The team behind the closely watched Verizon Data Breach Investigations Report has released its first Breach Impact Study, and the findings should get the attention of anyone running a collection operation. The median cost of a cyber incident nearly doubled between 2019 and 2024, and small businesses are absorbing losses that hit far harder relative to their size than those suffered by large enterprises.
The study, produced with cyber insurance data consortium CyberAcuView, analyzed roughly 70,000 U.S. cyber insurance claims filed between January 2019 and October 2025, including about 38,000 with recorded payouts. Half of all paid claims exceeded $83,000. The top 10% topped $920,000, and the most extreme 2.5% blew past $5 million.
The trend line is what matters. The median claim rose from roughly $60,000 in 2019 to $110,000 in 2024, an 80% increase over a period when inflation ran about 23%. Breaches are not just keeping pace with rising costs. They are getting genuinely more expensive.
Why this matters for the accounts receivable management industry: most collection agencies fall squarely into the study’s small business segment, defined as companies with less than $25 million in revenue, and that is where the pain is concentrated. The median SMB claim was a manageable-sounding $38,000, but in the top 10% of cases losses reached 3% of annual revenue, and in the most extreme cases they exceeded 7%. Large enterprises never saw losses top 2% of revenue, even in their worst cases. For an agency holding sensitive consumer financial data on thin margins, a bad breach is not an IT problem. It is an existential one.
The attack mix will sound familiar. Ransomware accounted for 39% of SMB claims and BEC another 19%, the same threats that have dominated the broader threat landscape for years. Business interruption has quietly become the single largest loss driver, growing from 21% of known losses in 2023 to 32% in 2024, a signal that downtime, not just data theft, is where the money bleeds out.
One more finding worth sitting with: organizations that last benchmarked their cyber insurance coverage before 2023 may be working from a loss model that no longer reflects reality. The study’s authors suggest the real question is not whether to carry coverage, but whether existing policy limits account for the long tail of outcomes rather than just the median case.
.




