The often-quoted $600 billion figure is a historical estimate, not a measured 2026 total. A Center for Strategic and International Studies (CSIS) report produced with McAfee and published on February 21, 2018, concluded that cybercrime cost the world close to $600 billion a year—nearly 1% of global gross domestic product (GDP). It compared with about $445 billion in CSIS’s 2014 study.
What the $600 billion estimate covers
The CSIS–McAfee report, Economic Impact of Cybercrime, attributed the annual loss to the worldwide economic effects of cybercrime. Its headline figure combines the value of stolen output and data with the costs of responding to attacks and protecting systems. CSIS identified James Andrew Lewis, a senior adviser (non-resident) in its Economic Security and Technology Department, as the report’s author.
CSIS’s wording was “close to $600 billion, nearly one percent of global GDP.” The estimate should therefore be read as an approximate, model-based annual loss for the period covered by the 2018 report—not as a tally of every cyber incident or a real-time account of losses in 2026.
Why the percentage can appear as 0.8% or nearly 1%
Different publications round the same estimate differently. CSIS presented the result as nearly 1% of global GDP. A 2024 Cybersecurity and Infrastructure Security Agency (CISA) study summarized the 2018 result as $600 billion, or 0.8% of global GDP. Those descriptions are not necessarily contradictory: the dollar figure and the GDP denominator are rounded, and the presentation depends on the source’s chosen year and calculation.
#1 Best Overall
How the major estimates differ
| Estimate | Publication | Method and population | Losses included or excluded | Uncertainty |
|---|---|---|---|---|
| About $445 billion annually | CSIS comparison with its 2014 study | Earlier CSIS estimate of global cybercrime costs | Scope and methods differ from the 2018 update; the comparison does not make the figures directly interchangeable | Not stated in the supplied source summary |
| Close to $600 billion annually | CSIS–McAfee, February 21, 2018 | Global estimate of cybercrime’s economic impact | Broad economic impact, including crime losses and associated costs as modeled by the report | Not stated in the supplied source summary |
| Approximately $500 billion annually | Lukošiūtė, Halstead and Righetti, 2026 paper/preprint | Composite of a UK business-victimization survey scaled globally, U.S. individual-victimization data scaled globally, and global cybersecurity-spending figures | Quantifiable direct losses, response costs and defense spending; harder-to-measure intellectual-property theft and reputational damage excluded | 90% confidence interval: $100 billion to $1 trillion |
The 2026 result is not a replacement price tag for the 2018 result. It uses different inputs and explicitly leaves out important effects that are difficult to quantify. The 2026 work surveyed 27 existing estimates before constructing its composite, and it is a paper/preprint rather than a settled official global measurement.
What “cost” means in practical terms
Direct losses
These are quantifiable amounts taken or destroyed through incidents, such as unauthorized transfers, fraud, ransom payments or the immediate value of disrupted activity. The exact categories and accounting rules vary by study.
Response and recovery
Organizations also spend money investigating incidents, restoring systems, notifying affected people, replacing equipment and meeting legal or operational obligations. A study that counts these expenses can produce a higher total than one that records only money stolen.
Defense spending
The 2026 composite includes global cybersecurity spending as one component. That choice treats defensive expenditure associated with cyber risk as part of the economic burden, even when the spending prevents a loss that never occurs. Estimates that omit defense spending will not be comparable with estimates that include it.
Recommended Free Tools
Rank #3
Costs that are hard to measure
The 2026 paper excludes intellectual-property theft and reputational damage because they are difficult to value consistently. Lost innovation, customer trust or future sales can be substantial without appearing as a clearly recorded transaction. The $500 billion composite therefore does not represent every conceivable consequence of cybercrime.
Why estimates move between studies
- Publication year: attack patterns, digital dependence, exchange rates and GDP change over time.
- Geography and scaling: survey results from the United Kingdom or United States must be extrapolated to countries with different internet use, reporting behavior and business structures.
- Population measured: household victims, businesses, governments and service providers can experience different types and sizes of loss.
- Definitions: one study may count prevention and response spending while another counts only realized theft or disruption.
- Under-reporting: victims may not detect incidents, may decline to report them or may not disclose the financial amount.
- Uncertainty: a wide interval can be more informative than a single precise-looking number when the underlying data are incomplete.
What the figures mean for household finances
A global estimate cannot tell an individual whether a particular account will be attacked or predict a household’s expected dollar loss. It does show that cybercrime is an economy-wide cost passed through many channels: fraudulent transactions, business interruption, higher security and compliance expenses, and the administrative work of recovering from incidents.
Rank #4
For personal-finance decisions, the useful response is not to treat $600 billion as a household bill. Instead, reduce the types of loss that are within your control:
- Use unique passwords for financial, email and phone accounts, stored in a reputable password manager.
- Turn on multifactor authentication, preferring an authenticator app or security key where a service supports it.
- Install operating-system and application updates promptly, especially on devices used for banking.
- Set transaction alerts and review bank and card statements so unauthorized activity is reported quickly.
- Verify payment requests through a separate, trusted channel; urgency and secrecy are common warning signs of fraud.
- Keep offline or otherwise protected backups of important records and use a recovery email and phone number you control.
How to read future cybercrime cost headlines
Before comparing a new number with $600 billion, check five details: the publication date, the countries and populations scaled, the categories of loss counted, whether defense and response spending are included, and the uncertainty range. A figure without those details can create a false impression of precision.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Best Value
On the evidence currently available in the cited material, the most accurate summary is: CSIS and McAfee estimated close to $600 billion per year in 2018, while a 2026 preprint produced a roughly $500 billion composite with a very wide $100 billion–$1 trillion 90% interval and a narrower scope. Neither should be presented as a definitive, directly measured 2026 global total.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




