06/12/2026
$20 billion. That's how much cybercrime cost organizations in 2025. π¨
And that's just what was reported.
The numbers behind that figure are worth slowing down on. Business email compromise accounted for over $3 billion in losses. Cryptocurrency investment scams hit $7.2 billion. 63 new ransomware variants identified in a single year, averaging more than five new variants every month, hitting healthcare, manufacturing, and government the hardest.
But the stat that should stop every compliance and security team cold is this one. π
22,000+ complaints referencing AI. $893 million in losses tied directly to it.
For the first time, there's documented, quantified evidence of cybercriminals using AI to run fraud at scale. Convincing phishing emails that pass every filter. Synthetic executive video authorizing wire transfers. Voice cloning that sounds exactly like the person you trust most.
The tells employees were trained to spot no longer work. Not because the training was wrong. Because the technology moved faster than anyone expected it to. β οΈ
For organizations going through SOC 2, ISO 27001, or any resilience focused assessment right now, this matters. The control environment being evaluated today needs to account for a threat landscape that looks meaningfully different than it did two years ago.
The data is in. The question is whether the controls are keeping up.
Source: FBI 2025 IC3 Annual Report.