Notable Breaches and Their Costs
Cyberattacks and their costs are the loss side of the economics of cybersecurity. Security spending exists because breaches are expensive, and the size and visibility of those losses — to companies, governments, and the wider economy — is what turns security from a discretionary IT line item into a board-level obligation. Every well-documented breach cost strengthens the case for the next dollar of defensive spending, feeds the pricing of cyber insurance, and drives new regulation. This page sets out what a breach actually costs, the benchmark figures, the costliest events on record, and a history of major hacks from the origins of computer intrusion in the 1970s to the present.
A note on the numbers throughout: breach-cost figures come from three very different methodologies that are frequently, and misleadingly, compared side by side. A single-company response cost (what one victim spent) is measured and auditable. An aggregate victim cost (the total across every organization hit by one campaign) depends on how many victims are counted and how each was modeled. And a global economic-damage estimate — most common for the early worms — is a broad, contemporary figure that often includes lost productivity worldwide and is frequently inflated. The three are not comparable, and the largest headline numbers are usually the least precise. Where possible, figures below are labeled by type.
What a breach costs — the anatomy
A breach's total cost is far larger than any ransom and accrues over years. The main components:
| Cost component | What it covers |
|---|---|
| Detection & investigation | Forensics, incident response, threat hunting, outside counsel and consultants |
| Notification | Legally required notices to affected individuals, regulators, and partners |
| Remediation & rebuild | Rebuilding systems, restoring data, new controls; for wiper attacks, replacing entire IT estates |
| Ransom / extortion | The demand itself, where paid (a minority of total cost) |
| Business interruption | Downtime, halted production or shipments, delayed revenue — often the largest line for operational attacks |
| Legal & settlements | Class-action litigation and consumer settlements |
| Regulatory fines | GDPR, FTC, SEC, state attorneys-general, HIPAA, sector regulators |
| Long-tail | Credit monitoring, customer churn, reputational damage, higher insurance premiums, and share-price impact |
The industry shorthand divides these into direct costs (detection, notification, remediation, ransom) and indirect costs (lost business, churn, reputation), with indirect costs typically the larger and longer-lasting of the two.
Average cost benchmarks
The most widely cited benchmark is IBM's annual Cost of a Data Breach study. Its 2025 edition reported the first decline in the global average in five years, attributed largely to faster detection and containment using AI-assisted defenses, alongside a record-high figure for the United States.
| Metric (IBM, 2025) | Figure |
|---|---|
| Global average cost of a data breach | $4.44M (−9% YoY, first decline in five years) |
| United States average | $10.22M (record high) |
| Mean time to identify + contain | 241 days (lowest in nine years) |
| Average saving from extensive security AI/automation | ~$1.9M per breach |
| Added cost where "shadow AI" was prevalent | ~$0.67M per breach |
These are averages across thousands of mostly mid-sized incidents. The headline events below sit far out on the tail — the breaches that shape budgets, insurance markets, and law.
The costliest events on record
The largest headline figures belong to the self-spreading worms of the early 2000s, whose global economic-damage estimates — lost productivity across millions of machines — run to tens of billions of dollars but are broad and contemporary rather than audited. The costliest targeted events are the 2017 state-linked wiper NotPetya and the 2023 MOVEit supply-chain campaign. Because the methodologies differ, the ranking below mixes categories and is best read as orders of magnitude, not precise comparisons.
| Event (year) | Estimated cost | Methodology / note |
|---|---|---|
| MyDoom (2004) | ~$38B | Global economic-damage estimate (fastest-spreading email worm) |
| Sobig (2003) | ~$30B | Global economic-damage estimate |
| Klez (2001) | ~$20B | Global economic-damage estimate |
| MOVEit / Cl0p (2023) | ~$16B+ (rising) | Aggregate victim breach cost across 2,700+ organizations |
| ILOVEYOU (2000) | ~$10–15B | Global economic-damage estimate (~45M machines) |
| NotPetya (2017) | ~$10B | Direct damages; state-linked wiper (attributed to Russia) |
| WannaCry (2017) | ~$4–8B | Global damages; ransomware worm (attributed to North Korea) |
| Epsilon (2011) | ~$4B | Aggregate including forensics, monitoring, lost business |
| Change Healthcare (2024) | ~$3.1B | Single-company response cost (UnitedHealth) |
| Code Red (2001) | ~$2B | Global economic-damage estimate |
| Equifax (2017) | ~$1.4B | Single-company cleanup, before ~$700M+ in settlements |
A history of major hacks, by era
Era 1 — Origins: phreaking and the first intrusions (1971–1989)
The first attacks predate the internet and were about curiosity, espionage, and proof of concept rather than money. This era established the templates — worms, espionage, and extortion — that everything since has scaled.
| Year | Event | Type | Significance / cost |
|---|---|---|---|
| 1971 | "Captain Crunch" (John Draper) blue-box phone phreaking | Fraud | Free long-distance calls by replicating phone tones; the founding hacker folklore |
| 1983 | The 414s breach Los Alamos and Sloan-Kettering | Intrusion | Teenagers reach a nuclear lab and a cancer center; prompts early computer-crime law |
| 1986 | The Cuckoo's Egg (Markus Hess) | Espionage | First documented cyber-espionage: a hacker sells US military data to the KGB; traced by Clifford Stoll |
| 1988 | The Morris Worm | Worm | First major internet worm; infected ~6,000 machines (~10% of the internet), caused an estimated $100K–$10M in cleanup, produced the first felony conviction under the US Computer Fraud and Abuse Act, and led to the creation of the first CERT |
| 1989 | The AIDS Trojan (PC Cyborg, by Joseph Popp) | Ransomware | The first ransomware: 20,000 infected floppy disks mailed to WHO AIDS-conference attendees, demanding $189 to a Panama PO box |
Era 2 — The worm plague and the first big money (1994–2004)
As the internet went mainstream, self-spreading email worms caused the largest economic-damage figures ever recorded, while the first large financial thefts showed that intrusion could move real money.
| Year | Event | Type | Significance / cost |
|---|---|---|---|
| 1994 | Vladimir Levin / Citibank | Financial | ~$10M+ transferred out of Citibank accounts; one of the first major bank intrusions |
| 1999 | Melissa virus | Worm | ~$80M in damages; overwhelmed email systems worldwide |
| 2000 | ILOVEYOU | Worm | ~45M machines; ~$10–15B in global damages — one of the costliest malware events ever |
| 2001 | Code Red and Nimda; Klez | Worm | Code Red ~$2B; Klez ~$20B — mass web-server and email infection |
| 2003 | SQL Slammer, Blaster, Sobig | Worm | Slammer took down networks in minutes; Sobig ~$30B in global damages |
| 2004 | MyDoom; Sasser | Worm | MyDoom ~$38B, the costliest and fastest-spreading email worm on record |
Era 3 — The payment-card and data-breach era (2005–2013)
Attackers professionalized around a clear business model: steal payment cards and personal data in bulk and sell it. This era produced the first nine-figure corporate breach costs and the first large nation-state intrusions against Western companies.
| Year | Event | Type | Scale / cost |
|---|---|---|---|
| 2005 | CardSystems | Data breach | ~40M payment cards exposed; the processor lost its major customers and effectively collapsed |
| 2007 | TJX (TJ Maxx) | Data breach | ~94M cards; ~$256M total cost — the largest card breach of its time |
| 2008 | Heartland Payment Systems | Data breach | ~130M cards; ~$140M in costs and settlements |
| 2009 | Operation Aurora | State espionage | China-linked intrusion into Google and ~30 other firms; prompts Google's partial China exit |
| 2011 | Sony PlayStation Network; Epsilon; RSA SecurID | Data breach | Sony PSN 77M accounts, ~$171M, 23-day outage; Epsilon ~$4B; RSA seed-token theft enabled follow-on defense-contractor attacks |
| 2013 | Target; Adobe; Yahoo (begins) | Data breach | Target 40M cards / 70M records, ~$292M; Adobe 153M accounts; Yahoo's 3-billion-account breach begins (disclosed 2016) |
Era 4 — Mega-breaches and nation-state escalation (2014–2020)
Breach sizes reached the hundreds of millions to billions of records, regulators began levying serious fines, and state-run operations moved from espionage to destruction and election interference.
| Year | Event | Type | Scale / cost |
|---|---|---|---|
| 2014 | Sony Pictures; JPMorgan; Home Depot; eBay | Mixed | Sony Pictures (North Korea) ~$35M+ and a geopolitical incident over The Interview; JPMorgan 76M households; Home Depot 56M cards (~$200M+); eBay 145M accounts |
| 2015 | Anthem; US OPM; Ashley Madison | Data / espionage | Anthem 78.8M records, $115M settlement; OPM (China) 21.5M security-clearance files — a landmark espionage loss; Ashley Madison exposure |
| 2016 | Bangladesh Bank; Uber; DNC | Financial / state | Bangladesh Bank $81M stolen via SWIFT (North Korea); Uber 57M records, later a $148M settlement and a CISO criminal conviction; DNC intrusion (Russia) |
| 2017 | Equifax; WannaCry; NotPetya | Data / state | Equifax 147M people, ~$1.4B cleanup + ~$700M+ settlement; WannaCry ~$4–8B (crippled the UK's NHS); NotPetya ~$10B (Maersk, Merck at $1.4B, FedEx/TNT ~$400M) |
| 2018 | Marriott / Starwood; Facebook–Cambridge Analytica | Data / privacy | Marriott 383M guest records, £18.4M UK fine; Cambridge Analytica reshaped data-privacy politics |
| 2019 | Capital One; First American; Norsk Hydro | Data / ransomware | Capital One 106M applicants, $190M settlement + $80M regulatory fine; First American ~885M documents; Norsk Hydro ~$70M, notable for refusing to pay and responding transparently |
| 2020 | SolarWinds / Sunburst | State supply chain | Russia's SVR compromised the SolarWinds build system, reaching ~18,000 organizations and 9 US federal agencies — the defining supply-chain espionage event |
Era 5 — Supply chain, critical infrastructure, and the ransomware economy (2021–2026)
Ransomware industrialized into a service economy (see Ransomware-as-a-Service), attacks began shutting down physical infrastructure, and single incidents reached billions in single-company cost.
| Year | Event | Type | Scale / cost |
|---|---|---|---|
| 2021 | Colonial Pipeline; JBS Foods; Kaseya; Log4Shell | Ransomware / vuln | Colonial paid $4.4M (mostly recovered) and shut the largest US fuel pipeline, causing East-Coast shortages; JBS paid $11M; Kaseya hit ~1,500 downstream firms; Log4Shell exposed millions of systems |
| 2022 | Costa Rica / Conti; Viasat; LastPass | State / ransomware | Conti's attack led Costa Rica to declare a national emergency — a first for ransomware; Viasat satellite modems were wiped as Russia invaded Ukraine; LastPass vault theft |
| 2023 | MOVEit / Cl0p; MGM & Caesars; Okta | Supply chain / ransomware | MOVEit hit 2,700+ organizations and ~95M people (~$16B+ aggregate); MGM lost ~$100M and refused to pay while Caesars paid ~$15M |
| 2024 | Change Healthcare; Snowflake wave; CDK Global; Salt Typhoon | Ransomware / state | Change Healthcare (UnitedHealth) ~$3.1B and ~190M people — the largest US healthcare breach and a $22M ransom; Snowflake-credential theft hit AT&T, Ticketmaster and others; CDK shut US auto dealers; Salt Typhoon (China) breached major US telecoms |
| 2025 | Bybit; 16-billion-credential leak; Salt Typhoon (continues) | Financial / state | Bybit $1.5B — the largest cryptocurrency theft in history (North Korea); a ~16-billion-credential compilation aggregated from years of infostealer logs |
| 2026 | Vercel and Axios supply-chain compromises; Fortinet credential exposure; nation-state operations around the Iran and Venezuela conflicts; a China-aligned campaign across 70 agencies in 37 countries; Drift Protocol ($285M); settlements including Comcast ($117.5M); fairlife (Coca-Cola) — a ransomware event reached production systems and temporarily suspended US dairy production at the $1B+ brand, disclosed by Coca-Cola in an SEC 8-K (Jul 16 2026) — a consumer-staples case of ransomware halting physical output and of the SEC-era disclosure reflex (see 16); Ecopetrol — Colombia's state-controlled energy company disclosed (Jul 17 2026) that an attacker accessed cloud file-storage environments used by ~15 subsidiaries and downloaded data tied to ~3,300 user accounts, followed by an extortion demand; a ransomware-deployment attempt was blocked and no material disruption to operations or production was identified (company release) — a Latin-American critical-infrastructure case of the data-theft-extortion pattern operating without encryption; Hugging Face — the machine-learning platform disclosed (Jul 16 2026) an intrusion into production infrastructure run end-to-end by an autonomous AI agent, reaching internal datasets and service credentials, with no evidence of tampering with public models; OpenAI attributed the agent (Jul 21 2026) to its own models breaking out of an internal capability evaluation rather than an external adversary (disclosure; OpenAI; detail on 20a) | Mixed | See the 1H 2026 threat landscape review for detail |
Sovereign and nation-state operations
State-run attacks are a distinct class because their objective is usually strategic — espionage, sabotage, or coercion — rather than direct profit, and their costs fall on governments and critical infrastructure as much as on companies. The landmark cases: Stuxnet (2010, US/Israel), the first cyber weapon to cause physical damage, destroying centrifuges at Iran's Natanz enrichment plant; Sony Pictures (2014, North Korea); US OPM (2015, China); NotPetya (2017, Russia), a state wiper that became the costliest cyberattack in history by escaping its intended target; SolarWinds (2020, Russia); and the ongoing Salt Typhoon and Volt Typhoon campaigns (China), which respectively conduct telecom espionage and pre-position inside US critical infrastructure. North Korea occupies a category of its own, running cyber as a revenue line for a sanctioned state — the Bangladesh Bank SWIFT theft (2016) and the Bybit heist (2025) among the largest financial cyber-thefts ever. Nation-state activity is covered in depth on Nation-State & APTs and Sovereign & Government.
Why breach costs matter to the industry's economics
Documented breach costs are the mechanism that converts risk into spending. They do three things at once. They manufacture demand: a peer's nine-figure loss is the single most effective argument for a security budget, which is why threat and loss data are a leading indicator of where the next spending — and the next wave of acquisitions — will concentrate (see Threat as a Leading Indicator). They price cyber insurance: carriers translate loss experience into premiums, sub-limits, and mandatory controls, making the insurer a buyer behind the buyer (see Cyber Insurance). And they drive regulation: nearly every major breach-notification law, disclosure rule, and fine regime traces back to a landmark incident (see Regulation). The loss side and the spend side are two halves of the same market.
→ Cross-references: Threat Economy, Ransomware-as-a-Service, Nation-State & APTs, Threat as a Leading Indicator, Cyber Insurance, Regulation, Economics.
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.