Every year, the FBI's Internet Crime Complaint Center (IC3) publishes a report that gets summarized into a single scary number. For 2025, that number is more than $20.8 billion in total reported losses across just over one million complaints, a 26 percent increase over 2024.1 Business email compromise (BEC) was the second-largest category by loss, with 24,768 complaints and roughly $3.05 billion in reported losses for the year.1
Numbers like that are useful for getting attention in a budget meeting. They're less useful for deciding what to actually do differently. Here's what the data does and doesn't tell you.
What it shows
BEC isn't a niche problem. Nearly 25,000 organizations and individuals filed a complaint about it in a single year, and the reported losses put it well ahead of most other cybercrime categories the FBI tracks.1 Unlike ransomware or a data breach, BEC usually doesn't involve malware or a dramatic technical compromise. It's typically a convincing email, a changed bank detail, or a well-timed request that looks like it came from someone the recipient trusts.
That pattern lines up with broader breach research. Verizon's 2025 Data Breach Investigations Report found a human element present in roughly six in ten confirmed breaches it analyzed, with social engineering as one of the more common breach patterns in the dataset.2 Put simply: a meaningful share of incidents still come down to someone acting on a message that looked legitimate enough.
What it doesn't show
The IC3 numbers are reported losses, not a census. They almost certainly undercount the real total, since not every incident gets reported, and reported losses don't map cleanly onto any single organization's risk. A $3 billion industry-wide figure says nothing about whether your organization's specific vendor-payment process, email controls, or employee habits would catch or miss a similar attempt.
It's also not evidence that any specific tool, training program, or vendor claim would have prevented a given loss. Headline statistics are useful for understanding scale and trend, not for predicting outcomes for a specific organization.
What's actually worth doing with this
Rather than reacting to the total dollar figure, it's more useful to look at how BEC attempts typically unfold and check your own process against a few specific points:
- Is a payment or bank-detail change ever approved based on an email alone, or does it require a callback to a number you already had on file?
- Would your team notice if a request came from a sender address that was one character off from a real vendor or executive?
- Does anyone besides the requester have to sign off on unusual payment requests, especially ones with urgency or secrecy attached?
- Is there a simple way for someone to report a suspicious message without it feeling like a hassle?
These are the same categories covered in our Email Fraud Readiness Checklist, which walks through account access, payment verification, technical controls, reporting, and executive-impersonation risk in more detail.
Want to talk through where your organization stands? A Human Risk Readiness Review is a no-cost conversation, not a test of your team.
Book a Human Risk Readiness ReviewNone of this is a guarantee. No checklist, training program, or managed service eliminates the possibility of business email compromise or any other incident. The goal is simply to close the most common, well-documented gaps first.
Sources
- FBI Internet Crime Complaint Center, 2025 IC3 Annual Report
- Verizon, 2025 Data Breach Investigations Report — Executive Summary