, the average was 11.4 % higher.

Cyber Attack Statistics

Considering that is very likely a significant number of cyber attacks go unreported, the cyber attack stats below probably don’t do justice to the grim reality.

19. The number of cyber attacks increased by 600% in 2017.

(Source: Symantec)

In 2016, there were only 6,000 reported cyber attacks worldwide. 2017 saw an increase of no less than 600%, reaching 50,000 cyber attacks during the year. There was an increase of 54% in mobile malware during the same year.

20. Verizon analysed more than 31,000 security incidents in its 2026 report.

(Source: Verizon DBIR)

The 2026 DBIR analysed more than 31,000 real-world security incidents, of which more than 22,000 were confirmed breaches.

The distinction matters and is often lost: an incident is any event compromising the integrity, confidentiality or availability of information, while a breach requires confirmed data disclosure. Roughly half of the incidents in this dataset were confirmed breaches.

21. The FBI received more than 3,600 ransomware complaints in 2025.

(Source: FBI IC3)

The FBI’s Internet Crime Complaint Center logged more than 3,600 ransomware complaints in 2025.

These are complaints reported to the FBI, not attacks. Ransomware is heavily under-reported, so the true number of incidents is far higher. This page previously claimed more than 4,000 ransomware attacks a day, which the complaint data does not support and which no source we could verify establishes.

22. The median ransom demand reached $1.32 million in 2025.

(Source: Sophos)

Sophos’s State of Ransomware 2025 reports a median initial ransom demand of $1,324,439.

The median amount actually paid was lower, at around $1 million, and 53% of organizations negotiated the demand down. The old $1,077 figure on this page came from an era of consumer-targeted ransomware; today’s operators price against organizations.

23. 49% of ransomware victims paid to get their data back.

(Source: Sophos)

Sophos found 49% of ransomware victims paid to recover their data, the second-highest payment rate in six years.

This page previously contained both 40% and 4% for the same statistic in different places, which was an internal contradiction rather than a change over time. The corrected figure is the Sophos one above. The alternative to paying is restoring from backup, and our backup statistics cover how often that actually works. For what a loss event costs once it happens, see our data loss statistics.

24. Ransomware appeared in 48% of breaches.

(Source: Verizon DBIR)

Verizon’s 2026 DBIR found ransomware present in 48% of breaches, up from 44% in the 2025 edition. Most victims still did not pay: the non-payment rate reached 69%.

That reverses the “ransomware is down” framing this page used to carry. Small and medium businesses bear the brunt: 88% of the ransomware breaches in the dataset hit SMBs. Our biggest data breaches page covers the incidents behind these numbers.

25. Bitcoin-mining software attacks are on the rise.

(Source: CSO)

It appears that the reason for the drop in ransomware attacks wasn’t an ethical one but a business-driven decision by attackers. Most of the recent cyber attacks were motivated differently.

Instead of demanding internet users to pay up in bitcoin for their data, attackers figured it would be easier and more lucrative to infect PCs with bitcoin-mining software. This way, the scam can go on for much longer without anyone noticing and earn attackers a lot more money in return.

During the first half of 2018, 90% of all remote code execution attacks were crypto mining-related, with more than 3 million crypto attacks happening between January and May.

26. 92% of malware is still delivered via email.

(Source: Verizon)

According to the Verizon data breach report and malware statistics available online, 92% of all malware attacks occur through email.

The most commonly used method of attack is phishing, a cyber attack that exploits the receivers’ lack of knowledge and/or attention to trick them they are receiving the email from someone else, typically a bank or someone requesting a payment.

It is appalling that people still fall for this type of scam. We should wise up and realize that money doesn’t fall from the sky and that we should never pay an “African prince” $1,000 so he can get his inheritance and send us a million bucks after he does. And if you run a business, make sure to get good spam protection on your email hosting.

27. 38% of all malicious file extensions are Word, Excel, and PowerPoint files.

(Source: CISCO)

An important piece of data related to the cyber attacks in 2018:

MS Office file extensions for Word, Excel, and PowerPoint represent the most common file attachments with malware. The reason behind this is the fact that most people think that the files came from a co-worker or a business partner, never suspecting malware hiding behind a table or a simple text document.

38% of all malicious files attached to emails are in one of the MS Office formats.

28. 56% of IT organizations recognize phishing as the biggest threat to their cybersecurity.

(Source: Cyberark)

A survey of more than 1,300 IT executives found that 56% consider phishing to be the biggest threat and allocate large chunks of their cybersecurity budgets to educate their employees about it.

29. 77% of cyber attacks were file-less in 2017.

(Source: CSO)

The days of .exe file attachments are far behind us. Nowadays, 77% of small and large-scale cyber attacks happen to be file-less or at least that was the case in 2017.

Fileless attacks rely on the software we already have installed on our computers, and they are far less obvious than the executable files that used to infect our devices years ago. Malware can hide in browser plug-ins, and MS Office macros or might exploit the flaws in server programs that can lead to data theft from the server.

30. 60% of all online fraud is committed through mobile devices.

(Source: RSA)

The preferred gateway of online fraudsters is mobile devices. 40% of fraud attempts are directed towards desktop users, while 60% of the malware infection efforts go to mobile. In addition, 80% of the malware that afflicts phones does so through apps rather than through a mobile web browser.

31. 98% of mobile malware targets Android phones.

(Source: Computerworld)

Kaspersky Lab states that mobile malware is the next big thing in the world of cybercrime. Data shows that 98% of all mobile malware attacks target Android devices, meaning that just 2% are aimed at iOS devices.

Mac users seem also to be safe from cyber attacks, as hackers also prefer to attack machines that run Windows.

32. 27% of malicious apps are lifestyle apps.

(Source: Symantec)

The biggest security threat comes from lifestyle apps. Data shows that 27% of all malicious apps belong to this category. Music apps are the second most common source of infection for mobile users, with 20% of all hacked apps coming from this category.

Wrap Up

These statistics are worrying, to be sure, but they also show that tech firms and governments haven’t given up the good fight.

Of course, the first line of defense is the way you configure your personal cybersecurity and the steps you take.

Hopefully, this round-up gave you a better idea of just how important cybersecurity is and what you can do to improve yours.

About Nick Galov

Author

Unaware that life beyond the internet exists, Nick is poking servers and control panels, playing with WordPress add-ons, and helping people get the hosting that suits them.

View all posts by Nick Galov →

About Branko Krstic

Editor

Branko is a round-the-clock tech geek and loving it. His ideal vacation destination is the Akihabara District (or really any place he can take his computer). If there’s a server out there, count on him to find out what it’s made of… and tell you all about it.

View all posts by Branko Krstic →