Ten years of business email compromise: $55.5 billion in global exposed losses

2024 United States Ongoing

In September 2024 the FBI's Internet Crime Complaint Center published a decade of business email compromise figures: $55.5 billion in global exposed losses across complaints filed between October 2013 and December 2023, including 158,436 US victims and $20.1 billion in US exposed losses. The same advisory records a 9% increase in identified global exposed losses in a single year, and a shift in where the stolen money is sent.

Year
2024
Where
United States
Outcome
Ongoing
Reported loss
$55.5 billion
Victims
164,982
Schemes
Business email compromise, Invoice and vendor fraud, Rental and real estate scams
Last reviewed
2026-09-06

The facts, as recorded

Why this case matters

Ten years in one number. $55.5 billion in global exposed losses is not a single fraud; it is a decade of a technique that has never stopped working, applied to the one function every organisation has — someone whose job is to send money when asked to.

“Exposed loss” is the right term to notice. It counts the money that was sent or attempted, not what stayed gone. Some of it is recovered, particularly where a recall goes out in the first hours. The gap between exposed loss and final loss is almost entirely a function of how fast the victim noticed.

The detail that changed

The advisory records a shift in where BEC money is sent: increasingly to institutions holding custodial accounts for third-party payment processors, peer-to-peer processors and cryptocurrency exchanges, rather than to an ordinary business account at an ordinary bank.

That matters for recovery. A wire to a business account at a domestic bank is the scenario a recall process was designed for. A transfer into a custodial account at a processor, then onward into crypto, crosses a boundary where the recall stops working — often within hours.

What it tells you about the scheme

The prevention advice IC3 gives is short, and every item is about verification rather than detection: use a secondary channel to confirm any change of account details, check the domain in the email against the one you already had, never supply credentials by email.

The reason it is framed that way is that BEC is often not detectable at the message level. In its most damaging form there is no malware, no bad grammar and no suspicious attachment — an attacker inside a real mailbox waits for a real invoice conversation and sends a revised one at the right moment. The message is not fake; the bank details are.

Sources

  1. Business Email Compromise: The $55 Billion Scam. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: Every figure above, the shift toward custodial and crypto recipients, and the recall guidance.
  2. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 2025 BEC complaint count and losses, and the payment-method split for BEC.

If a legal outcome in this case has changed, please tell us and the page will be corrected. See the corrections policy.