# Chart Index — California Cybersecurity Risk Report 2027

Files in charts/. Regenerate with scripts/make_charts.py. Values below are the complete underlying data for each chart; the website team should use these exact values for any re-rendering.

---

## CH-01 — Internet crime complaints filed by Californians, 2022–2025

- **File:** charts/CH-01_ca_ic3_complaints.png
- **Type:** Vertical bar, single series
- **Data:** 2022: 80,766 | 2023: 77,271 | 2024: 96,265 | 2025: 116,414
- **Source line:** Source: FBI IC3 annual reports 2022–2025. Chart: intSignal Research.
- **Caption:** After holding roughly flat through 2023, complaint volume from Californians rose 24.6 percent in 2024 and another 20.9 percent in 2025 to 116,414 — the most of any state.
- **Claims:** C-001, C-002, C-009
- **Alt text:** Bar chart of yearly internet crime complaints filed by Californians with the FBI. 2022: 80,766. 2023: 77,271. 2024: 96,265. 2025: 116,414, shown in dark blue to highlight the most recent year. The trend is flat through 2023 and then rises steeply.
- **Placement:** Report section 4.

## CH-02 — Reported cybercrime losses by Californians, 2023–2025

- **File:** charts/CH-02_ca_ic3_losses.png
- **Type:** Vertical bar, single series
- **Data (USD billions):** 2023: 2.16 | 2024: 2.539 | 2025: 3.675 (exact 2024: $2,539,041,635; exact 2025: $3,674,716,305)
- **Note:** 2022 omitted deliberately — the FBI published that year's California loss only as "more than $2 billion"; charting an approximation would overstate precision.
- **Source line:** Source: FBI IC3 annual reports 2023–2025. Chart: intSignal Research.
- **Caption:** California's reported losses rose 17.5 percent in 2024 and then 44.7 percent in 2025, reaching $3.67 billion — roughly $10.1 million per day and double second-ranked Texas.
- **Claims:** C-001, C-002, C-003, C-009, C-012
- **Alt text:** Bar chart of yearly reported cybercrime losses by Californians. 2023: $2.16 billion. 2024: $2.54 billion. 2025: $3.67 billion, shown in dark blue. The final bar shows a sharp jump.
- **Placement:** Report section 4.

## CH-03 — Days from breach occurrence to California AG notification

- **File:** charts/CH-03_ag_notification_lag.png
- **Type:** Vertical bar, distribution buckets (n = 1,442 notices, reported Jan 2024 – Aug 2026)
- **Data (notices; share):** 0–30 days: 61 (4%) | 31–60: 135 (9%) | 61–90: 162 (11%) | 91–180: 378 (26%) | 181–365: 476 (33%) | 366+: 230 (16%)
- **Median:** 174 days (174.5 exact). Buckets over 180 days are colored red to mark the long tail.
- **Source line:** Source: intSignal Research analysis of CA AG data breach register (accessed 2026-08-25).
- **Caption:** Across 1,442 breach notices with usable dates filed with the California Attorney General from January 2024 through August 2026, the median gap between breach occurrence and notification was 174 days. Only 4.2 percent of notices arrived within 30 days of the breach; 49 percent took more than six months. The gap measures the exposure window, not legal compliance — the statutory clock runs from discovery, not occurrence.
- **Claims:** C-010, C-011
- **Alt text:** Bar chart showing how many days elapsed between a data breach occurring and its notice reaching the California Attorney General, for 1,442 notices from January 2024 through August 2026. 0 to 30 days: 61 notices, 4 percent. 31 to 60 days: 135, 9 percent. 61 to 90 days: 162, 11 percent. 91 to 180 days: 378, 26 percent. 181 to 365 days: 476 notices, 33 percent, in red. More than a year: 230 notices, 16 percent, in dark red. Most notices arrive months after the breach.
- **Placement:** Report section 5.
