true, though arguably it's a good thing. In the sense that it moves more of the costs of malware to the organisations that are meant to be securing the data.
Previously, these costs were more borne by customers/clients/etc, and thus not taken as seriously - abstract costs and externalities.
Putting a clear number of the cost of poor cybersecurity should push more organisations to actually do something about it.