logo svg
logo

September 28, 2025

The cost of cybercrime statistics is projected to be $10.5 trillion annually by 2025

A CISO-ready briefing on FBI, IBM, APWG trends breach costs, attack velocity, top vectors and the practical controls that move risk down fast.

Mohammed Khalil

Mohammed Khalil

Featured Image

Cybercrime Statistics 2025

What Are Cybercrime Statistics and Why They Matter

Callout box mapping FBI, IBM, APWG, and Trend Micro to the kinds of cybercrime figures they publish

Cybercrime statistics measure the frequency, methods, and financial impact of online crimes fraud, hacking, ransomware, etc.. Agencies like the FBI’s Internet Crime Complaint Center IC3 and industry reports IBM, Trend Micro, APWG compile this data annually.

For example, the FBI’s latest report for calendar 2024 tallied 859,532 complaints of suspected internet crimes and >$16 billion in losses. These numbers jumped 33% from the prior year, signaling a rapid rise in attacks. In practical terms, a cyberattack hit businesses or individuals roughly every 39 seconds in 2023.

Why does this matter? These stats translate to real world impact: trillions of dollars lost, stolen data, and disrupted services. Cybercrime can cripple companies and essential services from small businesses to government agencies.

Understanding the scale such as the FBI's report or APWG’s 1,003,924 phishing incidents in Q1 2025 helps organizations prioritize security measures, budget, and training. Put bluntly, ignoring the data means risking your business.

Global Cost and Scope of Cybercrime

Line chart showing annual global cybercrime costs rising to $10.5 trillion by 2025, with a note of $333,000 per minute

Cybercrime has become a global economic juggernaut. CompTIA analysts estimate that annual global Cybercrime Expected to Cost the World $10.5 Trillion Annually by 2025 a 10% YOY increase more than the GDP of most countries. This includes direct losses, ransoms, theft plus recovery and reputational damage.

To put it another way, at $10.5 T/year the world is burning through roughly $333,000 per minute on cybercrime. Even today’s reported losses $16 B in 2024 are just the tip of the iceberg, since many crimes go unreported. For perspective, the FBI emphasizes that reporting is critical last year people over age 60 filed the most complaints and suffered nearly $5 B in losses.

Cybercrime now rivals or exceeds organized crime in scale. Gartner and WEF identify it as a top global risk. The FBI notes that even with active disruption efforts e.g. LockBit takedown, losses still climbed. High profile cases Colonial Pipeline, JBS and automated attacks Trend Micro saw 161 billion threats blocked in 2023 underscore the volume and automation of modern attacks. This global surge is why tracking these stats is crucial.

Top Cybercrime Attack Types 2024 2025

Stacked bar visual comparing major cyber threats, with notes: record phishing volume, 73% ransomware growth, multibillion BEC losses.

These categories overlap for instance, phishing often triggers breaches or ransomware. But combined, they paint a picture of a cybercriminal ecosystem that is automated, profitable, and constantly morphing. As one practitioner puts it: Hackers are targeting fewer victims with more advanced attacks 2023’s surge in endpoint malware shows this shift.

Cybercrime Impact by Industry

Heatmap showing healthcare and finance with highest breach costs, public sector and education with high attack frequency.

Certain industries consistently draw outsized attacks and losses. Key examples:

In summary, no sector is immune. Where data or money flows, criminals will follow. Sectors with valuable data health, finance or weaker security education, small biz see especially high attack rates and costs.

Mitigation Steps & Takeaways

Checklist graphic of priority security actions including phishing training, patching, IR drills, AI-assisted detection, and penetration testing.

Given these worrying stats, what can organizations do? Here’s a quick checklist:

  1. Prioritize Phishing Defense: Train employees rigorously on spotting phishing. Deploy email filtering and multifactor authentication. Remember, phishing remains the number 1 attack vector. Regularly test staff with simulated phishing.
  2. Backup and Patch: Maintain offline backups of critical data to survive ransomware. Ensure all systems are up to date unpatched software was involved in many attacks Verizon DBIR shows 32% of breaches exploited known vulnerabilities.
  3. Incident Response Planning: Develop and rehearse an incident response plan. Organizations often discover breaches late practicing IR can shave months off response time and save millions.
  4. Invest in Detection: Deploy modern security monitoring e.g. XDR and consider AI assisted tools to detect anomalies quickly. IBM found AI/automation can cut breach life by 108 days and save $1.76M per breach. Rapid detection is key: each hour of delay costs big money.
  5. Penetration Testing & Assessments: Regularly test your defenses internal/external pen tests, red teaming. Catching gaps early is far cheaper than fallout later. DeepStrike’s penetration testing services help find hidden vulnerabilities before attackers do.
  6. Leverage Data & Frameworks: Use these stats to justify security budget and controls. Align with frameworks like NIST CSF or ISO 27001 to cover high risk areas. For specific mapping, see NIST CSF pen testing guidance.
  7. Cyber Insurance & Compliance: If applicable, maintain cyber insurance and make sure to meet requirements like PCI DSS 11.3 or HIPAA’s pen test rules. Keep logs and evidence, as rising costs mean insurance claims are under more scrutiny. Check out our article on cyber insurance claims trends and data for more.

Organizations should think of these stats as a wake up call. More attacks mean more risk but also more actionable data. Track industry reports, adapt controls, and treat cyber defenses as a continuous investment, not a one time project.

Cybercrime statistics for 2024-2025 send a clear message: attacks are faster and more expensive than ever. Rising losses, booming ransomware, and unchecked phishing show that threat actors have the upper hand unless we adapt. Staying informed about these trends is step one; step two is action.

Dark call-to-action banner inviting readers to schedule a penetration test with DeepStrike

Ready to Strengthen Your Defenses? The threats of 2025 demand readiness. If you're looking to validate your security posture, identify hidden risks, or build a resilient defense strategy, DeepStrike is here to help. Our team of practitioners provides clear, actionable guidance to protect your business. Explore our penetration testing services to see how we can uncover vulnerabilities before attackers do. Drop us a line we’re always ready to dive in.

About the Author

Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security. Certified CISSP, OSCP and OSWE, he has led red team engagements for Fortune 500 firms in finance, healthcare, and tech. Mohammed dissects complex attack chains and builds resilient defenses by living the adversary’s methodology. With over a decade of hands-on experience, he’s passionate about translating these threats into practical security advice for organizations.

FAQs

Industry analysts estimate around $10.5 trillion per year by 2025. That includes direct losses, thefts, ransoms plus cleanup and downtime. Costs have been rising 10% annually, making cybercrime effectively one of the world’s largest economies.

Cybercriminals now launch attacks roughly every 30-40 seconds. For example, WatchGuard cites a study saying there were over 2,200 attacks per day in 2023 one every 39 seconds. Frequency is increasing: that’s faster than the 44 second interval noted for 2022.

According to IBM’s 2023 study, it was about $4.45 million globally. Critical sectors paid even more healthcare breaches averaged $10.93 M. Breach costs include detection, notification, remediation, and lost business.

Phishing and email fraud top the list by incident count FBI identified phishing/spoofing as the number 1 complaint in 2024. Ransomware is very common too, especially against enterprises. Global ransomware incidents grew 73% in 2023. Other frequent threats include business email compromise, malware infections, and data breaches. In short: email based scams phishing/BEC and data encrypting ransomware are the biggest risks.

Healthcare and finance lead in breach costs. Healthcare organizations see the highest per incident costs $10.93 M due to sensitive data and regulation. Financial services also have high breach costs $5.9 M plus heavy attack volume. Critical infrastructure and government face strategic threats, while education and small businesses suffer from rising ransomware. Sector specifics vary, but all sectors are targeted in today’s environment.

These statistics highlight where to focus defenses. For example, knowing phishing leads the way means beefing up email security and training. A high breach cost suggests investing in prevention backups, patching and quick detection. Companies should update risk assessments and controls based on these trends. In practice, use this data to justify budgets for staff training and testing.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us