Industry & Risk

Small Business Cyber Attack Statistics You Can Trust (2026)

Search for cyber risk numbers and you’ll meet the same one within about thirty seconds. Sixty percent of small businesses close within six months of a cyberattack. It turns up in vendor decks, news stories, government slides, and probably an email that landed in your inbox this month.

Here’s the awkward part. Nobody can point to the study.

That matters, because you’re most likely reading numbers like these to make a real decision about real money. So this page works a little differently. Every figure below carries a name and a year, and where the data is thin or argued over, we say so out loud. The good news is that the honest small business cyber attack statistics are useful enough on their own. They just tell a calmer story than the scary one.

What the credible data shows is a risk that’s common but survivable. The typical insured loss lands in the low six figures, not the millions, and most of the financial pain traces back to two unglamorous things: stolen email credentials and wire transfers that go to the wrong account.

Document with a checkmark and an X beside a shield

The statistic almost everyone repeats

Start with the one you’ve already seen, because you deserve to know why it isn’t in the rest of this article.

The claim that 60 percent of small businesses shut down within six months of an attack has been circulating since roughly 2011. It’s usually attributed to the National Cybersecurity Alliance. The Alliance has publicly said it did not produce that number and cannot verify where it came from, and it stopped using the figure in its own materials.

A closure rate that high would be one of the best documented facts in the insurance industry, tracked by every carrier and regulator in the country. Instead there’s no study underneath it.

None of that makes small business cyber risk imaginary. It just means you don’t need a made up number to justify taking it seriously.

The Alliance’s own statement on the statistic is worth two minutes if you’ve ever quoted it in a board meeting.

How often small businesses actually get attacked

Three sources carry most of the weight here, and they measure different things, which is exactly why it helps to look at all three.

Verizon’s 2026 Data Breach Investigations Report analyzed more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries, covering incidents from November 2024 through October 2025. Ransomware showed up in 48 percent of breaches. Breaches involving an organization’s supply chain rose 60 percent, and a third party now features in 48 percent of breaches, which is a quiet warning for any small business that leans on outside vendors for payroll, bookkeeping, or IT.

The FBI’s Internet Crime Complaint Center logged more than a million complaints in 2025 and $20.9 billion in reported losses, a 26 percent jump over the prior year. Ransomware complaints reached 3,611, up from 3,156 in 2024 and 2,825 in 2023. Bear in mind this is complaint data, so it only counts what people bothered to report.

Coalition, a cyber insurer with more than 100,000 policyholders skewed heavily toward small and midsize businesses, reported a claims rate of 1.54 percent for 2025. That’s arguably the most honest “how likely is this” number available to a small business owner, because it has a real denominator. Every policyholder is counted, not just the ones who answered a survey.

You’ll also see survey figures claiming anywhere from 40 to 80 percent of small businesses were attacked in a given year. Those swing that wildly because they depend on who was asked and on what each respondent counted as an attack. A blocked phishing email is not the same event as a locked server, but both get reported as “we were attacked.”

Figure Number Source and period
Breaches involving ransomware 48% Verizon DBIR 2026 (Nov 2024 to Oct 2025)
Reported US cybercrime losses $20.9 billion FBI IC3, 2025
Business email compromise losses $3.05 billion FBI IC3, 2025
Cyber insurance claims rate 1.54% Coalition, 2025 policy year
Average paid cyber claim $116,000 Coalition, 2025
Small storefront under a soft shield beside simple chart bars

Small business cyber attack statistics on cost and claims

This is where the picture sharpens, because insurance claims data tells you what incidents actually cost after the dust settles, not what a worst case scenario might theoretically run. Most small business cyber attack statistics you’ll find online skip this part, which is a shame, since it’s the part that maps to your bank account.

Coalition’s 2026 claims report, covering 2025, found the average paid claim fell 19 percent to $116,000. Ransomware was the most expensive category at an average loss of $269,000. Funds transfer fraud averaged $141,000, with frequency down 18 percent year over year.

Two numbers in that report deserve more attention than they usually get. Business email compromise and funds transfer fraud together accounted for 58 percent of incidents, so the majority of what actually happens to small businesses is a fake invoice or a redirected payment, not a dramatic hostage situation. Picture a bookkeeper at a twelve person contracting firm paying a supplier she’s paid every month for four years. This month the email says the bank details changed. It comes from the supplier’s real address, because someone got into that mailbox weeks ago and has been reading the thread. The money leaves on a Friday. Nobody notices until the supplier calls about a missed payment. And 64 percent of closed claims ended with no out of pocket loss for the policyholder, with $21.8 million in stolen funds clawed back over the year.

Ransom demands went the other direction. Initial demands surged 47 percent in 2025. But a record 86 percent of businesses refused to pay, which suggests backups and response plans are working better than they used to. Our guide to what ransomware insurance covers gets into where the money actually goes when a business says no.

Bar chart of average cyber insurance claim in 2025 by incident type

Then there’s the number you’ve seen in headlines. IBM’s 2026 Cost of a Data Breach Report put the global average breach at a record $4.99 million, and the US average at $11.5 million. Please read that carefully. That sample skews heavily toward large enterprises, and IBM’s last published breakout by organization size was back in 2023, which put companies under 500 employees at $3.31 million. That figure is now several years stale. If someone quotes you a multi million dollar average and implies it applies to a ten person shop, they’re stretching it.

If you’re trying to line these losses up against what coverage would actually cost you, our breakdown of cyber insurance costs in 2026 has current ranges by business size and industry, and you can request a free quote from that page.

How attackers get in

The 2026 DBIR breaks identity related initial access into three buckets: phishing at 16 percent, credential abuse at 13 percent, and pretexting at 6 percent. Compromised credentials were an initial access vector in 22 percent of breaches reviewed.

Put plainly, email and passwords are the front door. Not zero day exploits, not movie style hacking. Someone gets a login, or someone gets talked into changing a bank account on an invoice.

Envelope with a hook held back by a cyan shield

Artificial intelligence is showing up in the data now, though not quite the way the marketing suggests. Verizon found that 44 percent of AI assisted initial access techniques were phishing related, while noting that phishing’s overall share barely moved year over year. The reasonable read is that AI is raising the floor on how convincing a scam email looks, rather than blowing past defenses that already work. IBM separately put about one in four malicious breaches as AI involved, averaging near $6 million, again in an enterprise heavy sample.

This is also why insurers ask what they ask. Multifactor authentication, endpoint detection, and tested backups map directly onto the ways businesses actually get hit. If you’re wondering what a carrier will want to see before it quotes you, the controls insurers require in 2026 covers the whole list.

How many small businesses actually carry coverage

Roughly 17 percent of US small businesses hold a cyber policy. About 64 percent say they aren’t familiar with cyber insurance at all, and 48 percent of buyers only bought it after an incident had already happened to them.

That gap is closing slowly. Through April 2026, cyber insurance applications ran 18.5 percent ahead of the prior year and completed purchases were up 17.9 percent.

For context on the money involved, the median small business premium sits near $1,740 a year, or about $145 a month, for a typical policy. Set that beside a $116,000 average claim and the math is at least worth checking for your own situation. If you’re starting from scratch, our complete small business guide is the place to begin, and what cyber insurance actually covers explains the pieces of a policy in plain language.

Business owner standing beside a shield with a checkmark

How to read a cyber statistic without getting fooled

You’re going to keep running into small business cyber attack statistics, in sales emails, in trade press, in your accountant’s newsletter. Five quick checks will save you from most of the bad ones.

Find the primary source, not the blog that quoted it. If a statistic only ever links to another article, and that article links to a third, and none of them reach an actual report, treat it as folklore.

Check when the data was collected, not when the article was published. A piece dated 2026 can easily be recycling a 2019 survey. The DBIR is a good habit here, since it states its collection window plainly.

Ask who’s in the sample. IBM’s breach costs come mostly from large organizations. An insurer’s claims data comes mostly from small ones. Neither is wrong. They’re answering different questions.

Separate surveys from claims. Surveys measure what people say happened. Claims measure what an insurer paid. When the two disagree, the claims number is usually closer to your reality.

Be suspicious of round, dramatic, unchanging numbers. Real data moves. A statistic that’s been exactly 60 percent for fifteen years isn’t a measurement, it’s a slogan.

Key takeaways

  • The famous claim that 60 percent of small businesses close within six months of an attack has no verifiable source, and the group most often credited with it has disowned it.
  • Ransomware appeared in 48 percent of breaches in Verizon’s 2026 report, and US cybercrime losses reported to the FBI hit $20.9 billion in 2025.
  • The average paid cyber claim was $116,000 in 2025, down 19 percent, with ransomware averaging $269,000 and funds transfer fraud $141,000.
  • Business email compromise and funds transfer fraud made up 58 percent of incidents, so email and payments are where most small business losses start.
  • Only about 17 percent of US small businesses carry cyber insurance, while the median premium sits near $1,740 a year.
  • Multi million dollar breach averages come from enterprise heavy samples and don’t describe a small business incident.

Frequently asked questions

What percentage of cyberattacks target small businesses?

You’ll see figures from 40 to 80 percent, and honestly none of them are solid, because “attack” means different things in different surveys and small businesses underreport. The more useful number is Coalition’s 2025 claims rate of 1.54 percent, which tells you how many insured businesses actually filed a claim in a year.

How much does a cyberattack cost a small business?

Based on 2025 insurance claims, the average paid claim was $116,000. Ransomware events averaged $269,000 and funds transfer fraud averaged $141,000. Headline figures in the millions come from enterprise breach studies and don’t reflect a typical small business event.

Is it true that most small businesses close after a cyberattack?

There’s no credible evidence for it. The widely quoted 60 percent closure claim has no traceable study behind it. Attacks are expensive and disruptive, but the data doesn’t support the idea that most affected businesses fold.

What’s the most common type of cyber incident for a small business?

Email based fraud. Business email compromise and funds transfer fraud together accounted for 58 percent of the incidents Coalition observed in 2025. Ransomware gets the headlines, but a redirected invoice payment is far more likely to be what hits you.

Where can I find trustworthy cyber attack statistics?

Start with the Verizon Data Breach Investigations Report, the FBI’s annual Internet Crime Report, IBM’s Cost of a Data Breach study, and the claims reports insurers publish each spring. Each states its methodology, so you can see what’s being measured. If a statistic can’t be traced to something like these, skip it. Our cyber insurance glossary is handy for decoding the terms these reports use.

General information only, not legal, financial, or insurance advice. Cyber Insurance 101 is an independent information site, not an insurance carrier or a licensed agency. Coverage terms vary by policy and insurer. Any figures cited were accurate on the publish date and can change.

Leave a comment

Your email address will not be published. Required fields are marked *

๐Ÿ“ž Call Now Free Quote