Resolution criteria
This market resolves to YES if, at any point before January 1, 2029, a single cyberattack or single coordinated cyberattack campaign is estimated to have caused $30 billion (USD) or more in total damages or economic losses. Otherwise, this market resolves to NO.
Definition of a "Cyberattack": The incident must be a malicious, intentional intrusion, disruption, or exploitation of computer systems, networks, or operational technology by a threat actor (such as ransomware, wiper malware, malware-led supply chain compromises, or state-sponsored infrastructure attacks). Non-malicious IT failures, accidental software updates, or hardware malfunctions (e.g., the July 2024 CrowdStrike outage) do not qualify.
Coordinated Campaign: A series of closely related intrusions using the same malware strain, targeting the identical vulnerability, or executed by the same threat group within a defined timeframe (analogous to the NotPetya or WannaCry campaigns of 2017) will count as a single cyberattack.
Determination of Damages: The $30 billion threshold must be supported by estimates from reputable and authoritative entities, including:
Official government or security agencies (e.g., CISA, FBI IC3)
Multilateral financial institutions (e.g., IMF, World Bank)
Major global insurance, reinsurance, or risk-modeling firms (e.g., Lloyd's of London, Guy Carpenter, PCS, Parametrix)
Consensus reporting by major financial news outlets (e.g., Reuters, Bloomberg, The Wall Street Journal)
Timing: The cyberattack must occur before January 1, 2029. If the attack occurs near the end of 2028 but reliable damage estimates crossing the $30 billion threshold are not published until early 2029, the market will resolve to YES once those authoritative estimates become public.
Creator Discretion: If conflicting estimates exist, the market will resolve based on the consensus of major reporting. The market creator will have final discretion in assessing whether the $30B threshold has been met based on these public estimates.
Background
To date, the costliest malicious cyber incidents in history have generally hovered around the $10 billion mark. The 2017 NotPetya wiper malware campaign, which severely disrupted global shipping, logistics, and pharmaceutical giants, is widely cited as the most expensive single cyber incident on record, causing an estimated $10 billion in damage. More recently, the 2023 MOVEit SQL-injection supply chain exploit was estimated to have cumulative industry-wide impacts reaching up to $10 billion.
While aggregate global cybercrime costs are already measured in the trillions of dollars annually, a single cyberattack causing upwards of $30 billion in damages would represent an unprecedented, systemic escalation—likely involving the prolonged disruption of critical infrastructure, global financial networks, or massive software supply chains.