Guide

Malware statistics, honestly

Most malware statistics circulating online have no source and no date attached. Here is where the credible numbers come from, and which of them actually matter if you run a website or a server.

Before you publish this page

Every figure below is deliberately left blank. Malware statistics go stale within months and a wrong number is worse than none, so each slot names the report to take the figure from and the year to cite. Fill them in, link the source, and delete this box. Re-check them annually.

Numbers about malware get quoted loosely, and most of the ones circulating online have no source attached. This page is a short, honest look at what the credible annual reports actually measure — and what those measurements mean if you run a website or a server.

Where reliable malware data comes from

There is no single authority counting malware. The figures worth citing come from organisations publishing methodology alongside their numbers:

  • Verizon Data Breach Investigations Report (DBIR) — annual, based on real incident data. Good for how breaches begin and how long they go unnoticed.
  • Sucuri Hacked Website Report — specifically about compromised websites: what was found on them, which CMS platforms, which families of malware.
  • Google Transparency Report (Safe Browsing) — how many sites are flagged as unsafe, and how many warnings users are shown.
  • ENISA Threat Landscape — the EU agency's annual overview of attack trends.
  • UK Cyber Security Breaches Survey — a UK government statistical release, useful because it is broken down by business size.
  • AV-TEST Institute — maintains a running count of newly registered malware samples.

The numbers that actually matter to a site owner

Global malware sample counts make for big headlines and tell you almost nothing useful. If you run a handful of websites, these are the measures worth tracking:

How many websites are compromised

FIGURE NEEDED — number of sites Google Safe Browsing currently flags as unsafe. Source: Google Transparency Report, cite the retrieval date because it updates continuously.

Which platform is most affected

FIGURE NEEDED — share of cleaned websites running WordPress. Source: latest Sucuri Hacked Website Report. Worth pairing with the caveat that WordPress's share of infections largely tracks its share of the web rather than proving it is less secure.

How infections start

FIGURE NEEDED — proportion of compromises traced to out-of-date software or a known, already-patched vulnerability. Source: Sucuri or Verizon DBIR.

How long compromises go unnoticed

FIGURE NEEDED — median dwell time between initial compromise and discovery. Source: Verizon DBIR. This is usually the most persuasive statistic on the page, because it is far longer than most owners assume.

How often cleaned sites get reinfected

FIGURE NEEDED — reinfection rate following a cleanup that did not include hardening. Source: Sucuri, or your own case data once you have enough of it.

Use your own numbers where you can

First-party data is more defensible than a borrowed statistic and cannot be challenged as out of date. Once you have enough cleanups behind you, figures like the most common backdoor location, or the share of servers where more than one site was affected, are genuinely yours to publish.

Reading malware statistics without being misled

  • Check the year. A 2019 figure quoted as current is one of the most common errors in this subject.
  • Check what is being counted. Malware samples, infected devices and compromised websites are three different things with wildly different magnitudes.
  • Check who benefits. Vendor reports are useful, but a number produced by a company selling the remedy deserves the same scrutiny you would apply to ours.
  • Beware round numbers. Figures that are suspiciously tidy have usually been through several rounds of paraphrasing.

What the trend lines agree on

Individual numbers vary between sources, but the direction of travel is consistent across all of them, and it does not require a citation to state plainly: attacks on websites are overwhelmingly automated, they target known weaknesses rather than specific victims, and the gap between a vulnerability being published and being exploited at scale keeps shrinking. We look at why in why malware attacks are increasing.

Rather find out whether your own site is clean than read another statistic?

Related guides

Unlimited malware removal, for one monthly price.

We clean websites and VPS servers as often as it happens, monitor them 24/7, and harden them so it doesn't happen again.

Book a demo