Cyber crime now costs the world an estimated $10.5 trillion a year, more than every economy except the US and China. Learn how the underground cyber crime economy operates and how individuals, businesses and governments can combat it and protect themselves.
Somewhere on the dark web right now, a stolen credit card number is selling for less than a cup of coffee. A stolen health record goes for nearly 20 times that. Behind those price tags is a global criminal economy that runs around the clock and crosses every border, profiting from ordinary people and businesses who never see it coming.
Cybersecurity Ventures estimates cyber crime now costs the world $10.5 trillion a year, more than the economy of every country except the United States and China. The figure covers direct losses like stolen funds and fraud, plus the productivity and recovery costs that follow.
Canada isn’t insulated from this. Canadians reported $704 million in fraud losses to the Canadian Anti-Fraud Centre (CAFC) in 2025, and Canadian businesses spent $1.2 billion recovering from cyber incidents in 2023 alone.
Launching a cyber attack used to require real technical skills. Not anymore. Experienced developers now build ransomware and phishing kits, then rent them out to less skilled criminals for a cut of the profits, a model known as cyber crime-as-a-service. The people running the attacks keep the bulk of what they steal, while the developers take a share, much like a franchise. It’s a business model as much as a crime, and it scales the same way any franchise does.
That model has consolidated real power into a small number of dominant groups. The top 10 ransomware syndicates now account for 71% of all global victims, which means businesses and governments increasingly face fewer, but far more capable and well-resourced, adversaries.
Part of what fuels this is sheer volume. In June 2026, security researchers uncovered a database of 24 billion stolen credentials, spanning everything from personal email to corporate logins, pulled together from years of infostealer malware. That’s the raw inventory criminals draw on to run credential stuffing at scale.
Stolen data trades on the dark web like any other commodity, and the pricing reveals what criminals actually value. A stolen credit card number now sells for around $17. A stolen health record, which can’t simply be cancelled and reissued the way a card can, sells for closer to $300.
That stolen data doesn’t stop working after the first use. Criminals run automated bots that test breached email and password combinations across hundreds of other sites, a technique called credential stuffing, turning one leaked password into dozens of compromised accounts.
That’s not the only way stolen data keeps paying off. Some of it is being harvested under a strategy called steal-now-decrypt-later: criminals collect encrypted data today that they can’t read yet, betting that quantum computing will eventually be powerful enough to crack it open.
The reported numbers likely understate the problem too. The CAFC estimates only 5% to 10% of fraud victims ever file a report, which means the true scale of losses in Canada each year could run several times higher than what shows up in official statistics.
A growing share of cyber crime doesn’t rely on breaking through a firewall at all. Verizon’s 2026 Data Breach Investigations Report found the human element, whether by mistake or manipulation, is a factor in 62% of breaches.
Phishing casts a wide net with mass, generic emails designed to harvest login credentials. The new kind of “relationship based” social engineering is more deliberate: criminals research a specific target and use what they find, like a job title or a colleague’s name, to manipulate someone into breaking a normal security step.
Both rely on the same shortcut: urgency. A message that demands action right now gives someone less time to stop and check whether it’s real, which is exactly the point.
AI has only sharpened this tactic, making convincing enough to fool even careful employees. In Canada, 81% of businesses that faced fraud last year also faced an AI-enabled attack, according to KPMG.
BOXX is here to help individuals and households stay safe online. Cyberboxx® Home combines all-in-one insurance with always-on Cyberboxx® Assist preventive services, including dark web and credit monitoring that alerts individuals to signs of stolen credentials, identity theft and fraud. Access to the BOXX Hackbusters® breach response team also means individuals and families have a real human expert to call when they think something’s gone wrong.
When one compromised employee account or third-party vulnerability can shut down an entire network, the stakes are too high to ignore.
Business email compromise remains one of the costliest threats Canadian businesses face. It targets executive email accounts to request fraudulent wire transfers, often showing up as invoice fraud, and it’s most effectively stopped with a simple rule: verify any unexpected payment request through a second channel before it’s approved.
Multi-factor authentication is a close second. Even a successfully phished password isn’t enough on its own if an account also requires a second factor, ideally an app-based authenticator or a hardware key rather than a text message code.
Regular phishing simulations and security awareness training make a measurable difference too. Ongoing training cuts phishing click rates by 86% within a year, according to KnowBe4’s 2025 benchmarking report. Staff trained to notice a spoofed domain or an unusual billing request become a company’s strongest line of defence.
This is exactly where modern cyber insurance and built-in preventive tools earn its keep. Cyberboxx® Business combines insurance coverage with always-on security services, built to help a business predict, prevent, respond to and recover from these threats.
BOXX specifically covers AI and deepfake-related events, addressing exactly the kind of AI-driven social engineering criminals increasingly rely on.
Through Cyberboxx® Assist, included in every Cyberboxx® Business policy, continuous attack surface scanning flags vulnerabilities across a company’s public-facing systems before a criminal finds them first. Dark web monitoring works the same idea in reverse, scanning the same underground marketplaces and credential dumps criminals use, essentially seeing what hackers see about your business and your vendors, so a business can act fast and protect itself and its supply chain.
When something does get through, the BOXX Hackbusters® breach response team is available 24/7, no claim required first. A virtual Chief Information Security Officer is also available, giving businesses ongoing security guidance without the cost of hiring one full-time.
Cyber crime crosses borders by design, which limits what any individual or business can do alone. Governments and industry play a key role in keeping everyone safe online.
Public-private partnerships give investigators a head start. Tech companies and internet providers often spot new malware and botnet activity before anyone else. Sharing that intelligence with law enforcement in real time helps freeze stolen funds before they move through crypto exchanges.
Governments are also funding earlier digital literacy education and pushing for stronger cross-border cooperation, since many of these operations run from jurisdictions with little incentive to prosecute them.
More is needed than what’s currently in motion. Mandatory incident reporting would close the gap between what’s actually happening and what gets recorded, given only 5% to 10% of fraud victims file a report today, according to the CAFC. Faster extradition agreements and harmonized cyber crime laws would also make it harder for criminals to keep operating out of jurisdictions that simply look the other way.
None of this moves quickly. Treaties take years to negotiate and cyber crime units are often outpaced by the criminals they’re chasing. That’s part of why the burden still falls so heavily on individuals and businesses to protect themselves.
Cyber crime depends on trust that goes unchecked. A fake email that looks real or a call that sounds legitimate is often all it takes and criminals are counting on people not stopping to check.
Better cyber hygiene habits and stronger security defences help close the gap. So does preventive insurance and protection services built for how these threats evolve.
Fighting back at home, at work and across borders is how the whole cyber crime economy becomes harder to run.
Get the latest updates about Cyber Insurance and Protection with our newsletter.