Cyber Attack Statistics

244 STATS54 SOURCES

Latest Statistics

National security organizations faced an average of 137 attempted or successful cyberattacks per week in 2025, up from 127 cyberattacks per week in 2024.

EverfoxCYBER360: Defending the Digital Battlespace·Feb 10, 2026
National SecurityCyber Attack

Cyberattacks against agencies in the U.S. have surged 25% in the last year and occur more frequently on a weekly basis than in the UK.

EverfoxCYBER360: Defending the Digital Battlespace·Feb 10, 2026
National SecurityCyber AttackUSUK

Web applications are the most attacked service type at 61%, up from 41% in 2024; remote management protocols account for 15%.

Forescout Technologies Inc2025 Threat Roundup·Jan 29, 2026
Application SecurityRemote ManagementCyber Attacks

72% of CISOs agreed that their role has evolved to include leading their organization’s ability to recover continuity following a cyberattack or security incident.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryCyber IncidentCISOUKUS

In 2025, 57% of CISOs reported that their organizations took more than 4.5 days on average for full remediation and recovery after a cyber incident.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryIncident RemediationCyber IncidentUSUK

In 2025, not a single Chief Information Security Officer (CISO) reported being able to recover from a cyber incident within a day.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryCyber IncidentUSUK

In 2025, 19% of CISOs indicated that recovery efforts from cyber incidents extended as long as two weeks.

Absolute SecurityThe Resilient CISO: The State of Enterprise Cyber Resilience·Jan 8, 2026
Incident RecoveryCyber IncidentUSUK

48% of New Yorkers stated they have been the victim of a cyberattack at least once.

CommvaultSurvey: New Yorkers Demand Businesses Prioritize the Security and Resilience of Their Data – And are Penalizing Those that Don’t ·Dec 17, 2025
Cyber AttackConsumerUSNew York

43% of SMBs report they experienced a cyberattack in the past 5 years.

GuardzThe 2025 SMB Cybersecurity Survey ·Dec 17, 2025
SMBsUSCyber Attack

89% of schools experienced at least one cyber incident in the past year, primarily phishing, unauthorized access, and malware.

Action1Action1 Cybersecurity in Education Report 2025–2026·Dec 17, 2025
Cyber IncidentEducationPhishingUnauthorized AccessMalware

27% of SMBs said they were targeted in the past 12 months.

GuardzThe 2025 SMB Cybersecurity Survey ·Dec 17, 2025
SMBsUSCyber Attack

64% of SMB owners reportedly recovered quickly from a cyber attack.

GuardzThe 2025 SMB Cybersecurity Survey ·Dec 17, 2025
SMBsUSCyber AttackCyber Attack Recovery

3% of SMB owners faced severe, lasting damage following a cyber attack.

GuardzThe 2025 SMB Cybersecurity Survey ·Dec 17, 2025
SMBsUSCyber AttackCyber Attack Consequences

99% of organizations experienced at least one attack on their AI systems in the past year.

Palo Alto NetworksThe State of Cloud Security Report 2025·Dec 16, 2025
AI systemsCyber attack

83% of US organizations reported a rise in cyberattacks.

KPMG2025 KPMG Cybersecurity Survey ·Dec 15, 2025
Cyber attacksUS

47% of CISOs report being completely confident that AI-powered security tools can effectively defend against autonomous, AI-driven cyberattacks.

TrellixThe Mind of the CISO ·Dec 11, 2025
CISOAI DefenseAI-driven Cyberattacks

70% of organizations experienced at least one material third-party cyber incident in the past year.

MarshCyber catalyst report: Guiding priorities in cyber investments ·Dec 9, 2025
Third-Party RiskThird-Party Cyber Incident

Resilience Scores among organizations have remained statistically flat since 2023, with an average decline of 3%.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulationResilience

Senior participation in AI-scenario labs dropped by 14% year over year.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulationAI-scenario labsSenior leadership

Only 41% of organizations include non-technical roles in cyber incident simulations.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulation

60% of all cyber training focuses on vulnerabilities that are more than two years old.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulationVulnerabilities

The average containment time for simulated cyber attacks is 29 hours.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulationContainment

94% of organizations globally believe they are prepared for a major cyber incident.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulationPreparadness

Decision accuracy among teams responding to cyber incidents is only 22%.

Immersive2025 Cyber Workforce Benchmark Report ·Nov 17, 2025
Cybersecurity trainingCyber incident simulation

58% of IT and security leaders believe it would take at least two days to recover and achieve full-service operations post-compromise

Rubrik Zero LabsIdentity Crisis: Understanding & Building Resilience Against Identity-Driven Threats·Nov 13, 2025
Cyber attack consequences

In 2025, only 28% of IT and security leaders believed they could fully recover from a cyber incident in 12 hours or less, down from 43% in 2024

Rubrik Zero LabsIdentity Crisis: Understanding & Building Resilience Against Identity-Driven Threats·Nov 13, 2025
Cyber attack consequencesRecovery

44% of retailers reported experiencing a significantly higher volume of attacks in 2025.

LevelBlueBuild Cyber Resilience for a Stronger Retail Future·Nov 12, 2025
RetailCyber attacks

92% of organizations reported experiencing legal, regulatory, or compliance consequences, including fines, lawsuits, or other enforcement actions.

CohesityRisk-Ready or Risk-Exposed: The Cyber Resilience Divide·Nov 10, 2025
Cyber attack consequences

76% of organizations have experienced at least one material cyberattack.

CohesityRisk-Ready or Risk-Exposed: The Cyber Resilience Divide·Nov 10, 2025
Cyber attack consequences

70% of publicly traded companies reported adjusting earnings or financial guidance after a cyberattack.

CohesityRisk-Ready or Risk-Exposed: The Cyber Resilience Divide·Nov 10, 2025
Cyber attack consequences

68% of publicly traded companies said they observed an impact on their stock price after a cyberattack.

CohesityRisk-Ready or Risk-Exposed: The Cyber Resilience Divide·Nov 10, 2025
Cyber attack consequences

73% of privately held firms redirected budgets from innovation and growth initiatives after a cyberattack.

CohesityRisk-Ready or Risk-Exposed: The Cyber Resilience Divide·Nov 10, 2025
Cyber attack consequences

38% of all reported cyber incidents in the EU in 2024 targeted the public administration sector.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Cyber incidentPublic AdministrationEurope

Cybercrime operators accounted for approximately 16% of cyber incidents in the EU in 2024.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Cyber incidentCybercrime operatorEurope

Cyberespionage campaigns constituted 2.5% of all reported cyber incidents in the EU in 2024.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Cyber incidentCyberespionageEurope

Data breaches accounted for 17.4% of cyber incidents affecting public administration in the EU in 2024.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Data breachCyber incidentPublic AdministrationEurope

69% of cyber incidents in 2024 targeted central governments in the EU.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Cyber incidentCentral governmentEurope

60% of all reported cyber incidents in 2024 were Distributed Denial-of-Service (DDoS) attacks.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Cyber incidentDDoSEurope

Hacktivists were responsible for nearly 63% of cyber incidents in the EU in 2024.

ENISAENISA Sectorial Threat Landscape - Public Administration ·Nov 6, 2025
Cyber incidentHacktivismEurope

13% of CISOs oversee 50 or more security tools.

Nagomi Security2025 CISO Pressure Index,·Nov 5, 2025
Cyber incidentCISOUSSecurity tools