308 incidents latest Sep 23 updated Sep 23
Coming Fall of 2026 · the book behind the index
Built Wrong
Why Cybersecurity Keeps Failing and How We Can Rebuild It

This index is one number from a larger argument: that cybersecurity’s failure is structural, not technical. The foundations were wrong from the start, but we can rebuild.

Not yet published

Reported cybercrime losses have outgrown the stock market by more than six to one.

The Hacker in a Hoodie Index is the record behind that claim: what individual cyber incidents actually cost, each figure read from the document that reported it.

The index

What $100 became · 2014 → 2024

One hundred dollars, tracked two ways since 2014. The gap is the story.

Over 2014 to 2024, $100 tracking cybercrime losses reported to the FBI grew to $2,074, while $100 in the S&P 500 with dividends reinvested grew to $343: a difference of 6.05 times.

Hackers in hoodies
$100
S&P 500, dividends reinvested
$100

Cybercrime loss outgrew the market over the decade: $2,074 against $343, both in nominal dollars, measured from year-end 2014 to year-end 2024.

Hacker in a Hoodie Index: reported losses to the FBI Internet Crime Complaint Center, $800,492,073 in 2014 against $16,600,000,000 in 2024. Compound annual growth rate 35.42 percent.
35.4%/yr 10-year window · 2014–2024
34.2%/yr full record · 2001–2025
The IC3 growth rate barely moves across windows. The index is not built on a chosen base year, and the 6.05x multiple compares like with like: both figures are measured from year-end 2014 to year-end 2024, both in nominal dollars.
THE INDEX · LIVE · 2014 = 100

The gap is still widening

6.05x was the first reading, taken through 2024. The index carries it forward. As of 2025 it stands at 6.48x, and it moves as the ecosystem does.
BOOK · 2014-2024
6.05x
the first reading
LIVE · 2014-2025
6.48x
where it stands now
50010001500200025003000 '14'15'16'17'18'19'20'21'22'23'24'25 reporting change first reading, 6.05x IC3 lossS&P 500
Cybercrime loss (FBI IC3) and S&P 500 total return, each indexed to 100 at year-end 2014, both nominal. In 2025 reported loss rose 25.8% while the market rose 17.44%, so the gap widened from 6.05x to 6.48x. The book's 6.05x is the 2014-2024 reading and does not change; the index recomputes as each year posts.
Follow the record

New figures as they clear verification, and word when Built Wrong lands. No more email than the work warrants.

The Losses, Side By Side

What we’ve lost, by the numbers

Two documented measures of annual cybercrime loss, one log scale. The FBI IC3 series is a continuous annual reading from 2014 to 2025, and by the FBI’s own account a significant underestimation. These numbers are reported figures only. Chainalysis provides a yearly view of ransom payments.

$10M$100M$1B$10B 200120052010201520202025 IC3 $20.9B $0.82B
IC3 reported losses / US complaints / Verified
Chainalysis ransom payments / on-chain / revised
About that trillion-dollar number: the $10.5 trillion often quoted for global cybercrime is a forward projection from Cybersecurity Ventures, compounded from a 2015 base whose methodology is not disclosed. Because it is assumed rather than measured, it is excluded from the chart and the ledger, and noted only here. The trillion-dollar figure is constantly referred to in public messaging and presentations, due to the propagation of those numbers in AI learning data. Cybersecurity Ventures has never provided data that supports this forecast.
About 2010: the IC3 line skips 2010. The FBI’s own retrospective plots that year near $1.0B while its contemporaneous 2010 report recorded $485M. The two cannot both be right, so we leave the point out rather than choose.

The consequences that barely moved

Cost per breach barely moved.

Across more than a decade, while aggregate reported losses compounded at double digits, the modeled cost of a single breach grew about 3% a year, from $3.5M in 2014 to a record $4.99M in 2026.

If the per-event price is growing in the low single digits while the total keeps compounding at double digits, the growth is in volume and attack surface, not in severity. That is a finding the headline trillion-dollar number hides. IBM’s figure is the cost of one breach, shown here for shape, not added to the totals above.

$0$2M$4M$6M$8M$10M 2014201820222026 $4.99M

Featured

From the ledger

The biggest verified losses

Graded · Verified

Every loss here is Verified — the company’s own SEC filing states the figure, and the company name links to it. One incident, one figure, ranked by size, never rolled into a single total. Sort by any column.

The 10 largest of 28 Verified losses · each stated by the company’s own filing · one figure each, never added together · click a heading to sort
1UNITEDHEALTH GROUP INC $3.09BFeb 2024Healthcare and Life Sciences
2Coupang, Inc. $410MDec 2025Retail and Consumer
3UNITED NATURAL FOODS INC $400M est.Jun 2025Wholesale and Distribution
4AUTONATION, INC. $43MJul 2024Retail and Consumer
5EVERTEC, Inc. $37.7MAug 2025Technology and Software
6HALLIBURTON CO $35M est.Aug 2024Energy and Utilities
7F5, INC. $26.5MOct 2025Technology and Software
8CONDUENT Inc $25MApr 2025Professional and Business Services
9DAVITA INC. $25MApr 2025Healthcare and Life Sciences
10loanDepot, Inc. $24.6MJan 2024Financial Services
How each figure is graded VVerifiedthe linked primary document states it AAttesteda published report credits a named source IInferredno direct confirmation; a lead, not a figure The full standard →

On the Government Record · live

40SEC 8-K cyber-incident disclosures logged · 2026 year to date
All Verified · SEC 8-K cyber-incident filings, Item 1.05, Item 8.01, and Item 7.01
This counts the cyber incidents companies disclosed to the SEC on Form 8-K this year — the material-incident filings under Item 1.05, the cyber events reported under Item 8.01, and cyber disclosures made under Item 7.01 (Regulation FD). It is a count of disclosures, not a measure of total losses: most incidents never reach a public filing, and many are reported before any dollar figure exists. The ledger below also carries state-regulator breach and enforcement records, shown for context but not included in this count. It counts disclosed filings and never sums their figures.
Not yet quantified
VVerified
Astrana Health Management detected threat actors impersonating its own staff and spoofing the company's main corporate phone number to talk employees into handing over access sometime in September 2026. The company confirms private and confidential data was accessed, but will not yet say what kind, how much, or whose. The security boundary here was a familiar voice and a familiar caller ID, not any technical control. A phone number is not authentication, and Astrana built its access controls on the assumption that it was.
Professional and Business Services
SEC 8-K, Item 1.05
Initial attack type phishing or social engineering confirmed · Impact data theft confirmed
Not yet quantified
VVerified
United Underwriters filed a breach notice with the California Attorney General for an incident on April 7, 2026, and stopped there. No vector, no actor, no data type, no count: the filing names a date and nothing else. A notice that discloses only its own existence isn't transparency; it's compliance theater.
Insurance
California AG breach notification
Initial attack type not disclosed · Impact data theft
Not yet quantified
VVerified
ANUBIS claims to hold passport scans, personal identifiers, and internal files lifted from Fun For Less Tours, threatening publication within ten to eleven days of its December listing. The filing offers no confirmed entry point, no verified record count, and no proof beyond the extortion group's own countdown. Whatever door opened, it apparently led straight into a central reservation or document system where travelers' passports sat in one place, unsegmented from everything else.
Media and Entertainment
California AG breach notification
Initial attack type not disclosed · Impact data extortion confirmed + data theft · Actor ANUBIS
Not yet quantified
VVerified
Ridgeway Pharmacy's website, built and run by a third-party vendor, was accessed by an unauthorized party before the company learned of it on August 21, 2026. The notice names no entry point beyond the vendor-built site and no data type beyond 'personal information.' Ridgeway's internal systems were untouched, but that's little comfort to patients who had their data taken. Stolen is stolen, and Ridgeway was the entrusted steward for that data, regardless of the system it sat in.
Healthcare and Life Sciences
California AG breach notification
Initial attack type third-party or supply chain inferred · Impact data theft confirmed
Not yet quantified
VVerified
Opportune LLP's attorney general filing states that a breach occurred and stops there: no vector, no record count, no data type, no incident date. The only detailed account comes from the bad guy. Chaos, the ransomware group that claims to hold the firm's entire internal data environment, is using it as leverage. A filing that outsources its own facts to the extortionist has already lost the room. The control point here was disclosure itself, and Opportune ceded it to the attacker's press release.
Energy and Utilities
California AG breach notification
Initial attack type not disclosed · Impact ransomware inferred + data extortion · Actor Chaos
Showing the 5 most recent. View the complete ledger of 215 government-record incidents →
See the SEC's Item 1.05 material cyber incident filings on EDGAR →

Beyond the Filings

Graded · Attested / Inferred

Some losses surface outside any SEC filing: in a company’s own statement, a regulator or court record, or a news report crediting an identifiable source. Each is admitted on that attribution and graded by its strength. A figure credibly attributed to the company, a regulator, or a court is Attested; an estimate or reconstruction is Inferred. Each is logged on its own, with its source and grade, and like every figure here it stands alone, never combined into a total.

Not yet quantified
AAttested
Manage My Health's patient portal leaked 403,730 Health New Zealand documents and 22,609 patient files in December 2025, reaching almost 100,000 people, mostly in Northland. The Privacy Commissioner of New Zealand stated that Manage My Health and Health New Zealand “failed in their responsibilities”. The penalty? Nearly 5 months later, the commissioner declared that both organizations have until August 2027 to fix their security weaknesses. Yep, one whole year.
Healthcare and Life Sciences
Privacy Commissioner puts Manage My Health, Health NZ on notice after data breach
Initial attack type not disclosed · Impact data theft confirmed
AsusSep 2026
Not yet quantified
AAttested
Asus's eShop platform was accessed by an unnamed party, exposing customer contact details and order records; the notice names no vector, no actor, no count. No payment or bank data was taken, Asus stresses, but a name and an order history are plenty for the phishing campaign Asus itself now warns is coming. The storefront shifted from a customer service interface to a future crime facilitator in the blink of an eye.
Technology and Software
Asus warns customers of eshop data breach
Not yet quantified
AAttested
BigCommerce confirmed on September 17, 2026, that compromised credentials from Ribon and Ribon 1.5, third-party apps built by 'Be A Part Of,' a Fastr company, let attackers inject malicious scripts into merchant storefronts. One access key belonging to a single app vendor unlocked data across every store that had installed it, hundreds by Master of Malt's count, not the 'small number' BigCommerce named. The app marketplace was the real perimeter, and nobody was guarding it like one. What BigCommerce calls scope is really just how far one vendor's key happened to reach.
Retail and Consumer
BigCommerce warns customers of potential data leaks following cyber incident
Initial attack type third-party or supply chain confirmed · Impact data theft inferred
CrowdSecSep 2026
Not yet quantified
AAttested
CrowdSec's source code, roughly 300 repositories, 170 of them private, sat exposed after the May 2026 TanStack supply chain attack. Most likely culprit? A single compromised API key. That one key reached across the SaaS console, AWS operations, connectors, and automation scripts: one credential, one blast radius. CrowdSec states confidently that the source code can't be used to cause harm because it can't be used outside of its context. Not finding the leak of the source code for several months does make those reassurances seem a bit bold, given the circumstances.
Technology and Software
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Initial attack type third-party or supply chain confirmed · Impact data theft confirmed
Not yet quantified
AAttested
United Language Group's network was accessed by unauthorized outsiders for two days in July 2025, exposing claims and billing data that UnitedHealthcare and UnitedHealthcare Global had handed to it to translate: names, Social Security numbers, diagnoses, prescriptions, passports, driver's licenses, and financial account numbers, across 4,649 people. The notice names no entry point and no attacker; only the window forensics could confirm. A translation vendor became the de facto custodian of a health insurer's most sensitive records. Nobody built a perimeter around that arrangement.
Healthcare and Life Sciences
Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members
Initial attack type not disclosed · Impact data theft confirmed
Showing the 5 most recent. View the complete ledger of 93 media-reported incidents →

The record by sector

From the ledger
FROM THE LEDGER · INCIDENT COUNT · n = 308 incidents
Which sectors the tracked incidents fall in: a count of incidents, not a total of dollars. Each bar is that sector’s share of the 308 on the record, ranked; a floor, not a census.

Share of incidents tracked on this ledger, not of all breaches. Healthcare leads partly because mandatory breach-disclosure rules in that sector put more of its incidents into the public record, not because it is necessarily attacked more often.

See all 14 sectors and the full method →

The Verifiable Sources

FBI IC3
$20.9BLATEST · 2025
Counts
Losses from internet-crime complaints filed by US victims.
Excludes
Crime never reported; non-US victims; the great majority of incidents, where no complaint is filed.
Growth
34%/yr across 24 years (2001–2025)
VVerifiedAnnual, full series
FBI IC3 Annual Reports ↗
Chainalysis
$0.82BLATEST · 2025
Counts
Cryptocurrency payments to ransomware actors, traced on-chain.
Excludes
Recovery and downtime costs; untraced channels; anything that is not a ransom payment.
Growth
Volatile. Peaked $1.23B in 2023, fell since.
VVerifiedAnnual, revised · anchors
Chainalysis Crypto Crime Report ↗
IBM / Ponemon
$4.99MLATEST · 2026
Counts
Modeled average cost of a single data breach across ~600 organizations.
Excludes
Aggregate national or global totals. A per-event average, not a sum.
Growth
~3%/yr since 2014, to a record $4.99M in 2026.
AAttestedAnnual · anchors
IBM Cost of a Data Breach ↗
THE RULE It would be tempting to add these numbers up and put one big total at the top of the page. We do not, and we never will. Each line measures something different: different victims, different crimes, different units, overlapping in some places and blind to each other in others. Add them together and you get a number that means nothing, the kind of headline figure this index was built to refuse. So the sources stay side by side, each labeled for what it counts, and the arithmetic stays honest.
THE FLOOR The other temptation is to estimate what is missing and call the result the real number. We do not, and we never will. These are the losses someone measured. What no one measured has no number, only its absence. A figure that claims to cover the whole is not a larger version of this page. It is a projection, not a statistic.