Gitnux/Report 2026

Internet Dangers Statistics

FBI logged 791,790 ransomware incidents in 2022—learn the fastest ways to spot, stop, and reduce impact from today’s internet threats.
27Statistics
27Sources
6Sections
5mRead
3 days agoUpdated
Internet Dangers Statistics
Verified via a 4-step process
01Source

Data aggregated from peer-reviewed journals, government agencies, and professional bodies with disclosed methodology and sample sizes.

02Verify

Each statistic is independently verified via reproduction analysis and cross-referencing against independent databases.

03Grade

Figures are graded by cross-model consensus. Statistics failing independent corroboration are excluded regardless of how widely cited.

04Cite

Every figure carries a primary source. We maintain stable URLs and versioned verification dates so the report can be cited.

Read our full methodology →

Statistics that fail independent corroboration are excluded.

Next review Jan 2027
Internet dangers affect people and institutions—especially when breaches involve healthcare, payment systems, and organizations facing ransomware, phishing, and web app attacks. These risks are shaped by human behavior, heavy reliance on third parties, and the constant arrival of new vulnerabilities. On this page, you’ll explore how threats appear across channels, what gets exploited, and which defenses and response practices help limit damage.

Key Takeaways

  • 791,790 ransomware-related incidents were reported to the FBI in 2022
  • 55% of surveyed organizations experienced an insider-related security incident in the past 12 months (2023)
  • 51% of organizations experienced supply-chain security incidents (2023)
  • 462,198 new phishing sites were detected in Q4 2023
  • 36% of organizations reported web application attacks in 2023
  • 58% of organizations experienced an increase in phishing attacks in 2023
  • 67% of organizations use external or third-party services that could introduce cyber risk (2023)
  • 59% of ransomware victims reported paying the ransom (2023/2024 survey year)
  • 2.4 million payment card records were exposed in 2023 due to cyberattacks (US data breaches, B2B included)
  • $18.4 billion was the estimated global cost of cybercrime in 2023
  • 73% of breaches involved the human element in some way (2022)
  • 61% of organizations report they have experienced a phishing attack — indicates phishing prevalence as a commonly reported security event
  • 35% of web traffic is encrypted TLS in 2023 — indicates the share of traffic carried over encrypted channels (relevant to monitoring and visibility)
  • 1,000-plus vulnerabilities are disclosed daily on average (CVE listings) — indicates the rate of newly reported software weaknesses
  • 2023 saw an 8% increase in average breach investigation time compared with 2022 (mean days) — indicates worsening investigation duration

Cybercrime is rising fast, with phishing, ransomware, and third party risk impacting most organizations worldwide.

02 · Category

Threat Activity4 stats

01
61% of organizations report they have experienced a phishing attack — indicates phishing prevalence as a commonly reported security event
02
35% of web traffic is encrypted TLS in 2023 — indicates the share of traffic carried over encrypted channels (relevant to monitoring and visibility)
03
1,000-plus vulnerabilities are disclosed daily on average (CVE listings) — indicates the rate of newly reported software weaknesses
04
In 2023, 68% of malware samples were packed/obfuscated — indicates defensive significance for detection evasion techniques
Interpretation

Threat Activity Interpretation

Under the Threat Activity category, phishing stands out with 61% of organizations reporting attacks, while the threat landscape keeps accelerating as 1,000 or more vulnerabilities are disclosed daily and 68% of malware samples are packed or obfuscated.

03 · Category

Risk Exposure4 stats

01
73% of organizations use external or third-party services that could introduce cyber risk (2023) — indicates high reliance on third parties that can create additional attack paths
02
In 2024, 48% of organizations reported using managed detection and response (MDR) — indicates security tooling investment in detection capabilities
03
CISA’s KEV catalog had 295 vulnerabilities added by end of 2023 — indicates the volume of known exploited vulnerabilities defenders prioritize
04
In 2023, 41% of organizations reported using SBOMs for third-party risk management — indicates adoption of supply-chain visibility controls
Interpretation

Risk Exposure Interpretation

Risk exposure is intensifying as 73% of organizations depend on third parties while supply chain visibility is still only 41% using SBOMs, and the threat load is reflected in CISA’s KEV adding 295 vulnerabilities by end of 2023.

04 · Category

Incidents & Victims3 stats

01
791,790 ransomware-related incidents were reported to the FBI in 2022
02
55% of surveyed organizations experienced an insider-related security incident in the past 12 months (2023)
03
51% of organizations experienced supply-chain security incidents (2023)
Interpretation

Incidents & Victims Interpretation

For the Incidents and Victims lens, reported ransomware incidents hit 791,790 in 2022 while, in the past year, 55% of organizations faced insider-related security incidents and 51% dealt with supply chain security incidents, showing that victims are being impacted from multiple threat sources at once.

05 · Category

Mitigation & Controls3 stats

01
44% of organizations use phishing-resistant MFA (e.g., FIDO2/WebAuthn) — indicates partial adoption of higher-assurance authentication controls
02
71% of organizations have implemented some form of security automation in response workflows in 2023 — indicates growing use of automation to reduce response time
03
NIST SP 800-53 recommends MFA for privileged accounts; privileged access should be protected by MFA — indicates an explicit control expectation in a security framework
Interpretation

Mitigation & Controls Interpretation

The mitigation and controls picture is strengthening as 44% of organizations use phishing-resistant MFA and 71% have automated security response workflows, while NIST SP 800-53 explicitly calls for MFA on privileged accounts.

06 · Category

Industry Overview9 stats

01
34% of web applications in a large sample were found to be vulnerable to OWASP Top 10 issues (2023 testing results)
02
60% of exploited vulnerabilities in the CISA KEV catalog were known to be exploited within 1 year of public disclosure (2022 analysis)
03
18% of phishing messages used attachment-based delivery in 2023 (2023 study)
04
462,198 new phishing sites were detected in Q4 2023
05
36% of organizations reported web application attacks in 2023
06
2.4 million payment card records were exposed in 2023 due to cyberattacks (US data breaches, B2B included)
07
$18.4 billion was the estimated global cost of cybercrime in 2023
08
73% of breaches involved the human element in some way (2022)
09
2023 saw an 8% increase in average breach investigation time compared with 2022 (mean days) — indicates worsening investigation duration
Interpretation

Industry Overview Interpretation

Across the industry, multiple indicators point to persistent and rapidly weaponized risk, with 34% of tested web applications vulnerable to OWASP Top 10 issues in 2023 and 60% of CISA KEV exploited vulnerabilities already being exploited within a year of public disclosure.
Reference

Cite This Report

This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.

APA
Marcus Engström. (2026, February 13). Internet Dangers Statistics. Gitnux. https://gitnux.org/internet-dangers-statistics
MLA
Marcus Engström. "Internet Dangers Statistics." Gitnux, 13 Feb 2026, https://gitnux.org/internet-dangers-statistics.
Chicago
Marcus Engström. 2026. "Internet Dangers Statistics." Gitnux. https://gitnux.org/internet-dangers-statistics.