Ten years of business email compromise: $55.5 billion in global exposed losses
In September 2024 the FBI's Internet Crime Complaint Center published a decade of business email compromise figures: $55.5 billion in global exposed losses across complaints filed between October 2013 and December 2023, including 158,436 US victims and $20.1 billion in US exposed losses. The same advisory records a 9% increase in identified global exposed losses in a single year, and a shift in where the stolen money is sent.
- Year
- 2024
- Where
- United States
- Outcome
- Ongoing
- Reported loss
- $55.5 billion
- Victims
- 164,982
- Schemes
- Business email compromise, Invoice and vendor fraud, Rental and real estate scams
- Last reviewed
- 2026-09-06
The facts, as recorded
- Global exposed dollar loss between October 2013 and December 2023: $55,499,915,582.
- Total US victims over the same period: 158,436, with $20,089,561,364 in exposed loss.
- Total non-US victims: 6,546, with $1,638,490,375 in exposed loss.
- Between December 2022 and December 2023 there was a 9% increase in identified global exposed losses.
- IC3 recorded growth in BEC where funds were sent directly to institutions housing custodial accounts held by third-party payment processors, peer-to-peer processors and cryptocurrency exchanges.
- Financial-recipient reporting from June 2016 to December 2023 covers 89,756 US recipients ($17.5 billion) and 22,190 non-US recipients ($9.0 billion).
- IC3 advises contacting the financial institution immediately and requesting a recall, and filing at ic3.gov regardless of amount, so funds can be frozen.
Why this case matters
Ten years in one number. $55.5 billion in global exposed losses is not a single fraud; it is a decade of a technique that has never stopped working, applied to the one function every organisation has — someone whose job is to send money when asked to.
“Exposed loss” is the right term to notice. It counts the money that was sent or attempted, not what stayed gone. Some of it is recovered, particularly where a recall goes out in the first hours. The gap between exposed loss and final loss is almost entirely a function of how fast the victim noticed.
The detail that changed
The advisory records a shift in where BEC money is sent: increasingly to institutions holding custodial accounts for third-party payment processors, peer-to-peer processors and cryptocurrency exchanges, rather than to an ordinary business account at an ordinary bank.
That matters for recovery. A wire to a business account at a domestic bank is the scenario a recall process was designed for. A transfer into a custodial account at a processor, then onward into crypto, crosses a boundary where the recall stops working — often within hours.
What it tells you about the scheme
The prevention advice IC3 gives is short, and every item is about verification rather than detection: use a secondary channel to confirm any change of account details, check the domain in the email against the one you already had, never supply credentials by email.
The reason it is framed that way is that BEC is often not detectable at the message level. In its most damaging form there is no malware, no bad grammar and no suspicious attachment — an attacker inside a real mailbox waits for a real invoice conversation and sends a revised one at the right moment. The message is not fake; the bank details are.
Sources
- Business Email Compromise: The $55 Billion Scam. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: Every figure above, the shift toward custodial and crypto recipients, and the recall guidance.
- 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 2025 BEC complaint count and losses, and the payment-method split for BEC.