Key Takeaways
- In 2023, the FBI's Internet Crime Complaint Center (IC3) received 880,418 cybercrime complaints representing a 10% increase from 2022
- Cybercrime complaints increased by 22.9% globally in 2023, with 88 million incidents reported
- Cyber attacks occur every 39 seconds worldwide, equating to 2,244 per day
- Globally, cybercrime costs are projected to reach $10.5 trillion annually by 2025, up from $3 trillion in 2015
- U.S. losses from cybercrime complaints totaled $12.5 billion in 2023, a 22% increase from 2022
- Investment fraud topped cyber losses at $4.7 billion in 2023 per FBI IC3
- Phishing attacks rose by 58% in 2023, accounting for 36% of all data breaches according to Verizon's 2024 DBIR
- There were over 2.6 million phishing sites detected in Q4 2023 alone by APWG
- Business Email Compromise (BEC) scams caused $2.9 billion in U.S. losses in 2023
- In 2023, ransomware attacks impacted 71% of organizations surveyed by Sophos, with average recovery costs at $1.82 million per incident
- Ransomware payments hit $1.1 billion in 2023, per Chainalysis, with a 7.3% decrease from 2022 peak
- Average ransomware recovery cost reached $4.88 million in 2024 for large organizations, per Sophos 2024 report
- The 2023 MOVEit breach exposed data of 62 million individuals, one of the largest supply chain attacks
- 83% of organizations experienced more than one data breach in 2023, per IBM Cost of a Data Breach Report 2023
- Global data breach notifications hit 8,432 in 2023, exposing 4.35 billion records
Cybercrime surged globally in 2023, costing billions and impacting millions with record-breaking attacks.
Data Breaches
- The 2023 MOVEit breach exposed data of 62 million individuals, one of the largest supply chain attacks
- 83% of organizations experienced more than one data breach in 2023, per IBM Cost of a Data Breach Report 2023
- Global data breach notifications hit 8,432 in 2023, exposing 4.35 billion records
- Equifax breach of 2017 still cited, but 2023 saw breaches exposing 353 million records in US alone
- 5,199 US healthcare data breaches reported 2009-2023, affecting 259 million
- 2023 saw 2,118 publicly extorted victims by ransomware, per Zscaler
- 74% of breached records in 2023 from supply chain attacks, per Verizon
- Log4Shell exploits led to 25% of breaches in late 2021-2023, per CrowdStrike
- MGM Resorts breach via vishing exposed 10.6 million guest records
- Change Healthcare breach disrupted US prescriptions for weeks, affecting 1/3 of Americans
- 2023 breaches averaged 83 days to identify, per IBM
- Snowflake breaches exposed 165 million records via stolen creds
- 43% of breaches involved stolen credentials, per Verizon 2024
- AT&T breach leaked call records of 109 million customers
- 23andMe breach exposed 6.9 million users' DNA data
- 49% of large breaches from vulnerability exploits, per Ponemon
- Ticketmaster breach via Snowflake exposed 560 million users
- 12% of breaches led to ransomware deployment, per Verizon
- Oracle breach via Snowflake leaked 2 million records
- 78% of supply chain breaches from third-party creds, per IBM 2023
- Caesars Entertainment paid $15 million ransom after vishing
- 62% of breaches cost over $5 million including fines, per IBM
- Uber breach via social engineering exposed source code
- 34% of healthcare breaches from phishing, exposing 100M records
- 2023 average breach notification time 49 days, per RiskBased
- Fidelity breach exposed 77k customer SSNs via vendor
Data Breaches Interpretation
Financial Losses
- Globally, cybercrime costs are projected to reach $10.5 trillion annually by 2025, up from $3 trillion in 2015
- U.S. losses from cybercrime complaints totaled $12.5 billion in 2023, a 22% increase from 2022
- Investment fraud topped cyber losses at $4.7 billion in 2023 per FBI IC3
- Cryptocurrency thefts amounted to $3.8 billion in 2023, per Chainalysis
- Average cost of a data breach in 2023 was $4.45 million, per IBM
- Global cybercrime economy valued at $1.5 trillion in 2023, per McAfee
- Average BEC scam loss per victim $157,000 in 2023
- Confidence fraud losses reached $3.5 billion in 2023
- Dark web monitoring detected 15 billion credentials for sale in 2023, per Digital Shadows
- Global cyber insurance premiums rose 50% to $13 billion in 2023
- Personal info theft complaints 364,705 to IC3 in 2023
- Romance scams defrauded victims of $1.3 billion in 2023
- Tech support scams reported by 18,000 victims to IC3, losses $886 million
- Cryptojacking incidents up 29% to 4 million in 2023
- Extortion via ransomware without encryption rose to 25% of cases
- Job scam losses totaled $645 million in 2023
- Darknet markets transacted $1.7 billion in cybercrime goods 2023
- Prize scams cost seniors $574 million in 2023
- Global ransomware incidents 2,209 per day in 2023
- Cryptocurrency ATM scams rose 20% to $50 million losses
- Underground forums saw 400,000 new cybercrime ads in 2023
- Non-fungible token (NFT) scams stole $530 million in 2023
- Average downtime from ransomware 24 days in 2023
- Global cybercrime compliance costs $200 billion annually 2023
- Elder financial exploitation via cyber means $3B+ losses
Financial Losses Interpretation
Incident Frequency
- In 2023, the FBI's Internet Crime Complaint Center (IC3) received 880,418 cybercrime complaints representing a 10% increase from 2022
- Cybercrime complaints increased by 22.9% globally in 2023, with 88 million incidents reported
- Cyber attacks occur every 39 seconds worldwide, equating to 2,244 per day
- DDoS attacks surged 200% in 2023, with 8.46 million incidents, per Cloudflare
- IC3 complaints per capita highest in Nevada at 1 in 345 residents in 2023
- Cybersecurity Ventures predicts 3.5 million unfilled jobs by 2025 fueling crime
- Online predators targeted 500,000 children via grooming in 2023, per Interpol
- 1 in 10 organizations hit by ransomware weekly in 2023, per Barracuda
- Europol notes 7,000+ daily cyber attacks on EU infra in 2023
- 98% of cyber attacks rely on social engineering, per Verizon DBIR
- Malware encounters up 5% to 5.5 billion in 2023, per Cisco
- IoT DDoS attacks peaked at 3.2 Tbps in 2023
- State-sponsored attacks doubled to 1,200 in 2023, per Recorded Future
- 25% of firms faced ransomware, paying average $1.5 million, per Cybereason
- Mobile malware samples reached 12.7 million in 2023, per AV-TEST
- Cyber attacks on critical infrastructure up 380% in 2023, per CISA
- 6 million spam messages blocked daily by Google in 2023
- Botnet attacks hit 1,000 per second peak in 2023, per Akamai
- 99% of malware uses encryption to evade detection, per Zscaler 2023
- Phishing simulations show 27% click rate avg in enterprises 2023
- Zero-day exploits used in 3.8% of attacks but 40% of breaches
- CISA reported 800 vulnerabilities exploited in wild 2023
- 1.1 million unique malware samples daily in 2023 peak
- DDoS mitigation requests up 50% to 16 million in 2023
- 92% of large orgs multi-attacked in 2023, per Accenture
Incident Frequency Interpretation
Phishing and BEC
- Phishing attacks rose by 58% in 2023, accounting for 36% of all data breaches according to Verizon's 2024 DBIR
- There were over 2.6 million phishing sites detected in Q4 2023 alone by APWG
- Business Email Compromise (BEC) scams caused $2.9 billion in U.S. losses in 2023
- Verizon DBIR 2024 notes 68% of breaches involved a human element like phishing
- 300,497 phishing-related complaints to IC3 in 2023, up 21% from prior year
- Smishing attacks (SMS phishing) increased 358% in 2023, per Proofpoint
- Elder fraud via tech support scams cost $3.4 billion in 2023
- Phishing sites mimicking Microsoft increased 231% in 2023, per APWG
- Vishing (voice phishing) reports to IC3 hit 20,099 in 2023
- Spear-phishing success rate 36% higher with COVID themes in 2023, per KnowBe4
- Quishing (QR code phishing) up 51% in 2023, per Infosecurity Magazine
- BEC impersonation of vendors caused 70% of losses
- Email phishing rate 1 in 99 emails malicious in 2023, per SlashNext
- Proofpoint reports 84% employee click phishing links yearly
- Hybrid phishing (email+malware) up 45% in 2023
- WhatsApp phishing scams surged 1300% in 2023, per Kaspersky
- BEC via compromised email servers hit $43,000 avg loss
- Pharming attacks redirected 2.4 million visits in 2023, per Netcraft
- LinkedIn phishing up 127% targeting recruiters in 2023
- URL phishing variants grew 15% to 1.2 million daily
- SMS phishing success doubled with OTP requests in 2023
- Deepfake phishing fooled 35% of execs in tests 2023
- Generative AI boosted phishing creativity by 400%, per Darktrace 2023
- Brand impersonation phishing up 60% targeting banks
- QR code phishing embedded in 1 in 100 malicious emails
- Malicious SMS volume tripled to 1.3 billion in 2023
- AI-generated phishing emails evaded 65% of filters
Phishing and BEC Interpretation
Ransomware
- In 2023, ransomware attacks impacted 71% of organizations surveyed by Sophos, with average recovery costs at $1.82 million per incident
- Ransomware payments hit $1.1 billion in 2023, per Chainalysis, with a 7.3% decrease from 2022 peak
- Average ransomware recovery cost reached $4.88 million in 2024 for large organizations, per Sophos 2024 report
- 16,243 ransomware victims publicly disclosed in 2023, per Cyble research
- LockBit ransomware group claimed 2,617 victims in 2023
- ENISA Threat Landscape 2023 reports ransomware as top threat, with 66% attack increase
- Conti ransomware shutdown led to 20% drop in attacks mid-2022, but rebounded in 2023
- Ryuk ransomware variant caused $150 million in losses before decline
- BlackCat/ALPHV ransomware hit 0.4% of Fortune 1000 in 2023
- Maze ransomware leaked data from 100+ orgs before disbanding
- REvil ransomware seized by authorities, reducing attacks by 30%
- Hive ransomware dismantled, impacting 80 countries
- Clop ransomware exploited MOVEit flaw for $100 million haul
- Akira ransomware new group hit 100+ orgs in 6 months of 2023
- LockBit 3.0 variant used in 40% of ransomware in 2023
- Rhysida ransomware earned $4 million in 2023 debut
- Vice Society ransomware targeted education 50+ times in 2023
- Play ransomware group extorted 1 TB data from victims in 2023
- Snatch ransomware hit healthcare with 20 attacks in 2023
- BianLian ransomware stole 100 GB from orgs before takedown
- ALPHV claimed 100 victims monthly avg in 2023 peak
- RansomHub emerged post-ALPHV with 181 victims claimed
- DragonForce ransomware hit 30 orgs in first month 2023
- Medusa ransomware leaked 300 TB data before exit scam
- 8Base ransomware variant active in 200+ attacks 2023
- INC Ransom group claimed 50 victims in 2023
- BlackSuit ransomware earned $100M+ post-Royal exit
- Cyclops Blink malware hit 25 orgs in Q1 2023
Ransomware Interpretation
Sources & References
- Reference 1IC3ic3.govVisit source
- Reference 2CYBERSECURITYVENTUREScybersecurityventures.comVisit source
- Reference 3VERIZONverizon.comVisit source
- Reference 4SOPHOSsophos.comVisit source
- Reference 5IBMibm.comVisit source
- Reference 6DOCSdocs.apwg.orgVisit source
- Reference 7CHAINALYSISchainalysis.comVisit source
- Reference 8STATISTAstatista.comVisit source
- Reference 9CYBLEcyble.comVisit source
- Reference 10RISKBASEDSECURITYriskbasedsecurity.comVisit source
- Reference 11UNIVERSITYOFPHOENIXuniversityofphoenix.eduVisit source
- Reference 12SOCPRIMEsocprime.comVisit source
- Reference 13IDENTITYTHEFTidentitytheft.comVisit source
- Reference 14ENISAenisa.europa.euVisit source
- Reference 15BLOGblog.cloudflare.comVisit source
- Reference 16PROOFPOINTproofpoint.comVisit source
- Reference 17BLEEPINGCOMPUTERbleepingcomputer.comVisit source
- Reference 18HIPAAJOURNALhipaajournal.comVisit source
- Reference 19MCAFEEmcafee.comVisit source
- Reference 20CROWDSTRIKEcrowdstrike.comVisit source
- Reference 21ZSCALERzscaler.comVisit source
- Reference 22INTERPOLinterpol.intVisit source
- Reference 23MALWAREBYTESmalwarebytes.comVisit source
- Reference 24BARRACUDAbarracuda.comVisit source
- Reference 25KNOWBE4knowbe4.comVisit source
- Reference 26JUSTICEjustice.govVisit source
- Reference 27DIGITALSHADOWSdigitalshadows.comVisit source
- Reference 28EUROPOLeuropol.europa.euVisit source
- Reference 29INFOSECURITY-MAGAZINEinfosecurity-magazine.comVisit source
- Reference 30HHShhs.govVisit source
- Reference 31MARSHmarsh.comVisit source
- Reference 32CISCOcisco.comVisit source
- Reference 33SLASHNEXTslashnext.comVisit source
- Reference 34MANDIANTmandiant.comVisit source
- Reference 35CLOUDFLAREcloudflare.comVisit source
- Reference 36RECORDEDFUTURErecordedfuture.comVisit source
- Reference 37HELPNETSECURITYhelpnetsecurity.comVisit source
- Reference 38ATTatt.comVisit source
- Reference 39CYBEREASONcybereason.comVisit source
- Reference 40KASPERSKYkaspersky.comVisit source
- Reference 41FBIfbi.govVisit source
- Reference 42BLOGblog.23andme.comVisit source
- Reference 43AV-TESTav-test.orgVisit source
- Reference 44CISAcisa.govVisit source
- Reference 45NETCRAFTnetcraft.comVisit source
- Reference 46TICKETMASTERticketmaster.comVisit source
- Reference 47TRANSPARENCYREPORTtransparencyreport.google.comVisit source
- Reference 48AKAMAIakamai.comVisit source
- Reference 49LOOKOUTlookout.comVisit source
- Reference 50FINCENfincen.govVisit source
- Reference 51CAESARScaesars.comVisit source
- Reference 52DARKTRACEdarktrace.comVisit source
- Reference 53APWGapwg.orgVisit source
- Reference 54UBERuber.comVisit source
- Reference 55ACCENTUREaccenture.comVisit source
- Reference 56MICROSOFTmicrosoft.comVisit source
- Reference 57FIDELITYfidelity.comVisit source






