ByteSizedSecurity Cybersecurity Insights & Analysis
Threats 6 min read

Cybercrime Losses in 2026: The Index With No Grand Total

Marc David
Marc David Senior Security Engineer · CISSP
Cybercrime Losses Data Breach Costs SEC Disclosure
Cybercrime Losses in 2026: The Index With No Grand Total

Cybersecurity finally has a public breach ledger. Its most radical feature is a number it will never show you.

TL;DR: Security executive Richard Bird built The Hacker in a Hoodie Index, a live ledger of disclosed material breaches drawn from SEC 8-K filings and news reports, with every entry graded Verified, Attested, or Inferred. It deliberately refuses to sum the losses into one headline figure, because adding a verified dollar amount to a news-sourced guess produces a number backed by nothing. The data it does show is sharper than any total: over the last decade, reported cybercrime losses grew about 5.3x faster than the S&P 500, while the cost of a single breach barely moved.


For a field obsessed with numbers, cybersecurity has never had an honest scoreboard. We quote a $10.5 trillion global cybercrime figure in keynotes and board decks, yet no one points to where it was measured. There is no official, citable, source-graded record of what breaches have cost. A new project, built and maintained by one person, sets out to fill the gap, and the way it handles the missing total is the most interesting part.

Jump to a section:

What is the Hacker in a Hoodie Index?

Direct answer: It is a public, daily-updated ledger of disclosed material breaches, built by security executive Richard Bird. It pulls from SEC 8-K filings and news reports and grades every entry Verified, Attested, or Inferred.

The index is the work of Richard Bird, a longtime security leader and author, released ahead of his book Built Wrong. It runs on two ledgers he keeps current with scrapers he wrote himself, and it draws a direct line to Troy Hunt’s Have I Been Pwned: a resource nobody else was building, started small because there was nowhere else to look.

The first ledger reads from SEC EDGAR, tracking the 8-K disclosures public companies must file when they hit a material cyber incident, a requirement in force only since 2023. The second ledger covers incidents surfaced in company statements and news coverage. At the time of writing, the ledgers hold well over a hundred incidents, from a Coca-Cola subsidiary to a healthcare lab breach affecting more than half a million people, the kind of health-data exposure I wrote about in the iRhythm patient-records breach.

The grading is the part worth stealing. A primary SEC filing counts as Verified, a company’s own statement as Attested, and a news report as Inferred. One glance tells you how much a given entry carries.

How much does a data breach cost in 2026?

Direct answer: IBM’s widely cited report puts the global average near $4.44 million per breach in 2025, down about 9% from the prior year. It is a per-incident average, not a national total.

The reference figure most people reach for is IBM’s Cost of a Data Breach report, which lands at roughly $4.44 million per breach in its latest edition. It is a modeled average across hundreds of organizations, and it answers a narrow question: what does one breach cost a typical company?

Here is the detail the headlines skip. The per-breach cost has been close to flat for a decade, rising around 2% a year and then slipping in the latest reading. If the price of a single event is holding steady while total reported losses climb fast, the growth is not coming from breaches getting more expensive. It is coming from more of them, against a wider attack surface.

How fast are cybercrime losses growing?

Direct answer: Reported losses to the FBI’s IC3 reached about $20.9 billion in 2025 and have compounded near 35% a year for a decade, roughly 5.3x the total return of the S&P 500 over the same window.

The clearest signal comes from the FBI’s Internet Crime Complaint Center, whose reported losses reached about $20.9 billion in 2025. By the FBI’s own account it is an undercount, since most victims never file a complaint. Even so, the trend is steep: losses have compounded at roughly 35% a year, about 5.3 times the total return of the S&P 500 across the same decade.

The three sources the index leans on measure sharply different slices of the problem, which is exactly why it keeps them apart:

Source What it counts Latest (2025) Growth
FBI IC3 Reported losses from US victim complaints ~$20.9B ~35%/yr over the decade
Chainalysis On-chain ransom payments to attackers ~$0.82B Volatile; peaked in 2023
IBM / Ponemon Modeled average cost of one breach ~$4.44M ~2%/yr, then fell in 2025

Read the columns, not a sum. One is a national reported total, one is a traced crypto figure, one is a per-event average. They overlap in places and are blind to each other in others.

Why won’t the index add up the losses?

Direct answer: Because the entries count different things across different evidence tiers. Adding a verified SEC figure to an inferred news estimate creates a precise-looking headline with nothing solid behind it.

Most entries in the ledger are marked “not yet quantified,” and the ones carrying a figure come from different evidence tiers. A verified dollar loss in an SEC filing is not the same kind of fact as an estimate lifted from a news story. Treating them as interchangeable and adding them together yields a precise-looking number resting on air.

Bird’s own framing is blunt: summing the numbers turns data into a prediction, and the underreporting is severe enough to turn any headline total into a new myth with more citations attached. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest. The index also refuses the opposite temptation, estimating the unmeasured and calling the result the real number. What no one measured has no figure, only its absence.

Is the $10.5 trillion cybercrime number real?

Direct answer: No. The $10.5 trillion figure is a forecast from Cybersecurity Ventures, compounded from a 2015 base whose method was never published. The index excludes it as an assumption, not a measurement.

The industry’s favorite scare stat, the $10.5 trillion global cybercrime projection, is exactly the kind of number this project is built to avoid producing. It is a forecast from Cybersecurity Ventures, compounded from a 2015 base whose methodology was never disclosed, and it keeps circulating partly because AI systems trained on the open web repeat it back as fact.

The index leaves it off the chart and off the ledger on purpose. A figure claiming to cover the whole is not a bigger version of a real measurement; it is a projection wearing a statistic’s clothes. This is the same dynamic behind so much credential-theft and attack-volume reporting: the scary aggregate travels farther than the grounded, boring, verifiable detail.

What this means for how we measure security

The sharpest line in the whole project is not a statistic. As Bird told SecurityWeek: “We built cybersecurity as a tax, not a value-added business function.”

Business keeps score in dollars. Governments keep score in dollars. Consumers keep score in dollars. Cybersecurity is the one corporate function measured by activity instead of outcomes, treated as a cost of doing business rather than a tracked result. An index like this will not fix the problem overnight. What it offers is smaller and more useful: a citable, source-graded reference to check a claim against, the moment someone waves a trillion-dollar number at you.

The next time a vendor deck opens with a giant aggregate, ask the two questions this ledger is built on. Where was it measured, and what evidence grade does it carry? If the answer is a forecast, treat it like one.

Share This Article

Comments