California Leads the Nation in Cybercrime Losses — and the Gap Is Widening

The largest target, pulling away
California is the largest single target of cybercrime in the United States, and in the most recent year of complete federal data the gap between California and everywhere else widened sharply. In 2025, Californians filed 116,414 complaints with the FBI's Internet Crime Complaint Center and reported $3.67 billion in losses — first in the nation on both measures.
The direction matters as much as the total. Reported losses grew 44.7 percent in a single year, more than twice the state's 20.9 percent growth in complaint volume. Each incident is getting more expensive, not just more common. Averaged across the year, Californians reported losing roughly $10.1 million to internet crime every day.
These are the headline findings of the California Cybersecurity Risk Report 2027 from intSignal Research — an evidence-backed analysis built entirely on public data, with every figure traced to its source.
Disproportionate even for its size
California's exposure is outsized even after accounting for its population and economy. The state generated 11.5 percent of the nation's complaints but 17.6 percent of its reported losses, and its average reported loss per complaint — $31,566 — ran 52 percent above the national average of $20,699. On a per-resident basis, California ranked first among all fifty states at $93.37 per resident, and its total was 2.0 times second-ranked Texas.
Notably, California's complaint rate per resident is unremarkable — 13th among states. That is another way of seeing the core finding: California's problem is less that more people are victimized than that victimization in California costs far more per incident.
Where the losses concentrate
Two channels dominate:
- Cryptocurrency. Complaints with a cryptocurrency connection accounted for $2.10 billion — 57 percent of everything Californians reported losing.
- Older residents. Californians aged 60 and over reported $1.40 billion in losses — 38 percent of the state total from 19 percent of complaints.
The report also contributes an original analysis of California's own breach-notification record — 1,536 notices to the Attorney General — finding that breaches surface a median of 174 days after they occur, and that single vendor incidents cascade into notices from dozens of organizations at once.
What businesses should take from it
For California's small and mid-market businesses, the practical implications concentrate on a short list: identity and email controls, payment-verification habits, patching of internet-facing systems, vendor risk, and recoverable backups. Every item on it starts with knowing your own environment — which systems are unpatched, which accounts never had MFA enabled — and that is easier for a team without dedicated security staff when endpoint, identity, and vulnerability risk sit in one view rather than a separate console per tool. We break those into six security priorities for 2027, each tied to the evidence.
One caution runs through every figure: IC3 data measures only what victims report, and the FBI has estimated that in at least one case only about 20 percent of a group's victims came forward. Every number here is a floor, not an estimate of true losses.
Read the full analysis — including methodology, limitations, charts, and the downloadable evidence package — in the California Cybersecurity Risk Report 2027.
The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research, where each is traced to its source, method, and limitations.


