The Latest Statistics on Cyber Crime and Cybersecurity
Cyber crime stopped being a large-enterprise problem years ago. Attackers go after whoever is easiest to breach, and increasingly that means small and mid-sized businesses without a dedicated security team. The numbers below reflect where things actually stand heading into late 2026, not the projections that were floating around back in 2023, several of which have since resolved or been overtaken by newer data.
We've organized this by theme: overall cost, data breach economics, ransomware, phishing, workforce, and what's actually changed in the last year. Every figure links to its source so you can verify it yourself.
The overall cost of cybercrime, and why the old $10.5 trillion prediction now needs context
Cybersecurity Ventures famously predicted that cybercrime would cost the world $10.5 trillion annually by 2025. That prediction has now resolved: SentinelOne's 2026 cybersecurity statistics compilation puts the 2026 global loss estimate at $10.5 to $10.8 trillion, in line with the original forecast, alongside a separate IMF-cited estimate that puts the figure closer to $23 trillion by 2027 if current growth trends hold. Global cybersecurity spending itself is projected to reach roughly $240 billion in 2026, a 12.5% increase from 2025, according to the same compilation citing Fortune Business Insights.
Those are big, somewhat abstract numbers. Here's a more grounded one: a cyberattack on a firm with more than 1,000 employees in Europe or the US costs an estimated $53,000 on average, per the same SentinelOne report. That's the kind of number a small IT budget actually has to plan around.
Data breach costs: the first decline in five years
This is genuinely one of the more interesting shifts in the last year. IBM's 2025 Cost of a Data Breach Report found that the global average cost of a data breach dropped to $4.44 million, down 9% from $4.88 million the year before, the first decline in five years of tracking this metric. The driver, according to IBM, was faster breach containment powered by AI-assisted defenses: organizations identified and contained breaches in a mean time of 241 days, the fastest pace measured in nine years.
But there's a catch, and it's a meaningful one. The same report found that 97% of organizations that experienced an AI-related security incident said they lacked proper AI access controls. Among 600 organizations studied by the independent Ponemon Institute for the report, 63% had no AI governance policy in place to manage AI tool usage or prevent employees from turning to unapproved "shadow AI" tools. Organizations with a high level of shadow AI use saw an extra $670,000 tacked onto their average breach cost. In other words: AI is helping defenders respond faster, while simultaneously creating a new, under-governed attack surface. Both things are true at once, and pretending otherwise oversells the good news.
Ransomware: volume is up, but payment rates are falling
Ransomware statistics from the past year tell a more nuanced story than "attacks keep getting worse across the board." According to the Verizon 2026 Data Breach Investigations Report, ransomware now accounts for 48% of all data breaches globally, the highest share on record, up from 44% the year before. Claimed ransomware victims on public leak sites surged 58% in 2025, reaching 8,159 organizations.
Here's the part that cuts against the doom narrative: payment rates fell to a record low of 28 to 31% in 2025, down from 49% in 2024, as mean ransom demands actually dropped from $2.73 million to $1.32 million. Organizations are getting better, collectively, at refusing to pay and recovering through other means. IBM's X-Force Threat Intelligence Index 2026 identified 109 active ransomware groups operating in 2025, a 49% year-over-year increase, as law enforcement disruptions splintered several major operations, including a suspension of the RansomHub group in April 2025 that left an opening for the Qilin group to surge from 4% to 13% market share.
Industry breakdown matters a lot here. Healthcare faces the highest average ransom demand at $7.0 million, and a 66% rate of backup compromise that forces some hospitals to weigh payment against patient safety rather than pure financial calculation. Manufacturing is now the most frequently targeted sector by volume, accounting for 28.9% of victims listed on public leak sites in 2025.
Also read: How a Company Should Handle a Ransomware Attack
Phishing: still the most common way in
Phishing hasn't lost its place as the dominant entry point for attackers, it's actually grown its share. Verizon's 2025 DBIR found phishing present in 36% of all data breaches, and current 2026 forecasts from GetAstra project phishing will account for more than 42% of global breaches this year, driven substantially by AI-generated phishing content that's harder to spot than the typo-ridden emails of a few years ago. The Anti-Phishing Working Group (APWG) recorded 971,181 phishing attacks in Q1 2026 alone, up 13.8% from the previous quarter.
Healthcare is disproportionately exposed here too: KnowBe4 data cited by CNiC Solutions puts healthcare's "phish-prone percentage," meaning the share of employees who would click a simulated phishing link without training, at 41.9%, the highest of any industry tracked. Combined with IBM's healthcare breach cost figure of $7.42 million average, that susceptibility rate translates directly into financial exposure.
Cybersecurity workforce: the conversation has shifted from headcount to skills
For several years, coverage of the cybersecurity workforce led with a single dramatic number: the global "workforce gap," meaning the difference between the current headcount and the number of additional people organizations said they needed. That number has quietly disappeared from the latest research. The 2025 ISC2 Cybersecurity Workforce Study, based on a record survey of more than sixteen thousand professionals, explicitly states: "Respondents to the 2024 and 2025 studies have prioritized the need for critical skills as more important than the need for more people. Therefore, ISC2 has not included an estimate of the cybersecurity workforce gap this year."
That's a meaningful reframing, not a footnote. Tara Wisniewski, executive vice president of advocacy, global markets and member engagement for ISC2, explained the shift: "This year's record survey of more than sixteen thousand professionals shows that skills matter more than ever. Eighty-eight percent have already seen skills needs lead to real consequences, underscoring the importance of investing in people so organizations can adapt as risks evolve." She added that 70% of professionals surveyed are pursuing AI-related qualifications, anticipating that AI will push cybersecurity roles toward more strategic and communication-focused work rather than eliminating them.
The 2025 study also found that almost nine in ten professionals said their organization suffered a significant cybersecurity incident directly attributable to a skills gap, many more than once, and 95% said at least one critical skill was currently missing on their team, up five points from 2024. Meanwhile, hiring freezes, layoffs, and budget cuts that spiked in 2024 are beginning to stabilize rather than disappear, according to reporting on the study by Dan Lohrmann for GovTech, meaning budget pressure remains a constraint even as demand for specific skills climbs.
The US Bureau of Labor Statistics separately projects 32% job growth for information security analyst roles between 2022 and 2032, far above the average across all occupations, which suggests the long-term demand curve hasn't flattened even if the framing around "headcount gap" has changed.
What's genuinely changed since the last version of this report
A few honest corrections to how this topic used to be framed:
- The "COVID-19 drove remote work vulnerabilities" framing that dominated cybersecurity commentary through 2021 and 2022 is no longer a meaningful current driver. Remote and hybrid work are simply the baseline operating model for most organizations now, and the security architecture built around it (zero trust, identity-centric access control) has matured accordingly.
- End-of-life operating systems like Windows 7 and Server 2008/2012 are largely gone from production environments at this point; the current equivalent risk is unpatched cloud misconfigurations and stale open-source dependencies, which show up constantly in current breach data.
- The dominant attack vector conversation has shifted from "phishing versus malware" toward identity and credential abuse across cloud environments. Verizon's 2026 DBIR found that, for the first time in the report's 19-year history, exploiting known vulnerabilities has overtaken stolen credentials as the single most common breach entry point, a shift Verizon attributes directly to AI accelerating the pace at which attackers weaponize disclosed vulnerabilities.
Daniel Lawson, SVP Global Solutions at Verizon Business, summed up the throughline in the 2026 DBIR release: "While the velocity of cyber threats, driven by AI and faster vulnerability exploitation, is increasing, the foundational principles of security and strong risk management remain the most effective defense. The DBIR reinforces that these fundamentals still hold as organizations strive for resilience."
That's arguably the most useful takeaway in this entire post. The threat volume and sophistication numbers above are real and worth tracking, but the actual defense hasn't fundamentally changed: patch known vulnerabilities quickly, govern identity and access tightly, and don't let AI adoption outpace the security controls wrapped around it. Organizations getting breached in 2026 are, overwhelmingly, getting breached through gaps that were preventable with existing, unglamorous practices.
Also read: How to Remediate Cyber Threats | Common Network Vulnerability Types | Zero Click Attacks
