Archive for July 29, 2026

FCC blocks new foreign-made robots over security risks

Posted in Commentary with tags on July 29, 2026 by itnerd

The FCC has added foreign-produced advanced robotic devices to its Covered List, preventing new models from receiving the equipment authorization required for importation, marketing and sale in the U.S. The action follows national security determinations that the products pose unacceptable supply chain and cybersecurity risks.

According to the FCC, network-connected robots could be exploited to manipulate physical operations, collect sensitive data, conduct surveillance or be remotely commandeered, while connected power inverters could create vulnerabilities affecting critical infrastructure.

The restrictions apply only to new device models and do not affect previously authorized products already in the U.S. market.

Matt Wyckhouse. Founder & CEO, Finite State:

“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.

“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“Taken together with recent guidance from the Five Eyes and other federal agencies, this decision reflects a growing emphasis on the cybersecurity of cyber-physical systems and the resilience of the critical infrastructure that depends on them. We should pay close attention to these signals. They are likely indicative of how governments assess the evolving threat environment and where they see strategic risk increasing.

“Industrial robots are increasingly more than just machines, they are connected computers capable of sensing, deciding, and acting in the physical world. Many of today’s advanced robots have significant operational dependencies on cloud connectivity, AI services, remote management, identity systems, and vendor-operated infrastructure. The security question is not simply whether someone can hack the robot; it’s also what happens if the cloud, the vendor, or the communications path the robot depends on is compromised or unavailable.”

Seemant Sehgal, Founder & CEO, BreachLock:

“The FCC drew a line at the import stage, which is the wrong place to draw it if the goal is reducing risk. There are already authorized devices operating in U.S. networks that carry the same trust relationships, the same firmware update dependencies, and the same remote access capabilities as anything on the new restricted list. Blocking future imports without a plan for what is already inside the perimeter is a procurement policy dressed up as a security measure.”

John Strand, Owner, Black Hills Information Security, Inc.:

“I think these technology-specific bans feel very arbitrary. The security concerns people raise about robotics are the same concerns we’ve had with automobiles, drones, industrial control systems, smartphones, and just about every other connected technology. If it has software, it will have vulnerabilities. That’s simply the reality of modern computing.

“If the standard is that a technology could someday be exploited by a foreign adversary, then almost every technology would qualify. That’s why these policies can feel less like a coherent cybersecurity strategy and more like market protectionism wrapped in the language of national security. The focus should be on building resilient systems, validating software and hardware, and reducing risk regardless of who manufactures the technology, instead of singling out one category while ignoring the fact that the same security challenges exist across the entire technology ecosystem.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

“Nation-state attackers have spent a decade moving up the supply chain. Software exploits get patched. Firmware backdoors get caught in audits. Hardware is where verification breaks down, because you cannot audit a fabrication line you do not control.

“That is the security argument behind the FCC adding foreign-produced robots and power inverters to its Covered List this week. Network-connected humanoid robots carry cameras, LiDAR, and persistent connectivity. Inverters sit between solar panels, batteries, data center equipment, and the grid. Both create attack surface that defenders can monitor but cannot fully inspect when the hardware ships from a geopolitical competitor.

“I’ve done enough embedded-device assessments to know that firmware review catches what you can reach, and on hardware imported from an adversary nation, there are layers you simply cannot reach. Software backdoors exist in every copy, find one and you’ve found them all. Hardware is different.

“One unit gets pulled off the line or intercepted in shipping, altered with a modified chip, and put back. Intelligence agencies, including ours, have been doing this for years. You can tear down a sample unit, certify it clean, and have no way of knowing the next unit off the same line hasn’t been touched.

“The FCC has banned three product categories in seven months using the same Secure Networks Act written in 2019 for Huawei and ZTE. Drones in December, routers in March, now robots and power inverters. A White House interagency body issues a National Security Determination, the FCC updates its list, and the ban takes effect without new legislation.

“Watch the Conditional Approval list over the next 90 days. Fifteen non-Chinese UAS vendors cleared approval within months of the drones ban. Netgear and eero passed the router review within a month. Zero Chinese manufacturers have received approval in either category, and that ratio will hold for robots and inverters.”

For the record, China has reacted negatively to this and it sounds like they’re going to retaliate. Therefore it is unlikely that this is over.

Secure.com Names Cybersecurity Veteran Nicholette Brown Hill as Founding General Manager, Americas

Posted in Commentary with tags on July 29, 2026 by itnerd

Secure.com today announced that Nicholette Brown Hill has been named Founding General Manager, Americas and Head of Sales for Global Strategic Markets. The newly created executive role reflects the company’s push to accelerate growth and customer acquisition across North and South America as it expands its AI-native cybersecurity platform globally.

In her new role, Nicholette will oversee Secure.com’s growth strategy across the Americas while leading sales efforts for global strategic markets. She will focus on expanding customer acquisition, developing channel and alliance partnerships, and strengthening Secure.com’s position as a leader in cybersecurity risk visibility and continuous security validation.

Nicholette joins Secure.com with more than 20 years of experience leading sales organizations, strategic partnerships, corporate development, and go-to-market strategy across the cybersecurity, cloud, and enterprise technology sectors. Most recently, she served as Chief Strategy Officer at GUARDDOG.AI, where she led market expansion and built partnerships advancing AI-driven cybersecurity adoption.

Prior to GUARDDOG.AI, Nicholette held several executive leadership roles at Meriplex, including Vice President of Corporate Development and Strategic Alliances and Vice President of Sales and Channel. During her tenure, she drove brand development, built strategic partnerships, and executed growth strategies. She also supported the company’s successful recapitalization by Vitruvian Partners.

Her experience also includes executive sales roles at VMware and Rackspace, where she consistently delivered growth across enterprise, cloud, networking, and security markets.

Nicholette is expected to attend Black Hat USA in Las Vegas, August 3-5, where she will be available to meet with press, partners, and customers.

The appointment comes as Secure.com continues to expand its portfolio of cybersecurity risk management solutions designed to help organizations proactively identify vulnerabilities, assess exposure, and continuously improve resilience against evolving cyber threats.

The CISA issues guidance to isolate critical systems during cyberattacks

Posted in Commentary with tags on July 29, 2026 by itnerd

The CISA, in coordination with international partners, has released new CI Fortify guidance to help critical infrastructure organizations isolate vital operational technology (OT) and supporting systems during cyberattacks or periods of heightened cyber threat.

The guidance is intended to help operators maintain essential services while containing cyber incidents and recovering compromised systems.

The guidance recommends identifying critical operational systems and customers, establishing predefined network isolation points, preparing to operate disconnected from third-party networks for weeks to months, and regularly testing recovery plans.

The CISA said organizations should assume internet; telecommunications, vendors and other external dependencies may become unavailable during a major cyber incident or geopolitical crisis.

Donald McFarlane, Advisory Board Member, Xcape, Inc.

“This guidance is more than a checklist. The Five Eyes are telling critical infrastructure operators to prepare for the possibility that they may have to intentionally isolate from the Internet, vendor connectivity, telecommunications providers, and other external dependencies in order to continue delivering essential services during a major cyber incident or geopolitical crisis.

“Some FVEY partners are recommending planning for up to three months of isolated operations. That’s less a prediction of duration than a recognition that operators must be prepared to sustain essential services for as long as necessary.

“Perhaps the most significant shift is the planning assumption. For years, cyber defense has focused primarily on protecting the internet edges. This guidance recognizes that the operational edge is much broader. Critical infrastructure operators should increasingly view the communications fabric connecting remote sites, substations, treatment facilities, vendors, and control centers, including private telecommunications and point-to-point links, not simply as infrastructure they depend upon, but as part of the attack surface itself.

“Resilience should be engineered before a crisis. Organizations need to identify their critical systems, understand hidden dependencies, establish and exercise isolation procedures, and ensure they can continue operating safely when connectivity becomes a liability instead of an asset.”

Seemant Sehgal, Founder & CEO, BreachLock:

“What stood out to me is the instruction to treat carrier-provided services as untrusted and potentially hostile. Most OT operators have longstanding relationships with their telecoms vendors and have built operational trust into those relationships over years. That trust does not translate to technical assurance, and in a geopolitical crisis or major incident, the carrier network itself may be the vector, the casualty, or both.”

John Strand, Owner, Black Hills Information Security, Inc.:

“This really feeds into something I’ve been talking about for quite a while. We’re entering the age of agentic attacks and agentic AI, where vulnerabilities are being discovered and weaponized faster than organizations can respond. In many cases, there won’t be a patch immediately. Sometimes there won’t be a patch at all, especially when we’re talking about operational technology that’s decades old and can’t realistically be upgraded.

“That leaves every CISO with one unavoidable question. What are your compensating controls?

That’s why it’s encouraging to see CISA putting more emphasis on isolation and compensating controls. It shows a shift in thinking that’s been needed for years. We have to move beyond the idea that every security problem can be solved with EDR, firewalls, and patch management alone. Organizations need layered defenses that assume vulnerabilities will exist, patches will be delayed, and some systems simply cannot be fixed. The future of cybersecurity isn’t just about preventing compromise. It’s about building resilient environments that continue to protect critical systems even when traditional approaches no longer work.”

Dahvid Schloss, Chief Operating Officer, Suzu Labs:

“Most everything stated in the guidance has been common language and advice from security professionals for years, if not decades. That being said, it is quite refreshing that government agencies are finally stating the obvious and, in some places, going above and beyond in ways that most would loosely recommend but not push for enforcement.  There are two pieces within the guidance that I appreciated more than others. The first was explicitly calling out MPLS(Multiprotocol Label Switching) as not a security boundary. This is a common argument between IT and Security folks when talking Layer 2/3 security, but in the same way VLANs aren’t treated as a security boundary, neither can MPLS, so kudos to the ASD and others for calling that out in writing.

“The other great piece here is the recommendation to separate encryption from the OT devices themselves, and instead recommend prioritizing and implementing a dedicated crypto device to handle traffic. This is very much needed, especially with how quickly technology is advancing and how it may accelerate the rate at which modern encryption mechanisms become obsolete. OT devices average a 20-year lifecycle; the ability to upgrade and protect the network without a full tech refresh, which comes with its own set of availability risks, is key to future-proofing the security of the network. They also state that crypto should terminate on the OT-side router and not somewhere more convenient, which is a common trend I’ve seen when testing.

“Every time I’ve brought this up as a finding in the past, it was always a “yeah, we know, but it’s easier to manage this way”. If anything, changing the way CI implements crypto within the network would improve security 10-fold in my opinion.  Overall, this release is old guidance many security professionals have been screaming from the rafters for decades, but hey, hopefully this will create the change we have been asking for.”

Matt Wyckhouse. Founder & CEO, Finite State:

“We’re supportive of the FCC’s direction here. Supply chain resilience and onshoring of critical technology manufacturing matter to U.S. national security, and the risks documented in the government’s determinations, remote commandeering, surveillance, pre-installed backdoors, are real, not hypothetical. The additional measure we’d advocate is objectivity: pairing these steps with true security assessment of the devices themselves.

“From analyzing the firmware inside thousands of connected products, we see the same pattern everywhere. Security is a property of engineering, not geography. There is rigorously engineered, secure software coming out of foreign countries, and there is deeply insecure software shipping from U.S. companies. Country of origin is an important input to the risk analysis, particularly where software provenance is hard to establish, but an objective assessment of what’s actually in a device is what separates the secure from the vulnerable. That’s why the FCC’s proposed software and hardware bill-of-materials requirements are an encouraging step, and why pairing them with the substantive security requirements already developed under the Cyber Trust Mark, much as the EU is doing through the Cyber Resilience Act, would give the U.S. an approach that is both resilient and objective: one that strengthens the supply chain while raising the security bar for every device sold here, wherever it’s built.”

Organizations need to take what the CISA has done and not only build their own playbooks from it, but practise it and use it if required. That way it will reduce the level of pwnage if it comes to that.

Compromised npm packages are using blockchain transactions to hide their command-and-control 

Posted in Commentary with tags on July 29, 2026 by itnerd

Security firm Socket found that two Joyfill npm packages were compromised to deliver a remote access trojan that harvests browser data, crypto wallets, and Git and GitHub CLI credentials from developer machines. The malware resolves its command-and-control by chaining transactions across three separate blockchain networks, with a backup path to a hardcoded IP if that fails, letting the operators swap out their real infrastructure any time without ever republishing the malicious package.

Socket posted a write up about this here: Two Joyfill npm Beta Releases Compromised to Deliver DEV#POP…

Roman Sannikov, Global Research Coordinator, iCOUNTER

“The part of this that actually got my attention is the command-and-control setup. Chaining together transactions across three separate blockchain networks, with a fallback process that pulls a boot payload straight from a hardcoded IP if the primary chain fails, gives the operators a way to swap out their real payload infrastructure any time they want, without ever having to touch the npm package again. Persistence is really the whole game for a threat actor once they’re in, and this is one of the more ingenious ways I’ve seen someone build that in from day one. The credential harvesting tells the same story. Browser data, crypto wallet extensions, Git and GitHub CLI credentials, VS Code storage, basically anything a developer machine touches, that breadth isn’t what you build if you’re just trying to grab a batch of credentials to sell quickly. It’s what you build if you’re planning to operate inside these environments for a while. What I’d flag for defenders is that Socket still hasn’t nailed down how the packages got compromised in the first place, workstation, repo, CI pipeline, or stolen publishing credentials are all still open questions, and that answer is going to matter more than the malware itself, because it tells you where the next one comes from.”

Besides nailing down how these packages got compromised is an important step. But as a matter of course, software vendors of all sorts need to know what’s in their software and where it came from as well as be accountable for that by a third party. That is when we will see real change.

Guest Post – The great AI disconnect: New data reveals friction between AI policy and employee reality

Posted in Commentary with tags on July 29, 2026 by itnerd

Organisations are pouring investment into AI. But new data from the SAP Concur annual Global Business Travel Survey reveals that nearly three-quarters (70%) of Canadian business travellers have or would make use of unapproved AI tools, also known as ‘shadow AI’ for business travel.

The survey’s findings provide insight into how business travellers are using AI, where a lack of official tools leaves companies missing out, and what employers can learn from this disconnect.

Which business travellers are using shadow AI
Why do travellers turn to shadow AI? For 38% of respondents, it’s a matter of preference. They favour different tools over their company’s approved options. For another 32%, it’s about availability: their employers do not offer any AI tools for planning or booking travel. 

Demographics and work arrangements play a big role in who relies on unauthorised tools. Consideration steadily declines by generation: while more than three-quarters of Gen Z (79%) and Millennial (76%) travellers are open to using shadow AI, this falls 62% for Gen X and 49% for Boomers.

Workplace flexibility is another key differentiator, with remote workers (81%) saying they would turn to unapproved AI tools significantly more often than fully on-site employees (71%).

Whether employees travel for business internationally seems to make a difference, too. 75% of those who travel internationally have or would use shadow AI tools, compared to 63% of domestic travellers. 


The main ways travellers use AI-powered tools

Three-quarters of travellers (70%) say they have used AI-powered tools to support elements of business travel. The most popular use cases they report include planning their trip agenda (29%), tracking expenses during the trip (24%), and assessing the risks of the trip (20%).

Around a fifth (18%) use AI tools to rebook or make changes to their trip, as well as curate travel options during booking. A similar percentage (18%) use them to complete their expense report after the trip.


The shadow AI risk

These findings tell a cautionary tale: if there’s a gap between the AI tools employees want to use and what’s on offer, they’re likely to source their own alternatives.

“It’s a huge worry for business leaders. 96% of CFOs say they’re concerned by shadow AI in business travel”, says Brian Veloso, Managing Director at SAP Concur Canada. “As consumer AI tools proliferate, they open the door for employees to use unsanctioned systems for booking or planning business travel. Unfortunately, this shadow AI can create security risks, particularly when employees input sensitive data or connect business systems to unauthorised software. Leaders must educate workers on the risks and provide T&E tools that deliver the desired level of AI support.”


The AI features travellers really want

One way for businesses to keep AI usage on track is to understand how employees want to use AI in travel – and provide tools that suit those needs.

When asked, 38% of employees said they want AI integrations in other parts of the workflow (e.g. PowerPoint and their calendar). One in three employees (26%) said they would like AI embedded specifically into communication software (e.g. Teams, Slack), and another 26% want proactive AI that notifies them to book through push alerts or reminders.

Around a quarter of employees (22%) want chatbot interfaces within current booking tools, while 23% would like integrations in role-specific tools (e.g. CRM).

AI is already out on the road with business travellers. Now, it’s up to leaders to ensure corporate governance by offering approved, AI-powered tools that deliver what travellers actually want.

FCC proposal could force tech suppliers into equipment authorization rules

Posted in Commentary with tags on July 29, 2026 by itnerd

The FCC is considering a major expansion of its “Equipment Authorization Program” that could draw software developers, firmware providers, design houses and other technology suppliers into the agency’s regulatory system for the first time.

Under a Third Further Notice of Proposed Rulemaking adopted July 22, applicants could be required to submit signed hardware and software bills of materials (SBOMs) covering the hardware, software and firmware in a device. The disclosure would be required to identify: the  component producer, where components were designed, developed or manufactured, and the percentage of component value associated with each production location. Grantees could also be required to update the information within 30 days of material changes.

Because the FCC’s proposed definition of production includes design and development, the information may need to be collected from suppliers far removed from the company filing the application, including design houses and IP licensors with no direct relationship to that applicant.

Eric Greenwald, General Counsel, Finite State had this comment:

   “The FCC’s proposal would turn equipment authorization from a product review into a supply-chain transparency exercise. Applicants would file a signed HBOM and SBOM covering every component, including hardware, software and firmware, along with information about each component’s producer, place of production and share of value.

   “The applicant would be responsible for the filing, but the information would have to be collected from dozens of suppliers, including design houses and IP licensors with no direct relationship to the filer. That process would be onerous, and the results would not necessarily be reliable. Anyone submitting an application for FCC certification will need a way to verify independently what is actually in the device, down to the firmware.”

This is a good start, but this needs to be enforced strictly. Only then will we see meaningful changes.

UPDATE: Justin Beals, CEO & Founder of Strike Graph, an AI-native GRC and compliance automation platform adds this comment:

“Updated SBOM guidance is necessary, but guidance isn’t the hard part—verification is. Plenty of organizations can produce an SBOM document. Far fewer can prove the components listed in it are still accurate six months later, or that a control mapped to a framework requirement is actually being enforced in production.

This is the same gap we see across CMMC, FedRAMP, and every other framework leaning on SBOMs right now: a static list, filed once, treated as proof of ongoing security. It isn’t. It’s a snapshot.

The organizations that get ahead of this will be the ones building continuous validation into their SBOM process—not just generating the document to check a box, but proving its contents stay true over time. That’s the difference between attestation and evidence.”

Fortra Announces Expansion of Cloud Email Protection to Europ

Posted in Commentary with tags on July 29, 2026 by itnerd

Fortra today announced the expansion of its transformative Cloud Email Protection solution into Europe, enabling organizations to defend against advanced email threats while meeting European Union data residency requirements. 

Purpose-built for modern cloud environments, Fortra’s Cloud Email Protection stops threats that bypass traditional defenses using a combination of AI-powered detection, global threat intelligence from the Fortra platform, and automated remediation. As one of the industry’s early cloud-native email security platforms, Cloud Email Protection was created with machine learning and AI models as its core, helping organizations simplify and scale email protection while stopping threats like business email compromise, spear phishing, and targeted social engineering.   

Organizations across Europe increasingly require security solutions that allow sensitive email data to remain within European jurisdictions. Fortra’s European deployment in ISO27001/SOC2 datacenters enables customers to keep their data in-region, supporting local compliance requirements while maintaining enterprise-grade protection. 

Built with privacy-by-design principles, the platform minimizes the collection of personal information while protecting email communications through layered security controls including encryption, access management, and comprehensive auditing.   

Customers retain control of their data while benefiting from enterprise email security. Administrative access, data handling practices, and regional hosting support organizations’ strict sovereignty requirements.  

Learn more about the market’s most comprehensive cybersecurity platform at fortra.com

Road Trips, Remote Destinations and Reliable Connectivity Top Summer Travel Priorities Says Rogers

Posted in Commentary with tags on July 29, 2026 by itnerd

From road trips and cottage weekends to camping and backcountry escapes, most Canadians are embracing closer-to-home travel this summer. And according to a new survey, not being able to contact someone in an emergency is a trip dealbreaker for many.

The new Rogers survey, conducted using the Angus Reid Forum, found that three-quarters of Canadians said they planned to travel within Canada rather than far-away destinations. Among these travellers, road trips top the list with two-thirds saying they plan to hop into the car for their summer adventure. About four in 10 Canadian travellers plan to go to remote or off-the-grid areas.

But even as some travellers look to unplug, eight in 10 say they still expect connectivity when it matters. Not being able to contact someone in an emergency is a dealbreaker for trips for two-thirds of travellers.

Maps, Weather and Emergencies Matter Most

The survey found staying connected to practical tools tops entertainment and social media, with maps and navigation ranked as the most important (78%), followed by texting and messaging (62%), emergency services (60%), phone calls (55%) and weather apps (55%).

With Rogers Satellite, a first of its kind satellite-to-mobile service in Canada, travellers can use text-to-911 services as well as satellite-ready apps including WhatsApp, Messenger, Google Maps, X and AccuWeather in areas outside of traditional cellular coverage.

Connectivity Is Shaping Domestic Travel Decisions

Only 18 per cent of the country is covered by traditional wireless networks, including stretches of highways. Rogers Satellite helps give Canadians an extra layer of connectivity beyond the reach of these networks.

When travellers think about travelling to areas outside traditional cell coverage, connectivity is increasingly part of the plan:

  • 49% say reliable connectivity would make them more likely to explore remote destinations
  • 65% expect basic, reliable connectivity for calls, texts and navigation when travelling in rural or remote areas
  • 85% say reliable connectivity would make them feel safer in remote areas

To see where Rogers Satellite connectivity is available and to learn more about getting Rogers Satellite for $0 with new Rogers 5G+ mobile plans, visit rogers.com/satellite.

About the Survey 

The online survey was conducted by Rogers using Angus Reid Forum between June 17 and June 23, 2026, among 1,015 Canadians planning to travel within Canada during summer 2026. The survey was conducted nationally in English and French.  

Hacker mistake reveals ongoing attack on semiconductor company

Posted in Commentary with tags on July 29, 2026 by itnerd

Cybernews researchers uncovered an active ransomware campaign against multinational semiconductor company V-Silicon after discovering an exposed hacker server.

Here’s a timeline of the findings:

  1. Cybernews researchers discovered an exposed web directory that functioned as a staging server for a ransomware attack.
  2. A subsequent investigation linked the discovered infrastructure to an attack against V-Silicon, a multinational semiconductor company that develops chips used in smart TVs and display devices.
  3. The campaign was attributed to INC Ransomware, a ransomware-as-a-service (RaaS) operation that has been active since 2023.
  4. We alerted V-Silicon to the exposed data on July 17th. 
  5. One day later, the INC ransomware group published V-Silicon on its leak site, claiming responsibility for the attack.

What was found on the internal hacker server?

  • “The artifacts found on the exposed server indicate that during network enumeration, third-party infrastructure and data could have also been compromised”, Cybernews researchers explain.
  • The ransomware was built to run on a wide range of computer systems, suggesting that the attackers may have intended to encrypt embedded controllers, industrial systems, or older semiconductor manufacturing equipment.
  • Researchers noticed coding patterns that suggest some scripts may have been generated with AI.

For more information, here’s the full report: 

https://cybernews.com/security/hackers-exposed-ransomware-attack-v-silicon

Cybercrime victims lose an estimated $1.24 trillion a year 

Posted in Commentary with tags on July 29, 2026 by itnerd

Comparitech researchers have published an update to their 2023 study on the cost of cybercrime globally. The new study sees a significant increase in the annual estimated monetary impact of cybercrime — now at $1.24 trillion versus 2023’s figure of $714 billion. 

Key findings include: 

  • 103.9 million people fall victim to cybercrimes globally each year, or more than 1,577 victims per 100,000 people
  • The average victim loss is $9,468 per crime
  • Victims lose an estimated $1.24 trillion to cybercrime annually
  • The United States showed the biggest estimated losses at 6.7 million victims losing an estimated $138.9 billion

For full details, click here.