Statistics

Cybersecurity Statistics That Show Where the Real Losses Are Concentrated

Source-backed cybersecurity statistics on fraud, breaches, and attack pressure.

Cybersecurity statistics that show where the real losses are concentrated

Cybersecurity is not just a volume story. It is a concentration story: a small number of scam types, attack paths, and victim groups account for a very large share of reported losses.

The latest figures in this dataset show how quickly those losses stack up, where complaint volume is highest, and which categories are hitting people and organizations hardest.

Table of contents

Fast facts

  • The FBI IC3 received 880,418 complaints in 2023 and reported potential losses exceeding $12.5 billion, up nearly 10% in complaints and 22% in losses versus 2022 (IC3 Annual Report and Fraud Flyer).
  • In 2024, cyber-enabled fraud accounted for 333,981 complaints and $13.7 billion in losses (2024 IC3 Annual Report).
  • Cyber-enabled fraud represented 38% of all 2024 complaints and 83% of all 2024 losses reported to IC3 (2024 IC3 Annual Report).
  • Cryptocurrency fraud generated 149,686 complaints and $9.3 billion in losses in 2024 (2024 IC3 Annual Report).
  • Elder fraud complaints from victims over 60 reached 147,127 in 2024, with losses of $4.885 billion (2024 IC3 Annual Report).
  • Business email compromise generated $2,770,151,146 in losses in 2024 (2024 IC3 Annual Report).
  • Microsoft blocked 7,000 password attacks per second over the prior year (Microsoft Digital Defense Report 2024).
  • The 2024 Verizon DBIR analyzed 30,458 security incidents and 10,626 confirmed breaches (Verizon DBIR 2024).
  • CISA’s Protective DNS service blocked 1.26 billion malicious connections targeting federal agencies in FY24 (CISA 2024 Year in Review).

What the latest complaint totals show

The first thing these cybersecurity statistics make clear is that complaint volume and loss volume do not always move together in the same way. The FBI IC3 reported 880,418 complaints in 2023 and potential losses exceeding $12.5 billion, which was nearly 10% more complaints and 22% more losses than 2022 (IC3 Annual Report and Fraud Flyer). That gap matters because it shows the environment is not only noisy, it is becoming more expensive.

By 2024, cyber-enabled fraud alone accounted for 333,981 complaints and $13.7 billion in losses (2024 IC3 Annual Report). That category represented 38% of all complaints and 83% of all losses reported to IC3 in 2024 (2024 IC3 Annual Report). In other words, a relatively concentrated slice of reported activity is responsible for the overwhelming share of dollar damage.

A simple way to read the complaint data

The raw complaint count tells you how many people or organizations encountered a problem. The loss figure tells you how severe the problem became when money actually moved. In the IC3 data, the second number is often the one that should drive response priorities.

The scale of 2024 at a glance

CategoryComplaintsLossesSource label
Cyber-enabled fraud333,981$13.7 billion2024 IC3 Annual Report
Cryptocurrency fraud149,686$9.3 billion2024 IC3 Annual Report
Elder fraud, age 60+147,127$4.885 billion2024 IC3 Annual Report
Business email compromiseN/A$2,770,151,1462024 IC3 Annual Report
Investment fraudN/A$1,834,242,5152024 IC3 Annual Report

This table is useful because it highlights how much of the damage is concentrated in a few categories. Cyber-enabled fraud is the broadest bucket here, while cryptocurrency fraud, elder fraud, business email compromise, and investment fraud each contribute major loss totals (2024 IC3 Annual Report).

Which scam categories drive the biggest losses

Cryptocurrency fraud stands out because it combines large complaint volume with extremely large losses. In 2024, it generated 149,686 complaints and $9.3 billion in losses (2024 IC3 Annual Report). That is enough to place it among the highest-impact fraud categories in the dataset. The report also says cryptocurrency fraud losses increased 66% in 2024 (2024 IC3 Annual Report).

The victim age distribution for cryptocurrency fraud is also revealing. The largest age group to report cryptocurrency fraud was victims over 60 (2024 IC3 Annual Report). That group filed 33,369 complaints and reported $2,839,333,197 in losses (2024 IC3 Annual Report). Younger age bands were affected too, but the loss totals rise sharply with age in the reported data.

Cryptocurrency fraud by age group

Age groupComplaintsLossesSource label
Under 201,819$7,778,1572024 IC3 Annual Report
20-2913,591$370,443,3452024 IC3 Annual Report
30-3922,218$1,006,382,4582024 IC3 Annual Report
40-4922,555$1,462,040,9742024 IC3 Annual Report
50-5919,317$1,184,912,8542024 IC3 Annual Report
Over 6033,369$2,839,333,1972024 IC3 Annual Report

The pattern is straightforward: the older the victim group, the larger the reported losses tend to be in this category. That does not mean every older victim is targeted in the same way, but it does show why fraud prevention training has to be age-aware and channel-aware.

Elder fraud is another category where the loss totals deserve close attention. Complaints from victims over 60 reached 147,127 in 2024, and losses reached $4.885 billion (2024 IC3 Annual Report). Those complaints increased 46% in 2024, while losses increased 43% (2024 IC3 Annual Report). That is a large and fast-moving problem even before you break it into subtypes.

Business email compromise is a separate category, but it sits in the same high-loss tier. The reported loss total was $2,770,151,146 in 2024, compared with $2,946,830,270 in 2023 and $2,742,354,049 in 2022 (2024 IC3 Annual Report). That means the series remains enormous even when the year-to-year direction shifts. It is also a reminder that one category can stay persistently expensive without looking especially dramatic in any single month.

Investment fraud also remains a major loss engine. It produced $1,834,242,515 in losses in 2024, up from $1,243,010,600 in 2023 and $990,235,119 in 2022 (2024 IC3 Annual Report). Confidence fraud and romance fraud produced $389,312,356 in losses in 2024, compared with $356,888,968 in 2023 and $419,768,142 in 2022 (2024 IC3 Annual Report). These categories are useful to compare because they show how different fraud types can move in different directions even within the same reporting framework.

Loss leaders at a glance

  • Cryptocurrency fraud: $9.3 billion in 2024 losses (2024 IC3 Annual Report).
  • Elder fraud, victims over 60: $4.885 billion in 2024 losses (2024 IC3 Annual Report).
  • Business email compromise: $2,770,151,146 in 2024 losses (2024 IC3 Annual Report).
  • Investment fraud: $1,834,242,515 in 2024 losses (2024 IC3 Annual Report).
  • Confidence fraud/romance fraud: $389,312,356 in 2024 losses (2024 IC3 Annual Report).

Smaller categories can still be costly

Not every scam type needs enormous complaint volume to produce meaningful damage. Call center scams generated 53,369 complaints and $1.9 billion in losses (2024 IC3 Annual Report). Toll scams generated 59,271 complaints but only $129,624 in losses in the reported dataset (2024 IC3 Annual Report). Emergency scams generated 357 complaints and $2.7 million in losses (2024 IC3 Annual Report). Gold courier scams generated 525 complaints and $219 million in losses (2024 IC3 Annual Report).

Those differences matter because they show why complaint counts alone can be misleading. A category with fewer complaints may still be far more financially destructive per incident than a category with much higher volume.

Age patterns in fraud losses

The dataset repeatedly points to the same theme: age matters in the damage profile. The biggest cryptocurrency fraud loss total belongs to victims over 60, and elder fraud losses are also centered in the 60+ group (2024 IC3 Annual Report). That does not mean age is the only driver, but it is one of the clearest risk markers in the data.

A practical takeaway is that victim education has to be specific. Generic warnings about scams are not enough when the highest loss categories are tied to impersonation, investment pitches, and payment-transfer pressure. The data supports a more targeted approach built around the methods scammers actually use.

What the age split suggests

  • Older victims are responsible for the largest reported loss totals in several categories (2024 IC3 Annual Report).
  • Younger victims are not absent from the data, but the dollar damage is smaller in the under-20 and 20-29 bands for cryptocurrency fraud (2024 IC3 Annual Report).
  • The middle age bands still account for major losses, especially from 30-39 through 50-59 (2024 IC3 Annual Report).

The main message is not that one age group is careless. It is that fraudsters are extracting different amounts of money from different groups, and that pattern should shape prevention, verification, and recovery processes.

Business and enterprise attack pressure

Consumer fraud is only part of the story. The same dataset also includes indicators of pressure on businesses, public agencies, and infrastructure.

Microsoft reported that customers faced more than 600 million cybercriminal and nation-state attacks every day in 2024 (Microsoft Digital Defense Report 2024). More than 99% of identity attacks in Microsoft’s data were password attacks, and Microsoft blocked 7,000 password attacks per second over the prior year (Microsoft Digital Defense Report 2024). That pair of figures shows why credential security remains a core control rather than a niche concern.

Microsoft also mitigated 1.25 million DDoS attacks in the second half of 2024, which was a 4x increase compared with the prior year (Microsoft Digital Defense Report 2024). The report says Microsoft tracked 78 trillion security signals per day in 2024, up from 65 trillion per day in 2023 (Microsoft Digital Defense Report 2024). That is a jump of 13 trillion daily signals in one year, which is useful context for understanding the telemetry burden behind modern defense operations.

Enterprise threat indicators worth noting

  • More than 1,500 unique threat groups were tracked by Microsoft Threat Intelligence (Microsoft Digital Defense Report 2024).
  • More than 600 of those were nation-state threat actor groups (Microsoft Digital Defense Report 2024).
  • Microsoft tracked 300 cybercrime groups and 200 influence operations groups (Microsoft Digital Defense Report 2024).
  • Microsoft reassigned roughly 34,000 full-time equivalent engineers to security initiatives (Microsoft Digital Defense Report 2024).
  • Microsoft had 15,000 partners with specialized security expertise (Microsoft Digital Defense Report 2024).

These are not just abstract scale metrics. They explain why defensive tooling, identity controls, and coordinated response capacity are now table stakes for large platforms.

The Verizon DBIR adds another angle. Its 2024 report analyzed 30,458 security incidents and 10,626 confirmed breaches, spanning victims in 94 countries (Verizon DBIR 2024; Verizon DBIR media resources). Within that set, 68% of breaches involved a non-malicious human element, 14% involved exploitation of vulnerabilities as an initial access step, and 32% involved ransomware or extortion tactics (Verizon DBIR 2024). The report also says 15% of breaches involved a third party or supplier (Verizon DBIR 2024). That combination shows how many breaches still depend on people, process, and partner exposure rather than purely technical compromise.

Why the breach mix matters

If 68% of breaches involve a non-malicious human element, then awareness training alone is not enough, but it is also not optional (Verizon DBIR 2024). If 14% start with vulnerability exploitation, patch management and exposure reduction are obviously part of the answer (Verizon DBIR 2024). If 15% involve a third party or supplier, vendor risk has to be in scope from the start (Verizon DBIR 2024).

The same report says 62% of financially motivated incidents involved ransomware or extortion, with a median loss of $46,000 per breach (Verizon DBIR 2024). It also says ransomware was a top threat across 92% of industries, and vulnerability exploitation in breaches surged 180% year over year (Verizon DBIR analysis; Verizon DBIR 2024). That is a strong signal that adversaries are not choosing a single path. They are using whatever works at scale.

Threat activity and detection at scale

CISA’s activity data gives a view of the defensive side of the equation. The agency conducted 3,368 Pre-Ransomware Notifications since the initiative began, including 2,131 in FY24 alone (CISA 2024 Year in Review). It also released almost 1,300 cyber defense alerts, advisories, and products in FY24, including 58 joint-sealed cybersecurity advisories and co-sealed products (CISA 2024 Year in Review). CISA used administrative subpoena authority to identify and drive mitigation of over 1,200 vulnerable devices, and its Protective DNS service blocked 1.26 billion malicious connections targeting federal agencies in FY24 (CISA 2024 Year in Review).

These numbers matter because they show modern cyber defense is part alerting, part blocking, part remediation orchestration. The scale is high enough that no single tactic is sufficient.

The operational takeaway

If you are using cybersecurity statistics to prioritize controls, the data in this post supports a layered response:

  • Protect identities first, because password attacks dominate a huge share of identity abuse (Microsoft Digital Defense Report 2024).
  • Reduce exposure to fraud flows that involve payment transfer or impersonation, because those categories drive large reported losses (2024 IC3 Annual Report).
  • Treat vendor and third-party paths as first-class risk areas, because they appear in a meaningful share of breaches (Verizon DBIR 2024).
  • Keep detection and alerting capacity current, because the telemetry and attack volume are now measured in billions, trillions, and millions rather than isolated events (Microsoft Digital Defense Report 2024; CISA 2024 Year in Review).

How to read these cybersecurity statistics

The best way to use these numbers is to separate three different questions:

  1. How common is the activity?
  2. How much money does it cost?
  3. Who is most exposed?

The answer is not the same for every category. Cryptocurrency fraud is high on all three dimensions. Cyber-enabled fraud is the broadest loss bucket in the IC3 data. Business email compromise remains one of the most expensive single categories even when year-to-year totals fluctuate (2024 IC3 Annual Report).

The broader lesson is that cybersecurity statistics are most useful when they are tied to decisions. Use complaint totals to understand demand on support, reporting, and education. Use loss totals to rank the categories that deserve the most immediate financial controls. Use age, sector, and attack-path data to decide which audiences need the most specific defenses.

Written by

yourdefencenews.com Editorial Team

Editorial team

yourdefencenews.com publishes practical how-to guides and educational articles with clear steps and useful context.