Fact Check: Does cybercrime (really) cause three times as much damage as all natural disasters combined?

A claim currently circulating suggests that cybercrime causes three times as much financial damage worldwide as all natural disasters combined.thebrokernews verified this figure and arrived at a clear—yet surprising—conclusion. This […]


thebrokernews checked the figure—with a clear and surprising result.

thebrokernews checked the figure with a clear and surprising result.

thebrokernews checked the figure with a clear and surprising result.

A claim currently circulating suggests that cybercrime causes three times as much financial damage worldwide as all natural disasters combined.thebrokernews verified this figure and arrived at a clear—yet surprising—conclusion.

This claim regularly circulates in the media and at IT security conferences, though usually without citing a specific source. When searching for a media report, study, or institution that specifically cites this “three” figure, it becomes difficult: no such source could be identified. However, a 2023 documentary by the broadcaster arte states that “one in three Germans has been the victim of a successful cyberattack at some point” and that “researchers estimate that the annual damage caused by cyberattacks costs more than that caused by natural disasters.” And so, “one in three Germans” could translate into financial damage three times higher than that caused by natural disasters.

Where the comparison comes from

Cybercrime:

This figure is typically based on estimates from Cybersecurity Ventures, which suggests that cybercrime causes approximately $10.5 trillion in global damages and associated costs annually (with a projected increase to $12.2 trillion by 2031). This figure includes not only direct thefts or ransom payments, but also downtime, lost productivity, reputational damage, and forensic cleanup efforts. Cybersecurity Ventures itself merely states that the damage is “exponentially greater” than that caused by natural disasters. The source does not provide a specific multiplier figure.

Natural Disasters:

According to analyses by major reinsurers such as Swiss Re and Munich Re, total global losses from natural disasters amount to approximately 250 to 350 billion U.S. dollars in an average year. This figure is significantly more reliably substantiated than estimates of cybercrime, as it is based on observed loss data rather than projections. Swiss Re estimates total global economic losses (insured and uninsured losses combined) at $318 billion for 2024 and $220 billion for 2025. Munich Re puts the figures for the same years at $320 billion (2024) and $224 billion (2025), respectively.

The relation:

If we compare the $10.5 trillion to the $250 to $350 billion in damage caused by natural disasters, the calculated cyber damage would be many times higher than just three times that amount—more in the range of a factor of 30 to 40. The Swiss Cyber Security Days also cite a specific factor in this context: In an interview with Nicolas Mayencourt (CEO of Dreamlab Technologies), it is noted that natural disasters caused approximately $125 billion in damage in 2022, while cybercrime amounted to $5,000 billion. A cyberattack is thus forty times more costly than a natural disaster.

It should be noted, however, that the same expert cited a different figure at a later press conference during the Swiss Cyber Security Days (early 2025): There, he mentioned eight trillion Swiss francs in cyber damage worldwide per year, twenty times more than all natural disasters combined. The multipliers cited thus vary considerably even within the same source and conference series. This is further evidence that these are model estimates and not established facts.

The “3x” claim -if it refers to these orders of magnitude at all – is thus far below what even the cyber industry’s own model calculations yield.

Why the comparison doesn’t hold up

Comparing apples and oranges:

These two sets of figures are therefore hardly comparable from a methodological standpoint. Experts also criticize the projections on cybercrime, noting that they are difficult to verify because, for example, Cybersecurity Ventures does not disclose the methodology on which they are based.

More Realistic Cyber Statistics:

More conservative think tanks and economists such as the CSIS (Center for Strategic and International Studies), which, in collaboration with McAfee, most recently estimated the global cost of cybercrime at around 600 billion U.S. dollars, or more conservative projections by industry media based on that figure tend to estimate the actually measurable global damages caused by cybercrime at between 1.2 and 1.5 trillion U.S. dollars per year. Based on this more conservative estimate, the gap between this figure and the $250 to $350 billion in damage caused by natural disasters would narrow to a factor of about 4 to 6, bringing it closer to the commonly cited “3x” claim, though it still does not match it exactly.

For the DACH region, Bitkom’s “Economic Security” studies provide more specific, annually collected figures: The total damage caused by theft, espionage, and sabotage in Germany amounted to 266.6 billion euros in 2024, of which 178.6 billion euros was attributable to cybercrime. According to Bitkom, 2025 will even see a new record high of approximately 289.2 billion euros per year; see also the press release from the Federal Office for the Protection of the Constitution announcing the study.

The risk assessments conducted by companies themselves are also well-documented. Here, the trend is now even more evident than it was in 2024: In the current Allianz Risk Barometer 2026 For the fifth consecutive year, cyber incidents are the world’s biggest corporate risk, with the highest recorded percentage to date, 42 percent of responses, and a lead of ten percentage points over the second-ranked risk. Natural disasters have slipped to fifth place in the same ranking, partly due to a calmer hurricane season in 2025. As early as Allianz Risk Barometer 2024 For the third consecutive year, and for the first time by a significant margin, cyber incidents were the top global risk, while natural disasters rose from sixth place to third. The “third consecutive series” mentioned in the 2024 report is likely the actual source of the “3” association in the circulating claim, but it refers to a series of rankings spanning several years, not to a specific risk factor. With the updated 2026 figure (fifth consecutive series), this reference is now obsolete anyway.

Situation in Switzerland

In Switzerland, these trends are reflected on a smaller scale: Damage from severe weather—such as floods or mudslides causes hundreds of millions of francs in property damage each year. At the same time, according to the Federal Office for Cybersecurity (BACS) and Swiss Crime Prevention, ransomware incidents and online fraud have become one of the greatest risks for SMEs and government agencies, as system outages and extortion can result in massive economic losses in some cases. However, a reliable, directly comparable total figure for cybercrime-related losses in Switzerland—which would allow for a comparative analysis with natural disaster damage is not yet available.

On August 26, a massive glacier collapse triggered a devastating flash flood in Nepal and Tibet, leaving at least 270 people dead and more than 1,300 missing; a massive flash flood in the Himalayas swept away many people and entire villages. Among them are hundreds of missing tourists.

Don’t forget to fact-check

The claim that cybercrime causes three times more damage than all natural disasters combined could not be confirmed in any study or media report found using this exact wording. It appears to be based on a common but imprecise conflation of two things: a model estimate from the IT security industry (10.5 trillion U.S. dollars, Cybersecurity Ventures) and a ranking from the Allianz Risk Barometer, which has classified cybercrime as the top risk for the third consecutive year. Depending on which cybercrime estimate is used, the resulting multiplier is either significantly higher (30 to 40, based on the Cybersecurity Ventures figures) or significantly more moderate (4 to 6, based on the more conservative CSIS estimates). Neither data set supports a clean factor of three. The statement thus primarily reflects model assumptions and not a direct comparison of property damage measured using equivalent methods.

Binci Heeb

See also: Cyber Threats Remain the Top Risk for Businesses


Tags: #Claim #Comparison #Cybercrime #Damage #Fact Check #Relation