217 incidents latest Aug 21 updated Aug 23
Coming Fall of 2026 · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Not yet published

Reported cybercrime losses have outgrown the stock market by more than six to one.

The Hacker in a Hoodie Index is the record behind that claim: what individual cyber incidents actually cost, each figure read from the document that reported it.

The index

What $100 became · 2014 → 2024

One hundred dollars, tracked two ways since 2014. The gap is the story.

Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.

Hackers in hoodies
$100
S&P 500, dividends reinvested
$100

Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.

Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100

The gap is still widening

6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
50010001500200025003000 '14'15'16'17'18'19'20'21'22'23'24'25 reporting change first reading, 6.05x IC3 lossS&P 500
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Follow the record

New figures as they clear verification, and word when Built Wrong lands. No more email than the work warrants.

The Losses, Side By Side

What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.

The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 3% a year, from $3.5M in 2014 to a record $4.99M in 2026.

If the per-event price is growing in the low single digits while the total keeps compounding at double digits, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is the cost of one breach, shown here for shape, not added to the totals above.

$0$2M$4M$6M$8M$10M 2014201820222026 $4.99M

The biggest verified losses

Graded · Verified

Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size, never rolled into a single total. Sort by any column.

The 10 largest of 23 Verified losses · each stated by the company’s own filing · one figure each, never added together · click a heading to sort
1UNITEDHEALTH GROUP INC $3.09BFeb 2024Healthcare and Life Sciences
2Coupang, Inc. $410MDec 2025Retail and Consumer
3AUTONATION, INC. $43MJul 2024Retail and Consumer
4Sinqia S.A. $37.7MAug 2025Technology and Software
5HALLIBURTON CO $35MAug 2024Energy and Utilities
6F5, INC. $26.5MOct 2025Technology and Software
7CONDUENT Inc $25MApr 2025Professional and Business Services
8DAVITA INC. $25MApr 2025Healthcare and Life Sciences
9loanDepot, Inc. $24.6MJan 2024Financial Services
10UPBOUND GROUP, INC. $13MJul 2026Professional and Business Services
How each figure is graded VVerifiedthe linked primary document states it AAttesteda published report credits a named source IInferredno direct confirmation; a lead, not a figure The full standard →

On the Government Record · live

33SEC 8-K cyber-incident disclosures logged · 2026 year to date
All Verified · SEC 8-K material cyber-incident filings, Item 1.05 and Item 8.01
This counts the cyber incidents companies disclosed to the SEC on Form 8-K this year — the material-incident filings under Item 1.05 and the cyber events reported under Item 8.01. It is a count of disclosures, not a measure of total losses: most incidents never reach a public filing, and many are reported before any dollar figure exists. The ledger below also carries state-regulator breach and enforcement records, shown for context but not included in this count. It counts disclosed filings and never sums their figures.
ZeroStack Corp. disclosed a material cybersecurity incident under Item 8.01 (other events), not as a 1.05 (material incident), and the filing states nothing further: no entry point, no actor, no data type, no scope. That silence is itself the finding, since a disclosure obligation triggered by materiality has been met while the architecture that produced the exposure remains hidden. A filing can satisfy the law without telling anyone what actually failed.
SEC 8-K, Item 8.01
Not yet quantified
VVerifiedWholesale and Distribution
disclosed by Kern Psychiatric Health and Wellness Center, Inc
Kern Psychiatric Health and Wellness Center's patient data was exposed not on its own systems but on the network of Genesis Healthcare Management, the outsourced management company that discovered unauthorized file access on June 22, 2026. The data was among the most sensitive a person holds, Social Security numbers alongside diagnoses, prescriptions, and treatment records. Outsourcing the back office moved those records to a network the practice did not run.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences
ASOS traced unauthorized account access to credentials stolen in a different company's breach and reused against it. Nothing in ASOS's systems was breached; a valid credential was just presented by the adversary. Password-only authentication inherits every leak that credential ever appeared in, and the system just works as designed after it is leveraged.
California AG breach notification
Not yet quantified
VVerifiedRetail and Consumer
A social-engineering attack gave an unauthorized party access to Apollo cloud platforms for several days. Personal data, including Social Security numbers, was potentially exposed. A cloud trust model was defeated with one single successful call or message.
California AG breach notification
Not yet quantified
VVerifiedFinancial Services
AestoDec 2025
disclosed by Nebraska Orthopaedic Center, P.C.
Nebraska Orthopaedic Center was exposed through Aesto, the vendor holding its patient data in Amazon Web Services. An unauthorized actor copied protected health information, including identifiers that may include Social Security numbers. The trust boundary sat with the vendor, but the consequences fell right on top of the patients and the provider.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences
Showing the 5 most recent. View the complete ledger of 170 government-record incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →

Beyond the Filings

Graded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. Each is logged on its own, with its source and grade, and like every figure here it stands alone, never combined into a total.

The notice attached to this incident reads "to review," which means the source confirms nothing beyond a name and a date: not the vector, not the actor, not what was reached, not how many were affected. Apollo Global sits in the Index with a placeholder where an accounting should be. An institution's disclosure obligation is itself a control point, and a statement that has not yet been given is not transperancy, especially for customers. .
Apollo Global reveals data breach after hackers target financial firms
Not yet quantified
AAttestedFinancial Services
AlationAug 2026
AI data giant Alation confirmed a cyberattack, and the headline confirms nothing else: no entry point, no actor, no data type, no count of records or systems touched. That leaves a data-governance vendor built to sit inside other companies' data stacks, cataloging and connecting sensitive information as its core function, now acknowledging compromise without saying what that position exposed.
Alation Confirms Cyberattack: What Security Teams Need to Know
Not yet quantified
AAttestedTechnology and Software
CognizantAug 2026
Cognizant notified individuals of a data breach and is offering one million dollars in identity theft coverage. The headline confirms notification and a remediation gesture but does not name the entry point, the actor, the number affected, or the data types involved. A company built on managing other organizations' systems and data has disclosed a breach of unspecified scope, and the insurance offer addresses downstream harm, but not the architecture that allowed the exposure.
Cognizant notifies individuals of data breach; offers $1 mn identity theft cover
Not yet quantified
AAttestedProfessional and Business Services
disclosed by Pokemon Center
Another CEVA Logistics supply chain victim. Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information. CEVA's reply? Gotta get 'em all.
Pokémon Center data breach exposes customer info, cancels some orders
Not yet quantified
AAttestedTechnology and Software
SafePalAug 2026
SafePal disclosed a data breach affecting roughly 40,000 customers, exposing customer information associated with purchases while the company says wallet credentials, private keys, and recovery seeds were not compromised. This is high quality signal, cryptocurrrency relatedcustomer data that gives attackers a better map for phishing and social engineering. Exactly what adversaries want for conducting further identity based attacks.
SafePal Data Breach Hits Tens of Thousands of Customers - Infosecurity Magazine
Not yet quantified
AAttestedFinancial Services
Showing the 5 most recent. View the complete ledger of 47 media-reported incidents →

The record by sector

From the ledger
FROM THE LEDGER · INCIDENT COUNT · n = 215 incidents
Which sectors the tracked incidents fall in: a count of incidents, not a total of dollars. Each bar is that sector’s share of the 215 on the record, ranked; a floor, not a census.

Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.

See all 13 sectors and the full method →

The Verifiable Sources

FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.99MLATEST · 2026
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~3%/yr since 2014, to a record $4.99M in 2026.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.