245 incidents latest Aug 29 updated Aug 31
Coming Fall of 2026 · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Not yet published

Reported cybercrime losses have outgrown the stock market by more than six to one.

The Hacker in a Hoodie Index is the record behind that claim: what individual cyber incidents actually cost, each figure read from the document that reported it.

The index

What $100 became · 2014 → 2024

One hundred dollars, tracked two ways since 2014. The gap is the story.

Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.

Hackers in hoodies
$100
S&P 500, dividends reinvested
$100

Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.

Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100

The gap is still widening

6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
50010001500200025003000 '14'15'16'17'18'19'20'21'22'23'24'25 reporting change first reading, 6.05x IC3 lossS&P 500
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Follow the record

New figures as they clear verification, and word when Built Wrong lands. No more email than the work warrants.

The Losses, Side By Side

What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.

The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 3% a year, from $3.5M in 2014 to a record $4.99M in 2026.

If the per-event price is growing in the low single digits while the total keeps compounding at double digits, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is the cost of one breach, shown here for shape, not added to the totals above.

$0$2M$4M$6M$8M$10M 2014201820222026 $4.99M

The biggest verified losses

Graded · Verified

Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size, never rolled into a single total. Sort by any column.

The 10 largest of 23 Verified losses · each stated by the company’s own filing · one figure each, never added together · click a heading to sort
1UNITEDHEALTH GROUP INC $3.09BFeb 2024Healthcare and Life Sciences
2Coupang, Inc. $410MDec 2025Retail and Consumer
3AUTONATION, INC. $43MJul 2024Retail and Consumer
4Sinqia S.A. $37.7MAug 2025Technology and Software
5HALLIBURTON CO $35MAug 2024Energy and Utilities
6F5, INC. $26.5MOct 2025Technology and Software
7CONDUENT Inc $25MApr 2025Professional and Business Services
8DAVITA INC. $25MApr 2025Healthcare and Life Sciences
9loanDepot, Inc. $24.6MJan 2024Financial Services
10UPBOUND GROUP, INC. $13MJul 2026Professional and Business Services
How each figure is graded VVerifiedthe linked primary document states it AAttesteda published report credits a named source IInferredno direct confirmation; a lead, not a figure The full standard →

On the Government Record · live

36SEC 8-K cyber-incident disclosures logged · 2026 year to date
All Verified · SEC 8-K cyber-incident filings, Item 1.05, Item 8.01, and Item 7.01
This counts the cyber incidents companies disclosed to the SEC on Form 8-K this year — the material-incident filings under Item 1.05, the cyber events reported under Item 8.01, and cyber disclosures made under Item 7.01 (Regulation FD). It is a count of disclosures, not a measure of total losses: most incidents never reach a public filing, and many are reported before any dollar figure exists. The ledger below also carries state-regulator breach and enforcement records, shown for context but not included in this count. It counts disclosed filings and never sums their figures.
ShinyHunters claims it vished several McKesson employees' Okta credentials, then walked those single sign-on logins straight into Salesforce and Snowflake. McKesson has not confirmed the entry point or the data taken; only the extortion group has spoken. Single sign-on was built to make log-ins easy, but when secured incorrectly (or not at all) it is just the easy button to own an entire company. The group claims roughly 284 million patient records, the kind of data no reset can undo.
SEC 8-K, Item 7.01
Not yet quantified
VVerifiedWholesale and Distribution
A cybersecurity incident on August 25, 2026, knocked out Boston Scientific's order processing and shipping worldwide. The filing names no entry point, no actor, no data type, because the investigation hasn't reached that far yet. When core operations can't survive one unnamed intrusion, the systemic fragility was built in long before the attacker showed up. Global disruption isn't the sign of a sophisticated adversary; it's the sign of a single point of failure wearing a lot of hats.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedHealthcare and Life Sciences
AestoDec 2025
disclosed by Livara Health Medical Group - dba SpineZone
SpineZone's patient records were exposed not on its own network but inside Aesto Health, the Birmingham vendor it paid to migrate and archive data into Amazon Web Services. The breach window ran from December 2 to December 18, 2025, and it took Aesto until May 2026 to confirm what protected health information had actually been taken. Names, Social Security numbers, driver's license numbers, financial account details, and full medical and billing histories moved through that one AWS account, along with the records of more than two dozen other providers' patients. SpineZone outsourced the archive; it did not outsource the liability for losing it.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences
AestoDec 2025
disclosed by Together Women's Health LLC - Aesto
Together Women's Health filed its breach notice under Aesto, the same vendor whose AWS environment has already surfaced in other patients' notifications this year. The letter names Social Security numbers and two dates in December 2025, and stops there: no stated entry point, no actor, no count of people affected. A filing this thin is its own kind of disclosure. When a vendor keeps reappearing as the common thread across unrelated clinics, the failure isn't in any one exam room; it's in the shared filing cabinet everyone quietly outsourced to.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences
Nutex Health's servers were accessed and drained by an unnamed third party sometime before the August 24, 2026 filing. The entry point unstated, the count unstated, the haul spanning patient, employee, provider, and financial records in one undifferentiated pull. A vague reference to "unauthorized activity involving data stored" on their network. Data didn't steal your data, the adversary did.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedProfessional and Business Services
Showing the 5 most recent. View the complete ledger of 178 government-record incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →

Beyond the Filings

Graded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. Each is logged on its own, with its source and grade, and like every figure here it stands alone, never combined into a total.

Norcross, Georgia, was hit by ransomware on August 1, with no vector named, no actor named, and no accounting of what data, if any, left the network. City officials notified police and cybersecurity professionals and kept most services running while restoration continued. Calling in digital fixers after the fact is incident response, not architecture. The filing never says what allowed the encryption in. An organization that cannot name the crack in its defenses has not yet found the boundary that failed.
Metro Atlanta city hit by ransomware, working on full system restoration
Not yet quantified
AAttestedPublic Sector and Education
HasbroAug 2026
A single compromised employee account exposed Social Security numbers, financial account details, card numbers, and driver's license information for 436 Massachusetts employees. Hasbro has not said how the account was hijacked, when it was noticed, or how many employees beyond Massachusetts were affected. An account is not a perimeter; it is one point of failure wearing an employee badge. Hasbro calls this unrelated to March's outage, but two collapses in one year from the same company describe a design, not a coincidence.
Toy-making giant Hasbro disclose data breach affecting employees
Not yet quantified
AAttestedRetail and Consumer
ATF confirmed a 'major incident' only after Qilin's ransomware gang posted the agency's name to its dark web leak site, not from its own monitoring. The bureau says the breach was confined to a standalone system, separate from its enterprise network and eForms. Qilin has not said whether it stole data or demanded a ransom, and ATF has not said what that system held. An agency that tracks explosives learned about its own breach from the people who lit the fuse. Or, it knew about it and didn't bother to disclose it.
ATF confirms “major incident” after recent Qilin breach claims
Not yet quantified
AAttestedPublic Sector and Education
MAG's breach note names neither the entry point nor the attacker, only the wreckage: 8.7 million customers' emails, phone numbers, vehicle registration numbers, and postcodes, pulled from the car park, lounge, and wifi sign-up systems shared across Manchester, Stansted, and East Midlands. Three airports ran their ancillary bookings through one common system, so a single hole became a three-airport hole. MAG points out that no bank details were held there, as if a name, a plate number, and a postcode were not already enough to track someone.
UK airports operator hit by cyber-attack and customer data accessed
Not yet quantified
AAttestedTransportation and Logistics
CarharttAug 2026
ShinyHunters says it pulled more than 50GB from Carhartt's Databricks analytics platform, claiming the intrusion on August 13 and later publishing the archive after Carhartt declined a $3.3 million ransom demand. How the platform was actually entered, credentials, misconfiguration, or something else, is not stated; Carhartt has not confirmed the breach at all. Troy Hunt's independent analysis puts the toll at 12.9 million accounts, names, emails, phones, addresses, and over 15,000 internal @carhartt.com employee addresses sitting in the same analytics warehouse as the customer file. An analytics platform became the record of the whole company, employees, and customers alike, and nobody built a wall between them.
Carhartt data breach exposes information of 12.9 million accounts
Not yet quantified
AAttestedRetail and Consumer
Showing the 5 most recent. View the complete ledger of 67 media-reported incidents →

The record by sector

From the ledger
FROM THE LEDGER · INCIDENT COUNT · n = 241 incidents
Which sectors the tracked incidents fall in: a count of incidents, not a total of dollars. Each bar is that sector’s share of the 241 on the record, ranked; a floor, not a census.

Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.

See all 13 sectors and the full method →

The Verifiable Sources

FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.99MLATEST · 2026
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~3%/yr since 2014, to a record $4.99M in 2026.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.