Cointime

Download App
iOS & Android

Cybercrime - Trends Overview & 2024 Forecast

Cybercrime - Trends Overview & 2024 Forecast

Article Highlights

  • Cybercrime: A Crisis Imposing A Rising Burden on the Global Economy
  • Distributed Workforce, Digital Economy: Prey for Social Engineering Attacks
  • Compromised Credentials: Social Engineering Attack Fuel, Protect Passwords
  • Anti-phishing Protection: The First Line of Defense
  • 2024 Forecast: +19% Growth from 2023, Up from +16% 2020-2023 Baseline

Each month FYEO publishes an update on cybersecurity developments, trends and the volume of leaked credentials added to our exposed login credential database (now 27 billion and growing). For a broader perspective on cybercrime and its attack vectors, here we step back from the near-term particulars to look at trends using data from other sources and provide a forecast for 2024.

The Big Picture: Cybercrime - A Growing Burden on The Global Economy

Global GDP & The Cost of Cybercrime

Based on data from the IMF (global GDP) and Statista (cybercrime), cyber attacks pose increasing burden on the global economy. Since the 2020 COVID pandemic, cybercrime is growing at 40% annual rate, almost 6x faster than the global economy, spurred as the world became rapidly more digital out of necessity due to the impact of the COVID pandemic. Were cybercrime a global GDP component, it would represent almost $0.08 on every $1.00 produced in 2023, up from just under $0.01 in 2017, a development of staggering import.

How Is This Happening?: Social Engineering, Business Email Compromise & Credential Attacks

Two sources, IBM Security and Verizon, have been publishing annual reports since 2006. From IBM Security, the annual “Cost of a Data Breach” (CDB) Report offers financial cost data for 11 attack vector types, 16 countries/regions and 17 different industry sectors. From Verizon, the annual “Data Breach Investigations Report” (DBIR) which covers 21 industries in 81 countries with data from 67 contributing organizations (interestingly, not from IBM Security). 

Given the impact COVID had on the global economy in terms of how and where business was done, we use the IBM and Verizon databases to examine the 2020-2023 period in order to see how cyber attack vectors have shifted. 

Clearly, Social Engineering & Business Email Compromise (BEC) is the standout attack vector with a +55% compound annual growth rate (CAGR). Feeding this accelerated growth, Credential Losses, a +13% CAGR, provide the necessary inputs (e.g. logins, personally identifiable information (PII)) to fuel Social Engineering & BEC attacks. Meanwhile, System Error and Accidental Device Loss vector, a +25% CAGR, reflects the difficulties in supporting a distributed workforce that more often than not is using personal devices. 

All told, these three vectors represent an estimated $44 billion in cumulative data breach costs over the 2020-2023 period and are growing at a combined +24% annual rate. Together, the five attack vectors generated $83 billion in data breach costs, growing at a +16% annual rate.

Data Breach Costs & Growth Rates

2024 Forecast: Data Breach Costs Accelerating to +19% from 2020-2023 +16% Pace

Given the relative shift and growth rate of the attack vectors analyzed, 2024 is forecast to have data breach costs of $27 billion, +19% over 2023. This marks an acceleration from the 2020-2023 baseline growth rate of +16% and stems primarily from Social Engineering & BEC expanding +56%. 

Apart from the continued steady supply of leaked PII from System Error & Accident and Credentials attack vectors, factors supporting further acceleration for the Social Engineering & BEC attack vector is the use of Artificial Intelligence to improve both the quality of phishing emails and the range of languages in which they will be delivered.

Reconciliation: Top-Down versus Bottom-Up Perspectives

There is admittedly a significant difference between the Statista cybercrime data series when compared with the IBM Security and Verizon data. The table below offers a summary of the difference between the top-down and bottom-up perspectives. Verizon comments that “the only certain thing about information security is that nothing is certain.” 

As such, trying to assess the extent of data breach costs is akin to looking at an iceberg where only a small portion is observable above the ocean’s surface. So, we look here for confirmation primarily that the growth rates are above that of the global economy and rising.

Conclusion: What To Do Now? Don’t Panic, Let’s Talk

At FYEO, we offer solutions for threat intelligence and password security that are decentralized, powered by AI and informed by our leaked credential database of over 27 billion records (and growing).

For example, as identity wallet use expands, the chance cybercriminals shift their focus to exploit potential vulnerabilities only grows, a development making the importance of identity protection even more paramount.

We have built a truly decentralized solution to combat this problem. Now in closed beta, FYEO Identity is a decentralized password manager that uses public/private key technology to help keep your credentials secure from bad actors with a real-time built-in Identity monitoring system that leverages FYEO's breach database of over 27 billion leaked emails & passwords.

Your keys, your data, for your eyes only (i.e. FYEO)!

Comments

All Comments

Recommended for you

  • BTC breaks through $69,000

     the market shows BTC breaking through $69,000, currently at $69,021.49, with a 24-hour increase of 1.15%. The market is highly volatile, please manage your risk accordingly.

  • Spanish Foreign Minister: Not worried about any consequences of refusing US access to military bases

     on March 3 local time, Spanish Foreign Minister Alvarez defended the Spanish government's refusal to provide the Rota and Moron military bases to the United States for participation in attacks on Iran. Alvarez stated that the operation initiated by the United States and Israel is not supported by the United Nations and is not part of the bilateral agreements allowing the use of the aforementioned Spanish sovereign military bases. Alvarez also said that the Spanish government is not concerned that this stance will have any consequences. Alvarez stated: "The position of the Spanish government represents the will of the vast majority of the Spanish people as well as the vast majority of people worldwide, which is to defend the UN Charter, respect international law, and believe that cooperation is always more powerful than confrontation."

  • Spot gold plunges nearly $100 in the short term.

     spot gold plunged nearly 100 dollars in a short time, spot gold fell below 5170 dollars/ounce, with a daily decline of 2.94%. 

  • BTC falls below $67,000

    the market shows BTC fell below $67,000, currently at $66,996.93, with a 24-hour increase of 1.18%. The market is highly volatile, please manage your risk accordingly.

  • ETH breaks $2,000

    the market shows ETH breaking through $2000, currently at $2001.64, with a 24-hour increase of 2.89%. The market is highly volatile, please manage your risks accordingly.

  • The US spot Bitcoin ETF saw a net inflow of $962.48 million yesterday.

    according to Trader T's monitoring, the US spot Bitcoin ETF had a net inflow of 962.48 million USD yesterday.

  • BTC falls below $66,000

     the market shows BTC fell below 66,000 USD, currently at 65,986.66 USD, with a 24-hour decline of 1.31%. The market is highly volatile, please manage your risks accordingly.

  • BTC falls below $66,000

     the market shows BTC fell below $66,000, currently at $65,973.16, a 24-hour drop of 2.66%. The market is highly volatile, please manage your risks accordingly.

  • ETH breaks $2,000

    market shows ETH breaking through $2000, currently at $2000.29, with a 24-hour increase of 3.73%. The market is volatile, please manage your risk accordingly.

  • The United States uses Anthropic's artificial intelligence technology in its airstrikes in the Middle East.

     United States used Anthropic's artificial intelligence technology in airstrikes in the Middle East, and just hours before the attack, Trump had just issued a ban against Anthropic.