At a glance
Cyber warfare now sits inside a much larger security picture: nonstop identity attacks, DDoS surges, influence operations, and state-linked targeting all overlap in the same threat environment. The numbers below show why defenders increasingly have to treat cyber warfare as a system problem rather than a single-attack problem.
Contents
- The scale of the threat
- What the major datasets say
- Where attacks concentrate
- State, criminal, and infrastructure pressure
- Why defense exercises matter
- What the statistics imply for organizations
The scale of the threat
Cyber warfare statistics do not describe a single conflict channel. They point to a layered environment where nation-state activity, cybercrime, availability attacks, fraud, and influence operations all compete for the same defender attention.
A useful starting point is the volume of hostile activity. Microsoft said customers face more than 600 million cybercriminal and nation-state attacks every day (Microsoft Digital Defense Report 2024). That is not just a headline number. It sets the scale for how much automated scanning, credential abuse, and opportunistic targeting defenders have to absorb continuously.
The identity layer is especially intense. Microsoft said more than 99% of its 600 million daily identity attacks are password-based (Microsoft Digital Defense Report 2024). Microsoft also blocked 7,000 password attacks per second over the past year (Microsoft Digital Defense Report 2024). Together, those figures show that cyber warfare pressure often starts with the simplest access path available.
The denial-of-service layer is also moving fast. Microsoft mitigated 1.25 million DDoS attacks in the second half of the year (Microsoft Digital Defense Report 2024). That volume was a 4x increase versus the prior year (Microsoft Digital Defense Report 2024). When the availability threat line rises that sharply, it signals that disruption can be deployed at scale, repeatedly, and with low friction.
What the major datasets say
The best cyber warfare statistics become clearer when grouped by source. Different organizations measure different parts of the problem, but the overlap is instructive.
| Source | Key statistic | What it suggests |
|---|---|---|
| Microsoft Digital Defense Report 2024 | 78 trillion security signals per day, up from 65 trillion in 2023 (Microsoft Digital Defense Report 2024) | Massive telemetry footprint and rising detection load |
| Microsoft Digital Defense Report 2024 | More than 1,500 unique threat groups tracked (Microsoft Digital Defense Report 2024) | A crowded adversary ecosystem |
| ENISA Threat Landscape 2024 | Seven prime cybersecurity threats identified (ENISA Threat Landscape 2024) | Threat activity clusters into recurring categories |
| IC3 Annual Report 2024 | 859,532 complaints and $16.6 billion in losses (IC3 Annual Report 2024) | Large-scale victimization remains financially material |
| NATO Secretary General’s Annual Report 2024 | USD 486 billion spent on defence in Europe and Canada (NATO Secretary General’s Annual Report 2024) | Cyber defense sits inside broader security investment |
| CWIX 2024 | Nearly 500 capabilities tested (NCIA CWIX 2024) | Interoperability is a practical requirement, not a theory |
One of the most important signals is telemetry scale. Microsoft’s insights were informed by 78 trillion security signals per day in 2024 (Microsoft Digital Defense Report 2024). That was up from 65 trillion per day in 2023 (Microsoft Digital Defense Report 2024). The jump matters because it shows the monitoring problem is expanding even before defenders decide how to respond.
The adversary mix is also broad. Microsoft tracked more than 600 nation-state threat actor groups, 300 cybercrime groups, and 200 influence operations groups (Microsoft Digital Defense Report 2024). That breakdown makes cyber warfare look less like a single arena and more like a competition of specialized actors with different goals.
Where attacks concentrate
Cyber warfare statistics are most useful when they show concentration, because concentration tells defenders where to spend finite effort. Microsoft’s sector data gives a strong example. Microsoft said Education and Research became the second-most targeted sector by nation-state threat actors in 2024 (Microsoft Digital Defense Report 2024). Microsoft also said its top targeted sector by nation-state actors was IT at 24% (Microsoft Digital Defense Report 2024). Education and Research accounted for 21% of the top targeted sectors globally (Microsoft Digital Defense Report 2024). Government accounted for 12% (Microsoft Digital Defense Report 2024).
The rest of the top list shows that pressure is spread across sectors that are operationally significant rather than randomly chosen. Think tanks and NGOs accounted for 5% (Microsoft Digital Defense Report 2024). Transportation accounted for 5% (Microsoft Digital Defense Report 2024). Consumer retail accounted for 5% (Microsoft Digital Defense Report 2024). Finance accounted for 5% (Microsoft Digital Defense Report 2024). Manufacturing accounted for 4% (Microsoft Digital Defense Report 2024). Communications accounted for 4% (Microsoft Digital Defense Report 2024). All other sectors accounted for 16% (Microsoft Digital Defense Report 2024).
That distribution suggests two things. First, attackers are not concentrating only on classic security targets. Second, they are also hitting sectors with information value, infrastructure value, or downstream influence value.
The FBI’s IC3 data reinforces the financial side of this concentration. The IC3 received 859,532 complaints in 2024 (IC3 Annual Report 2024). Those complaints produced $16.6 billion in losses (IC3 Annual Report 2024). The 2024 loss total was 33% higher than 2023 (IC3 Annual Report 2024). That is a large year-over-year jump, and it shows that even when defenders focus on cyber warfare in the military or state context, the victimization pipeline in civilian environments remains huge.
Losses by complaint type
A small set of attack patterns produced a large amount of harm. Cyber-enabled fraud generated 333,981 complaints and $13.7 billion in losses (IC3 Annual Report 2024). Cyber-enabled fraud accounted for 38% of complaints and 83% of losses in the IC3 report (IC3 Annual Report 2024). That imbalance matters because it shows that a relatively narrow slice of behavior can dominate total damage.
Phishing/Spoofing generated 193,407 complaints (IC3 Annual Report 2024). That makes credential manipulation one of the most common gateway behaviors in the wider cyber threat picture. The prevalence aligns with Microsoft’s finding that more than 99% of its 600 million daily identity attacks are password-based (Microsoft Digital Defense Report 2024). The two datasets point in the same direction: access compromise still starts with very old mechanics.
Extortion and sextortion remain material too. Extortion/sextortion generated 54,936 complaints and $33.5 million in losses (IC3 Annual Report 2024). Extortion/sextortion complaints increased 59% from 2023 (IC3 Annual Report 2024). That growth rate matters because it shows coercive cybercrime is not fading into the background. It is continuing to scale.
State, criminal, and infrastructure pressure
Cyber warfare is not only about state-on-state intrusion. It is also about the pressure that state and non-state activity place on critical infrastructure, public administration, and security planning.
Microsoft tracked more than 600 nation-state threat actor groups and more than 1,500 unique threat groups overall (Microsoft Digital Defense Report 2024). Those figures suggest the state threat environment is embedded in a much bigger field of adversarial activity. Microsoft also reassigned roughly 34,000 full-time equivalent engineers to security initiatives (Microsoft Digital Defense Report 2024). That detail is important because it reflects organizational response scale as part of the threat environment itself.
The government and public-sector exposure is visible in the IC3 report as well. Public administration IC3 complaints generated $1.571 billion in losses for critical infrastructure-related cases (IC3 Annual Report 2024). That line matters because it connects cyber incidents to essential services and administrative continuity.
The age breakdown in the IC3 report shows that the economic consequences are not distributed evenly across populations. Complaints from victims age 60+ totaled 147,127 and $4.8 billion in losses (IC3 Annual Report 2024). Complaints from victims 50-59 totaled 84,540 and $2.5 billion in losses (IC3 Annual Report 2024). Complaints from victims 40-49 totaled 112,755 and $2.2 billion in losses (IC3 Annual Report 2024). Complaints from victims 30-39 totaled 108,899 and $1.4 billion in losses (IC3 Annual Report 2024). Complaints from victims 20-29 totaled 71,399 and $540.1 million in losses (IC3 Annual Report 2024). Complaints from victims under age 20 totaled 17,993 and $22.5 million in losses (IC3 Annual Report 2024).
That age profile suggests cyber pressure is broad, but the financial burden rises sharply with older groups. For defenders, that means cyber warfare statistics should not be read only through a military lens. They also reveal where public harm is most expensive.
Crypto and impersonation cases
The IC3 report also separates some of the most operationally relevant scam patterns. Tech Support scams generated 2024 complaints with $107,429,709 in losses in the crypto-ATM use table (IC3 Annual Report 2024). Extortion generated 4,189 complaints with $5,601,953 in losses in the crypto-ATM use table (IC3 Annual Report 2024). Impersonation generated 1,786 complaints with $44,587,335 in losses in the crypto-ATM use table (IC3 Annual Report 2024). Investment scams tied to crypto ATM use generated 606 complaints and $38,090,269 in losses (IC3 Annual Report 2024).
Those numbers are small compared with the overall IC3 totals, but they are still large enough to matter strategically. They show how specific payment or transfer patterns can be exploited repeatedly. They also reinforce that cyber warfare statistics should include the financial plumbing that turns compromise into loss.
Why defense exercises matter
Cyber warfare readiness is not proven by policy statements. It is tested through joint exercises, interoperability work, and live capability validation. The available statistics show that these exercises operate at meaningful scale.
Locked Shields 2024 involved 4,000 experts from more than 40 countries (NCIA Locked Shields 2024). Locked Shields 2024 also included more than 200 experts working with Latvia in Riga (NCIA Locked Shields 2024). That suggests a large and geographically distributed training environment, with real collaboration under pressure.
Cyber Coalition 2024 had almost 200 participants on-site at the Estonian Cyber Range (NATO ACT Cyber Coalition 2024). Cyber Coalition 2024 had more than 1,300 cyber defenders from NATO Allies and Partners (NATO ACT Cyber Coalition 2024). Cyber Coalition has been a NATO planning staple since 2008 (NATO ACT Cyber Coalition 2024). That longevity matters because cyber readiness is a recurring discipline, not a one-off event.
Counter-UAS TIE24 added another layer. It had 450 participants, including 19 Allied Nations and three Partner Nations (NCIA Counter Drone Exercise 2024). Ukraine participated in Counter-UAS TIE24 for the first time (NCIA Counter Drone Exercise 2024). More than 60 systems and technologies were tested live in the exercise (NCIA Counter Drone Exercise 2024). The presence of live systems matters because cyber warfare increasingly overlaps with drones, sensors, command systems, and other connected assets.
CWIX 2024 shows the interoperability side most clearly. CWIX 2024 had more than 2,500 participants, tested nearly 500 capabilities, and involved 42 NATO nations and partners (NCIA CWIX 2024). That kind of scale indicates that cyber defense planning is deeply tied to communication and interoperability.
What the statistics imply for organizations
For organizations trying to interpret cyber warfare statistics, the practical lesson is not just “attack volume is high.” The data points to a few sharper operational conclusions.
-
Identity is a frontline control problem. Microsoft said more than 99% of its 600 million daily identity attacks are password-based (Microsoft Digital Defense Report 2024). That means weak or legacy authentication remains a major opening.
-
Availability defense cannot be treated as a secondary concern. Microsoft mitigated 1.25 million DDoS attacks in the second half of the year (Microsoft Digital Defense Report 2024), and that volume was 4x higher than the prior year (Microsoft Digital Defense Report 2024). Organizations that rely on uptime need a resilience plan, not just perimeter controls.
-
Sector exposure is uneven. IT led the targeted sector list at 24% (Microsoft Digital Defense Report 2024), while Education and Research reached 21% (Microsoft Digital Defense Report 2024) and Government 12% (Microsoft Digital Defense Report 2024). Organizations should benchmark themselves against their real sector risk, not an average risk model.
-
Financial harm can outgrow complaint counts. Cyber-enabled fraud was 38% of complaints but 83% of losses in the IC3 report (IC3 Annual Report 2024). That means the most damaging patterns are not always the most numerous.
-
Cooperation matters because the threat ecosystem is plural. Microsoft tracked more than 1,500 unique threat groups (Microsoft Digital Defense Report 2024), while NATO exercises brought together thousands of participants across dozens of countries (NCIA Locked Shields 2024; NCIA CWIX 2024). The statistics suggest that no single team can cover the full problem alone.
For readers tracking cyber warfare trends, the key point is that scale, diversity, and persistence all show up at once. The daily attack volume is huge. The adversary ecosystem is fragmented. The targets include both strategic institutions and ordinary victims. The result is a security environment where the headline threat and the day-to-day criminal threat reinforce each other rather than compete.