Desk live·
ForensicPost
Breaches/Analysis/File 25-0616

The Most Expensive Sector to Be Breached In

Financial institutions recorded the highest average breach cost of any sector at $6.08 million, while direct ransomware attacks on them rose from 156 in 2024 to 202 in 2025.

Constructed geometry · not a chart of case data
TargetFinancial sector
ActorMultiple
S. Rosler11 min readConfidence: medium3 sources reviewed

Published research puts the average cost of a data breach at a financial institution at $6.08 million, the highest of any sector, and records direct ransomware attacks on financial institutions rising from 156 in 2024 to 202 in 2025.

Highest Cost, And It Is Not Mostly The Attack

Finance tops the cost table for reasons largely unrelated to attacker capability. It has the densest regulatory obligations, the most expensive mandatory notification requirements, the highest litigation exposure, and supervisory consequences — examinations, remediation programmes, capital implications — that no other sector carries.

A retailer and a bank suffering identical intrusions produce very different invoices, and the difference is regulation rather than damage. That is worth stating plainly, because the figure is routinely cited as evidence that finance is attacked harder.

156 To 202 Is A Real Number In A Way Most Of These Are Not

This desk spends much of this corpus discounting percentage increases as artefacts of disclosure. This one deserves better treatment: financial institutions operate under the most stringent incident-reporting obligations of any commercial sector, so the count is closer to a census than the equivalent figure in retail or manufacturing.

A roughly 30% rise in a well-observed population is a stronger finding than a doubling in a badly-observed one — the argument made about the healthcare register at 25-0630, applied to a second sector.

The Cost Is Not Where The Risk Is

A $6.08 million average is, for a large institution, an operational expense rather than a threat to viability. The systemic concern in finance has never been the direct cost of a breach.

It is availability: a payment system, a clearing function or a core banking platform stopping. There is no equivalent to the $6.08 million figure for that scenario, because no register measures it — the availability gap this desk filed at 26-0209, in the sector where it would matter most.

This is an analysis file

Built on published sector research, listed below. Cost figures are averages across differing methodologies. Corrections: corrections@forensicpost.com.

Sources
  1. Data breach in financial institutions 2025: a CISO’s guideDeepStrike
  2. Ransomware in financial services: insights and cybersecurity guideInvenio IT
  3. Financial institutions face new and emerging cyber risksMunich Re
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary