
When Cybercrime magazine predicted in 2020 that the scourge of cyberattacks would cost the world $10.5trn by 2025, many considered the estimate to be wildly exaggerated. In fact, it is turning out to be absolutely correct. The actual cumulative cost of cyberattacks in 2024 was $9.5trn and, although the figures aren’t yet out for 2025, the rate of increase is on target. Considering that the price of these pernicious economic invasions was $3trn in 2015, cybercrime has clearly become a growth industry of apocalyptic proportions. If cybercrime were seen as an economy in its own right, it would be the third biggest in the world after the US and China. And the damage is mounting by the day.
As Cybercrime magazine’s editor-in-chief Steve Morgan wrote at the time about the exponential danger of these attacks: “They represent the greatest transfer of economic wealth in history, risks the incentives for innovation and investment, is exponentially larger than the damage inflicted from natural disasters in a year, and will be more profitable than the global trade of all major illegal drugs combined.” Legendary investor and economic philosopher Warren Buffett agrees, describing cybercrime as mankind’s main problem and ranking it as a bigger threat to humanity than nuclear weapons.
Assembly lines hit
Many victim companies can attest to that, as the following recent examples show. South Korean e-commerce platform Coupang took a hit in December 2025 that stole the personal details of nearly 35 million users. A month earlier, attackers cracked the commercially sensitive data of over 200 companies connected through the system of Salesforce, a customer relationship management platform. In September the assembly lines of British automotive giant Jaguar Land Rover ground to a halt for several weeks after the shadowy Spider group of young hackers mounted a ransomware attack that cost the group about $2.2bn in lost production. And in April cyber-criminals penetrated the digital and in-store operations of one of the UK’s favourite retailers, Marks & Spencer, with devastating effect – the group suffered a loss of between £200m–£300m. This has been coming for a long time.
Warren Buffett described cybercrime as a bigger threat to humanity than nuclear weapons
The founder of a cyberprotection company told me years ago how he was able to convince sceptical major banks that they were highly vulnerable. “I asked the board permission for my experts to try and hack into their systems,” he said. “I estimated it would take 20 minutes.” And it usually did.
Just about every day these attacks are ravaging businesses, governments and other organisations worldwide. “In 2025 major cybercrime attacks on businesses were dominated by massive cryptocurrency thefts, sophisticated third-party vendor breaches, and disruptive ransomware,” reports the Centre for Strategic and International Studies. To take just ransomware, also in 2025 a gang was able to halt emergency services across several American states in an attack at OnSolve, a critical risk management provider, in a CodeRED alert system breach.
Hardly a month passes without a damaging and sometimes crippling attack by a wide variety of cybercriminals that run from computer-savvy youths who think it is fun to government-sponsored agencies engaged in systematic industrial espionage. For instance, according to the Centre for Strategic and International studies, in December 2025 a Russia-linked group named Electrum knocked out about 30 sites in Poland’s energy grid. In January 2026 Pakistan’s Transparent Tribe launched a campaign on a wide variety of Indian institutions including government departments in retaliation for fighting on the border. Also in January a unit of Russia’s military intelligence service placed a creeping multi-stage infection in government departments in Central and Eastern Europe. In a nice irony, around the same time Russia was hit in what was surely a spoof attack, when deliveries of the Vladimir Bread Factory, a key regional producer, were thrown into chaos after a tit-for-tat raid corrupted its online systems.
State-sponsored cybercrime is highly organised. In March another Russian cybercrime cell demanded payment after breaching the systems of the German Democratic Socialist Party while, in America, Iranian hacker Handala heavily disrupted the operations of Stryker, a manufacturer of medical devices, in what it claimed was retaliation for the US bombing of the girls’ school in the south of the country. Few countries are immune. In another example of state-backed cyberterrorism, all four of Singapore’s biggest telecommunications companies suffered a months-long invasion by UNC3886, a China-linked group, in July 2025.
Dark web
Cybercrime investigators say the dark web, impenetrable to everybody except skilled practitioners, has become a gigantic pool for the malware, exploit kits and other tools that are used to inflict economic mayhem. These weapons have become so powerful that they could disable the economy of a city, state or even an entire country.

But cyberattacks also cause untold damage at all levels. As insurance industry magazine Atlas records, citing the Data Breach Investigations Report, there were more than 22,000 cyber-incidents in 2025 involving public and private organisations in 139 countries. Individuals count among the victims, no less than 426 million suffering data breaches.
The hardest-hit nation is the US, followed by France, India, Germany and Russia. “Data breaches are no longer isolated incidents but a real threat that has become an integral part of today’s digital environment,” notes Atlas. In other words, any enterprise that has an online presence could be in the firing line.
Although the rapid spread of artificial intelligence is blocking some of these attacks, the economic damage continues to mount. In 2025 the average cost of a cyberattack was put at $4.44m but it is more than double that in the US at $10.2m. At this rate we are heading to financial Armageddon, according to the IMF. As just about every business, big or small, goes online – or works with others who are online – the risks multiply. “This phenomenon generates colossal economic costs that could affect macro-financial stability on a global scale,” the IMF warns, forecasting cumulative losses of $23trn by 2027 incurred from direct losses triggered by ransomware, data theft, embezzlement and fraud, among others, as well as indirect costs such as reputational damage, legal fees and regulatory fines. For instance, in a typical example of collateral damage the British government had to come up with an emergency £1.7bn loan to prop up Jaguar Land Rover and its lengthy chain of suppliers.
No industry is safe. In 2025, the worst year so far for cybercrime, Japanese brewer Asahi had to stop all production across the entire Asia-Pacific, while Australia’s Qantas airline suffered a data leak of about five million customers. While the latter attack didn’t shut down the system, the carrier was immediately hit by an avalanche of class-action threats and official fines that some sources say could go as high as $4.6bn.
The ingenuity of cybercriminals keeps improving. One of their favourite scams is known as ‘CEO fraud’ whereby the criminal poses as the boss by using artificially generated videos and voice to trick an employee into transferring money or disclosing commercially confidential information.
Although there is insurance cover against cybercrime, it is expensive in what is a fast-growing market. In 2024, according to market sources, premiums valued at $15.3bn were written in 2024 and they are rising all the time. One of the giants of the industry, Munich Re, estimates the market will hit $32.4bn by 2030. But of course the economic damage has already been done.
Non-state actors
Digitisation lies at the heart of what experts see as a phenomenon that could play havoc with life as we know it. “Over the next two decades militancy, terrorism and organised crime will profoundly change as non-state armed actors adopt many of the same technologies used by conventional armies and everyday society,” warned experts from American think tank, Brookings Institute, in early 2026 in a chilling assessment of where things are heading. “Criminal and militant groups are already espousing many emerging and existing technologies – using drones for smuggling and violence, artificial intelligence systems to develop new synthetic drugs, and digital currencies to hide and launder money.”
Previously, the Brookings Institute argues, terrorists, drug cartels and quasi-military groups needed large swathes of territory to wage crime and exercise control by physical domination. “Today however, new technologies, such as synthetic drugs production, digital payment systems, artificial intelligence and networked devices, are eroding the traditional benefits and reasons for holding territory, especially its role in generating revenue,” the institute explains. This may prove to be a prophetic observation that identifies AI-enabled scams, online fraud, ransomware operations and cryptocurrency-based laundering that yield “earnings larger than the taxation of legal or illegal economies.”
The institute’s calculations suggest that the new wired, always-on brand of criminals rack up global profits of over a trillion dollars a year – and up to hundreds of billions in the US alone. “Over time, these activities will supplement and increasingly displace more traditional sources of income for criminals and militants,” it concludes. And they are running less risk. Without troubling the underground arms market that is under constant surveillance by the authorities, well-organised Brazilian gangs are printing high-powered rifles by 3D – ‘ghost guns’ that can’t be traced. And, learning from the military, targets can be taken out from great distances by relatively cheap drones.
The overall consequence is that it will become much harder for traditional law enforcement to police crime that is committed far from where the damage is caused. As experts warn, a handful of individuals are already running automated scams, deepfake identity fraud and algorithmic phishing, often from locations like basements in distant cities that are hard to detect. In short, economic havoc can be caused remotely on a shoestring.


