Quick Summary
Covering the latest research from top Wall Street investment banks

AI May Amplify the Macro Cost of Cyberattacks in the U.S.

Institution
Goldman Sachs
Date
2026-05-12
Authors
Jessica Rindels
Company
-
Ticker
-
Industry
Macroeconomics / Cybersecurity / AI
Rating
-
NeutralLow confidenceThe report argues that AI models will be more favorable to attackers in the near term, potentially leading to faster, larger-scale, and more sophisticated cyberattacks, and increasing direct losses, response and recovery costs, cybersecurity spending, and regulatory costs.
AuthorsJessica Rindels
Business segmentsCybersecurity、AI models、Critical infrastructure、Corporate IT spending、Federal cybersecurity spending
Research firm divisions/subsidiariesGoldman Sachs(Other)

AI summary card

AI May Amplify the Macro Cost of Cyberattacks in the U.S.

Goldman Sachs estimates total U.S. cyberattack costs at about $300 billion in 2025, or roughly 1% of GDP, and expects AI-assisted attacks to significantly push those costs higher over the next few years.

This report is a macro thematic study and does not provide individual stock ratings, target prices, or upside.
U.S. macroCybersecurityAI riskCritical infrastructureCorporate IT spendingRegulatory costs
  • AI models lower the barrier to attack, enabling attackers to discover and exploit software vulnerabilities faster and at lower cost.
  • The direct monetary loss from cyberattacks is only part of the total cost; it also includes productivity losses, downstream spillovers, recovery and response costs, regulatory fines, and cybersecurity spending.
  • The report estimates total U.S. cyberattack costs in 2025 at about $300 billion, including roughly $53 billion in adjusted direct losses, about $163 billion in response, recovery, and business interruption costs, and about $91 billion in cybersecurity spending.
  • AI can also strengthen defense through automated threat detection, faster response, and simulated attacks to identify vulnerabilities in advance, but in the near term the net effect may still lean toward attackers.
  • If a cyberattack hits critical infrastructure or a widely used technology platform, potential losses could be meaningfully larger than those from a normal technical outage.

Report interpretation

Overview

This report discusses how AI development affects cyber risk and estimates the potential macroeconomic cost of cyberattacks on the U.S. economy. It first reviews common cyberattack types and recent cases, then analyzes how AI can strengthen both attack and defense capabilities, and finally folds direct losses, data breach costs, spillover effects, productivity losses, and cybersecurity spending into a total cost estimate.

Core views

The core view is that cyberattack frequency and cost have risen significantly over the past decade, and AI models further lower the technical and cost barriers for attackers, which may make attacks faster, larger, and more sophisticated in the near term. Over the longer term, if AI defense tools continue to improve and reduce exploitable vulnerabilities, the balance between offense and defense could eventually shift toward defenders. The report estimates total U.S. cyberattack costs in 2025 at about $300 billion, or around 1% of GDP.

Analysis framework

The report uses a Q&A-style macro framework, combining FBI IC3 reports, IBM, Verizon, HackerOne, the U.S. government budget, industry surveys, and academic research to evaluate attack frequency, direct losses, indirect costs, defense spending, and changes in AI model capabilities. It also uses historical high-impact cyberattack cases, critical infrastructure attack data, losses from outages at major technology platforms, and AI model cyber offense/defense testing results to explain the potential macro transmission channels.

Methodology notes

  • Macro cost estimationBreakdown of total cyberattack cost

    Direct losses, response and recovery costs, business interruption costs, cybersecurity spending

    The report adjusts the FBI-reported direct monetary losses for underreporting, then adds data breach costs, spillover effects on other companies, productivity losses, and public- and private-sector cybersecurity spending to estimate the total economic cost.

  • Risk analysisNet risk judgment for AI offense and defense

    Attackers benefit more in the short term; defenders may benefit over the long term

    The report cites research suggesting that many AI cybersecurity capabilities can be reused by attackers, and that AI may reduce attack costs more than it reduces defense costs, implying a higher net risk in the short term. Over the long run, if defense tools reduce exploitable vulnerabilities, the risk balance may improve.

  • Case comparisonImpact of critical infrastructure and large technology platforms

    Systemic disruption and trust restoration costs

    The report uses critical infrastructure attacks and outages at large technology platforms to show that if a widely used platform suffers a cyberattack, the costs can include not only downtime losses but also data destruction, asset losses, validation work, and long-term trust restoration costs.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • U.S. macroeconomy
    Rising cyberattack costs may act as a tax-like drag
    Strengths
    The report provides a quantifiable total cost framework and combines direct and indirect costs in one assessment.
    Weaknesses
    The incremental impact of AI-assisted attacks is still difficult to estimate precisely, and the report acknowledges that it is too early for a definitive forecast.
    Comparison
    Compared with looking only at FBI-reported losses, the total cost including underreporting, recovery, productivity losses, and security spending is significantly higher.
    Risks
    If attack frequency, regulatory costs, or critical infrastructure incidents exceed expectations, total costs could move even higher.
  • Cybersecurity value chain
    Higher AI risk may strengthen security budgets and tool demand
    Strengths
    Average corporate cybersecurity budgets, federal budgets, and bug bounty spending all point to rising defensive investment.
    Weaknesses
    Higher cybersecurity spending is itself an economic cost and may not fully translate into profit growth.
    Comparison
    AI can improve both threat detection and simulated attack capabilities, but it can also be reused by attackers, making defense needs more complex.
    Risks
    If AI attack capabilities spread faster than defensive capabilities, customer budgets may shift from prevention toward emergency recovery and compliance spending.
  • Critical infrastructure companies
    Downtime, data destruction, and trust restoration costs create higher tail risk
    Strengths
    The importance of critical infrastructure makes security spending and regulatory attention relatively rigid.
    Weaknesses
    Losses from an attack can be highly nonlinear and may spill over to supply chains and downstream companies.
    Comparison
    Even a normal technology outage can cause losses of more than $1 billion; because cyberattacks add data validation and trust restoration complexity, potential losses can be even higher.
    Risks
    Ransomware, zero-day vulnerabilities, and supply-chain attacks may lead to prolonged operational disruption.
  • AI models and software engineering platforms
    Improved model capabilities bring both productivity gains and cyber abuse risks
    Strengths
    Models can be used to automatically detect threats, help fix vulnerabilities, and simulate attacks.
    Weaknesses
    The same capabilities can lower the barrier for attackers by helping with malware development, phishing, and exploit generation.
    Comparison
    The report argues that AI is more likely to favor attackers in the near term, while whether defenders outperform over the long term depends on the maturity of security controls.
    Risks
    The more models can perform complex software engineering tasks, the more they may be used for highly automated cyberattacks.
  • VZ.US, XYZ.US, USE.US
    The securities codes appearing in entity recognition do not constitute investment advice in this report
    Strengths
    These codes can be used as follow-up entities for verification.
    Weaknesses
    The body of the report does not provide fundamental analysis, ratings, or target prices for these securities.
    Comparison
    This report is a U.S. macro and cybersecurity thematic study, not an individual stock coverage report.
    Risks
    Misreading file names or entity-extraction results as stock recommendations could lead to incorrect investment mapping.

Key data

  • Estimated total U.S. cyberattack cost in 2025About $300 billionRoughly 1% of U.S. GDP, including direct losses, indirect costs, and cybersecurity spending.
  • Adjusted direct monetary lossesAbout $53 billionBased on the FBI IC3's reported 2025 losses of $20.9 billion, adjusted for underreporting and ransomware underreporting.
  • Response, recovery, and business interruption costsAbout $163 billionIncludes data breach costs, downstream effects on other businesses, and productivity losses.
  • Cybersecurity spendingAbout $91 billionIncludes about $20.8 billion in federal cybersecurity spending and about $70 billion in private-sector cybersecurity spending.
  • Number of FBI IC3 cyber incident reports in 2025More than 1 millionThe report suggests the actual incidence may be higher because many attacks are never discovered or reported.
  • Average monetary loss per reported attack in 2025About $20,000; AI-related attacks about $40,000The report treats this as a lower-bound cost measure.
  • Average cybersecurity spending of mid-sized and large companies in 2025About $25 millionBased on corporate survey data.
  • Impact of AI-driven cybersecurity automation on data breach costsReduces costs by about $1.9 millionIBM data show that AI security automation can also shorten the time needed to identify and contain a breach.
  • Time to breach by cyber criminalsAbout 29 minutes in 2025, versus about 98 minutes in 2021The report cites CrowdStrike data to show that attack speed has increased significantly.
  • Success rate in AI model cyber offense/defense testingClaude Mythos Preview at about 73%The chart shows that by around 2026, frontier models have materially higher success rates in simulated enterprise cyberattack challenges.

Impact & implications

The investment implications mainly run through three channels: macro costs, corporate operating risk, and cybersecurity spending. If AI-assisted cyberattacks increase, companies may face higher costs for protection, compliance, insurance, recovery, and business interruption, and tail risk for critical infrastructure and large technology platforms becomes more pronounced. At the same time, demand may continue to grow for cybersecurity tools, AI-driven threat detection, identity and access management, bug bounty programs, offensive/defensive exercises, and simulated attack capabilities.

Risks

  • AI models may be used by attackers to find and exploit zero-day vulnerabilities more quickly.
  • Actual cyberattack incidence and losses may be underestimated due to underreporting.
  • Attacks on critical infrastructure or major technology platforms may cause long-term losses beyond those of ordinary outages.
  • Higher corporate cybersecurity and compliance spending may compress margins.
  • In the near term, AI defense tools may not fully offset the rise in attack capabilities enabled by AI.
  • Regulatory costs and disclosure requirements may rise after major attack events.

What to watch

  • Trends in the number of cyber incidents and monetary losses reported in FBI IC3 data.
  • The share of total losses attributable to AI-related cyberattacks.
  • Ransomware and data breach incidents in critical infrastructure sectors.
  • Changes in U.S. federal cybersecurity budgets and corporate cybersecurity budgets.
  • Improvements in AI model capabilities for software engineering, vulnerability discovery, and cyber offense/defense testing.
  • Adoption rates for AI-driven security automation, zero-trust architecture, identity and access management, and bug bounty programs.
  • Regulatory requirements for cybersecurity disclosure, data protection, and critical infrastructure defense.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins