Which US States Are Most At Risk From Cyber Attacks? 

Global cyber crime costs are projected to soar from $9.22 trillion in 2024 to $13.82 trillion by 2028. In the United States alone, these costs are forecasted to exceed $452 billion in 2024. 

Alarmingly, in 2023, three in four companies in the United States were at risk of a material cyber attack.

With this in mind, cyber security and compliance company  Kiteworks has sought to identify the US states where businesses are most at risk of cyber attacks. 

To do so, the company created a points-based index which analysed a variety of factors such as annual victim counts, financial losses from cyber attacks, increases in both victims and losses, and the types of cyber attacks experienced.

Key findings for Most at Risk Top 4 States:

  • Colorado is the state where businesses are most at risk of cyber attacks, with a risk score of 7.96. Colorado has seen a 58.7% increase in victim losses since 2017.
  • With the highest population of 38 million, California’s annual cyber attack losses amount to over $656 million (656,847,391).
  • The state of Missouri has the biggest four-year moving increase in financial losses attributed to cyber attacks, with a 136% increase since 2017.
  • Virginia is the only state to see a decrease in cyberattack victims since 2017, with a decrease of 10.8%.

source: Kiteworks

Colorado is the state where businesses are most at risk of cyber attacks, with a risk score of 7.96 out of 10. Despite its mid-sized population of 5,877,610, Colorado experienced the highest rate of cyber attacks since 2017 and has reported 10,776 annual victims from 2020. 

Despite only seeing a moving increase of 3.8% in victims since 2017, the state has faced significant financial losses due to cyberattacks, with a 58.7% increase in losses since 2017, amounting to $104,476,603. 
This is 65% higher than in the neighbouring state of Utah ($53,047,234). 

This could be due to Colorado’s ageing population, as reports show people over the age of 75 are most likely to report repeat cybercrime victimisation.

New York is in second place, with a risk score of 7.84 out of 10. As the fourth most populous state with 19,571,216 residents, New York reported 27,205 annual victims between 2020-2023. By contrast, Massachusetts reported one third the number of victims (8,749) over the same period as New York. New York has seen a 14.4% increase in victims over four years, with reports showing cyberattack complaints up 53% since 2022. 

The financial losses from cyberattacks in New York state have also surged by 75.7%, totalling a staggering $440,673,485 lost. 

Nevada ranks third with a risk score of 7.62 out of 10, reflecting the state's growing vulnerability to cyber attacks. With a population of 3,194,176, Nevada reported 10,551 annual victims from 2020 to 2023.  The state has experienced a significant 27.6% increase in victim counts over four years, indicating a rapid rise in cybercrime incidents. Just earlier this year, the state's Gaming Control Board’s website was hit with a cyberattack, resulting in the site being offline for several days. 

The financial losses from cyber attacks have risen in Nevada by 25.2% since 2017, totaling to $44,994,168, 72% more than the neighbouring state of Idaho ($12,427,049).

The Most Common Cyber Attacks

Business Email Compromise:  (BEC) is the cyber attack in the United States with the highest financial impact, with losses exceeding $1 billion ($1,747,924,931) since 2020 and an average loss of $88,350 per incident. 
BEC attacks involve fraudsters impersonating business executives or employees to deceive victims into transferring funds or revealing sensitive information. 

Credit Card & Cheque Fraud: Ranking second, causing $516,046,155 in total losses and an average loss of $27,039 per incident. This fraud typically involves unauthorised use of payment information. 
Malware Attacks, in third place, have resulted in losses of $237,469,021 with an average loss of $83,235 per incident.

Non-payment/Non-delivery attacks:  Are amongst the most common US online threat since 2020 with 60,113 incidents, which involve victims being deceived and into paying for undelivered goods or services. 

Personal data breaches: Another very common form of attack, with 40,523 incidents, which can involve unauthorised access to sensitive information often leading to identity theft and fraud.

Kiteworks' VP of Marleting & Reserach, Patrick Spencer, commented “Our study reveals a concerning trend: cyberattacks are on the rise, both in frequency and financial impact. As cyber threats continue to evolve, proactive investment in advanced security technologies and employee training can significantly enhance a company's resilience against cybercrime, as well as a greater focus on data security."

“Businesses should adopt a content-defined zero trust approach to secure their sensitive communications... By consolidating email, file sharing, SFTP, managed file transfer, and web forms into a private content network protected by a hardened virtual appliance, organisations can ensure that sensitive content is only accessed by authorised users... 

This approach provides advanced security, comprehensive governance, and regulatory compliance, ensuring the protection of sensitive content.” Spencer advises.

Image: Ideogram

You Might Also Read: 

High Stakes: Business Email Compromise:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Attack On Transport For London Exposed Passenger Bank Details
Meta Bans Russian Media From Facebook »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

FarrPoint

FarrPoint

FarrPoint is a specialist telecoms consultancy providing a range of services including cyber security assessments and technical assurance to safeguard your data.

Institute for Cyber Security Innovation - Royal Holloway

Institute for Cyber Security Innovation - Royal Holloway

The Institute for Cyber Security Innovation aims to bring together Academia, Industry and Government to be a catalyst for applied research and innovation in cyber security policy and solutions.

Romanian Association for Electronic Industry & Software (ARIES)

Romanian Association for Electronic Industry & Software (ARIES)

ARIES is the Romanian Association for Electronic Industry and Software, the biggest and most influental organization created for the IT&C industry in Romania.

Inky Technology Corp

Inky Technology Corp

Inky® Phish Fence is an email protection gateway that uses sophisticated AI, machine learning and computer vision algorithms to block deep sea phishing attacks that get through every other system.

iONLINE

iONLINE

iONLINE delivers high quality IT services and solutions to businesses in Azerbaijan.

Dracoon

Dracoon

DRACOON is market leader in the German-speaking region for secure enterprise file sharing.

Smart Contract Security Alliance

Smart Contract Security Alliance

The Smart Contract Security Alliance supports the blockchain ecosystem by building standards for smart contract security and smart contract audits.

Crypsis

Crypsis

Crypsis was built based on a shared vision of creating a more secure digital world by providing the highest quality incident response, risk management, and digital forensic services.

Wiser Market

Wiser Market

Wiser Market is a leading company in global online brand protection services, intellectual property protection, anti-Counterfeit & trademark infringements.

State Service of Special Communications & Information Protection of Ukraine (SSSCIP)

State Service of Special Communications & Information Protection of Ukraine (SSSCIP)

State Service of Special Communications and Information Protection is the technical security and intelligence service of Ukraine, under the control of the President of Ukraine.

Midwest Cyber Security Alliance (MCSA)

Midwest Cyber Security Alliance (MCSA)

Midwest Cyber Security Alliance is a nonprofit, nonpartisan collaboration of individuals, businesses, government entities, and professionals advocating for more effective cyber security solutions.

Seemplicity

Seemplicity

Seemplicity revolutionizes the way security teams work by automating, optimizing and scaling all risk reduction workflows in one workspace.

CyBourn

CyBourn

Cybourn's diverse offerings include engineering, analysis, product development, assessment, and advisory services in the cybersecurity space.

Cypago

Cypago

Cypago provides a powerful yet easy-to-use Compliance Orchestration Platform to automate the compliance process end-to-end.

SyberFort

SyberFort

SyberFort offers a suite of SAAS-based platforms designed to fortify your digital defenses including Threat Intelligence and Brand Protection.

Winslow Technology Group (WTG)

Winslow Technology Group (WTG)

Winslow Technology Group is a leading provider of IT Solutions, Managed Services, and Cybersecurity Services dedicated to providing exceptional business outcomes for our customers since 2003.