GITNUXREPORT 2026

Cybersecurity Attacks Statistics

Ransomware and phishing attacks escalated sharply and grew more costly in 2023.

Min-ji Park

Min-ji Park

Research Analyst focused on sustainability and consumer trends.

First published: Feb 13, 2026

Our Commitment to Accuracy

Rigorous fact-checking · Reputable sources · Regular updatesLearn more

Key Statistics

Statistic 1

51% of DDoS attacks targeted gaming industry in Q1 2024.

Statistic 2

Global DDoS attack volume hit 25 million in 2023.

Statistic 3

Average DDoS attack duration 10 hours in 2023.

Statistic 4

3.8 billion DDoS bits/sec peak attack recorded Oct 2023.

Statistic 5

71% of DDoS attacks under 10 Gbps in 2023.

Statistic 6

UDP floods comprised 55% of DDoS attacks in Q4 2023.

Statistic 7

Financial services faced 20% DDoS surge in 2023.

Statistic 8

98% of DDoS attacks multi-vectored in 2023.

Statistic 9

IoT botnets powered 40% of DDoS in 2023.

Statistic 10

Average cost of DDoS attack downtime $40,000/hour 2023.

Statistic 11

1.6 Tbps largest DDoS attack mitigated by Google in 2023.

Statistic 12

DDoS on Ukraine peaked at 6 Tbps during 2022 conflict.

Statistic 13

25% increase in HTTPS DDoS attacks in 2023.

Statistic 14

Gaming platforms saw 1 million DDoS attacks monthly 2023.

Statistic 15

DNS amplification DDoS averaged 100 Gbps in 2023.

Statistic 16

60% of orgs experienced DDoS in past year 2023 survey.

Statistic 17

NTP reflection attacks down 50% but still 15% of total 2023.

Statistic 18

E-commerce DDoS up 200% during Black Friday 2023.

Statistic 19

42% of DDoS from state-sponsored actors in 2023.

Statistic 20

Memcached amplification DDoS hit 1.3 Tbps peak 2023.

Statistic 21

Telecom sector absorbed 30% of all DDoS traffic 2023.

Statistic 22

SYN flood attacks 25% of volumetric DDoS 2023.

Statistic 23

80% of DDoS lasted under 1 hour but repeated 2023.

Statistic 24

AWS mitigated 2.3 Tbps DDoS in Oct 2020 ongoing trend 2023.

Statistic 25

Application layer DDoS up 15% targeting APIs 2023.

Statistic 26

500,000 RPS largest HTTP DDoS in 2023.

Statistic 27

Botnets like Mirai variants fueled 35% DDoS 2023.

Statistic 28

Ransomware groups used DDoStorsion in 10% attacks 2023.

Statistic 29

Global DDoS capacity reached 15 million servers 2023.

Statistic 30

Slowloris application DDoS evaded 20% protections 2023.

Statistic 31

Global data breaches exposed 8.36 billion records in 2023.

Statistic 32

Equifax breach 2017 exposed 147 million personal records.

Statistic 33

Average cost of data breach hit $4.88 million in 2023 IBM report.

Statistic 34

MOVEit breach 2023 affected 62 million individuals.

Statistic 35

83% of breaches involved cloud misconfigurations in 2023.

Statistic 36

Yahoo 2013-2014 breaches exposed 3 billion accounts.

Statistic 37

MGM Resorts breach 2023 cost $100 million in losses.

Statistic 38

39 seconds average time to exfiltrate data in breaches 2023.

Statistic 39

Change Healthcare breach 2024 disrupted 1/3 of US payments.

Statistic 40

74% of breaches involved external actors per Verizon 2024.

Statistic 41

Marriott breach 2018-2020 exposed 500 million guests.

Statistic 42

Average stolen records per breach 25,000 in healthcare 2023.

Statistic 43

SolarWinds breach 2020 compromised 18,000 orgs.

Statistic 44

82 days average time to identify and contain breach 2023.

Statistic 45

LinkedIn 2021 breach scraped 700 million user data.

Statistic 46

Optus breach 2022 exposed 10 million customer records.

Statistic 47

54% of breaches exploited stolen credentials 2023.

Statistic 48

Twitter 2022 breach affected 200+ million users via API.

Statistic 49

Average breach notification time 49 days in 2023.

Statistic 50

T-Mobile 2023 breach leaked 37 million customer data.

Statistic 51

17% increase in breach costs for financial services 2023.

Statistic 52

Capital One 2019 breach exposed 100 million applications.

Statistic 53

65% of breaches involved sensitive personal info 2023.

Statistic 54

Snowflake breaches 2024 affected 165 orgs via stolen creds.

Statistic 55

Uber 2022 breach via social engineering exposed internal tools.

Statistic 56

28 days average data exposure time pre-detection 2023.

Statistic 57

AT&T 2024 breach leaked 73 million customer records.

Statistic 58

2.5 million malware samples detected daily in 2023.

Statistic 59

Emotet malware infected 1.7 million systems before 2021 takedown.

Statistic 60

94% of malware uses Windows as primary target 2023.

Statistic 61

Crypto-jacking malware attacks up 29% in 2023.

Statistic 62

WannaCry ransomware malware hit 200,000+ systems in 150 countries 2017.

Statistic 63

Fileless malware comprised 77% of detections in 2023.

Statistic 64

Android malware samples reached 5.5 million in 2023.

Statistic 65

TrickBot malware evolved to 200 variants by 2023.

Statistic 66

1 in 10 downloads contained malware in 2023.

Statistic 67

Supply chain malware like SolarWinds affected 18k orgs.

Statistic 68

Mac malware detections up 50% to 300k in 2023.

Statistic 69

Banking trojans stole $1B+ via malware in 2023.

Statistic 70

56% of orgs hit by malware per 2023 Verizon DBIR.

Statistic 71

Cobalt Strike malware cracked used in 60% APTs 2023.

Statistic 72

IoT malware infections doubled to 2.8B in 2023.

Statistic 73

Spyware malware in Pegasus affected 50k+ phones.

Statistic 74

Rootkits evaded 40% AV in enterprise 2023 tests.

Statistic 75

Adware bundled in 80% freeware downloads 2023.

Statistic 76

Qakbot malware disrupted 700k infections by FBI 2023.

Statistic 77

Mobile ransomware up 93% to 24k samples 2023.

Statistic 78

90% malware delivered via email attachments 2023.

Statistic 79

Lumma stealer malware hit 350k systems Q1 2024.

Statistic 80

Polymorphic malware variants 4.3 million unique 2023.

Statistic 81

RATs like njRAT used in 25% targeted attacks 2023.

Statistic 82

Phishing emails accounted for 36% of initial ransomware access in 2023 Verizon DBIR.

Statistic 83

82% of breaches involved human element, primarily phishing in 2023.

Statistic 84

Average phishing campaign success rate led to 5.3% click-through in 2023.

Statistic 85

Spear-phishing incidents rose 20% year-over-year in 2023 Proofpoint report.

Statistic 86

90% of successful breaches started with phishing email in 2022.

Statistic 87

Business email compromise (BEC) via phishing cost $2.9B in losses in 2023.

Statistic 88

74% of phishing sites used HTTPS in Q4 2023, per APWG.

Statistic 89

Smishing attacks increased 400% from 2022 to 2023.

Statistic 90

68% of organizations faced phishing attempts weekly in 2023.

Statistic 91

Vishing calls impersonating IT support rose 15% in 2023.

Statistic 92

Phishing was initial vector in 16% of all breaches per 2024 DBIR.

Statistic 93

Average time to detect phishing breach was 16 days in 2023.

Statistic 94

300,000 unique phishing sites detected daily in 2023 by APWG.

Statistic 95

BEC scams using phishing averaged $120,000 loss per incident in 2023.

Statistic 96

83% of UK businesses hit by phishing in past year per 2023 survey.

Statistic 97

QR code phishing (quishing) attacks up 51% in 2023.

Statistic 98

44% of phishing emails bypassed secure email gateways in 2023.

Statistic 99

Phishing success rate among millennials was 12% higher than average in 2023.

Statistic 100

1 in 99 emails was phishing in 2023 enterprise analysis.

Statistic 101

AI-generated phishing emails increased 600% in early 2024.

Statistic 102

92% of malware delivered via phishing in 2023.

Statistic 103

SMS phishing (smishing) rose to 45% of mobile attacks in 2023.

Statistic 104

65% of C-suite targeted by whale phishing in 2023.

Statistic 105

Phishing training reduced click rates by 40% in trained orgs 2023.

Statistic 106

22% of breaches attributed to phishing per IBM 2023.

Statistic 107

Unique phishing attacks hit 5 million in 2023 APWG data.

Statistic 108

70% of phishing used social media for recon in 2023.

Statistic 109

Average BEC phishing loss $46,000 in 2023 FBI stats.

Statistic 110

56% increase in phishing domains registered in 2023.

Statistic 111

Healthcare phishing incidents up 25% in 2023.

Statistic 112

40% of employees clicked phishing links despite training 2023.

Statistic 113

In 2023, ransomware attacks increased by 20% globally, with the healthcare sector experiencing a 30% rise compared to 2022.

Statistic 114

The average ransomware recovery cost reached $1.54 million in the US in 2021, excluding ransom payments.

Statistic 115

66% of ransomware victims paid the ransom in 2023, up from 37% in 2021.

Statistic 116

LockBit ransomware group claimed responsibility for 25% of all ransomware incidents tracked in Q1 2024.

Statistic 117

Average time to detect and contain a ransomware attack was 24 days in 2023.

Statistic 118

75% of ransomware attacks in manufacturing involved data exfiltration in 2023.

Statistic 119

Ransom demands averaged $1.77 million in 2023, a 20% increase from prior year.

Statistic 120

Conti ransomware variant affected over 1,000 victims worldwide before its disruption in 2022.

Statistic 121

93% of ransomware attacks in 2023 used phishing as initial access vector.

Statistic 122

UK organizations hit by ransomware saw costs rise 11% to $3.3 million average in 2023.

Statistic 123

Ryuk ransomware caused $150 million in damages across 2020 attacks on US healthcare.

Statistic 124

48% of breached organizations in 2023 faced ransomware, per Verizon DBIR.

Statistic 125

Average paid ransom was $812,380 in Q4 2023, down 7% from previous quarter.

Statistic 126

Hive ransomware disrupted 1,500 victims before FBI takedown in 2023.

Statistic 127

Ransomware hit 75% of healthcare providers surveyed in Sophos 2023 report.

Statistic 128

BlackCat/ALPHV claimed 190 victims in 2023 with average payout $2.5M.

Statistic 129

37% of ransomware attacks in 2023 resulted in multiple incidents per organization.

Statistic 130

REvil ransomware attacks peaked at 400+ victims in 2021 before shutdown.

Statistic 131

Average downtime from ransomware was 24 days for affected businesses in 2023.

Statistic 132

Clop ransomware exploited MOVEit vulnerability affecting 2,000+ orgs in 2023.

Statistic 133

62% of ransomware payments went to Russian-based groups in 2023.

Statistic 134

Average ransomware cost in retail sector was $2.37 million in 2023.

Statistic 135

Akira ransomware emerged in 2023 targeting 100+ Windows/Linux systems.

Statistic 136

80% of ransomware victims in 2023 used backups for recovery.

Statistic 137

LockBit 3.0 variant used in 40% of Q2 2024 attacks tracked.

Statistic 138

Ransomware attacks on education sector up 51% in 2023.

Statistic 139

Average negotiation time for ransomware was 6 days in 2023.

Statistic 140

DarkSide ransomware caused Colonial Pipeline shutdown in 2021.

Statistic 141

54% of orgs hit by ransomware in 2023 were small businesses.

Statistic 142

RansomHub group launched 100+ attacks post-LockBit leak in 2024.

Trusted by 500+ publications
Harvard Business ReviewThe GuardianFortune+497
While ransomware attacks continue to escalate globally, with a shocking 66% of victims now paying the ransom, the true digital battlefield in 2023 was dominated by phishing, which served as the entry point for a staggering 93% of these costly and disruptive incidents.

Key Takeaways

  • In 2023, ransomware attacks increased by 20% globally, with the healthcare sector experiencing a 30% rise compared to 2022.
  • The average ransomware recovery cost reached $1.54 million in the US in 2021, excluding ransom payments.
  • 66% of ransomware victims paid the ransom in 2023, up from 37% in 2021.
  • Phishing emails accounted for 36% of initial ransomware access in 2023 Verizon DBIR.
  • 82% of breaches involved human element, primarily phishing in 2023.
  • Average phishing campaign success rate led to 5.3% click-through in 2023.
  • Global data breaches exposed 8.36 billion records in 2023.
  • Equifax breach 2017 exposed 147 million personal records.
  • Average cost of data breach hit $4.88 million in 2023 IBM report.
  • 51% of DDoS attacks targeted gaming industry in Q1 2024.
  • Global DDoS attack volume hit 25 million in 2023.
  • Average DDoS attack duration 10 hours in 2023.
  • 2.5 million malware samples detected daily in 2023.
  • Emotet malware infected 1.7 million systems before 2021 takedown.
  • 94% of malware uses Windows as primary target 2023.

Ransomware and phishing attacks escalated sharply and grew more costly in 2023.

DDoS

  • 51% of DDoS attacks targeted gaming industry in Q1 2024.
  • Global DDoS attack volume hit 25 million in 2023.
  • Average DDoS attack duration 10 hours in 2023.
  • 3.8 billion DDoS bits/sec peak attack recorded Oct 2023.
  • 71% of DDoS attacks under 10 Gbps in 2023.
  • UDP floods comprised 55% of DDoS attacks in Q4 2023.
  • Financial services faced 20% DDoS surge in 2023.
  • 98% of DDoS attacks multi-vectored in 2023.
  • IoT botnets powered 40% of DDoS in 2023.
  • Average cost of DDoS attack downtime $40,000/hour 2023.
  • 1.6 Tbps largest DDoS attack mitigated by Google in 2023.
  • DDoS on Ukraine peaked at 6 Tbps during 2022 conflict.
  • 25% increase in HTTPS DDoS attacks in 2023.
  • Gaming platforms saw 1 million DDoS attacks monthly 2023.
  • DNS amplification DDoS averaged 100 Gbps in 2023.
  • 60% of orgs experienced DDoS in past year 2023 survey.
  • NTP reflection attacks down 50% but still 15% of total 2023.
  • E-commerce DDoS up 200% during Black Friday 2023.
  • 42% of DDoS from state-sponsored actors in 2023.
  • Memcached amplification DDoS hit 1.3 Tbps peak 2023.
  • Telecom sector absorbed 30% of all DDoS traffic 2023.
  • SYN flood attacks 25% of volumetric DDoS 2023.
  • 80% of DDoS lasted under 1 hour but repeated 2023.
  • AWS mitigated 2.3 Tbps DDoS in Oct 2020 ongoing trend 2023.
  • Application layer DDoS up 15% targeting APIs 2023.
  • 500,000 RPS largest HTTP DDoS in 2023.
  • Botnets like Mirai variants fueled 35% DDoS 2023.
  • Ransomware groups used DDoStorsion in 10% attacks 2023.
  • Global DDoS capacity reached 15 million servers 2023.
  • Slowloris application DDoS evaded 20% protections 2023.

DDoS Interpretation

While the gaming industry unwittingly became the world's most popular stress test platform, absorbing half of all DDoS attacks, the rest of the digital landscape was caught in a relentless, multi-vectored assault where botnets are cheap, state actors are bold, and every hour of downtime racks up a bill that would make a CFO cry.

Data Breaches

  • Global data breaches exposed 8.36 billion records in 2023.
  • Equifax breach 2017 exposed 147 million personal records.
  • Average cost of data breach hit $4.88 million in 2023 IBM report.
  • MOVEit breach 2023 affected 62 million individuals.
  • 83% of breaches involved cloud misconfigurations in 2023.
  • Yahoo 2013-2014 breaches exposed 3 billion accounts.
  • MGM Resorts breach 2023 cost $100 million in losses.
  • 39 seconds average time to exfiltrate data in breaches 2023.
  • Change Healthcare breach 2024 disrupted 1/3 of US payments.
  • 74% of breaches involved external actors per Verizon 2024.
  • Marriott breach 2018-2020 exposed 500 million guests.
  • Average stolen records per breach 25,000 in healthcare 2023.
  • SolarWinds breach 2020 compromised 18,000 orgs.
  • 82 days average time to identify and contain breach 2023.
  • LinkedIn 2021 breach scraped 700 million user data.
  • Optus breach 2022 exposed 10 million customer records.
  • 54% of breaches exploited stolen credentials 2023.
  • Twitter 2022 breach affected 200+ million users via API.
  • Average breach notification time 49 days in 2023.
  • T-Mobile 2023 breach leaked 37 million customer data.
  • 17% increase in breach costs for financial services 2023.
  • Capital One 2019 breach exposed 100 million applications.
  • 65% of breaches involved sensitive personal info 2023.
  • Snowflake breaches 2024 affected 165 orgs via stolen creds.
  • Uber 2022 breach via social engineering exposed internal tools.
  • 28 days average data exposure time pre-detection 2023.
  • AT&T 2024 breach leaked 73 million customer records.

Data Breaches Interpretation

Despite staggering statistics showing billions of records exposed and costs soaring to millions per incident, the true scandal is that most breaches stem from preventable errors like cloud misconfigurations and reused passwords, turning cybersecurity into a self-inflicted crisis.

Malware

  • 2.5 million malware samples detected daily in 2023.
  • Emotet malware infected 1.7 million systems before 2021 takedown.
  • 94% of malware uses Windows as primary target 2023.
  • Crypto-jacking malware attacks up 29% in 2023.
  • WannaCry ransomware malware hit 200,000+ systems in 150 countries 2017.
  • Fileless malware comprised 77% of detections in 2023.
  • Android malware samples reached 5.5 million in 2023.
  • TrickBot malware evolved to 200 variants by 2023.
  • 1 in 10 downloads contained malware in 2023.
  • Supply chain malware like SolarWinds affected 18k orgs.
  • Mac malware detections up 50% to 300k in 2023.
  • Banking trojans stole $1B+ via malware in 2023.
  • 56% of orgs hit by malware per 2023 Verizon DBIR.
  • Cobalt Strike malware cracked used in 60% APTs 2023.
  • IoT malware infections doubled to 2.8B in 2023.
  • Spyware malware in Pegasus affected 50k+ phones.
  • Rootkits evaded 40% AV in enterprise 2023 tests.
  • Adware bundled in 80% freeware downloads 2023.
  • Qakbot malware disrupted 700k infections by FBI 2023.
  • Mobile ransomware up 93% to 24k samples 2023.
  • 90% malware delivered via email attachments 2023.
  • Lumma stealer malware hit 350k systems Q1 2024.
  • Polymorphic malware variants 4.3 million unique 2023.
  • RATs like njRAT used in 25% targeted attacks 2023.

Malware Interpretation

Cyber threats have evolved into a relentless, shape-shifting tidal wave that proves no platform is safe and that even our most trusted digital tools can be cunningly turned against us.

Phishing

  • Phishing emails accounted for 36% of initial ransomware access in 2023 Verizon DBIR.
  • 82% of breaches involved human element, primarily phishing in 2023.
  • Average phishing campaign success rate led to 5.3% click-through in 2023.
  • Spear-phishing incidents rose 20% year-over-year in 2023 Proofpoint report.
  • 90% of successful breaches started with phishing email in 2022.
  • Business email compromise (BEC) via phishing cost $2.9B in losses in 2023.
  • 74% of phishing sites used HTTPS in Q4 2023, per APWG.
  • Smishing attacks increased 400% from 2022 to 2023.
  • 68% of organizations faced phishing attempts weekly in 2023.
  • Vishing calls impersonating IT support rose 15% in 2023.
  • Phishing was initial vector in 16% of all breaches per 2024 DBIR.
  • Average time to detect phishing breach was 16 days in 2023.
  • 300,000 unique phishing sites detected daily in 2023 by APWG.
  • BEC scams using phishing averaged $120,000 loss per incident in 2023.
  • 83% of UK businesses hit by phishing in past year per 2023 survey.
  • QR code phishing (quishing) attacks up 51% in 2023.
  • 44% of phishing emails bypassed secure email gateways in 2023.
  • Phishing success rate among millennials was 12% higher than average in 2023.
  • 1 in 99 emails was phishing in 2023 enterprise analysis.
  • AI-generated phishing emails increased 600% in early 2024.
  • 92% of malware delivered via phishing in 2023.
  • SMS phishing (smishing) rose to 45% of mobile attacks in 2023.
  • 65% of C-suite targeted by whale phishing in 2023.
  • Phishing training reduced click rates by 40% in trained orgs 2023.
  • 22% of breaches attributed to phishing per IBM 2023.
  • Unique phishing attacks hit 5 million in 2023 APWG data.
  • 70% of phishing used social media for recon in 2023.
  • Average BEC phishing loss $46,000 in 2023 FBI stats.
  • 56% increase in phishing domains registered in 2023.
  • Healthcare phishing incidents up 25% in 2023.
  • 40% of employees clicked phishing links despite training 2023.

Phishing Interpretation

Despite the constant digital arms race, humans remain the achingly soft underbelly of cybersecurity, with phishing—our seemingly unshakable penchant for clicking—persistently unlocking the front door for a staggering array of expensive digital disasters.

Ransomware

  • In 2023, ransomware attacks increased by 20% globally, with the healthcare sector experiencing a 30% rise compared to 2022.
  • The average ransomware recovery cost reached $1.54 million in the US in 2021, excluding ransom payments.
  • 66% of ransomware victims paid the ransom in 2023, up from 37% in 2021.
  • LockBit ransomware group claimed responsibility for 25% of all ransomware incidents tracked in Q1 2024.
  • Average time to detect and contain a ransomware attack was 24 days in 2023.
  • 75% of ransomware attacks in manufacturing involved data exfiltration in 2023.
  • Ransom demands averaged $1.77 million in 2023, a 20% increase from prior year.
  • Conti ransomware variant affected over 1,000 victims worldwide before its disruption in 2022.
  • 93% of ransomware attacks in 2023 used phishing as initial access vector.
  • UK organizations hit by ransomware saw costs rise 11% to $3.3 million average in 2023.
  • Ryuk ransomware caused $150 million in damages across 2020 attacks on US healthcare.
  • 48% of breached organizations in 2023 faced ransomware, per Verizon DBIR.
  • Average paid ransom was $812,380 in Q4 2023, down 7% from previous quarter.
  • Hive ransomware disrupted 1,500 victims before FBI takedown in 2023.
  • Ransomware hit 75% of healthcare providers surveyed in Sophos 2023 report.
  • BlackCat/ALPHV claimed 190 victims in 2023 with average payout $2.5M.
  • 37% of ransomware attacks in 2023 resulted in multiple incidents per organization.
  • REvil ransomware attacks peaked at 400+ victims in 2021 before shutdown.
  • Average downtime from ransomware was 24 days for affected businesses in 2023.
  • Clop ransomware exploited MOVEit vulnerability affecting 2,000+ orgs in 2023.
  • 62% of ransomware payments went to Russian-based groups in 2023.
  • Average ransomware cost in retail sector was $2.37 million in 2023.
  • Akira ransomware emerged in 2023 targeting 100+ Windows/Linux systems.
  • 80% of ransomware victims in 2023 used backups for recovery.
  • LockBit 3.0 variant used in 40% of Q2 2024 attacks tracked.
  • Ransomware attacks on education sector up 51% in 2023.
  • Average negotiation time for ransomware was 6 days in 2023.
  • DarkSide ransomware caused Colonial Pipeline shutdown in 2021.
  • 54% of orgs hit by ransomware in 2023 were small businesses.
  • RansomHub group launched 100+ attacks post-LockBit leak in 2024.

Ransomware Interpretation

While ransomware attacks are becoming more frequent, expensive, and brazenly effective—with more victims paying up despite the staggering recovery costs—the sobering truth is that our collective cybersecurity hygiene, from phishing resilience to patch management, remains woefully inadequate against these persistently evolving criminal enterprises.

Sources & References