October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

IMF: Financial Firms Reported Nearly $12 Billion in Direct Cyberattack Losses, 2004–2023

The IMF’s nearly $12 billion estimate covers direct reported cyber losses at financial firms from 2004 through 2023—not the full economic cost of cyberattacks.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Financial firms reported nearly $12 billion in direct losses from cyber incidents over the 2004–2023 period covered by the International Monetary Fund’s April 2024 analysis. The IMF says $2.5 billion of that reported total came since 2020. These figures capture reported direct losses—not the full economic cost of cyberattacks—and they are not an updated cumulative total through 2026.

What the IMF’s nearly $12 billion figure measures

The estimate comes from the IMF’s April 2024 Global Financial Stability Report, Chapter 3. It is based on reported direct losses associated with cyber incidents affecting financial firms, drawing on Advisen Cyber Loss Data, the Depository Trust and Clearing Corporation, and IMF staff calculations. The report’s observation window runs from 2004 through 2023.

“Direct losses” are not the same as total harm. Firms may not report every cost, and the IMF notes that indirect effects—including lost business, reputational damage, and later investment in security—can be difficult to measure or emerge over time. The nearly $12 billion figure should therefore be read as an estimate of reported direct losses, not a comprehensive accounting of cybercrime’s cost to finance.

How much of the reported loss is recent?

The IMF says financial firms reported $2.5 billion in direct cyber-incident losses since 2020. That is part of the nearly $12 billion reported for the full 2004–2023 window, not an additional amount.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The IMF’s companion April 9, 2024 blog post also describes extreme cyber losses as having risen more than fourfold since 2017 to $2.5 billion. That is a separate description of extreme losses; it should not be substituted for, or added to, the cumulative direct-loss totals above.

Which parts of finance were affected?

In the IMF’s dataset, almost one-fifth of reported cyber incidents during the prior two decades affected the financial sector. Banks were the most frequent financial-sector targets, followed by insurers and asset managers. The report found greater exposure among advanced-economy institutions, especially in the United States, than among firms in emerging-market and developing economies. These are patterns in the dataset, not evidence that other regions or subsectors are safe.

When can a firm-level attack become a financial-stability problem?

The IMF says cyber incidents had not yet become systemic at the time of its April 2024 report, but warns that the probability of severe incidents and their potential macrofinancial effects had increased. It identifies three ways an incident could spread beyond the firm first affected:

  • Confidence: a serious breach or service failure can weaken trust in a firm or the financial system.
  • Service disruption: outages affecting payments or other critical services can harm customers and institutions that depend on them.
  • Interconnectedness: technological and financial links can transmit disruption between firms, potentially creating funding pressure or solvency concerns.

Shared technology providers can concentrate exposure: a 2023 ransomware attack on a cloud IT service provider caused simultaneous outages at 60 US credit unions, according to the IMF. Cyber incidents can also cross borders; an attack may originate outside a firm’s home country, and proceeds may move across borders.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Finance Record Book for Small Churches
  • Enough forms for 1 year for churches of approximately 150 members
  • 5 3/16" x 9"
  • Includes forms for church receipts, member contributions, and disbursements

The IMF blog reports modest, somewhat persistent deposit outflows at smaller US banks following cyberattacks, but says no significant “cyber runs” had occurred at the time. That distinction matters: the report describes a potential channel of concern, not a claim that cyber-triggered runs had already taken place or that they could not happen.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the IMF says firms, boards and authorities should do

The IMF’s recommendations span individual firms and the public institutions responsible for oversight. They are resilience measures, not a guarantee that attacks can be prevented.

  • Financial firms: develop and test response and recovery procedures. The IMF blog gives antimalware and multifactor authentication as examples of cyber hygiene.
  • Boards: take responsibility for cybersecurity governance and risk culture, support cyber hygiene and training, and ensure access to cybersecurity expertise.
  • Supervisors and national authorities: strengthen cybersecurity strategies and regulatory and supervisory frameworks, improve incident reporting and information sharing, build workforce capacity, and establish response protocols and crisis-management frameworks.

The IMF blog says about half of surveyed countries had a national financial-sector cybersecurity strategy or dedicated cybersecurity regulations. This is a survey finding attributed to central banks and supervisory authorities, not a comprehensive census of every country’s readiness.

Quick Recap

Bestseller No. 3
Finance Record Book for Small Churches
Finance Record Book for Small Churches
Enough forms for 1 year for churches of approximately 150 members; 5 3/16" x 9"; Includes forms for church receipts, member contributions, and disbursements
$12.72

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.