Verizon report: the median loss from business email compromise in recent years is $50K and the median ransomware damage over the past two years doubled to $26K
A smorgasbord of data in Verizon's annual breach report — When a vulnerability in the ubiquitous open-source tool log4j …
Context & Ripple Effects
Verizon’s figures add a median-loss lens to earlier coverage that showed business email compromise accounting for roughly half of estimated cybercrime losses in an FBI-reported 2019 loss tally. They also distinguish ransomware damage from ransom payments, after reporting had documented a sharp rise in ransomware payment levels in 2021.
The report matters because it puts two common business attack types on comparable, business-level loss measures: $50K for business email compromise and $26K for ransomware damage. The doubling in ransomware damage suggests that operational consequences remain material even when the reported median is below prior payment-focused estimates.
First-order effects
- Businesses gain a current benchmark for prioritizing controls around payment fraud and ransomware recovery: the reported median loss is $50K for business email compromise, while median ransomware damage reached $26K after doubling over two years.
- Security leaders and insurers must separate ransomware’s total business damage from the ransom itself; the report’s damage metric is not directly comparable with payment-only surveys.
Second-order effects
- Email-security, identity, and payment-verification vendors have a clearer case to position their products against business email compromise losses, while backup, recovery, and incident-response providers can point to the rising cost of ransomware disruption.
- Organizations may put more emphasis on limiting blast radius and restoring operations, rather than treating ransomware solely as a negotiation or payment decision; earlier survey evidence that many organizations had been hit reinforces that exposure is broad across surveyed organizations.
Third-order effects
- If loss measures become more consistently reported, cyber-risk decisions may shift from headline ransom amounts toward comparable measures of operational and fraud impact across attack types.
- The pattern supports a broader move toward evidence-based cyber-risk reporting, though differences in incident definitions and measurement methods will continue to limit direct comparisons between reports.
The trend: Cybersecurity reporting is moving from attack counts and ransom headlines toward business-impact metrics that guide resilience, fraud prevention, and risk-transfer decisions.