# Table Index — California Cybersecurity Risk Report 2027

## T-01 — California IC3 trend, 2022–2025 (report section 4)

| Year | CA complaints | CA reported losses | CA rank (losses) |
|---|---|---|---|
| 2022 | 80,766 | more than $2.0B | 1st |
| 2023 | 77,271 | $2.16B | 1st |
| 2024 | 96,265 | $2,539,041,635 | 1st |
| 2025 | 116,414 | $3,674,716,305 | 1st |

Source: FBI IC3 annual reports 2022–2025. Claims: C-001, C-002, C-009. Note: 2022 loss displayed at the FBI's published precision and excluded from percentage calculations. Publication rule: do not replace "more than $2.0B" with a specific number.

## T-02 — Vendor cascades in the CA AG breach register (report section 5)

| Breach date signature | Distinct organizations filing | Pattern |
|---|---|---|
| 02/21/2024 | 32 | Pharmaceutical manufacturers and patient-assistance programs notifying after an incident at a shared distribution/services provider |
| 12/13–12/16/2024 | 9 | Affiliated California radiation-oncology practices |
| 11/01/2024 (incl. combined signatures) | 14 | California community health centers tied to shared administrative infrastructure |
| 10/29/2023 | 8 | Life insurers and retirement-plan providers notifying after an incident at a shared benefits-platform vendor |
| 05/30/2023 | 5+ | Organizations downstream of the 2023 mass file-transfer software exploitation |

Source: intSignal Research analysis of the CA AG breach register (accessed 2026-08-25); scripts/analyze_ag_register.py. Claims: C-010, C-013. Publication rules: (a) counts are distinct filing organizations per shared breach-date signature, not affected individuals; (b) the 11/01/2024 figure of 14 combines the exact "11/01/2024" signature (8 orgs) with the "11/01/2024, 10/02/2025" signature (6 orgs); (c) pattern descriptions characterize filer composition without asserting forensic attribution of a specific named vendor as the incident source.
