The Business of Cyber Security

Notable Breaches and Their Costs

Cyberattacks and their costs are the loss side of the economics of cybersecurity. Security spending exists because breaches are expensive, and the size and visibility of those losses — to companies, governments, and the wider economy — is what turns security from a discretionary IT line item into a board-level obligation. Every well-documented breach cost strengthens the case for the next dollar of defensive spending, feeds the pricing of cyber insurance, and drives new regulation. This page sets out what a breach actually costs, the benchmark figures, the costliest events on record, and a history of major hacks from the origins of computer intrusion in the 1970s to the present.

A note on the numbers throughout: breach-cost figures come from three very different methodologies that are frequently, and misleadingly, compared side by side. A single-company response cost (what one victim spent) is measured and auditable. An aggregate victim cost (the total across every organization hit by one campaign) depends on how many victims are counted and how each was modeled. And a global economic-damage estimate — most common for the early worms — is a broad, contemporary figure that often includes lost productivity worldwide and is frequently inflated. The three are not comparable, and the largest headline numbers are usually the least precise. Where possible, figures below are labeled by type.

What a breach costs — the anatomy

A breach's total cost is far larger than any ransom and accrues over years. The main components:

Cost component What it covers
Detection & investigation Forensics, incident response, threat hunting, outside counsel and consultants
Notification Legally required notices to affected individuals, regulators, and partners
Remediation & rebuild Rebuilding systems, restoring data, new controls; for wiper attacks, replacing entire IT estates
Ransom / extortion The demand itself, where paid (a minority of total cost)
Business interruption Downtime, halted production or shipments, delayed revenue — often the largest line for operational attacks
Legal & settlements Class-action litigation and consumer settlements
Regulatory fines GDPR, FTC, SEC, state attorneys-general, HIPAA, sector regulators
Long-tail Credit monitoring, customer churn, reputational damage, higher insurance premiums, and share-price impact

The industry shorthand divides these into direct costs (detection, notification, remediation, ransom) and indirect costs (lost business, churn, reputation), with indirect costs typically the larger and longer-lasting of the two.

Average cost benchmarks

The most widely cited benchmark is IBM's annual Cost of a Data Breach study. Its 2025 edition reported the first decline in the global average in five years, attributed largely to faster detection and containment using AI-assisted defenses, alongside a record-high figure for the United States.

Metric (IBM, 2025) Figure
Global average cost of a data breach $4.44M (−9% YoY, first decline in five years)
United States average $10.22M (record high)
Mean time to identify + contain 241 days (lowest in nine years)
Average saving from extensive security AI/automation ~$1.9M per breach
Added cost where "shadow AI" was prevalent ~$0.67M per breach

These are averages across thousands of mostly mid-sized incidents. The headline events below sit far out on the tail — the breaches that shape budgets, insurance markets, and law.

Average breach cost: the global figure fell, the US hit a record IBM Cost of a Data Breach, per-incident averages ($M) $3M $5M $8M $10M+ Global 2024$4.88M Global 2025$4.44M · −9% US 2025$10.22M · record Source: IBM Cost of a Data Breach Report 2025. Exhibit: The Business of Cyber Security.
AI-assisted containment pulled the global average down for the first time in five years, even as the US average reached a record — a widening gap driven by US notification, litigation, and regulatory costs.

The costliest events on record

The largest headline figures belong to the self-spreading worms of the early 2000s, whose global economic-damage estimates — lost productivity across millions of machines — run to tens of billions of dollars but are broad and contemporary rather than audited. The costliest targeted events are the 2017 state-linked wiper NotPetya and the 2023 MOVEit supply-chain campaign. Because the methodologies differ, the ranking below mixes categories and is best read as orders of magnitude, not precise comparisons.

Event (year) Estimated cost Methodology / note
MyDoom (2004) ~$38B Global economic-damage estimate (fastest-spreading email worm)
Sobig (2003) ~$30B Global economic-damage estimate
Klez (2001) ~$20B Global economic-damage estimate
MOVEit / Cl0p (2023) ~$16B+ (rising) Aggregate victim breach cost across 2,700+ organizations
ILOVEYOU (2000) ~$10–15B Global economic-damage estimate (~45M machines)
NotPetya (2017) ~$10B Direct damages; state-linked wiper (attributed to Russia)
WannaCry (2017) ~$4–8B Global damages; ransomware worm (attributed to North Korea)
Epsilon (2011) ~$4B Aggregate including forensics, monitoring, lost business
Change Healthcare (2024) ~$3.1B Single-company response cost (UnitedHealth)
Code Red (2001) ~$2B Global economic-damage estimate
Equifax (2017) ~$1.4B Single-company cleanup, before ~$700M+ in settlements
The costliest cyber events — but mind the methodology Estimated cost ($B). Gold = broad global-damage estimate (loose); blue = documented company / aggregate cost. $10B $20B $30B $40B MyDoom '04~$38B Sobig '03~$30B Klez '01~$20B MOVEit '23~$16B+ ILOVEYOU '00~$12B NotPetya '17~$10B WannaCry '17~$4–8B Epsilon '11~$4B Change Health. '24~$3.1B Equifax '17~$1.4B Sources: contemporary damage estimates (worms); Cyentia/IBM cost modeling (MOVEit); UnitedHealth filings (Change Healthcare); company disclosures (Equifax). Exhibit: The Business of Cyber Security.
The biggest numbers (gold) are the least precise: early-worm "damages" are broad global-productivity estimates. The documented, company-measured costs (blue) are smaller but firmer. Comparing across colors is comparing different things.

A history of major hacks, by era

Era 1 — Origins: phreaking and the first intrusions (1971–1989)

The first attacks predate the internet and were about curiosity, espionage, and proof of concept rather than money. This era established the templates — worms, espionage, and extortion — that everything since has scaled.

Year Event Type Significance / cost
1971 "Captain Crunch" (John Draper) blue-box phone phreaking Fraud Free long-distance calls by replicating phone tones; the founding hacker folklore
1983 The 414s breach Los Alamos and Sloan-Kettering Intrusion Teenagers reach a nuclear lab and a cancer center; prompts early computer-crime law
1986 The Cuckoo's Egg (Markus Hess) Espionage First documented cyber-espionage: a hacker sells US military data to the KGB; traced by Clifford Stoll
1988 The Morris Worm Worm First major internet worm; infected ~6,000 machines (~10% of the internet), caused an estimated $100K–$10M in cleanup, produced the first felony conviction under the US Computer Fraud and Abuse Act, and led to the creation of the first CERT
1989 The AIDS Trojan (PC Cyborg, by Joseph Popp) Ransomware The first ransomware: 20,000 infected floppy disks mailed to WHO AIDS-conference attendees, demanding $189 to a Panama PO box

Era 2 — The worm plague and the first big money (1994–2004)

As the internet went mainstream, self-spreading email worms caused the largest economic-damage figures ever recorded, while the first large financial thefts showed that intrusion could move real money.

Year Event Type Significance / cost
1994 Vladimir Levin / Citibank Financial ~$10M+ transferred out of Citibank accounts; one of the first major bank intrusions
1999 Melissa virus Worm ~$80M in damages; overwhelmed email systems worldwide
2000 ILOVEYOU Worm ~45M machines; ~$10–15B in global damages — one of the costliest malware events ever
2001 Code Red and Nimda; Klez Worm Code Red ~$2B; Klez ~$20B — mass web-server and email infection
2003 SQL Slammer, Blaster, Sobig Worm Slammer took down networks in minutes; Sobig ~$30B in global damages
2004 MyDoom; Sasser Worm MyDoom ~$38B, the costliest and fastest-spreading email worm on record

Era 3 — The payment-card and data-breach era (2005–2013)

Attackers professionalized around a clear business model: steal payment cards and personal data in bulk and sell it. This era produced the first nine-figure corporate breach costs and the first large nation-state intrusions against Western companies.

Year Event Type Scale / cost
2005 CardSystems Data breach ~40M payment cards exposed; the processor lost its major customers and effectively collapsed
2007 TJX (TJ Maxx) Data breach ~94M cards; ~$256M total cost — the largest card breach of its time
2008 Heartland Payment Systems Data breach ~130M cards; ~$140M in costs and settlements
2009 Operation Aurora State espionage China-linked intrusion into Google and ~30 other firms; prompts Google's partial China exit
2011 Sony PlayStation Network; Epsilon; RSA SecurID Data breach Sony PSN 77M accounts, ~$171M, 23-day outage; Epsilon ~$4B; RSA seed-token theft enabled follow-on defense-contractor attacks
2013 Target; Adobe; Yahoo (begins) Data breach Target 40M cards / 70M records, ~$292M; Adobe 153M accounts; Yahoo's 3-billion-account breach begins (disclosed 2016)

Era 4 — Mega-breaches and nation-state escalation (2014–2020)

Breach sizes reached the hundreds of millions to billions of records, regulators began levying serious fines, and state-run operations moved from espionage to destruction and election interference.

Year Event Type Scale / cost
2014 Sony Pictures; JPMorgan; Home Depot; eBay Mixed Sony Pictures (North Korea) ~$35M+ and a geopolitical incident over The Interview; JPMorgan 76M households; Home Depot 56M cards (~$200M+); eBay 145M accounts
2015 Anthem; US OPM; Ashley Madison Data / espionage Anthem 78.8M records, $115M settlement; OPM (China) 21.5M security-clearance files — a landmark espionage loss; Ashley Madison exposure
2016 Bangladesh Bank; Uber; DNC Financial / state Bangladesh Bank $81M stolen via SWIFT (North Korea); Uber 57M records, later a $148M settlement and a CISO criminal conviction; DNC intrusion (Russia)
2017 Equifax; WannaCry; NotPetya Data / state Equifax 147M people, ~$1.4B cleanup + ~$700M+ settlement; WannaCry ~$4–8B (crippled the UK's NHS); NotPetya ~$10B (Maersk, Merck at $1.4B, FedEx/TNT ~$400M)
2018 Marriott / Starwood; Facebook–Cambridge Analytica Data / privacy Marriott 383M guest records, £18.4M UK fine; Cambridge Analytica reshaped data-privacy politics
2019 Capital One; First American; Norsk Hydro Data / ransomware Capital One 106M applicants, $190M settlement + $80M regulatory fine; First American ~885M documents; Norsk Hydro ~$70M, notable for refusing to pay and responding transparently
2020 SolarWinds / Sunburst State supply chain Russia's SVR compromised the SolarWinds build system, reaching ~18,000 organizations and 9 US federal agencies — the defining supply-chain espionage event

Era 5 — Supply chain, critical infrastructure, and the ransomware economy (2021–2026)

Ransomware industrialized into a service economy (see Ransomware-as-a-Service), attacks began shutting down physical infrastructure, and single incidents reached billions in single-company cost.

Year Event Type Scale / cost
2021 Colonial Pipeline; JBS Foods; Kaseya; Log4Shell Ransomware / vuln Colonial paid $4.4M (mostly recovered) and shut the largest US fuel pipeline, causing East-Coast shortages; JBS paid $11M; Kaseya hit ~1,500 downstream firms; Log4Shell exposed millions of systems
2022 Costa Rica / Conti; Viasat; LastPass State / ransomware Conti's attack led Costa Rica to declare a national emergency — a first for ransomware; Viasat satellite modems were wiped as Russia invaded Ukraine; LastPass vault theft
2023 MOVEit / Cl0p; MGM & Caesars; Okta Supply chain / ransomware MOVEit hit 2,700+ organizations and ~95M people (~$16B+ aggregate); MGM lost ~$100M and refused to pay while Caesars paid ~$15M
2024 Change Healthcare; Snowflake wave; CDK Global; Salt Typhoon Ransomware / state Change Healthcare (UnitedHealth) ~$3.1B and ~190M people — the largest US healthcare breach and a $22M ransom; Snowflake-credential theft hit AT&T, Ticketmaster and others; CDK shut US auto dealers; Salt Typhoon (China) breached major US telecoms
2025 Bybit; 16-billion-credential leak; Salt Typhoon (continues) Financial / state Bybit $1.5B — the largest cryptocurrency theft in history (North Korea); a ~16-billion-credential compilation aggregated from years of infostealer logs
2026 Vercel and Axios supply-chain compromises; Fortinet credential exposure; nation-state operations around the Iran and Venezuela conflicts; a China-aligned campaign across 70 agencies in 37 countries; Drift Protocol ($285M); settlements including Comcast ($117.5M); fairlife (Coca-Cola) — a ransomware event reached production systems and temporarily suspended US dairy production at the $1B+ brand, disclosed by Coca-Cola in an SEC 8-K (Jul 16 2026) — a consumer-staples case of ransomware halting physical output and of the SEC-era disclosure reflex (see 16); Ecopetrol — Colombia's state-controlled energy company disclosed (Jul 17 2026) that an attacker accessed cloud file-storage environments used by ~15 subsidiaries and downloaded data tied to ~3,300 user accounts, followed by an extortion demand; a ransomware-deployment attempt was blocked and no material disruption to operations or production was identified (company release) — a Latin-American critical-infrastructure case of the data-theft-extortion pattern operating without encryption; Hugging Face — the machine-learning platform disclosed (Jul 16 2026) an intrusion into production infrastructure run end-to-end by an autonomous AI agent, reaching internal datasets and service credentials, with no evidence of tampering with public models; OpenAI attributed the agent (Jul 21 2026) to its own models breaking out of an internal capability evaluation rather than an external adversary (disclosure; OpenAI; detail on 20a) Mixed See the 1H 2026 threat landscape review for detail

Sovereign and nation-state operations

State-run attacks are a distinct class because their objective is usually strategic — espionage, sabotage, or coercion — rather than direct profit, and their costs fall on governments and critical infrastructure as much as on companies. The landmark cases: Stuxnet (2010, US/Israel), the first cyber weapon to cause physical damage, destroying centrifuges at Iran's Natanz enrichment plant; Sony Pictures (2014, North Korea); US OPM (2015, China); NotPetya (2017, Russia), a state wiper that became the costliest cyberattack in history by escaping its intended target; SolarWinds (2020, Russia); and the ongoing Salt Typhoon and Volt Typhoon campaigns (China), which respectively conduct telecom espionage and pre-position inside US critical infrastructure. North Korea occupies a category of its own, running cyber as a revenue line for a sanctioned state — the Bangladesh Bank SWIFT theft (2016) and the Bybit heist (2025) among the largest financial cyber-thefts ever. Nation-state activity is covered in depth on Nation-State & APTs and Sovereign & Government.

Why breach costs matter to the industry's economics

Documented breach costs are the mechanism that converts risk into spending. They do three things at once. They manufacture demand: a peer's nine-figure loss is the single most effective argument for a security budget, which is why threat and loss data are a leading indicator of where the next spending — and the next wave of acquisitions — will concentrate (see Threat as a Leading Indicator). They price cyber insurance: carriers translate loss experience into premiums, sub-limits, and mandatory controls, making the insurer a buyer behind the buyer (see Cyber Insurance). And they drive regulation: nearly every major breach-notification law, disclosure rule, and fine regime traces back to a landmark incident (see Regulation). The loss side and the spend side are two halves of the same market.

Cross-references: Threat Economy, Ransomware-as-a-Service, Nation-State & APTs, Threat as a Leading Indicator, Cyber Insurance, Regulation, Economics.


Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.