RansomwareClock.org


Reported Cost of Ransomware Attacks 2025 YTD

$

Aggregated Estimate from Public and Private Sources, Reflects Reported Attacks Only. Actual cost estimated to be significantly higher.


The forecast for cybercrime in 2024 is harsh with attacks increasing in frequency, sophistication, and severity. We must work together to protect our companies and communities from the financial, operational, and emotional trauma of cyber-attacks.

Cyber Stats


$1.85m


average cost for remediation, business downtime, lost orders, operational costs, etc. 2X vs year ago. Recovery cost is 10X the size of the ransom payment. Sophos, The State of Ransomware 2021

93%


consider an organization's trustworthiness prior to purchasing. 59% would avoid doing business with a company cyberattacked in the past 12 months. Arcserve 2020 Survey

11 seconds


a new ransomware attack hits this year. Cybersecurity Ventures. (In the time it takes you to read this cyber stat, another business has been hit with a ransomware attack.)

207 days


days is the average time to identify a breach. Meaning the bad guys are in your system for over 6-months. IBM Security Cost of a Data Breach Report 2020.

Only 21%


of security professionals think their current security controls are adequate. Forrester State of Enterprise IoT Security in North America

21 days


days is the average downtime caused by a ransomware attack. Coveware Q4, 2020

Spotlight


Read More

CISA


The Cybersecurity and Infrastructure Security Agency (CISA) was founded in 2018 and is a standalone United States federal agency, organized under the Department of Homeland Security (DHS). It exists to...

RECENT ATTACKS & NEWS


October 1, 2026

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the...

Read More

October 1, 2026

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The...

Read More

October 1, 2026

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post...

Read More

October 1, 2026

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are...

Read More

October 1, 2026

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post...

Read More

October 1, 2026

AI Has Changed Attack Speed, Not Security Fundamentals

As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals....

Read More

October 1, 2026

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post Zimbra Vulnerability Exploited in...

Read More

October 1, 2026

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its...

Read More

October 1, 2026

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network

The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post Treasury Blacklists Most-Wanted...

Read More

October 1, 2026

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days...

Read More

In Case of Cyber Attack Emergency



If a ransomware incident occurs at your organization, CISA, FBI, and NSA recommend the following actions:

Contact your Local FBI Office - https://www.fbi.gov/contact-us/field-offices

Report a Complaint to the FBI’s Internet Criminal Complaint Center: www.IC3.gov


Technical Expertise/Crisis Communications