Business Email Compromise Cost $3 Billion in 2025 — and It Runs on Your Payment Process

The second-costliest crime in America attacks a process, not a network
Cyber-enabled fraud produced 85 percent of all losses reported to the FBI's Internet Crime Complaint Center in 2025 — $17.7 billion nationally. Investment fraud led the list, but the category that should concern every business most is business email compromise: $3.05 billion in reported losses across 24,768 complaints, per the data reviewed in the California Cybersecurity Risk Report 2027.
BEC deserves that attention for three reasons. It remains the second-costliest crime type in America, with a six-figure average loss per complaint. It targets ordinary payment workflows rather than exotic technology. And wire transfer or ACH was the reported transaction channel in 86 percent of BEC losses — which tells you exactly where the money leaves.
Why BEC beats companies of every size
BEC succeeds because it attacks process, not infrastructure. A convincing email — from a spoofed or compromised account posing as an executive, a vendor, or a title company — asks someone in finance to send or redirect a payment. No malware is required; the vulnerability is a human being with authority to move money and no independent way to confirm the request is real.
That is why company size offers no protection. Real-estate wire fraud alone ran to $275 million nationally, moving through escrow and title workflows. The same techniques point at payroll, invoices, and vendor bank-account changes. If your organization can be persuaded to change where a payment goes based on an email, you are exposed regardless of your security budget.
The near-zero-cost control that stops it
Given BEC's toll and its 86 percent reliance on wire and ACH, out-of-band verification of any new or changed payment instruction is the single highest-leverage fraud control available to a business — at essentially no cost. The rule is simple and absolute: whenever payment details are created or changed, confirm them through a separate, known channel — a phone call to a number you already have on file, not the number in the email.
Around that habit, a few controls compound its effect:
- Multi-factor authentication on email and financial systems, so a stolen password does not become a sending inbox.
- Email authentication — SPF, DKIM, and DMARC — to make spoofing your domain harder and flag look-alikes.
- Awareness aimed at the real scenario: urgency, secrecy, and a last-minute change to payment details are the signatures worth training on. (See our deeper explainer on defending against business email compromise.)
Each of those is a coverage question more than a purchase. The usual failure is not a missing product but one executive mailbox that never had MFA turned on, or a former employee's account still able to send. Finding those gaps across every account at once is what unified identity and email security management is for.
When it happens anyway, speed is everything
Even good programs get caught occasionally, and there the clock decides the outcome. The FBI's Financial Fraud Kill Chain froze $679 million of $1.16 billion in attempted thefts in 2025 — a 58 percent success rate — but only because victims reported immediately to their bank and to the IC3. Recovery windows are measured in hours. Every finance team should know, in advance, exactly who to call the moment a fraudulent transfer is suspected.
BEC is the rare high-dollar threat where the best defense is a discipline, not a purchase. The businesses that lose to it are almost always the ones that trusted an email over a phone call.
The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research, where each is traced to its source, method, and limitations.


