Cryptocurrency Now Drives 57% of California's Cybercrime Losses

One channel, more than half the losses
California's cybercrime losses are not spread evenly across dozens of scam types. They concentrate. In 2025, complaints with a cryptocurrency connection accounted for $2.10 billion — 57 percent of everything Californians reported losing to internet crime — the highest of any state, according to intSignal Research's analysis of FBI Internet Crime Complaint Center data.
That share is higher than the country as a whole: cryptocurrency's 57 percent of California losses exceeds the 54 percent national share. Nationally, cryptocurrency-linked losses reached $11.37 billion in 2025 (up 22 percent year over year), with investment fraud alone accounting for $7.2 billion. The FBI's Los Angeles field office has named cryptocurrency fraud, extortion, and phishing/spoofing as the most-reported crime types among Californians.
Why the losses are so large per incident
Cryptocurrency's dominance of the loss column helps explain a separate California finding: the state's average reported loss per complaint reached $31,566 in 2025, 52 percent above the national average of $20,699. Part of that gap reflects the composition of California fraud — a heavier weighting toward high-dollar categories like cryptocurrency investment fraud — and part likely reflects the state's wealth profile. The report does not attribute the gap to any single cause, but the arithmetic is clear: when a large share of losses runs through investment scams that drain entire portfolios, the average incident is far more expensive.
The mechanics matter for how you defend against it. Most cryptocurrency fraud is not a technical compromise of a wallet; it is social engineering — "pig-butchering" investment schemes, fake platforms, romance-to-investment pipelines, and extortion — that persuades a victim to move money voluntarily. Once funds are converted to cryptocurrency and moved, recovery is rare.
What this means for businesses
Cryptocurrency fraud reads as a consumer-investment story, but it reaches businesses through two doors:
- Employee-targeted extortion and investment scams use company email and communications channels. The same phishing and spoofing techniques that lead the state's complaint counts are the entry point.
- Treasury and payment fraud. Any business that touches cryptocurrency, or whose staff can be induced to send funds, faces the same irreversibility problem — a mistaken or fraudulent transfer is effectively unrecoverable.
The defenses are unglamorous and effective: out-of-band verification before any funds move, multi-factor authentication on financial and email systems, and awareness aimed at the specific lures — urgency, secrecy, "guaranteed" returns, and pressure to move to an unfamiliar platform. When fraud does occur, speed of reporting is what enables recovery: the FBI's Financial Fraud Kill Chain froze $679 million of $1.16 billion in attempted thefts in 2025, a 58 percent success rate that depends on victims reporting to their bank and the IC3 immediately.
A closing caution: every IC3 figure measures only what victims report. Cryptocurrency fraud carries heavy stigma, and true losses are almost certainly higher than the reported $2.10 billion.
The figures in this article are drawn from the California Cybersecurity Risk Report 2027 by intSignal Research, where each is traced to its source, method, and limitations.


