13 Types of Cyber Attacks and What They Cost (2026)
·16 min read
Key Takeaways
Americans filed 1,008,597 cybercrime complaints in 2025 and lost $20.877 billion, up 26% from 2024.
Phishing leads by volume with 191,561 complaints, but business email compromise leads by damage with $3.05 billion in losses from under 25,000 complaints.
Exploiting a software vulnerability is now the top entry point at 31% of breaches, pushing stolen credentials out of first place for the first time in nineteen years.
The widely repeated claim that 91% of attacks start with phishing is no longer supported by forensic breach data.
One in four malicious breaches were AI-enabled, and the FBI recorded 22,364 AI-related complaints worth $893.3 million in losses.
Last year Americans filed more than a million cybercrime complaints with the FBI, and lost nearly $21 billion doing it. Here is the strange part: the attack people report most often is nowhere near the attack that drains the most money. Knowing the types of cyber attacks is useful. Knowing which ones actually empty bank accounts is what keeps you safe. This guide covers all 13, what each one really costs in the United States, and how attackers changed their playbook in 2026.
What Counts as a Cyber Attack?
A cyber attack is any deliberate attempt to break into, damage, or take control of a computer system, network, or account. The key word is deliberate. A hard drive that dies on its own is a failure. A hard drive encrypted by someone demanding $50,000 is an attack.
Attack vs. threat vs. vulnerability
These three get mixed up constantly, and the difference matters when you read security reports.
1. A vulnerability is a weakness that exists, like unpatched software or a reused password.
2. A threat is someone who might exploit that weakness.
3. An attack is the moment they actually do it.
If you want the wider picture of how defense works as a discipline, our guide to what cybersecurity actually covers walks through the fundamentals. This article stays focused on the attacks themselves.
How Cyber Attacks Actually Start in 2026
Most articles on this topic still open with a claim you have probably seen: that 91% of cyber attacks begin with a phishing email. It gets repeated in training decks, vendor blogs, and LinkedIn posts every week.
It is no longer true, and tracing it back, it was never well sourced.
Why "91% start with phishing" is no longer true
Verizon's 2026 Data Breach Investigations Report, built from forensic analysis of real breach casework, found that 31% of breaches now begin with attackers exploiting a software vulnerability. That pushed stolen credentials out of the top spot for the first time in the report's nineteen-year history.
Think about what that means in practice. The attacker did not trick anyone. Nobody clicked anything. They scanned for a server running software that had a known flaw, and walked in through the flaw.
Verizon also found that ransomware now shows up in 48% of breaches, and that roughly 15% of attack techniques are being boosted by generative AI. Mobile users click malicious links at rates about 40% higher than desktop users, which is worth remembering the next time you approve something from your phone while walking.
Vulnerability exploitation became the leading initial access vector in 2026.
Why IBM and Verizon disagree on the top vector
Here is a detail almost nobody explains, and it confuses a lot of readers.
IBM's Cost of a Data Breach Report 2026 names phishing as the most common initial attack vector for the fourth year running. Verizon names vulnerability exploitation. Both are credible. Both are correct.
They measure different populations. IBM surveys organizations that were breached and asks them how it happened, so the answer reflects what companies believe and can identify. Verizon analyzes forensic incident data, where investigators reconstruct the entry point from evidence. Human memory favors the phish people remember. Forensics favors the server flaw nobody noticed.
The practical takeaway: patching and phishing training are not competing priorities. Skip either one and you have left a door open.
The 13 Most Common Types of Cyber Attacks
The thirteen attack types that matter most in 2026 are phishing, malware, ransomware, business email compromise, credential attacks, vulnerability exploitation, DoS and DDoS, man-in-the-middle, SQL injection, cross-site scripting, insider threats, supply chain attacks, and AI-enabled attacks.
Each one below includes what it is, how it works, and a real US figure where federal data provides one.
1. Phishing
Fake messages designed to make you hand over credentials or money. The FBI's 2025 Internet Crime Report logged 191,561 phishing and spoofing complaints, more than any other crime type.
The variants matter because they target different people:
1. Spear phishing targets one named person using real details about their job.
2. Whaling targets executives specifically, usually with wire transfer requests.
3. Smishing arrives by text message, often as a fake delivery or bank alert.
4. Vishing comes by phone call, increasingly with a cloned voice.
What to do: verify any payment or credential request through a channel you chose yourself, not one the message gave you.
2. Malware
Malicious software installed on a device to steal, damage, or spy. Viruses, worms, trojans, spyware, and keyloggers all sit under this label.
Reported on its own, malware is comparatively rare in FBI data, with 893 complaints and about $19.4 million in losses in 2025. That low number is misleading rather than reassuring. Most malware arrives as part of a larger incident and gets reported under that incident's category instead.
3. Ransomware
Malware that encrypts your files and demands payment for the key. Modern crews add a second squeeze, threatening to publish stolen data whether or not you pay.
The FBI received 3,611 ransomware complaints in 2025 with roughly $32.3 million in reported losses. That looks small next to other categories, and it is the most misread statistic in cybersecurity. Ransomware complaint counts stay low because victims are organizations, not individuals, and organizations often report through other channels or not at all. Verizon's forensic data showing ransomware in 48% of breaches tells the truer story.
Ransomware is also the threat most concentrated on hospitals, schools, water utilities, and local government.
4. Business Email Compromise
An attacker impersonates an executive, a vendor, or a title company and redirects a legitimate payment to their own account. No malware. No broken firewall. Just a convincing email arriving at the right moment.
BEC generated only 24,768 complaints in 2025, but $3.05 billion in losses. That works out to roughly $123,000 per complaint, and it makes BEC the single most financially dangerous attack type facing American businesses.
What to do: require a callback to a known phone number for any change to payment details. This one control stops most BEC losses.
5. Credential and Password Attacks
Brute forcing, password spraying, and credential stuffing all aim at the same thing: logging in as you, legitimately, using a password that leaked somewhere else.
Credential abuse fell to 13% of initial access in Verizon's 2026 data, down from the top spot. It fell because vulnerability exploitation rose, not because passwords got safer.
6. Vulnerability and Zero-Day Exploitation
Attacking a flaw in software before it is patched. A zero-day is a flaw the vendor does not yet know about, which is why there is no fix available on day zero.
Now the leading entry point at 31% of breaches. Verizon found that attackers are moving faster than defenders are patching, which is why unpatched edge devices and VPN appliances keep showing up in breach reports.
7. DoS and DDoS Attacks
Flooding a service with traffic until real users cannot reach it. A distributed version uses thousands of hijacked devices, a botnet, to generate that flood.
Botnets accounted for about 7% of cyber threat complaints reported to the FBI in 2025. The damage here is downtime and lost revenue rather than stolen data.
8. Man-in-the-Middle Attacks
The attacker quietly sits between you and the service you are using, reading or altering what passes through. Unsecured public Wi-Fi is the classic setting.
HTTPS everywhere has made this harder than it was a decade ago, which is why attackers increasingly target the session token after login instead of the traffic itself.
9. SQL Injection and Code Injection
Typing database commands into a website input field that was never built to reject them. A login box expecting a username receives instructions to dump the customer table instead.
Still effective after twenty-five years, because it depends on a developer forgetting one line of input validation.
10. Cross Site Scripting
Planting malicious script inside a trusted website so it runs in the browser of everyone who visits. Comment sections and search results are common entry points. The victim never leaves a site they trust, which is exactly what makes it work.
11. Insider Threats
Damage caused by someone who already has legitimate access. Some are malicious, like a departing employee copying client lists. Many are accidental, like a misconfigured cloud bucket left open to the internet.
Personal data breaches produced 67,456 complaints and about $1.31 billion in losses in 2025, and insider mistakes contribute meaningfully to that figure.
12. Supply Chain Attacks
Compromising a vendor to reach the vendor's customers. One break-in, hundreds of victims. Software update mechanisms and managed service providers are the favored routes because both are trusted by design.
13. AI-Enabled Attacks
The newest category, and the fastest moving. In 2025, the FBI added artificial intelligence as a tracked descriptor for the first time, recording 22,364 AI-related complaints and $893.3 million in losses.
Covered in depth in the AI section below.
Most Common vs. Most Costly: Two Very Different Rankings
Security awareness training usually ranks attacks by how often they happen. Budget decisions should rank them by what they cost. Those two lists barely overlap, and the gap is where most organizations misallocate their spending.
Both columns below come from the same FBI IC3 dataset for calendar year 2025.
Attack type
Complaints filed
Reported losses
Average loss per complaint
Phishing / spoofing
191,561
$215.8 million
~$1,127
Extortion
89,129
$122.5 million
~$1,374
Personal data breach
67,456
$1.31 billion
~$19,493
Tech support scams
47,794
$2.13 billion
~$44,664
Business email compromise
24,768
$3.05 billion
~$123,006
Ransomware
3,611
$32.3 million
~$8,950
Malware
893
$19.4 million
~$21,691
Three things jump out.
Phishing leads by volume and lags badly by value. It is the most reported attack in America and ranks nowhere near the top by dollars. It is the doorway, not the destination.
BEC is the quiet giant. Fewer than 25,000 complaints, over $3 billion gone. An attack that requires no malware at all costs American businesses more than every ransomware incident combined, by a factor of roughly ninety.
Phishing losses are climbing fast even as complaints fall. Reported phishing losses went from about $70 million in 2024 to $215.8 million in 2025, a jump of roughly 208%, while complaint volume actually dipped slightly from 193,407. Fewer attacks, far more money per attack. Attackers got more selective and more effective at the same time.
For context, total reported losses across all categories reached $20.877 billion in 2025, up 26% from 2024, from 1,008,597 complaints.
The most reported attack and the most expensive attack are not the same one.
How AI Changed These Attacks in 2026
Artificial intelligence has not invented new attack categories so much as removed the friction from old ones. The tells people were trained to spot- awkward grammar, generic greetings, robotic phone voices- are mostly gone.
IBM's 2026 research found that one in four malicious breaches were AI-enabled, and that AI-driven attacks rose 56% year over year. The global average cost of a breach reached a record $4.99 million, up 12%.
Deepfake voice and video fraud
Cloned voices now appear in wire transfer requests and in what the FBI calls distress scams, where a synthetic voice imitates a relative in trouble. American victims reported over $5 million lost to distress scams alone in 2025, and more than $30 million to business email compromise schemes with an AI component.
Voice cloning has also reached job interviews. The FBI documented fake candidates using voice spoofing during remote interviews, where lip movement failed to match the audio. The goal there was not money directly. It was network access.
Cloned voices have moved from novelty to a documented fraud technique.
AI-generated phishing at scale
Generating a thousand personalized, well-written phishing emails used to take a team. It now takes a prompt. Romance and confidence scams with an AI link cost victims over $19 million in 2025, and employment scams with an AI element added nearly $13 million more.
Prompt injection against business AI tools
The newest surface. Hidden instructions are planted in a document, a webpage, or an email, and the company's own AI assistant reads and obeys them. The employee never sees the instruction. The tool acts on it anyway.
Attackers follow two things: money and urgency. Sectors with both get hit most.
Critical infrastructure takes the heaviest ransomware pressure, because hospitals, utilities, and municipal systems cannot tolerate downtime and are more likely to pay.
Financial services and real estate absorb the worst BEC damage, since large wire transfers are routine and a redirected payment looks normal until it clears.
Healthcare carries unusually expensive breaches, because patient records are valuable and disclosure rules are strict.
Small businesses are targeted constantly and defended least. There is no security team, and the same phishing email that an enterprise filter would catch lands directly in the owner's inbox.
Older Americans carry a disproportionate share of the financial damage. FBI data shows complainants aged 60 and above filed 201,266 complaints in 2025 and lost about $7.7 billion, well over a third of the national total.
How to Defend Against Each Attack Type
Generic advice does not help much here, so this maps defenses to the specific attacks they stop.
1. Against phishing, smishing, and vishing: use phishing-resistant multi-factor authentication such as a hardware key or passkey. SMS codes can be intercepted. Hardware keys cannot be phished.
2. Against BEC: require voice verification through a previously known number before any payment detail changes. Never use contact details supplied in the request itself.
3. Against vulnerability exploitation: patch internet-facing systems first, especially VPNs, firewalls, and edge appliances. These are where attackers look first.
4. Against ransomware: keep offline or immutable backups and test a restore. A backup nobody has restored is a theory, not a plan.
5. Against credential attacks: use a password manager, unique passwords everywhere, and check your accounts against known breach data.
6. Against SQL injection and XSS: validate and sanitize every input server side. This is a development standard, not an optional hardening step.
7. Against insider threats: grant the least access each role needs and revoke it the day someone leaves.
8. Against supply chain attacks: know which vendors hold access to your systems and what happens if one of them is breached.
9. Against AI-enabled attacks: agree on a verbal code phrase with family and finance staff for urgent requests. A cloned voice cannot guess a word it never heard.
Most security frameworks group attacks into four families: malware, social engineering such as phishing, network attacks like DDoS and man in the middle, and application attacks like SQL injection. Every specific attack fits into one of these four.
Phishing, by a wide margin, in reported complaints. The FBI logged 191,561 phishing and spoofing complaints in 2025, more than any other single category.
As of 2026, exploiting a software vulnerability is the leading entry point at 31% of breaches, ahead of stolen credentials at 13%. Phishing remains a major route but is no longer the automatic answer.
Ransomware is one type of malware. Malware is the whole family of malicious software. Ransomware is the branch that encrypts your files and demands payment.
Attacks that use artificial intelligence to scale or improve deception, including cloned voices, deepfake video, mass personalized phishing, and prompt injection against company AI tools. The FBI recorded 22,364 AI-related complaints in 2025.
The Bottom Line
The different types of cyberattacks are not equally dangerous, and the ones that dominate the headlines are not the ones that dominate the losses. Phishing floods inboxes while business email compromise quietly moves billions. Ransomware barely registers in complaint counts while shutting down hospitals.
Two habits cover most of the risk: verify money requests through a channel the sender did not choose, and patch anything facing the internet before you do anything else. Neither is exciting. Both are cheaper than the alternative.
Which of these attacks has come closest to catching you or your company? Share it in the comments, and send this to whoever handles your payments.
Published by AI Learning 360
AI Learning 360 Editorial Team
Published by AI Learning 360, a resource that produces source-based artificial intelligence and technology guides for beginners, students, and working professionals. This guide draws on primary data from the FBI Internet Crime Complaint Center, Verizon's Data Breach Investigations Report, and IBM's Cost of a Data Breach research.
Stay Ahead of New Cyber Attacks
Get plain-English breakdowns of new attack types and AI security threats as the data lands.