Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Why Breach Costs Are Rising—and What a Reported $75 Million Ransom Really Means

IBM reported a $4.88 million global average breach cost in 2024; separately, researchers attributed a reported $75 million ransom to Dark Angels. The figures are not comparable—and recovery readiness can limit the damage.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The global average cost of a studied data breach reached $4.88 million in IBM’s 2024 report. Separately, researchers attributed a reported $75 million ransom payment to the Dark Angels ransomware group. The figures describe different things: one is an average estimate of total breach costs across a study sample; the other is an exceptional payment in one case whose victim was not publicly identified in the coverage.

Two figures, two different measures

The July 31, 2024 Computer Weekly report brought together two developments: IBM’s estimate that the global average cost of a data breach had risen to $4.88 million, and a reported ransom payment of about $75 million attributed by researchers to Dark Angels.

These figures are not directly comparable. IBM’s figure estimates the total financial impact of breaches in a defined study. The $75 million figure is a ransom payment reported in one unusual case. It is not evidence that the average breach costs $75 million, nor does it explain IBM’s year-over-year increase.

What is known about the reported $75 million ransom?

Zscaler ThreatLabz and Chainalysis research was cited in reporting on a payment of approximately $75 million attributed to the Dark Angels group. It was described at the time as the largest known or reported ransomware payment. The victim was not identified in the coverage, and the figure should be treated as a researcher-attributed report rather than a public confirmation by the victim. Zscaler’s material citing its ThreatLabz report is available in its ransomware report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A ransom is only one possible part of an incident’s bill. A company may also face lost sales or production, emergency infrastructure replacement, forensic investigation, legal and regulatory work, customer notification and support, contractual penalties, public-relations costs, insurance effects, and long-term remediation. The available coverage does not establish the victim’s full costs or whether payment restored its systems or protected its data.

Why a company might consider paying

Executives may weigh payment against prolonged downtime, the cost and time required to rebuild, safety concerns, threats to publish stolen data, and the effect on customers, suppliers, or employees. An expert quoted in the coverage suggested attackers may research a target’s finances and set a demand below the expected cost of disruption. That is a possible strategy, not an established explanation for this unidentified victim.

Payment does not guarantee a working decryption tool, complete recovery, deletion of stolen data, continued confidentiality, or freedom from repeat extortion. A payment decision is not simply an IT call: it can involve executive leadership, legal counsel, incident responders, insurers, law enforcement, sanctions and financial-crime compliance, and privacy advisers. Organizations must assess whether payment is lawful in the relevant jurisdiction and whether it is likely to change the operational outcome.

What IBM’s breach-cost average represents

IBM and the Ponemon Institute studied 604 organizations affected by breaches across 16 countries or regions and 17 industries. IBM reported a global average breach cost of $4.88 million, 10% higher than the previous year. About 70% of surveyed organizations reported moderate or significant operational disruption. These are findings from that study sample, not a prediction for every company or every breach. See IBM’s 2024 report summary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The cost estimate covers more than technical cleanup. It includes categories such as lost business, detection and escalation, notification, post-breach response, customer support and credit monitoring, legal and regulatory consequences, investigation, and remediation. Because the figure is an average, a small number of very expensive incidents can influence it; it should not be read as a standard invoice or a typical ransom amount.

Geography and period matter. Computer Weekly reported a UK average of £3.58 million for breaches during March 2023–February 2024. That UK figure and IBM’s $4.88 million global average refer to different geographies and currencies and should not be combined.

Why the financial impact can keep growing

The costs surrounding an intrusion can exceed the immediate price of rebuilding systems. Extended disruption can interrupt sales, production, or essential services. Complex environments spread data and systems across cloud services, private cloud, and on-premises infrastructure, making it harder to see what was affected and restore it in the right order. Third-party dependencies, regulatory investigations, customer support, and shortages of experienced security staff can add time and expense.

IBM found that breaches involving data distributed across multiple environments cost more than $5 million on average and took about 283 days to identify and contain. In a separate UK context, Computer Weekly reported that incidents involving data-visibility gaps averaged roughly £3.5 million and took more than 250 days to identify and contain. The figures come from different geographic and reporting contexts; they are not interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The route an attacker uses to get in is also distinct from what later drives the largest losses. An initial attack vector is the first access route, while the damage may grow through subsequent access to other systems, data theft, or disruption. For the UK figures reported by Computer Weekly, average breach costs by initial vector were:

Initial attack vector Reported average breach cost
Malicious insiders £4.36 million
Stolen or compromised credentials £4.27 million
Business email compromise £4.03 million
Phishing £3.59 million

These are average breach costs associated with the study categories, not average ransom payments. A stolen credential or phishing message may be an entry point; the final financial impact depends on what the attacker can reach and how quickly the organization contains and recovers from the incident.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the findings say about security automation

IBM reported that organizations using security AI and automation across prevention, detection, investigation, and response had lower average breach costs and faster identification and containment than organizations that had not deployed those capabilities. Computer Weekly summarized the UK comparison as about 106 days faster and roughly £1.06 million lower average cost. IBM also reported that organizations whose own security teams and tools detected a breach had costs nearly $1 million lower on average than organizations whose breaches were identified by attackers, such as through extortion.

These are associations, not proof that AI alone caused the difference or a guarantee of savings from a particular product. Better-funded organizations may be more likely to adopt automation and have stronger controls overall. Poorly designed automation can also accelerate mistakes. Tools are most useful when they have reliable telemetry, trained operators, sensible playbooks, and human approval for high-impact actions; they do not replace access controls, patching, segmentation, or tested recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where businesses can reduce the financial exposure

Limit access and contain compromised accounts

  • Use phishing-resistant multifactor authentication for privileged and remote access where feasible, and strengthen privileged-access management.
  • Remove dormant accounts, rotate exposed credentials, and restrict administrative access to the least privilege needed.
  • Monitor identity-provider and administrator activity. Multifactor authentication alone does not prevent session theft, help-desk social engineering, compromised endpoints, or abuse of legacy access paths.

Make it harder for an incident to spread

  • Segment networks and restrict remote-management tools so a compromised account or device cannot automatically reach every critical system.
  • Prioritize prompt patching of internet-facing systems and review access between business-critical environments.
  • Centralize useful identity, endpoint, cloud, and network logs, and ensure alerts are monitored. A SIEM, SOAR, EDR, or MDR product without staffing, tuning, and response ownership can add alert volume without improving containment.

Prove that recovery will work

  • Keep isolated or immutable backup copies with administrative credentials separate from everyday production access.
  • Test restoration, not just backup completion. Include identity services, hypervisors, DNS, networking, and SaaS data as well as file servers.
  • Set recovery-time and recovery-point objectives for critical services, then measure them in exercises. Plan how essential operations can continue manually during a prolonged outage.

Prepare decision-making before an incident

  • Preselect incident-response and legal contacts, and define how insurers, law enforcement, privacy advisers, and communications teams will be brought in.
  • Review insurance notification requirements and establish who can authorize emergency network isolation.
  • Document a lawful, executive-level process for evaluating any ransom demand, including sanctions screening and assessment of whether payment could realistically aid recovery.
  • Identify the systems whose outage would threaten safety, revenue, or essential operations, and rehearse restoration priorities.

Executive pre-incident checklist

  • Can the organization quickly identify and disable a compromised privileged account?
  • Can responders isolate affected systems while preserving evidence?
  • Have critical services been restored from isolated backups in a timed exercise?
  • Are legal, insurer, incident-response, law-enforcement, and communications contacts current?
  • Is there a clear approval path for emergency containment and any ransom-related decision?
  • Do exercises measure actual recovery time rather than assume backups are sufficient?

For any security automation or response service, evaluate what it prevents, detects, contains, or helps recover; whether it is self-managed or managed; its integration with identity, endpoints, cloud, backups, and ticketing; 24/7 monitoring; human approval and rollback controls; deployment and staffing demands; data-retention and residency terms; incident support; and total cost of ownership. The reported payment is a reason to assess resilience, not evidence that any one vendor or the most expensive platform would have prevented it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.