Skip to main content

CNiC Solutions

Finance professional pausing to verify an email payment request by phone, illustrating business email compromise risk

Business email compromise is the quiet giant of cybercrime. It rarely involves malware or a dramatic breach, yet in 2025 it cost victims $3.05 billion across 24,768 reported complaints, making it the second most expensive cybercrime the FBI tracks. The whole scam runs on one thing: a convincing email that asks someone to move money.

Key Takeaways

  • BEC losses hit $3.05 billion in 2025 across 24,768 complaints, the FBI’s second-costliest cybercrime behind investment fraud (FBI IC3).
  • Losses are still climbing, up from $2.77 billion in 2024, and complaints rose from 21,442 to 24,768 in a single year (FBI IC3).
  • BEC has drained more than $55.4 billion worldwide across 305,000-plus incidents between 2013 and 2023 (FBI IC3 public service announcement).
  • The average reported loss is about $123,000 per complaint, while the median transaction sits near $50,000, so a few huge wires pull the average up (CNiC analysis of FBI IC3 and Verizon DBIR data).
  • BEC is under 2.5% of all cybercrime complaints but nearly 15% of all reported losses, an outsized-impact profile (FBI IC3 2025 totals).
  • Roughly 60% of breaches involve a human element, and BEC exploits it directly through impersonation, not code (Verizon 2025 DBIR).
  • Fast reporting recovers real money: the FBI’s Recovery Asset Team froze more than $507 million in fraudulent domestic wires in 2025 (FBI IC3).

What’s in This Report

BEC Losses in 2025: A Record $3 Billion

The FBI’s Internet Crime Complaint Center, known as the IC3, is the single best public source for BEC data because it collects fraud reports directly from victims across the United States and abroad. Its 2025 Internet Crime Report is the most recent full-year dataset available heading into 2026, and the BEC numbers in it are stark.

In 2025 the IC3 received 24,768 BEC complaints carrying $3,046,598,558 in reported losses. That places BEC second on the entire crime-loss chart, behind investment fraud at $8.65 billion and ahead of tech support scams at $2.13 billion. For a category that almost never makes headlines, BEC quietly out-costs ransomware, data breaches, and every form of extortion combined.

Put in context, total cybercrime losses reported to the IC3 reached $20.877 billion in 2025 across more than one million complaints, a 26% jump from the year before. BEC accounts for a large slice of that total while representing only a sliver of the complaint volume, a pattern that says a great deal about how efficient this scam is at extracting money.

 

 

Infographic of 2025 BEC stats: $3.05B in losses, 24,768 complaints, 2nd-costliest cybercrime, and $55.5B lost since 2013
BEC cost $3.05 billion across 24,768 complaints in 2025, the FBI’s second-costliest cybercrime. (Source: FBI IC3 2025)

 

 

$3.05B
reported BEC losses in 2025, up from $2.77 billion in 2024 (FBI IC3)
24,768
BEC complaints filed with the FBI IC3 in 2025, up from 21,442 the prior year
#2
BEC’s rank among all cybercrime loss categories in 2025, behind only investment fraud
$20.877B
total cybercrime losses reported to the IC3 in 2025, up 26% year over year

Top Five Cybercrime Loss Categories, 2025 (FBI IC3)

Investment fraud
$8.65B
Business email compromise
$3.05B
Tech support scams
$2.13B
Confidence and romance
$0.93B
Government impersonation
$0.80B

See how managed cybersecurity defends against email fraud

Source: FBI IC3 2025 Internet Crime Report

A Decade of Growth: The $55 Billion Trajectory

One bad year would be a problem. A decade of compounding losses is a trend, and BEC is firmly in trend territory. In September 2024 the FBI issued a public service announcement titled “Business Email Compromise: The $55 Billion Scam,” summarizing a full decade of reporting. Between October 2013 and December 2023, the IC3 tallied 305,033 BEC incidents and $55,499,915,582 in exposed losses worldwide.

Within that decade of data, United States victims alone accounted for 158,436 incidents and $20.09 billion in losses. The FBI also flagged a 9% increase in identified global exposed losses in just the twelve months between December 2022 and December 2023, driven in part by fraudsters routing stolen funds through third-party payment processors and cryptocurrency exchanges to move money faster and cover their tracks.

The year-over-year annual figures tell the same story from a different angle. Reported BEC losses have hovered near or above the $2.7 billion mark every year, then pushed past $3 billion in 2025. The scam is not fading as awareness grows; it is adapting.

$55.5B
total exposed BEC losses worldwide, October 2013 to December 2023 (FBI IC3 PSA)
305,033
BEC incidents reported globally across that same decade
$20.1B
exposed BEC losses among United States victims alone (158,436 incidents)

Reported BEC Losses by Year, 2022 to 2025 (FBI IC3)

2022
$2.74B
2023
$2.95B
2024
$2.77B
2025
$3.05B

Source: FBI IC3 Public Service Announcement I-091124-PSA | FBI IC3 2025 Internet Crime Report

Why Each BEC Attack Hits So Hard

The reason BEC ranks so high on the loss chart while staying low on the complaint chart is simple arithmetic: each successful attack steals a lot. This is not a scam that nets a few dollars at a time. It targets the exact moment a business is about to send a large, legitimate-looking payment, then redirects it.

Divide the 2025 losses by the 2025 complaints and the average reported BEC loss lands at roughly $123,000. The Verizon Data Breach Investigations Report, which draws on the same IC3 data, reports a median BEC transaction closer to $50,000. The gap between those two numbers is the whole story: most attacks steal tens of thousands, but a long tail of enormous real estate and vendor wires drags the average far above the middle.

 

 

Infographic showing BEC is under 2.5% of cybercrime complaints but about 15% of losses, with a $123K average versus a $50K median loss
BEC is under 2.5% of complaints but nearly 15% of all cybercrime losses. (Sources: FBI IC3, Verizon DBIR)

 

 

~$123,000
average reported loss per BEC complaint in 2025 (CNiC analysis of FBI IC3 data)
~$50,000
median BEC transaction amount reported by the Verizon DBIR
~15%
of all 2025 cybercrime losses came from BEC, despite it being under 2.5% of complaints

The IBM Cost of a Data Breach Report reinforces the point from the breach side. When BEC escalates into a full data breach through a compromised inbox, phishing was the leading initial attack vector in 2025, averaging $4.8 million per breach and taking 254 days to identify and contain. The email that starts a BEC and the email that starts a breach are often the same email.

Source: Verizon 2025 Data Breach Investigations Report | IBM Cost of a Data Breach 2025

How a BEC Scam Actually Works

Understanding the mechanics is what makes the statistics useful, because BEC is preventable once you see the pattern. The FBI defines BEC as a scam targeting businesses and individuals that perform wire transfers, carried out by compromising or impersonating a trusted email account to request an unauthorized transfer of funds.

There is no exploit and no malware in a classic BEC. The attacker either breaks into a real email account, often using credentials stolen through phishing, or registers a lookalike domain that reads correctly at a glance. From there they watch, learn the language of a pending deal, and strike at the moment a payment is expected with a note that feels routine: new wire instructions, an updated bank account, a rushed request marked confidential.

The most exploited scenarios are consistent year after year. Fraudsters impersonate a real estate agent or title company and reroute a homebuyer’s closing wire. They spoof a known vendor and swap the bank details on a legitimate invoice. They pose as a company executive and pressure the finance team into an urgent transfer. More recently, the FBI notes fraudsters increasingly funnel stolen funds into custodial accounts at financial institutions and cryptocurrency platforms, which makes recovery harder.

 

 

Four-step infographic of how a BEC scam works: compromise an email, study the deal, send an urgent wire request, reroute the funds
BEC follows a predictable four-step pattern built on trust and timing, not malware. (Source: FBI IC3)

 

 

Myth: A Firewall or Antivirus Will Stop BEC

This is the most dangerous misconception about business email compromise. BEC carries no malicious attachment for antivirus to catch and triggers no intrusion alert for a firewall to block, because the email is either sent from a genuine, compromised account or from a convincing lookalike. The attack targets human trust and a business process, not a technical vulnerability. That is exactly why the defenses that work are procedural, verifying payment changes out of band, and identity-based, locking down the inbox with multi-factor authentication, rather than a box on the network.

Artificial intelligence has sharpened every step of this playbook. In 2025 the FBI logged more than $30 million in losses to BEC scams that involved AI, where chat generators produced flawless executive-sounding emails and voice cloning was used to phone in wire requests. IBM found that generative AI has cut the time to write a convincing phishing email from as long as 16 hours down to about 5 minutes, which means more attacks, better crafted, aimed at more targets.

$30M+
reported losses to AI-enabled BEC scams in 2025, including voice cloning and AI-written emails (FBI IC3)
5 min
time for generative AI to write a convincing phishing email, down from up to 16 hours (IBM 2025)

Secure your business email and Microsoft 365

Source: FBI IC3 2025 Internet Crime Report | IBM Cost of a Data Breach 2025

 

CNiC Solutions — Cybersecurity

 

Who BEC Targets Most

BEC does not strike at random. It follows money and process, which means the businesses and roles most exposed are the ones that move funds on a schedule: real estate, construction, professional services, manufacturing supply chains, and any finance team that pays vendors by wire or ACH.

The FBI’s 2025 age-group data shows losses concentrated among working-age professionals, the people with signing authority. Victims aged 40 to 49 reported the largest BEC losses at $624 million, followed closely by the 50 to 59 group at $618 million. Even complainants over 60, often assumed to be the primary fraud target, lost $568 million to BEC, a figure that jumped sharply from $385 million the year before.

The real estate sector deserves special attention because the losses per incident are enormous. The FBI’s own case files from 2025 include a Missouri senior who nearly wired more than $1.3 million to a fraudster impersonating a title company during a home closing, and an Oregon city government office that reported a BEC loss of over $6 million. Critical infrastructure organizations are squarely in the crosshairs too: the IC3 handled 655 emergency recovery cases from critical-sector businesses in 2025 alone.

$624M
BEC losses reported by victims aged 40 to 49 in 2025, the highest of any age group (FBI IC3)
$568M
BEC losses among victims over 60 in 2025, up from $385 million in 2024
4,566
BEC complaints from victims over 60 in 2025, a common route for real estate fraud

Reported BEC Losses by Victim Age Group, 2025 (FBI IC3)

Under 20
$15M
20 to 29
$46M
30 to 39
$357M
40 to 49
$624M
50 to 59
$618M
60 and over
$568M

Talk to CNiC about protecting your business

Source: FBI IC3 2025 Internet Crime Report

BEC and the Human Element

Zoom out to the broadest breach dataset available and BEC’s core insight repeats: cybercrime is overwhelmingly a people problem. The Verizon 2025 Data Breach Investigations Report, built on more than 22,000 security incidents and 12,195 confirmed breaches, found that roughly 60% of all breaches involve a human element, whether a mistake, a click, or a manipulation.

BEC lives inside the social engineering slice of that human element. Verizon groups most BEC activity under pretexting, the tactic where an attacker invents a believable scenario to trick a target, as opposed to phishing, which dangles a malicious link or attachment. Pretexting has grown sharply and now rivals phishing as a share of social engineering incidents, and it is the pattern that best describes a fake wire request from a trusted name.

This is why BEC resists purely technical fixes. The attacker is not defeating your security stack, they are borrowing a trusted identity and exploiting a normal business habit: doing what the boss or the vendor asks, quickly. Defenses have to address the human process, not just the network.

~60%
of all breaches involve a human element, the category BEC exploits directly (Verizon 2025 DBIR)
22,000+
security incidents analyzed in the 2025 DBIR, with 12,195 confirmed breaches
No malware
required for a classic BEC, which is why antivirus and firewalls do not catch it

Source: Verizon 2025 Data Breach Investigations Report

What Actually Stops BEC

The encouraging part of the data is that BEC is one of the more preventable cybercrimes, because it depends on a single unverified decision to move money. Close that gap and the scam collapses. The controls that work are well established and, unlike the losses, inexpensive.

Verify every payment change out of band. This is the highest-value habit by far. Any request to change bank details, reroute a wire, or rush a transfer gets confirmed by phone to a known, previously verified number, never a number or reply address supplied in the email itself. A thirty-second callback stops a six-figure loss.

Lock down the inbox with multi-factor authentication. Since most BEC starts by compromising a real email account, MFA on every mailbox removes the attacker’s easiest entry point. Deploy email authentication such as SPF, DKIM, and DMARC so spoofed lookalike domains are flagged or rejected before they reach a person. Train the team continuously, especially the finance and executive staff who are impersonated, so an urgent wire request triggers suspicion instead of speed.

Speed also matters once fraud is discovered. The FBI operates a Recovery Asset Team that can freeze fraudulent transfers through its Financial Fraud Kill Chain, but only if the victim reports fast. In 2025 that team froze more than $507 million across 3,574 domestic cases, plus another $172 million internationally. Money reported within hours can still be clawed back; money reported next week usually cannot.

$507M+
fraudulent domestic transfers frozen by the FBI’s Recovery Asset Team in 2025, across 3,574 cases
$172M
additional funds frozen internationally through the FBI’s Financial Fraud Kill Chain in 2025
Minutes
the window that matters most: fast reporting is what makes recovery possible

Most small and midsize businesses do not have the time or in-house expertise to stand up email authentication, enforce MFA everywhere, run ongoing training, and monitor for compromise all at once. That is precisely the work a managed IT and security partner handles as a package, with a single accountable owner setting the policy and keeping it enforced.

Get a Virtual CIO to own your payment-security policy

Source: FBI IC3 2025 Internet Crime Report | CISA guidance on social engineering and phishing

Summary Table: Every Stat in One Place

Statistic Figure Source Year
Reported BEC losses $3,046,598,558 FBI IC3 2025
BEC complaints filed 24,768 FBI IC3 2025
BEC rank among cybercrime loss categories #2 FBI IC3 2025
Reported BEC losses (prior year) $2,770,151,146 FBI IC3 2024
BEC complaints (prior year) 21,442 FBI IC3 2024
Total cybercrime losses, all categories $20.877B FBI IC3 2025
Cumulative global BEC exposed losses $55.5B FBI IC3 PSA 2013-2023
Cumulative global BEC incidents 305,033 FBI IC3 PSA 2013-2023
United States BEC exposed losses (cumulative) $20.09B FBI IC3 PSA 2013-2023
Average reported loss per BEC complaint ~$123,000 CNiC analysis of FBI IC3 2025
Median BEC transaction amount ~$50,000 Verizon DBIR 2025
BEC losses by victims aged 40 to 49 (highest) $624M FBI IC3 2025
BEC losses by victims aged 50 to 59 $618M FBI IC3 2025
BEC losses by victims over 60 $568M FBI IC3 2025
Reported losses to AI-enabled BEC $30M+ FBI IC3 2025
Breaches involving a human element ~60% Verizon DBIR 2025
Phishing as leading breach vector, average cost $4.8M IBM 2025
Domestic fraudulent transfers frozen (Recovery Asset Team) $507M+ FBI IC3 2025
International funds frozen (Financial Fraud Kill Chain) $172M FBI IC3 2025
Year-over-year rise in total cybercrime losses +26% FBI IC3 2025

Frequently Asked Questions

How much did business email compromise cost in 2025?

The FBI’s 2025 Internet Crime Report recorded $3,046,598,558 in reported BEC losses across 24,768 complaints. That made BEC the second-costliest cybercrime tracked by the IC3 in 2025, behind only investment fraud, and it was up from $2.77 billion in 2024.

Is business email compromise increasing?

Yes. Reported BEC losses rose from $2.77 billion in 2024 to $3.05 billion in 2025, and complaint volume climbed from 21,442 to 24,768 over the same year. Cumulatively, the FBI logged more than $55.4 billion in exposed BEC losses and over 305,000 incidents worldwide between October 2013 and December 2023.

What is the average loss in a BEC attack?

Dividing the FBI’s 2025 BEC losses by its complaint count gives an average reported loss of roughly $123,000 per BEC complaint. The Verizon DBIR, drawing on IC3 data, puts the median BEC transaction closer to $50,000. The average sits well above the median because a small number of very large real estate and vendor wires pull it upward.

Who does business email compromise target?

BEC targets any business or individual that regularly sends wire transfers, with real estate closings, vendor invoices, and payroll among the most exploited. In the FBI’s 2025 data, victims aged 40 to 59 reported the largest BEC losses, and complainants over 60 alone lost more than $568 million to BEC.

How can businesses prevent BEC?

The most effective defenses are multi-factor authentication on email, out-of-band verification of any payment or bank-detail change through a known phone number, email authentication like DMARC, and staff training. Speed also matters after the fact: the FBI’s Recovery Asset Team froze more than $507 million in fraudulent domestic transfers in 2025, but only when victims reported quickly.

Methodology & Sources

Every figure in this report traces to a Tier 1 primary source. No statistic is derived from blog-to-blog citation. Figures are current as of the most recent published edition of each report at the time of writing.

  • FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report. Source of the 2025 BEC losses and complaint count, the crime-type loss ranking, total cybercrime losses, age-group loss breakdown, AI-enabled BEC losses, and the Recovery Asset Team freeze figures.
  • FBI IC3 Public Service Announcement, “Business Email Compromise: The $55 Billion Scam” (I-091124-PSA, September 2024). Source of the cumulative 2013 to 2023 global and United States BEC totals.
  • Verizon, 2025 Data Breach Investigations Report (DBIR). Based on more than 22,000 incidents and 12,195 confirmed breaches. Source of the human-element share and the median BEC transaction amount.
  • IBM, Cost of a Data Breach Report 2025. Source of the phishing initial-vector cost and the generative-AI phishing-speed figure.

 

back to blog