Computer Virus Statistics 2026

Computer viruses are no longer just a consumer PC problem. The latest data shows a threat landscape shaped by massive malware volumes, faster delivery methods, more credential theft, and continued ransomware pressure across critical sectors. The numbers below show how large the malware ecosystem has become and how modern attacks now spread through email, exposed services, stolen identities, and trusted platforms.

computer virus statistics
computer virus statistics

Key computer virus statistics

  • AV-TEST says it now registers over 450,000 new malicious programs and potentially unwanted applications per day.
  • Windows malware samples in AV-TEST’s AV-ATLAS database grew from 920 million to 995 million from 2024 to 2025, an increase of 8.15%.
  • AV-TEST also reports over 37 million Android apps infected with malware and 1 million MacOS malware samples.
  • Microsoft says it blocks approximately 4.5 million new malware attempts every day and screens 5 billion emails for malware and phishing.
  • IBM observed an 84% increase in emails delivering infostealers in 2024.
  • IBM says identity abuse accounted for 30% of cases in 2024, while ransomware represented 28% of malware cases.
  • The FBI’s IC3 logged 263,455 cyber threat complaints and $1.571 billion in losses in 2024.
  • IC3 also recorded 4,878 critical infrastructure complaints, and ransomware complaints in critical infrastructure rose 9% from 2023.
  • Fortinet reported a 42% increase in compromised credentials for sale and a 500% increase in credential logs on darknet forums.
  • CrowdStrike found that 79% of detections in 2024 were malware-free, showing that many modern intrusions now rely on stolen access and legitimate tools instead of classic virus payloads.

Malware volume by platform

Classic malware is still overwhelmingly a Windows problem by sheer volume, but Android and Mac threats remain large enough to matter at consumer and enterprise scale.

LabelBarValue
Windows malware samples
 
995,000,000
Android malware apps
 
37,000,000
MacOS malware samples
 
1,000,000

Max = 995,000,000. Widths: Windows malware samples 100.00%, Android malware apps 3.72%, MacOS malware samples 0.10%.

How modern malware campaigns first get access

Email and human manipulation still matter, but exposed web assets and remote services remain major entry points. That means patching and email security have to work together, not separately.

LabelBarValue
Phishing/social engineering
 
28%
Web-facing assets
 
18%
External remote services
 
12%
Supply chains
 
3%

Max = 28. Widths: Phishing/social engineering 100.00%, Web-facing assets 64.29%, External remote services 42.86%, Supply chains 10.71%.

What threat actors are trying to achieve

Modern malware activity is usually tied to money or monetizable data. Even when a ransomware payload is not deployed, data theft and extortion remain core outcomes.

LabelBarValue
Data theft
 
37%
Extortion
 
33%
Human-operated ransomware
 
19%
Infrastructure building
 
7%
Espionage
 
4%

Max = 37. Widths: Data theft 100.00%, Extortion 89.19%, Human-operated ransomware 51.35%, Infrastructure building 18.92%, Espionage 10.81%.

Critical infrastructure sectors with the most ransomware complaints

Ransomware pressure is especially visible in critical infrastructure. Manufacturing, healthcare, and government facilities each posted large complaint counts in the FBI’s latest IC3 data.

LabelBarValue
Critical manufacturing
 
258
Healthcare/public health
 
238
Government facilities
 
220
Financial services
 
190
Information technology
 
138

Max = 258. Widths: Critical manufacturing 100.00%, Healthcare/public health 92.25%, Government facilities 85.27%, Financial services 73.64%, Information technology 53.49%.

What these computer virus statistics mean

The biggest takeaway is that malware volume is still expanding even as attackers increasingly shift toward identity abuse, data theft, and malware-light intrusions. In other words, organizations still have to defend against classic viruses, trojans, spyware, and ransomware, but they also have to protect credentials, browsers, cloud tenants, email systems, and remote access tools.

That change is why the modern computer virus story is no longer just about executable files. It is also about infostealers, credential resale markets, and trusted tools used maliciously. When almost four out of five detections can be malware-free, stopping infection means combining endpoint security with phishing resistance, fast patching, MFA, access control, and better visibility across the environment.

For businesses, the practical lesson is simple: malware defense still matters, but it now has to sit inside a broader identity-first security strategy. For consumers, the same trend means safer browsing habits, software updates, password managers, and phishing-resistant MFA are now just as important as antivirus software.

Sources

  • AV-TEST. Malware Statistics & Trends Report. https://www.av-test.org/en/statistics/malware/
  • Microsoft. Microsoft Digital Defense Report 2025. https://www.microsoft.com/en-us/corporate-responsibility/cybersecurity/microsoft-digital-defense-report-2025/
  • Microsoft. Cybersecurity overview. https://www.microsoft.com/en-us/corporate-responsibility/topics/cybersecurity/
  • IBM. IBM X-Force 2025 Threat Intelligence Index. https://www.ibm.com/thought-leadership/institute-business-value/en-us/report/2025-threat-intelligence-index
  • FBI Internet Crime Complaint Center. 2024 IC3 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
  • Fortinet. 2025 Global Threat Landscape Report. https://www.fortinet.com/resources/reports/threat-landscape-report
  • CrowdStrike. 2025 Global Threat Report Executive Summary. https://www.crowdstrike.com/en-us/resources/reports/global-threat-report-executive-summary-2025/

You cannot copy content of this page

Scroll to Top