Cyber Tips Cyber Insurance 101

The True Cost of the Underground Cyber Crime Economy

Cyber crime now costs the world an estimated $10.5 trillion a year, more than every economy except the US and China. Learn how the underground cyber crime economy operates and how individuals, businesses and governments can combat it and protect themselves.

Somewhere on the dark web right now, a stolen credit card number is selling for less than a cup of coffee. A stolen health record goes for nearly 20 times that. Behind those price tags is a global criminal economy that runs around the clock and crosses every border, profiting from ordinary people and businesses who never see it coming. 

Cybersecurity Ventures estimates cybercrime now costs the world $10.5 trillion a year, more than the economy of every country except the United States and China. The figure covers direct losses like stolen funds and fraud, plus the productivity and recovery costs that follow. 

The US isn’t insulated from this. The FBI’s Internet Crime Complaint Center logged $20.9 billion in reported cybercrime losses in 2025, and business email compromise alone cost American businesses $3.04 billion the same year.

How the Underground Cybercrime Economy Works Today

Launching a cyber attack used to require real technical skill. Not anymore. Experienced developers now build ransomware and phishing kits, then rent them out to less skilled criminals for a cut of the profits, a model known as cybercrime-as-a-service. The people running the attacks keep the bulk of what they steal, while the developers take a share, much like a franchise. It’s a business model as much as a crime, and it scales the same way any franchise does. 

That model has consolidated real power into a small number of dominant groups. The top 10 ransomware syndicates now account for 71% of all global victims, which means businesses and governments increasingly face fewer, but far more capable and well-resourced, adversaries. 

Part of what fuels this is sheer volume. In June 2026, security researchers uncovered a database of 24 billion stolen credentials, spanning everything from personal email to corporate logins, pulled together from years of infostealer malware. That’s the raw inventory criminals draw on to run credential stuffing at scale. 

Stolen data trades on the dark web like any other commodity, and the pricing reveals what criminals actually value. A stolen credit card number now sells for around $17. A stolen health record, which can’t simply be cancelled and reissued the way a card can, sells for closer to $300. 

That stolen data doesn’t stop working after the first use. Criminals run automated bots that test breached email and password combinations across hundreds of other sites, a technique called credential stuffing, turning one leaked password into dozens of compromised accounts. 

That’s not the only way stolen data keeps paying off. Some of it is being harvested under a strategy called steal-now-decrypt-later: criminals collect encrypted data today that they can’t read yet, betting that quantum computing will eventually be powerful enough to crack it open. 

The reported numbers likely understate the problem too. Reported US losses for the top fraud categories total around $13 billion, but the true figure is likely closer to $95 billion once underreporting is factored in, according to the Consumer Federation of America.

How Social Engineering and Phishing Exploit Human Trust

A growing share of cybercrime doesn’t rely on breaking through a firewall at all. Verizon’s 2026 Data Breach Investigations Report found the human element, whether by mistake or manipulation, is a factor in 62% of breaches. 

Phishing casts a wide net with mass, generic emails designed to harvest login credentials. The new kind of “relationship based” social engineering is more deliberate: criminals research a specific target and use what they find, like a job title or a colleague’s name, to manipulate someone into breaking a normal security step. 

Both rely on the same shortcut: urgency. A message that demands action right now gives someone less time to stop and check whether it’s real, which is exactly the point. 

AI has only sharpened this tactic, making deepfake and AI-driven fraud convincing enough to fool even careful employees. In the US, 86% of business leaders with cybersecurity responsibilities reported at least one AI-related incident in the past 12 months, according to Cisco’s 2025 Cybersecurity Readiness Index.

What Individuals Can Do to Protect Themselves from Cybercrime

  • Secure your network and devices: change default router passwords, turn on WPA3 encryption, keep firmware updated, put smart devices on a separate guest network and turn on multi-factor authentication wherever it’s offered. 
  • Watch for early warning signs: freeze your credit if your data’s been exposed, and check bank statements for small test transactions criminals use to verify a stolen card still works. 
  • Use a password manager and MFA: unique, complex passwords for every account close off the credential-stuffing problem almost entirely. Adding multi-factor authentication (MFA) also decreases the risk of fraudulent logins. 
  • Report online fraud: reporting to the police and the FBI’s Internet Crime Complaint Center (IC3) helps investigators track patterns and occasionally recover funds before they disappear.

BOXX is here to help individuals and households stay safe online. Cyberboxx® Home combines all-in-one insurance with always-on Cyberboxx® Assist preventive services, including dark web and credit monitoring that alerts individuals to signs of stolen credentials, identity theft and fraud. Access to the BOXX Hackbusters® breach response team also means individuals and families have a real human expert to call when they think something’s gone wrong. 

How Businesses Can Build Stronger Cyber Defences 

When one compromised employee account or third-party vulnerability can shut down an entire network, the stakes are too high to ignore. 

Business email compromise remains one of the costliest threats American businesses face. It targets executive email accounts to request fraudulent wire transfers, often showing up as invoice fraud, and it’s most effectively stopped with a simple rule: verify any unexpected payment request through a second channel before it’s approved. 

Multi-factor authentication is a close second. Even a successfully phished password isn’t enough on its own if an account also requires a second factor, ideally an app-based authenticator or a hardware key rather than a text message code. 

Regular phishing simulations and security awareness training make a measurable difference too. Ongoing training cuts phishing click rates by 86% within a year, according to KnowBe4’s 2025 benchmarking report. Staff trained to notice a spoofed domain or an unusual billing request become a company’s strongest line of defence. 

This is exactly where modern cyber insurance and built-in preventive tools earn its keep. Cyberboxx® Business combines insurance coverage with always-on security services, built to help a business predict, prevent, respond to and recover from these threats. 

BOXX specifically covers AI and deepfake-related events, addressing exactly the kind of AI-driven social engineering criminals increasingly rely on. 

Through Cyberboxx® Assist, included in every Cyberboxx® Business policy, continuous attack surface scanning flags vulnerabilities across a company’s public-facing systems before a criminal finds them first. Dark web monitoring works the same idea in reverse, scanning the same underground marketplaces and credential dumps criminals use, essentially seeing what hackers see about your business and your vendors, so a business can act fast and protect itself and its supply chain. 

When something does get through, the BOXX Hackbusters® breach response team is available 24/7, no claim required first. A virtual Chief Information Security Officer is also available, giving businesses ongoing security guidance without the cost of hiring one full-time.

How Governments Can Combat the Underground Cybercrime Economy

Cybercrime crosses borders by design, which limits what any individual or business can do alone. Governments and industry play a key role in keeping everyone safe online. 

Public-private partnerships give investigators a head start. Tech companies and internet providers often spot new malware and botnet activity before anyone else. Sharing that intelligence with law enforcement in real time helps freeze stolen funds before they move through crypto exchanges. 

Governments are also funding earlier digital literacy education and pushing for stronger cross-border cooperation, since many of these operations run from jurisdictions with little incentive to prosecute them. 

More is needed than what’s currently in motion. Mandatory incident reporting would close the gap between what’s actually happening and what gets recorded, given reported losses likely understate the true scale by a factor of seven or more, according to the Consumer Federation of America. Faster extradition agreements and harmonized cybercrime laws would also make it harder for criminals to keep operating out of jurisdictions that simply look the other way. 

None of this moves quickly. Treaties take years to negotiate and cybercrime units are often outpaced by the criminals they’re chasing. That’s part of why the burden still falls so heavily on individuals and businesses to protect themselves. 

How Businesses and Individuals Can Combat Cybercrime

Cybercrime depends on trust that goes unchecked. A fake email that looks real or a call that sounds legitimate is often all it takes and criminals are counting on people not stopping to check. 

Better cyber hygiene habits and stronger security defences help close the gap. So does preventive insurance and protection services built for how these threats evolve. 

Fighting back at home, at work and across borders is how the whole cybercrime economy becomes harder to run. 

Latest posts

Cyber Tips Cyber Insurance 101
The True Cost of the Underground Cyber Crime Economy

The True Cost of the Underground Cyber Crime Economy

Cyber crime now costs the world an estimated $10.5 trillion a year, more than every economy except the US and China. Learn how the underground cyber crime economy operates and how individuals, businesses and governments can combat it and protect themselves.

Cyber Tales
Cyber Tales: Can I Buy a Vowel for $50K?

Cyber Tales: Can I Buy a Vowel for $50K?

A business nearly lost $50,000 because of a single missing letter in an email – proving that tiny mistakes can have huge consequences.

Cyber Tips Cyber Insurance 101
Why American Small Businesses Need to Buy Cyber Insurance

Why American Small Businesses Need to Buy Cyber Insurance

Only 17% of US small businesses carry cyber insurance, even though nearly half face an attack every year. Here’s why getting modern cyber insurance matters and how it helps small businesses predict, prevent, respond to and recover from cyber threats.

Sign up for the BOXX Insurance Newsletter

Get the latest updates about Cyber Insurance and Protection with our newsletter.