Business email compromise is the quiet giant of cybercrime. It rarely involves malware or a dramatic breach, yet in 2025 it cost victims $3.05 billion across 24,768 reported complaints, making it the second most expensive cybercrime the FBI tracks. The whole scam runs on one thing: a convincing email that asks someone to move money.
The FBI’s Internet Crime Complaint Center, known as the IC3, is the single best public source for BEC data because it collects fraud reports directly from victims across the United States and abroad. Its 2025 Internet Crime Report is the most recent full-year dataset available heading into 2026, and the BEC numbers in it are stark.
In 2025 the IC3 received 24,768 BEC complaints carrying $3,046,598,558 in reported losses. That places BEC second on the entire crime-loss chart, behind investment fraud at $8.65 billion and ahead of tech support scams at $2.13 billion. For a category that almost never makes headlines, BEC quietly out-costs ransomware, data breaches, and every form of extortion combined.
Put in context, total cybercrime losses reported to the IC3 reached $20.877 billion in 2025 across more than one million complaints, a 26% jump from the year before. BEC accounts for a large slice of that total while representing only a sliver of the complaint volume, a pattern that says a great deal about how efficient this scam is at extracting money.

Top Five Cybercrime Loss Categories, 2025 (FBI IC3)
The chart makes BEC’s position clear: it is not the flashiest crime, but it is one of the two that move the most money. And unlike investment fraud, which mostly targets individuals, BEC is aimed squarely at organizations and the people inside them who are authorized to send payments. That is why it belongs at the top of any business risk register, right alongside the threats covered in our wider look at the latest phishing statistics for 2026.
See how managed cybersecurity defends against email fraud
Source: FBI IC3 2025 Internet Crime Report
One bad year would be a problem. A decade of compounding losses is a trend, and BEC is firmly in trend territory. In September 2024 the FBI issued a public service announcement titled “Business Email Compromise: The $55 Billion Scam,” summarizing a full decade of reporting. Between October 2013 and December 2023, the IC3 tallied 305,033 BEC incidents and $55,499,915,582 in exposed losses worldwide.
Within that decade of data, United States victims alone accounted for 158,436 incidents and $20.09 billion in losses. The FBI also flagged a 9% increase in identified global exposed losses in just the twelve months between December 2022 and December 2023, driven in part by fraudsters routing stolen funds through third-party payment processors and cryptocurrency exchanges to move money faster and cover their tracks.
The year-over-year annual figures tell the same story from a different angle. Reported BEC losses have hovered near or above the $2.7 billion mark every year, then pushed past $3 billion in 2025. The scam is not fading as awareness grows; it is adapting.
Reported BEC Losses by Year, 2022 to 2025 (FBI IC3)
These figures almost certainly understate the true scale. The IC3 only sees fraud that victims choose to report, and many businesses quietly absorb a BEC loss rather than disclose it. The real ten-year total is higher than $55 billion. What the reported data captures reliably is direction, and the direction is up.
Source: FBI IC3 Public Service Announcement I-091124-PSA | FBI IC3 2025 Internet Crime Report
The reason BEC ranks so high on the loss chart while staying low on the complaint chart is simple arithmetic: each successful attack steals a lot. This is not a scam that nets a few dollars at a time. It targets the exact moment a business is about to send a large, legitimate-looking payment, then redirects it.
Divide the 2025 losses by the 2025 complaints and the average reported BEC loss lands at roughly $123,000. The Verizon Data Breach Investigations Report, which draws on the same IC3 data, reports a median BEC transaction closer to $50,000. The gap between those two numbers is the whole story: most attacks steal tens of thousands, but a long tail of enormous real estate and vendor wires drags the average far above the middle.

Two Tier 1 datasets read together explain why a single BEC email can be so devastating. The FBI reports the total and the count; Verizon reports the median.
Formula: $3,046,598,558 (FBI IC3 2025 BEC losses) ÷ 24,768 (BEC complaints) = roughly $123,000 average reported loss per complaint, against a Verizon median of about $50,000.
An average that runs about two and a half times the median means the distribution is heavily skewed by a handful of very large frauds. In practical terms, most businesses that get hit lose a painful five-figure sum, but the ones caught mid-closing on a property or paying a spoofed seven-figure vendor invoice lose enough to threaten the whole company. Planning only for the “typical” $50,000 loss underestimates the tail risk that actually bankrupts firms. Calculation and interpretation original to CNiC Solutions, using figures from the FBI IC3 2025 Internet Crime Report and the Verizon 2025 DBIR.
The IBM Cost of a Data Breach Report reinforces the point from the breach side. When BEC escalates into a full data breach through a compromised inbox, phishing was the leading initial attack vector in 2025, averaging $4.8 million per breach and taking 254 days to identify and contain. The email that starts a BEC and the email that starts a breach are often the same email.
Source: Verizon 2025 Data Breach Investigations Report | IBM Cost of a Data Breach 2025
Understanding the mechanics is what makes the statistics useful, because BEC is preventable once you see the pattern. The FBI defines BEC as a scam targeting businesses and individuals that perform wire transfers, carried out by compromising or impersonating a trusted email account to request an unauthorized transfer of funds.
There is no exploit and no malware in a classic BEC. The attacker either breaks into a real email account, often using credentials stolen through phishing, or registers a lookalike domain that reads correctly at a glance. From there they watch, learn the language of a pending deal, and strike at the moment a payment is expected with a note that feels routine: new wire instructions, an updated bank account, a rushed request marked confidential.
The most exploited scenarios are consistent year after year. Fraudsters impersonate a real estate agent or title company and reroute a homebuyer’s closing wire. They spoof a known vendor and swap the bank details on a legitimate invoice. They pose as a company executive and pressure the finance team into an urgent transfer. More recently, the FBI notes fraudsters increasingly funnel stolen funds into custodial accounts at financial institutions and cryptocurrency platforms, which makes recovery harder.

This is the most dangerous misconception about business email compromise. BEC carries no malicious attachment for antivirus to catch and triggers no intrusion alert for a firewall to block, because the email is either sent from a genuine, compromised account or from a convincing lookalike. The attack targets human trust and a business process, not a technical vulnerability. That is exactly why the defenses that work are procedural, verifying payment changes out of band, and identity-based, locking down the inbox with multi-factor authentication, rather than a box on the network.
Artificial intelligence has sharpened every step of this playbook. In 2025 the FBI logged more than $30 million in losses to BEC scams that involved AI, where chat generators produced flawless executive-sounding emails and voice cloning was used to phone in wire requests. IBM found that generative AI has cut the time to write a convincing phishing email from as long as 16 hours down to about 5 minutes, which means more attacks, better crafted, aimed at more targets.
Secure your business email and Microsoft 365
Source: FBI IC3 2025 Internet Crime Report | IBM Cost of a Data Breach 2025
BEC does not strike at random. It follows money and process, which means the businesses and roles most exposed are the ones that move funds on a schedule: real estate, construction, professional services, manufacturing supply chains, and any finance team that pays vendors by wire or ACH.
The FBI’s 2025 age-group data shows losses concentrated among working-age professionals, the people with signing authority. Victims aged 40 to 49 reported the largest BEC losses at $624 million, followed closely by the 50 to 59 group at $618 million. Even complainants over 60, often assumed to be the primary fraud target, lost $568 million to BEC, a figure that jumped sharply from $385 million the year before.
The real estate sector deserves special attention because the losses per incident are enormous. The FBI’s own case files from 2025 include a Missouri senior who nearly wired more than $1.3 million to a fraudster impersonating a title company during a home closing, and an Oregon city government office that reported a BEC loss of over $6 million. Critical infrastructure organizations are squarely in the crosshairs too: the IC3 handled 655 emergency recovery cases from critical-sector businesses in 2025 alone.
Reported BEC Losses by Victim Age Group, 2025 (FBI IC3)
The takeaway for a small or midsize business is that your highest-risk employees are not the junior staff, they are the controllers, office managers, and owners with the authority to approve a payment. Those are precisely the accounts an attacker studies and impersonates, and precisely the accounts that need the strongest protection.
Talk to CNiC about protecting your business
Source: FBI IC3 2025 Internet Crime Report
Zoom out to the broadest breach dataset available and BEC’s core insight repeats: cybercrime is overwhelmingly a people problem. The Verizon 2025 Data Breach Investigations Report, built on more than 22,000 security incidents and 12,195 confirmed breaches, found that roughly 60% of all breaches involve a human element, whether a mistake, a click, or a manipulation.
BEC lives inside the social engineering slice of that human element. Verizon groups most BEC activity under pretexting, the tactic where an attacker invents a believable scenario to trick a target, as opposed to phishing, which dangles a malicious link or attachment. Pretexting has grown sharply and now rivals phishing as a share of social engineering incidents, and it is the pattern that best describes a fake wire request from a trusted name.
This is why BEC resists purely technical fixes. The attacker is not defeating your security stack, they are borrowing a trusted identity and exploiting a normal business habit: doing what the boss or the vendor asks, quickly. Defenses have to address the human process, not just the network.
The consistent message across the FBI, Verizon, and IBM is that BEC succeeds by targeting trust and routine. That reframes the defensive job. It is less about buying another detection tool and more about hardening the human workflow around payments, which is a manageable, teachable problem for any business willing to build the habit.
Source: Verizon 2025 Data Breach Investigations Report
The encouraging part of the data is that BEC is one of the more preventable cybercrimes, because it depends on a single unverified decision to move money. Close that gap and the scam collapses. The controls that work are well established and, unlike the losses, inexpensive.
Verify every payment change out of band. This is the highest-value habit by far. Any request to change bank details, reroute a wire, or rush a transfer gets confirmed by phone to a known, previously verified number, never a number or reply address supplied in the email itself. A thirty-second callback stops a six-figure loss.
Lock down the inbox with multi-factor authentication. Since most BEC starts by compromising a real email account, MFA on every mailbox removes the attacker’s easiest entry point. Deploy email authentication such as SPF, DKIM, and DMARC so spoofed lookalike domains are flagged or rejected before they reach a person. Train the team continuously, especially the finance and executive staff who are impersonated, so an urgent wire request triggers suspicion instead of speed.
Speed also matters once fraud is discovered. The FBI operates a Recovery Asset Team that can freeze fraudulent transfers through its Financial Fraud Kill Chain, but only if the victim reports fast. In 2025 that team froze more than $507 million across 3,574 domestic cases, plus another $172 million internationally. Money reported within hours can still be clawed back; money reported next week usually cannot.
Most small and midsize businesses do not have the time or in-house expertise to stand up email authentication, enforce MFA everywhere, run ongoing training, and monitor for compromise all at once. That is precisely the work a managed IT and security partner handles as a package, with a single accountable owner setting the policy and keeping it enforced.
Get a Virtual CIO to own your payment-security policy
Source: FBI IC3 2025 Internet Crime Report | CISA guidance on social engineering and phishing
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Reported BEC losses | $3,046,598,558 | FBI IC3 | 2025 |
| BEC complaints filed | 24,768 | FBI IC3 | 2025 |
| BEC rank among cybercrime loss categories | #2 | FBI IC3 | 2025 |
| Reported BEC losses (prior year) | $2,770,151,146 | FBI IC3 | 2024 |
| BEC complaints (prior year) | 21,442 | FBI IC3 | 2024 |
| Total cybercrime losses, all categories | $20.877B | FBI IC3 | 2025 |
| Cumulative global BEC exposed losses | $55.5B | FBI IC3 PSA | 2013-2023 |
| Cumulative global BEC incidents | 305,033 | FBI IC3 PSA | 2013-2023 |
| United States BEC exposed losses (cumulative) | $20.09B | FBI IC3 PSA | 2013-2023 |
| Average reported loss per BEC complaint | ~$123,000 | CNiC analysis of FBI IC3 | 2025 |
| Median BEC transaction amount | ~$50,000 | Verizon DBIR | 2025 |
| BEC losses by victims aged 40 to 49 (highest) | $624M | FBI IC3 | 2025 |
| BEC losses by victims aged 50 to 59 | $618M | FBI IC3 | 2025 |
| BEC losses by victims over 60 | $568M | FBI IC3 | 2025 |
| Reported losses to AI-enabled BEC | $30M+ | FBI IC3 | 2025 |
| Breaches involving a human element | ~60% | Verizon DBIR | 2025 |
| Phishing as leading breach vector, average cost | $4.8M | IBM | 2025 |
| Domestic fraudulent transfers frozen (Recovery Asset Team) | $507M+ | FBI IC3 | 2025 |
| International funds frozen (Financial Fraud Kill Chain) | $172M | FBI IC3 | 2025 |
| Year-over-year rise in total cybercrime losses | +26% | FBI IC3 | 2025 |
Every figure in this report traces to a Tier 1 primary source. No statistic is derived from blog-to-blog citation. Figures are current as of the most recent published edition of each report at the time of writing.
For journalists and researchers: The statistics in this report may be cited with attribution to CNiC Solutions and a link to this page. The CNiC Solutions Analysis box (the average-versus-median BEC loss comparison) is original derived analysis and should be attributed to CNiC Solutions alongside the underlying FBI IC3 and Verizon sources.
A browser push notification scam hijacks a real, useful browser feature (the small alerts that news…
A backup is the difference between a bad afternoon and a closed business. When ransomware hits,…
Email is still the front door attackers knock on first. In 2024 the FBI's Internet Crime…
Yes: almost every business that offers Wi-Fi to customers, clients, or visitors needs a separate guest…