With cybersecurity reports and fraud studies launching almost weekly, it can be hard to keep track of the latest stats related to:
- Account takeover (ATO)
- Ransomware
- Malware
- Session hijacking
- Business email compromise (BEC)
- Fraud and identity theft
- Digital identity threats
At SpyCloud, we know our readers need the latest cybersecurity statistics to bolster their case for investing in solutions to combat cybercrime and protect employees and customers. Here is the latest list of cybersecurity statistics you should know for 2025.
Account Takeover (ATO) Statistics:
- More than 75% of security leaders rank account takeovers as one of the top four cyber threats organizations face globally. Abnormal Security’s 2024 State of Cloud Account Takeovers Report
- ATO attacks increased 24% year-over-year in 2024. Sift’s Q3 2024 Digital Trust Index
- Account takeover fraud resulted in nearly $13 billion in losses in 2023. 2024 AARP & Javelin Fraud Study
- 83% of organizations experienced at least one instance of account takeover in the past year. Abnormal Security’s 2024 State of Cloud Account Takeovers Report
- 24% of consumers were a victim of ATO in 2024, up from 18% in 2023. Sift’s Q3 2024 Digital Trust Index
- Four out of five consumers would stop shopping on a site where they’d been a victim of ATO. Sift’s Q3 2024 Digital Trust Index
- Only 43% of account takeover victims were notified by the company that their information had been compromised. Sift’s Q3 2023 Digital Trust & Safety Index
- An annual analysis of recaptured data from the darknet shows a 74% password reuse rate for users exposed in two or more breaches in the last year. SpyCloud 2024 Annual Identity Exposure Report
Ransomware Statistics:
- Ransom payments surged last year, with a 2.6x increase in the average payment. Sophos State of Ransomware Report 2024
- Nearly two-thirds of ransom demands last year were for $1 million or more, with an average of $4.3 million. Sophos State of Ransomware Report 2024
- 92% of organizations were affected by ransomware in some capacity over the past 12 months, and 62% of those that were impacted ended up paying a ransom. SpyCloud 2024 Malware and Ransomware Defense Report
- The sector most heavily impacted by ransomware attacks was the construction industry in 2023. eCrime Ransomware and Data Leak Site Report 2023
- The IC3 received 2,825 complaints in 2022 identified as ransomware, reflecting losses of more than $59.6 million. FBI Internet Crime Report 2023
- In 2022, the IC3 received 1,193 complaints regarding ransomware attacks on critical infrastructure organizations, with 14 of the 16 critical infrastructure sectors having at least one member fall victim to an attack. Healthcare was the sector with the most reported attacks. FBI Internet Crime Report 2023
- According to security leaders, the top three perceived riskiest entry points for ransomware are:
#1 Phishing and social engineering
#2 Third-party access
#3 Stolen cookies that enable session hijacking
SpyCloud 2024 Malware and Ransomware Defense Report - More than one-third of North American and European companies who experienced a ransomware event in 2023 had at least one infostealer infection prior to being attacked. SpyCloud 2023 Ransomware Defense Report
Malware Statistics:
- In 2024, the use of infostealer malware by cybercriminals doubled. Expel 2025 Annual Threat Report
- 86% of security professionals reported being “extremely or significantly concerned” about harmful future attacks stemming authentication, identity, session, and other data exfiltrated from malware-infected devices. SpyCloud 2024 Malware and Ransomware Defense Report
- 5% of 721.5 million exposed username and password combinations recovered from the criminal underground were exfiltrated from malware-infected devices in 2022. SpyCloud 2023 Malware Readiness & Defense Report
- At least 54% of malware-infected devices had an antivirus or EDR program installed at the time of successful malware execution. SpyCloud 2024 Malware and Ransomware Defense Report
- The average infostealer malware log contains credentials from 26 business applications. SpyCloud 2023 Malware Readiness & Defense Report
- Malware analysis now ranks as one of the top three skills needed to succeed as a SOC analyst. Tines Voice of the SOC 2023
Phishing Statistics:
- Credential theft attacks stemming from phishing campaigns rose dramatically in the second half of 2024, increasing by 703%. SlashNext Phishing Intelligence Report
- Phishing/social engineering was reported to be the most common entry point used by attackers to gain initial access for ransomware attacks in 2024. SpyCloud 2024 Malware and Ransomware Defense Report
- 8 out of 10 organizations had at least one individual who fell victim to a phishing attempt by CISA Assessment teams. CISA Phishing Assessment Infographic
Session Hijacking Statistics:
- Session cookie theft via adversary-in-the-middle (AiTM) phishing attacks account for 15% of phishing attacks. Expel Quarterly Threat Report Q2 2023
- SpyCloud researchers recaptured 20 billion stolen cookie records from the dark web in 2023. SpyCloud 2024 Identity Exposure Report
- Security teams reported that MFA bypass via session hijacking was one of the top three attack vectors for ransomware events they experienced in the past 12 months. SpyCloud 2024 Malware and Ransomware Defense Report
Data Breach Statistics:
- There were 3,158 publicly reported data breaches in 2024, resulting in a 211% year-over-year increase in victims.. Identity Theft Resource Center’s 2024 Data Breach Report
- The global average cost of a data breach reached an all-time high in 2024, increasing to USD $4.88 million. IBM Cost of a Data Breach Report 2024
- The research in this year’s report showed compromised credentials as the most common attack vector in reported data breaches, representing 16% of all breaches and overtaking the place of phishing, which held the number one spot last year. IBM Cost of a Data Breach Report 2024
- The use of stolen credentials remains the primary way into organizations, with 24% of breaches involving credentials as the top “action” to entry taken. Verizon 2024 Data Breach Investigations Report
- Third-party risk remains a substantial issue, with 15% of breaches involved third-party infrastructures, including partner networks and software supply chain issues. Verizon 2024 Data Breach Investigations Report
- The most frequently breached industries in 2024 were the financial services and healthcare industries. Identity Theft Resource Center’s 2024 Data Breach Report
- 44% of data breach victims tell friends and family not to associate with a brand that’s been breached. Telesign’s Trust Index
Business Email Compromise (BEC) Statistics:
- The average cost of a BEC claim skyrocketed from $84,000 in 2022 to $183,000 in 2023. NetDiligence Cyber Claims 2024 Study
- There was a 65% increase in identified global exposed losses from Business Email Compromise fraud. FBI PSA: Business Email Compromise (BEC): The $43 Billion Scam
- Pretexting, including BEC, overtook phishing as the most prevalent social engineering tactic in 2022, with BEC attacks accounting for more than 50% of social engineering incidents. Verizon 2023 Data Breach Investigations Report
- The median open rate for text-based BEC attacks is nearly 28%. Abnormal Intelligence H1 2023 Report
- BEC was the attack vector for 10% of data breaches in 2024, and was also one of the costliest vectors. IBM Cost of a Data Breach Report 2024
Fraud & Identity Theft Statistics:
- American adults lost a total of $43 billion to identity fraud in 2023. 2024 AARP & Javelin Fraud Study
- 1 in every 11 new account creations are attacks. LexisNexis Risk Solutions Cybercrime Report
- Of 19,778 complaints received by the FBI, associated losses from identity theft were $126 million. FBI Internet Crime Report 2023
- In the past 2 years, 37% of consumers had new accounts opened using their identity. Aite-Novarica U.S. Identity Theft: The Stark Reality
- Every $1 lost to fraud costs financial services firms $4.23, and every $1 lost to fraud costs merchants $3.75. LexisNexis True Cost of Fraud Study
- Card Not Present (CNP) losses are estimated to grow to $48 billion in 2023, an increase of 16% from $41 billion in 2022. Juniper Research Online Payment Fraud: Market Forecasts, Emerging Threats & Segment Analysis 2022-2027
- New accounts are 9.5 times riskier than mature accounts. NICE Actimize 2023 Fraud Insights Report
- Attempted fraud transactions have increased by 92% and attempted fraud amounts have jumped by 146%. NICE Actimize 2023 Fraud Insights Report
- As many as 1 in 5 password reset attempts from desktop browsers are fraud. Consistently identified as a high-risk touchpoint, password reset attacks have grown by 135% year-over-year. LexisNexis Risk Solutions Cybercrime Report
- The types of fraud most concerning to fraud executives at financial institutions: ACH fraud and P2P fraud (both with 39% of fraud executives concerned. The types of fraud attacks most concerning? Synthetic identities resulting from application fraud and wire fraud resulting from ATO. Aite-Novarica Market Trends in Fraud for 2022 and Beyond: New Fraudsters, New Era
- Online payment fraud losses are set to exceed $206 billion between 2021 and 2025. Juniper Research Online Payment Fraud: Emerging Threats, Segment Analysis & Market Forecasts 2021-2025
Digital Identity Threat Statistics:
- The digital identity has become a top attack vector – 91% of organizations reported an identity-related breach in the past year. IDSA’s 2024 Trends in Securing Digital Identities Report
- 22% of businesses see managing and securing digital identities as the number one priority of their security program, up from 17% in 2023. Only 2% of businesses don’t see securing identities as a top 10 priority. IDSA’s 2024 Trends in Securing Digital Identities Report
- Over half (57%) of organizations are putting a major focus on managing identity sprawl. IDSA’s 2024 Trends in Securing Digital Identities Report
- Identity-related incidents in 2024 were primarily driven by phishing (69%) and stolen credentials (37%). Also in the list of frequent incidents include compromised privileged identities, social engineered passwords, third-party or supply chain attacks, and insider attacks. IDSA’s 2024 Trends in Securing Digital Identities Report
- Identity-based attacks continue to rise YoY, up 4% from 2023. Expel 2025 Annual Threat Report
- The average digital identity exposure amounts to:
- 4 unique exposed usernames / email addresses
- 9 breach exposures
- 15 breach records
- Email accompanied by a password 67% of the time
- Information about the network or physical location of the user 25% of the time
- A 1 in 5 chance of already being the victim of an infostealer infection
- SpyCloud 2024 Identity Exposure Report
For more insights,
get the 2024 Identity Exposure Report.
About SpyCloud: SpyCloud transforms recaptured darknet data to protect businesses from cyberattacks. Its products operationalize Cybercrime Analytics (C2A) to produce actionable insights that allow enterprises to proactively prevent ransomware and account takeover, safeguard employee and consumer identities, and investigate cybercrime incidents. Its unique data from breaches, malware-infected devices, successful phishes, and other underground sources also powers many popular dark web monitoring and identity theft protection offerings. SpyCloud customers include more than half of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies around the world. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to make the internet safer with automated solutions that help organizations combat cybercrime.
To get insights on your company’s compromised data, check your exposure today.