Since we are hot on the subject of ransomware, we thought it would be interesting to revisit the breach impact data provided by our partner, the FBI Internet Crime Complaint Center (IC3).34
When we last reviewed this data in the 2021 DBIR, we found that 90% of the incidents reported to the IC3 had no financial loss result, but for the remaining 10%, the median amount lost was $11,500, and the range of losses in 95% of the cases were between $70 and $1.2 million.
In reviewing Figure 33, of the incidents with loss, the calculated median more than doubled to $26,000, and the 95% range of losses expanded to sit between $1 and $2.25 million, putting that upper bound in scarier territory if you are a small business. The FBI did find that only 7% of the incidents had losses in this case, so it’s not all bad news.
Now, before any one of you makes a snarky quip about inflation and the base rate of the economy, here is the unusual part: When combining the paid-out transactions to the threat actors on the same time period, we get a much smaller median—$10,000 (Figure 34), and this median is actually less than the two previous years when the DBIR team has had access to this dataset.