Business email compromise cost victims who reported to the FBI US$3.05 billion in 2025, the second-largest loss of any crime type in the FBI IC3 2025 Internet Crime Report, published in April 2026. Those losses came from 24,768 complaints, just 2.5% of everything IC3 received, yet about 15% of all reported losses. Insurers and treasurers see the same imbalance: BEC and funds transfer fraud made up 58% of claims in Coalition's 2026 Cyber Claims Report, and BEC, attempted or actual, reached 74% of the organizations that experienced payments fraud in the AFP 2026 Payments Fraud and Control Survey of 465 US treasury practitioners. BEC is a low-volume, high-value crime that runs on trust in ordinary payment workflows rather than on malware.
Four forces shape BEC in 2026. Volume is automated: Microsoft counted about 10.7 million BEC attacks in the first quarter of 2026 and nearly 9 million in April alone (Microsoft Threat Intelligence, Q1 2026; Q2 2026). The money still leaves by wire: wire transfer or ACH made up 86% of the payment methods named in 2025 BEC complaints to the FBI, and the average wire Fortra saw requested in BEC attacks rose 45% to US$61,732 in Q2 2026 (APWG). A hijacked mailbox is optional: 39% of funds transfer fraud events at Coalition involved no confirmed email compromise (Coalition). Recovery is getting harder: across all fraud types, the FBI's Recovery Asset Team froze 58% of the money it chased in 2025, down from 82% in 2020 (FBI IC3 2025). The figures below are written for finance and treasury teams, CISOs, auditors, insurers and journalists in the United States and Canada.
This post is the Stingrai research team's canonical 2026 reference for business email compromise. It assembles more than 150 figures from 12 primary publishers: the FBI's Internet Crime Complaint Center (IC3), FinCEN, Verizon, Microsoft, APWG (with BEC data from Fortra), Coalition, Arctic Wolf, the Association for Financial Professionals, the Canadian Anti-Fraud Centre, the RCMP, the Canadian Centre for Cyber Security and Nacha. Lead data is full-year 2025 telemetry, the freshest available, with quarterly 2026 figures where publishers have released them; primary publishers have not yet released full-year 2026 reports as of October 2026. Every stat carries its source, year, and methodology window so any claim can be audited inline.
Key BEC statistics for 2026
BEC losses reported to the FBI (2025): US$3,046,598,558 across 24,768 complaints, up 10% in dollars and 15.5% in complaints from 2024 (FBI IC3, 2025 Internet Crime Report).
BEC rank among FBI crime types (2025): second by losses after investment fraud, ninth by number of complaints (FBI IC3, 2025 Internet Crime Report).
Average reported loss per BEC complaint (2025): about US$123,000, roughly six times the US$20,699 average across all complaints (Stingrai calculation from FBI IC3 2025 figures).
Payment methods named in BEC complaints (2025): wire transfer or ACH 86%, prepaid or gift cards 7%, peer-to-peer transfers 3% (FBI IC3, 2025 Internet Crime Report).
BEC and funds transfer fraud share of Coalition's cyber insurance claims (2025): 58%; 52% of funds transfer fraud claims began as BEC (Coalition, 2026 Cyber Claims Report).
Organizations hit by attempted or actual BEC (2025): 74% of organizations that experienced payments fraud, up from 63% in 2024, in AFP's January 2026 survey of 465 US treasury practitioners (AFP, 2026 Payments Fraud and Control Survey; AFP 2025 key highlights).
Share of targeted funds the FBI's Recovery Asset Team froze, all fraud types (2025): 58% of US$1.16 billion, down from 82% in 2020; most kill-chain cases were historically BEC (FBI IC3, 2025 Internet Crime Report).
Global exposed BEC losses, October 2013 to December 2023: US$55.5 billion across 305,033 incidents (FBI IC3, PSA I-091124-PSA).
Average amount requested in wire-transfer BEC attacks (Q2 2026): US$61,732, up 45% from Q1 2026 (APWG, Phishing Activity Trends Report Q2 2026).
BEC attacks detected by Microsoft (Q1 2026): about 10.7 million, with nearly 9 million more in April 2026 alone (Microsoft Threat Intelligence; Microsoft Q2 2026).
BEC share of Arctic Wolf incident response cases (November 2024 to November 2025): 26%; email phishing caused 85% of those with a confirmed root cause (Arctic Wolf, 2026 Threat Report).
Spear phishing losses in Canada (2025): C$67.9 million from 571 victims, the second-largest fraud loss reported to the CAFC (Canadian Anti-Fraud Centre).
Key takeaways
Volume metrics make BEC look small; dollar metrics show it is not. BEC was 2.5% of complaints to the FBI in 2025 but about 15% of reported losses (FBI IC3 2025), and Microsoft found BEC was only 2% of the threats it observed yet a more frequent attack outcome (21%) than ransomware (16%) (Microsoft Digital Defense Report 2025). Budgets built from alert counts will underweight it.
The money still leaves through the payment run, but not only by wire. Wire or ACH carried 86% of the payment methods in 2025 BEC complaints (FBI IC3 2025). In AFP's survey, 49% of organizations that experienced payments fraud said BEC used wire transfers in 2025, down from 63% in 2024, while ACH debits (34%) and checks (33%) rose; respondents could name more than one method (AFP 2026 key highlights). Controls belong on every payment change, not on wires alone.
A compromised mailbox is no longer required. At Coalition, 39% of funds transfer fraud events involved no confirmed email compromise and 20% were driven by fraudulent instructions sent directly to banks (Coalition 2026). Microsoft found 82% to 92% of first-contact BEC emails in the first half of 2026 were generic openers such as "Are you at your desk?": the fraud happens in the conversation that follows.
Speed decides recovery, and recovery is getting harder. The FBI's Recovery Asset Team froze 58% of the US$1.16 billion it chased across all fraud types in 2025, down from 82% in 2020, as volumes grew, international transfers were added and tech support and account takeover cases rose alongside BEC (FBI IC3 2025). BEC accounted for about half of the US$182.2 million that FinCEN's Rapid Response Program partners froze in fiscal year 2025 (FinCEN).
Canada reports fewer victims, but each loss is large. Spear phishing cost Canadians C$67.9 million across 571 victims in 2025, about C$119,000 per victim (Stingrai calculation), and the RCMP estimates only 5 to 10% of fraud and cybercrime is reported (CAFC; RCMP).
Methodology and limitations
This reference uses the newest edition of each primary source available on October 1, 2026, the research cutoff:
FBI IC3: the 2025 Internet Crime Report (published April 2026, calendar 2025 complaints) and the 2016 to 2024 editions, each year taken from its own report; BEC public service announcements I-091019-PSA (September 2019), I-050422-PSA (May 2022), I-060923-PSA (June 2023) and I-091124-PSA (September 2024); and PSAs I-042425-PSA (April 2025), I-030926-PSA (March 2026) and I-061626-PSA (June 2026).
FinCEN: Year in Review for fiscal year 2025 (published May 2026, October 2024 to September 2025) and the Financial Trend Analysis of BEC in the real estate sector (March 2023, Bank Secrecy Act filings from January 2020 to December 2021).
Verizon: Verizon 2026 Data Breach Investigations Report (May 19, 2026, incidents from November 1, 2024 to October 31, 2025) and Verizon 2025 Data Breach Investigations Report (April 2025).
Microsoft: Digital Defense Report 2025 (October 16, 2025, July 2024 to June 2025) and Microsoft Threat Intelligence email threat reports for Q1 2026 (April 30, 2026) and Q2 2026 (July 23, 2026), plus a September 10, 2026 campaign analysis.
APWG: Phishing Activity Trends Reports for Q1 2024 through Q2 2026 (published May 2024 to September 2026), with BEC data contributed by Fortra.
Coalition: 2026 Cyber Claims Report (March 5, 2026, 2025 claims from more than 100,000 policyholders in the United States, Canada, the United Kingdom, Australia and Germany).
Arctic Wolf: 2026 Threat Report (February 2026, incident response cases from November 1, 2024 to November 1, 2025).
Association for Financial Professionals (AFP): 2026 Payments Fraud and Control Survey (April 14, 2026, 465 US treasury practitioners surveyed in January 2026 about 2025) and the 2025 survey's key highlights (2024 data and the 2014 to 2024 series).
Canada: Canadian Anti-Fraud Centre top-fraud tables for 2025 (February 25, 2026) and 2024 (February 2025), its February 2024 release on 2023 spear phishing losses, RCMP releases from February 2024 and November 2025, the RCMP's BEC guidance page, and the Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026.
Nacha: Operating Rules risk management amendments (Phase 1 effective March 20, 2026; Phase 2 effective June 19, 2026).
The sources measure different things, so their figures are reported side by side, never added together. IC3's annual reports publish analyst-adjusted losses on complaints, assign each complaint a single crime type and describe their statistics as a point-in-time assessment that may change. IC3's public service announcements report exposed losses instead, which include both actual and attempted losses and draw on law enforcement and financial institution filings as well as complaints. One reconciliation note: the Verizon 2025 Data Breach Investigations Report, citing the FBI IC3, says "more than $6.3 billion was transferred" in BEC scams in 2024, while IC3's own 2024 report lists US$2.77 billion in adjusted BEC losses; the two describe different measures and should not be compared as one number. AFP percentages describe the treasury professionals who answered, and AFP labels its BEC trend chart as a percent of organizations experiencing payments fraud. Coalition and Arctic Wolf shares describe each firm's own claims and casework. Canadian figures are in Canadian dollars and were not converted.
Averages per complaint and per victim, shares of totals and multi-year sums are Stingrai calculations from the published figures and are labeled as such. Stats that could not be traced to a named primary dataset on at least one verification pass, including several BEC growth percentages that circulate in vendor marketing without a stated methodology, were dropped rather than estimated. For phishing volume, click rates and lure trends, see our phishing statistics for 2026; this post covers the fraud that phishing and pretexting are used to commit.
BEC by the yardstick: eight ways to measure it
The same threat looks tiny or dominant depending on what is counted. Quote the yardstick with the number.
What is counted | BEC share | Period | Source |
|---|---|---|---|
Threats Microsoft observed | 2% | July 2024 to June 2025 | |
Complaints to the FBI | 2.5% | 2025 | FBI IC3 2025, Stingrai calculation |
Email attack types in email security gateway data, median percentage by month | 3.6% | 2026 report dataset | |
Losses reported to the FBI | 14.6% | 2025 | FBI IC3 2025, Stingrai calculation |
Outcomes of attacks Microsoft observed (ransomware: 16%) | 21% | July 2024 to June 2025 | |
Incident response cases | 26% | November 2024 to November 2025 | |
Cyber insurance claims, BEC plus funds transfer fraud | 58% | 2025 | |
Organizations that experienced payments fraud and were hit by attempted or actual BEC | 74% | 2025 | AFP 2026 survey, 465 respondents |
BEC losses reported to the FBI, 2016 to 2025
The longest consistent BEC series is the FBI's annual Internet Crime Report. Each row below comes from that year's own edition, not from a later restatement.
Year | BEC complaints | Adjusted BEC losses (US$) | Average loss per complaint (US$, Stingrai calculation) | Source |
|---|---|---|---|---|
2016 | 12,005 | 360,513,961 | about 30,000 | |
2017 | 15,690 | 676,151,185 | about 43,000 | |
2018 | 20,373 | 1,297,803,489 | about 64,000 | |
2019 | 23,775 | 1,776,549,688 | about 75,000 | |
2020 | 19,369 | 1,866,642,107 | about 96,000 | |
2021 | 19,954 | 2,395,953,296 | about 120,000 | |
2022 | 21,832 | 2,742,354,049 | about 126,000 | |
2023 | 21,489 | 2,946,830,270 | about 137,000 | |
2024 | 21,442 | 2,770,151,146 | about 129,000 | |
2025 | 24,768 | 3,046,598,558 | about 123,000 |

Figure 1: Adjusted BEC losses and complaints reported to the FBI, 2016 to 2025, each year from its own Internet Crime Report. Source: FBI IC3 Internet Crime Reports.
Losses grew 8.5 times between 2016 and 2025 while complaints only doubled, so the average reported BEC loss climbed from about US$30,000 to about US$123,000. The average peaked at about US$137,000 in 2023 and has eased since: losses fell 6% in 2024 while complaints held steady, and in 2025 complaints grew faster than dollars (15.5% against 10%). Across the ten reports, adjusted BEC losses total about US$19.9 billion (Stingrai sum). BEC was the costliest crime type in every IC3 report from 2016 through 2021; investment fraud overtook it in the 2022 report and has led every year since.
Where BEC ranks among FBI crime types in 2025
IC3 received 1,008,597 complaints with US$20.877 billion in losses in 2025, and it attributes almost 85% of those losses to cyber-enabled fraud. Within that, BEC is the second-largest loss category, behind investment fraud and ahead of tech support scams (FBI IC3 2025).
Rank by 2025 losses | Crime type | 2025 losses (US$) | 2025 complaints |
|---|---|---|---|
1 | Investment | 8,648,617,756 | 72,984 |
2 | Business email compromise | 3,046,598,558 | 24,768 |
3 | Tech and customer support | 2,134,675,818 | 47,794 |
4 | Personal data breach | 1,314,923,988 | 67,456 |
5 | Confidence and romance | 929,287,469 | 23,159 |
By number of complaints, BEC ranks ninth. Phishing and spoofing (191,561 complaints), extortion, investment, personal data breach, non-payment and non-delivery, tech support, government impersonation and identity theft all drew more complaints, but none of the eight produced more losses than BEC except investment fraud.
Global exposed losses from FBI public service announcements
IC3's BEC public service announcements add law enforcement and financial institution data to complaints and report exposed losses, a measure that includes attempted as well as actual losses. The windows overlap and start on different dates, so these are cumulative snapshots, not annual figures.
Public service announcement | Window | Incidents | Exposed loss (US$) |
|---|---|---|---|
I-091019-PSA, September 10, 2019 | June 2016 to July 2019 | 166,349 | 26,201,775,589 |
I-050422-PSA, May 4, 2022 | June 2016 to December 2021 | 241,206 | 43,312,749,946 |
I-060923-PSA, June 9, 2023 | October 2013 to December 2022 | 277,918 | 50,871,249,501 |
I-091124-PSA, September 11, 2024 | October 2013 to December 2023 | 305,033 | 55,499,915,582 |
The September 2024 update, the most recent BEC exposed-loss announcement on ic3.gov as of October 1, 2026, found BEC reported in all 50 states and 186 countries, with more than 140 countries receiving fraudulent transfers, and a 9% increase in identified global exposed losses between December 2022 and December 2023. Banks in the United Kingdom and Hong Kong often acted as the intermediary stop for funds, followed by China, Mexico and the United Arab Emirates.
Older victims, AI and cryptocurrency in the 2025 BEC data
Complainants aged 60 and over: 4,566 BEC complaints and US$568.0 million in losses in 2025, up 38% and 48% from 2024; IC3 notes the count includes older complainants reporting on behalf of a business (FBI IC3 2025).
BEC with an AI reference: 135 complaints and US$30.3 million in losses, about 1% of BEC losses (Stingrai calculation); IC3 lists chat generators that mimic executives and voice cloning used to request wire payments as ways AI can be used in BEC.
BEC with a cryptocurrency nexus: 1,526 complaints and US$83.8 million in losses.
How BEC money moves: wire, ACH, gift cards and payroll
Wire transfer or ACH accounted for 86% of the payment methods named in 2025 BEC complaints to IC3, followed by prepaid or gift cards (7%), peer-to-peer transfers (3%), checks or cashier's checks (2%) and debit or credit cards (2%) (FBI IC3 2025). The Verizon 2025 Data Breach Investigations Report says the median amount of money extracted from BEC victims "has settled around the $50,000 mark," a figure "based on 19,000 different complaints," and that wire transfer "made up approximately 88% of all BEC proceeds" (Verizon 2025 Data Breach Investigations Report).
Treasury teams report a wider spread of payment rails. In the AFP surveys, wires stayed the most common BEC payment method named in 2025, but their share fell while ACH debits and checks rose; respondents could name more than one method:
Payment method used in BEC (share of organizations experiencing payments fraud) | 2024 | 2025 |
|---|---|---|
Wire transfers | 63% | 49% |
ACH debits | 26% | 34% |
Checks | 26% | 33% |
ACH credits | 50% | 31% |
Real-time payments (RTP and FedNow) | 3% | 6% |
Gift cards | 6% | 6% |
Source: AFP 2026 Payments Fraud and Control Survey Report: Key Highlights, underwritten by Truist; 465 respondents surveyed in January 2026.
What attackers ask for is a different picture from what victims lose. In Fortra's BEC data, gift cards were the most requested cash-out in Q2 2026, at 54% of scams, ahead of wire transfers (17%), payroll diversion (10%) and French-language Interac rent-payment requests aimed at Canadian renters (9%) (APWG Q2 2026). Gift cards also led in Q1 2026, at 48% against 19% for wires (APWG Q1 2026). Requests are cheap to send; the payment methods victims report to the FBI are overwhelmingly wires and ACH.

Figure 2: Average amount requested in wire-transfer BEC attacks observed by Fortra, Q1 2024 to Q2 2026, each quarter from its own report. Source: APWG Phishing Activity Trends Reports.
The average wire request swings with the campaigns running in a given quarter: it nearly doubled to US$128,980 in Q4 2024, fell 67% to US$42,236 in Q1 2025, and stood at US$61,732 in Q2 2026. The number of wire-transfer BEC attacks Fortra observed rose 136% in Q4 2025 and 88% in Q2 2026, quarter over quarter. Fortra attributes much of that volume to Scripted Sparrow, a group it first observed in June 2024 that sends as many as 6 million targeted emails a month to accounts payable teams with fake executive coaching invoices and a spoofed approval thread, usually for just under US$50,000, and that uses money mules in the United States and Canada (APWG Q3 2025; APWG Q4 2025; APWG Q2 2026). In Q1 2026, 72% of the BEC attacks Fortra saw were sent from free webmail accounts.
Payroll diversion
Payroll diversion redirects an employee's direct deposit to an account the criminal controls. Microsoft saw payroll update requests grow 15% in February 2026 to their highest volume in eight months, then fall from roughly 4% of BEC attacks in March to 2.3% by June (Microsoft Q1 2026; Microsoft Q2 2026). Payroll diversion made up 11% of BEC cash-out requests in Fortra's Q1 2026 data and 10% in Q2 2026. IC3 has also warned that criminals buy search ads impersonating employee self-service payroll sites to capture credentials and change direct deposit details (I-042425-PSA).
Invoice and vendor fraud
AFP respondents reported invoice fraud at 26% of organizations that experienced payments fraud in 2025, rising to 40% among companies with at least US$1 billion in revenue and more than 100 payment accounts, and manipulated ACH or wire instructions at 33% (AFP 2026 key highlights). In the previous survey, vendor impersonation was cited by 60% of respondents and third-party impersonation was the most frequent BEC type at 63% (AFP 2025 key highlights). Invoice themes come and go in email telemetry: Microsoft saw invoice-themed BEC fall to under 0.4% of attacks by June 2026, from around 3.6% in March (Microsoft Q2 2026), then documented an August 3 to 5, 2026 campaign of more than a million emails in which attackers posed as chief executives and asked accounts payable staff to process an ACH payment of nearly US$50,000, backed by a fabricated vendor thread and invoice (Microsoft, September 10, 2026).
BEC attack volume and tactics in 2025 and 2026
The Microsoft Digital Defense Report 2025, covering July 2024 to June 2025, found BEC was just 2% of the threats Microsoft observed but a more frequent attack outcome (21%) than ransomware (16%). Microsoft describes BEC as typically starting with identity compromise through phishing or password spraying, then moving to inbox rule manipulation, unauthorized SharePoint access, internal phishing, email thread hijacking and new MFA method registration or MFA tampering. Those steps are detection points for defenders.
Microsoft's quarterly email reports give the freshest volume data:
Period | BEC attacks Microsoft detected | Generic first-contact messages | Explicit payment or document requests |
|---|---|---|---|
Q1 2026 | about 10.7 million | 82% to 84% each month | 9% to 10% |
April 2026 | nearly 9 million, up 121% from March | 87% to 92% each month in Q2 | 3% to 8% in Q2 |
May 2026 | 3.4 million | same Q2 range | same Q2 range |
June 2026 | 3.9 million | same Q2 range | same Q2 range |
Sources: Microsoft Q1 2026 and Microsoft Q2 2026 email threat landscape reports.
Microsoft called April 2026 the most anomalous BEC data point in more than a year and attributed it to a small number of high-volume campaigns; May and June returned to the monthly baseline of the prior year. On June 1, 2026, one automated campaign reached more than 67,000 users across more than 42,000 organizations, almost all in the United States, in under three hours, using a sales-executive pretext to ask for aging reports and customer contacts and a payroll diversion pretext in the name of the chief executive or president.
The Verizon 2026 Data Breach Investigations Report, built on 31,861 incidents and 22,625 confirmed breaches between November 2024 and October 2025, adds the breach view:
Email attack types, median percentage by month, in email security gateway data: phishing 80%, malware 10%, telephone-call back email 5% and BEC 3.6%.
Pretexting: present in 38% of social engineering incidents, against 66% for phishing.
Social Engineering pattern: the third most common breach pattern, representing 16% of all breaches; the human element was present in 62% of breaches.
Pretexting as an initial access vector: reached 6% in all breaches; Verizon added Pretexting to its tracked initial access vectors in the 2026 edition.
Beyond email: 41% of Social Engineering breaches involve social vectors other than just email, and the median click rate of simulations on phone-centric methods is closer to 2% against 1.4% for email phishing simulations, an increase of 40%, though Verizon cautions that the phone-based sample was small (35 campaigns).
For the wider human-layer picture, including vishing, deepfake-enabled fraud and security awareness outcomes, see our social engineering statistics for 2026.
Insurance claims and incident response data
Claims and incident response data show what BEC costs once it lands. Coalition's 2026 Cyber Claims Report covers 2025 claims across more than 100,000 policyholders:
Coalition metric, 2025 claims | Value |
|---|---|
BEC and funds transfer fraud (FTF) share of all claims | 58% |
FTF share of claims, the second-most common event | 27% |
Change in BEC claim frequency | up 15% |
Average BEC claim severity | US$27,000, down 28% |
Average FTF claim severity | US$141,000, down 14% |
FTF claims that originated as BEC | 52%, average loss US$112,000 |
FTF claims that were a direct result of social engineering | 71% |
FTF events with no confirmed email compromise | 39% |
FTF events driven by fraudulent instructions sent directly to banks | 20% |
Stolen funds clawed back for policyholders | US$21.8 million, average recovery US$202,000 |
Sources: Coalition 2026 Cyber Claims Report announcement (March 5, 2026) and report summary.
For comparison, Coalition's average claim across all types was US$116,000 in 2025 and its average ransomware claim was US$269,000. Our cyber insurance statistics for 2026 cover premiums, coverage and claims beyond BEC.
The Arctic Wolf 2026 Threat Report draws on incident response engagements from November 1, 2024 to November 1, 2025. BEC made up 26% of cases, one percentage point below the prior report, and ransomware and BEC together accounted for 70%. Among BEC cases with a confirmed root cause, email phishing caused 85%, up from 74% in the previous report, while previously compromised accounts or credentials fell from 18% to 10%. The sectors most represented in Arctic Wolf's BEC cases were, in order, finance and insurance, legal, education and nonprofit, manufacturing, and business services. Arctic Wolf saw a dip in May followed by a surge in June and July, and its responders attribute some of BEC's staying power to attackers using AI to run campaigns at scale and impersonate more convincingly.
Recovery: how much stolen BEC money comes back
The FBI's Recovery Asset Team runs the Financial Fraud Kill Chain, which asks receiving banks to freeze fraudulent transfers. Each row below comes from that year's Internet Crime Report.
Year | Scope as IC3 describes it | Losses the team sought to freeze (US$) | Frozen (US$) | Published rate |
|---|---|---|---|---|
2020 | 1,303 incidents, transfers to domestic accounts | 462,967,964 | 380,211,432 | 82% |
2021 | 1,726 BEC complaints, domestic transfers | 443,448,237 | 328.32 million | 74% |
2022 | 2,838 BEC complaints, domestic transfers | about 590.6 million | about 433 million | 73% |
2023 | 3,008 incidents | 758.05 million | 538.39 million | 71% |
2024 | 3,020 complaints, domestic and international | 848.4 million | 561.6 million | 66% |
2025 | 3,900 incidents, domestic and international | 1,163,919,846 | 679,013,183 | 58% |

Figure 3: Losses the FBI's Recovery Asset Team tried to freeze and funds frozen, 2020 to 2025, each year from its own Internet Crime Report; 2021 and 2022 cover BEC complaints only, 2023 covers every kill-chain incident, and 2024 and 2025 also include other fraud types and international transfers. Source: FBI IC3 Internet Crime Reports.
The rate is not strictly like for like: the team took on international transfers in April 2024, and IC3's 2025 report says that while most kill-chain cases used to be BEC, 2025 brought a rise in tech support and account takeover cases, some involving 50 or more transfers to different banks at once (FBI IC3 2025). The direction is still clear: the dollars at stake more than doubled between 2020 and 2025 while the share frozen fell. In 2025 the team froze US$146.6 million of US$261.5 million in kill-chain losses reported by critical infrastructure organizations (56%), and it initiated 104 kill-chain actions on BEC cases, including real estate BEC, for victims aged 60 and over.
Recovery data from other publishers points the same way:
FinCEN Rapid Response Program, fiscal year 2025: US$362.6 million reported, US$182.2 million (50%) frozen by partners and US$95.5 million returned to victims; BEC accounted for US$90,954,662 of the frozen funds, about half (Stingrai calculation). Since 2015 the program has frozen more than US$1.76 billion and returned US$991 million (FinCEN Year in Review FY2025).
Real estate BEC recoveries, 2020 to 2021: in FinCEN's review of 2,013 incidents, filers reported full recovery in 22.21%, partial recovery in 14.51% and no recovery in 20.37%, institutions blocked or declined the transfer in 12.47%, and the outcome was unclear in 30.45% (FinCEN Financial Trend Analysis).
Corporate losses after payments fraud, 2025: 48% of organizations under US$1 billion in revenue that experienced payments fraud incurred a loss, and 24% of those recovered nothing; 66% of larger organizations faced a loss and 19% recovered nothing (AFP 2026 key highlights).
Insurer clawbacks, 2025: Coalition recovered US$21.8 million in stolen funds for policyholders, an average of US$202,000 per recovery (Coalition).
The FBI's case write-ups show how much timing matters. In March 2023 a critical infrastructure construction project entity in New York reported a US$50 million BEC loss, and the team froze US$44,936,460 at the receiving bank plus US$1,008,526 from second-hop transfers (FBI IC3 2023). In September 2024 a US$6,661,650 BEC transfer led to US$5.1 million being frozen, and in 2025 a city government office in Oregon recalled a wire of more than US$6 million after an earlier kill-chain freeze flagged the same receiving account (FBI IC3 2024; FBI IC3 2025).
BEC by sector: real estate, legal, construction and finance
No primary source publishes BEC losses for every industry, so this section uses the closest primary evidence for each.
Real estate, title and mortgage closings
FinCEN, 2020 to 2021: 2,260 Bank Secrecy Act filings reported about US$893 million in real estate BEC; 2,013 incidents in the period were worth US$710 million. 37% of incidents impersonated title and closing entities, and nearly 88% made their first transfer to an account at a US depository institution. FinCEN found individual homebuyers suffer disproportionately (FinCEN).
IC3, 2020 to 2022: victim reports of BEC with a real estate nexus rose 27% and victim losses rose 72% (I-060923-PSA).
IC3 case write-ups: a homebuyer in Connecticut who wired US$426,000 on spoofed attorney instructions got US$425,000 back in 2023; Denver buyers had US$955,060 of a US$956,342 wire returned in 2024; and in 2025 the team froze the receiving account after a Missouri senior closing on a property got email posing as the title company with wire instructions for more than US$1.3 million, while buyers who wired more than US$449,000 on email that impersonated their attorneys had the full amount held at the receiving bank.
2026 warning: IC3 warned in June 2026 of an identity theft scheme in which criminals pose as owners of vacant parcels to realtors and title companies and route sale proceeds to a co-conspirator attorney (I-061626-PSA).
Breach data: the Verizon 2026 Data Breach Investigations Report counted 505 incidents and 499 confirmed breaches in real estate, where System Intrusion, Social Engineering and Miscellaneous Errors represent 85% of breaches.
IC3's separate Real Estate crime type (12,368 complaints and US$275.1 million in 2025) covers real estate investment, rental and timeshare fraud, so it should not be read as closing-wire BEC. Lenders and servicers comparing testing providers can start with our ranking of penetration testing companies for mortgage lenders.
Law firms and legal services
Legal was the second most represented sector in Arctic Wolf's BEC incident response cases (Arctic Wolf 2026), which also lists attorney impersonation as a distinct BEC type that often targets junior staff. Microsoft names Storm-2126, a BEC group active since 2017, as targeting US real estate businesses and law firms (Microsoft Digital Defense Report 2025). Law firms that move client funds also sit inside the closing-wire cases above. Our ranking of penetration testing companies for law firms covers what clients and bar rules ask of a firm's testing.
Construction, engineering and architecture
None of the primary sources used here publishes a construction-specific BEC loss figure, but related evidence points the same way. Microsoft tracks Storm-2227, active since 2021, as targeting US construction and architecture firms. In IC3's 2023 report, a critical infrastructure construction project entity in New York reported a US$50 million BEC loss, and the FBI's Recovery Asset Team froze about US$45.9 million of it. In March 2026 the FBI warned that criminals were impersonating city and county planning and zoning officials to collect fake permit fees by wire transfer, peer-to-peer payment or cryptocurrency from land-use permit applicants nationwide (I-030926-PSA). The Verizon 2026 Data Breach Investigations Report counted 843 incidents and 828 confirmed breaches in construction, where System Intrusion, Social Engineering and Basic Web Application Attacks represent 95% of breaches. Our ranking of penetration testing companies for construction and engineering firms covers project portals, subcontractor access and progress-payment fraud.
Banks, insurers and financial services
Finance and insurance was the most represented sector in Arctic Wolf's BEC cases. Financial services made up 7% and insurance 2% of the BEC activity Microsoft observed from January to June 2025, and financial services accounted for 14% of the targeting in Microsoft's June 1, 2026 automated campaign. The Verizon 2026 Data Breach Investigations Report recorded 3,809 incidents and 1,300 confirmed breaches in finance, where the top social actions were Phishing and Pretexting and Phishing is seen more than twice as often as Pretexting. Treasury teams are the usual first line: AFP respondents most often named treasury as the unit that discovered attempted fraud (83%) and actual fraud (55%) in 2025.
Education, nonprofits and government
Research and academia accounted for 49% of the BEC activity Microsoft observed from January to June 2025, followed by telecommunications at 11%, financial services at 7% and logistics at 6%. Education and nonprofit ranked third in Arctic Wolf's BEC cases. Public bodies are targeted too: the Oregon city government office in the FBI's 2025 case write-ups had wired more than US$6 million before the recall.
Business email compromise in Canada
The Canadian Anti-Fraud Centre records BEC under spear phishing, which it defines as fraudsters pretending to be legitimate sources to convince businesses or individuals to send money, using existing relationships (CAFC). The RCMP describes spear phishing as including BEC (RCMP).
Year | Spear phishing reports | Victims | Reported losses (C$) | Rank by loss | Source |
|---|---|---|---|---|---|
2025 | 813 | 571 | 67.9 million | 2nd, after investments | |
2024 | 937 | 608 | 67.3 million | 2nd, after investments | |
2023 | not published | not published | more than 58 million (businesses only) | top three by financial impact | |
2020 | not published | not published | almost 30 million | not stated |
Spear phishing losses were roughly flat between 2024 and 2025 while reports fell 13% and victims fell 6%, so the loss per victim rose to about C$119,000 from about C$111,000 (Stingrai calculation). In 2025, spear phishing accounted for nearly a tenth of the more than C$704 million in fraud losses reported to the CAFC. The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 notes that spear phishing has one of the highest reported levels of financial impact on victims.
The reporting gap is large: the RCMP estimates only 5 to 10% of fraud and cybercrime incidents in Canada are reported (RCMP, November 2025). Cross-border evidence fills some of it. Canada was the largest source of complaints to the FBI's IC3 from outside the United States in 2025, at 7,479 complaints across all crime types. Microsoft lists Storm-0259 as targeting small and medium businesses in the United States, Canada and the United Kingdom. Fortra reports Scripted Sparrow money mules in Canada and French-language Interac rent scams aimed at Canadian renters (APWG Q2 2026). Fast reporting works across the border too: on February 2, 2024, the CAFC, the US Secret Service and a financial institution froze a C$615,820 transfer after a Canadian business reported spear phishing, and the Secret Service has helped the CAFC return more than C$3 million since 2021 (CAFC). Our Canada cyber attack statistics for 2026 cover the wider Canadian fraud and breach picture.
AI, deepfakes and BEC
AI is changing how convincing BEC messages are faster than it is changing how money is stolen. IC3 linked 135 BEC complaints and US$30.3 million in 2025 losses to AI, about 1% of BEC losses, and noted that not all BEC tactics are AI-enabled (FBI IC3 2025). Microsoft's September 2026 analysis found indicators consistent with generative AI in the templates of a million-message executive impersonation campaign, 87.7% of it aimed at US users. AFP respondents reported deepfake attempts at 7% of organizations that experienced payments fraud in 2025, rising to 13% at companies with at least US$1 billion in revenue and more than 100 payment accounts.
Nacha's 2026 fraud monitoring rules
US businesses that send ACH payments gained a new obligation in 2026. Nacha's risk management amendments define False Pretenses as inducing a payment by misrepresenting identity, authority to act for another person or the ownership of the account to be credited, which Nacha says covers BEC, vendor impersonation and payroll impersonation (Nacha). Phase 1 took effect on March 20, 2026 for all originating banks, for originators, third-party service providers and third-party senders that originated or transmitted 6 million or more ACH entries in 2023, and for receiving banks that received 10 million or more entries in 2023. Phase 2 extends the requirements to every other non-consumer originator, third-party service provider, third-party sender and receiving bank from June 19, 2026, with a practical effective date of June 22, 2026 because of the federal holiday. Originating parties must have risk-based processes and procedures reasonably intended to identify ACH entries initiated due to fraud, and receiving banks must have processes to identify incoming credits suspected of being unauthorized or authorized under False Pretenses; both must be reviewed at least annually.
What this means for defenders
Put the control where the money moves. Verify every new payee, changed bank detail and payroll change through a separate channel using contact details already on file, as IC3 recommends, and log the check. Wire or ACH made up 86% of the payment methods in 2025 BEC complaints, and 39% of organizations in the AFP survey still receive genuine emails that fraudsters have intercepted.
Defend the mailbox as an identity system. Microsoft found BEC usually starts with phishing or password spraying and continues through inbox rules, thread hijacking and new MFA method registration. Alert on those events, require phishing-resistant MFA for finance roles and review OAuth consent grants. Our guide to detecting adversary-in-the-middle phishing covers the session-token side.
Write the first-hour runbook now. It should name who calls the bank to request a recall and a hold harmless letter, and who files with IC3 or the CAFC with full transaction details. Across all fraud types, the FBI's Recovery Asset Team froze 58% of targeted funds in 2025, and every hour of delay gives the money time to move again.
Test people with the pretexts attackers actually use. Generic openers, executive and vendor impersonation, payroll changes and phone follow-ups are the 2026 pattern, and the Verizon 2026 Data Breach Investigations Report found a 40% increase in the median click rate of phone-centric simulations over email phishing simulations, though Verizon cautions that the phone-based sample was small (35 campaigns). Measure reporting rate and time to report, not only clicks.
Test the finance applications, not only the inbox. Coalition found 20% of funds transfer fraud events came from fraudulent instructions sent directly to banks and 39% happened without a confirmed email compromise. Supplier portals, payroll self-service and treasury platforms need authorization testing on who can change bank details.
How Stingrai tests the controls BEC exploits
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For finance and treasury teams, a BEC-focused engagement tests the controls behind the numbers above. Stingrai's phishing campaigns are run by its penetration testers rather than a self-service platform: they research the organization, build bespoke pretexts that are approved in writing and mimic trusted providers, and use a custom Gophish and Evilginx stack that captures session tokens, so MFA-bypass susceptibility is measured alongside clicks. Social engineering engagements combine targeted email with phone pretexts and can be aimed at accounts payable, payroll and the help desk, which is how a call-back verification step gets tested under realistic pressure. Reports cover credential submission, MFA-bypass susceptibility, reporting rate, time to first report and a detection timeline, and findings are posted to the PTaaS portal with free on-call remediation support. Cloud penetration testing treats Microsoft 365 and Entra ID as an attack path, from app registrations and consent grants to Conditional Access gaps, and web application testing covers supplier and payroll portals where a bank-detail change is one authorization check away from fraud.
Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP run each human-led engagement, reviewed by the team lead and an engagement partner. The team has published 18 CVEs, and Stingrai holds a 5.0 rating across 20 Clutch reviews. Engagements run as one-time assessments or continuous programs, and the results give auditors and insurers evidence that payment-change controls hold under realistic pressure. Phishing and social engineering scopes are quoted individually through the quote form. For one web application and its APIs, published prices are US$3,000 per assessment or US$650 per month for the Autonomous Pentest by Snipe, Stingrai's AI agent for web applications and APIs, which carries the No High or Critical Finding = Don't Pay guarantee, and US$6,800 per assessment or US$1,275 per month for the Hybrid Pentest, in which Snipe and penetration testers test together; the monthly prices are for 12-month continuous plans (pricing).
Frequently Asked Questions
How much did business email compromise cost in 2025?
Victims reported US$3,046,598,558 in adjusted business email compromise losses to the FBI in 2025, across 24,768 complaints, according to the FBI IC3 2025 Internet Crime Report published in April 2026. That is up 10% from US$2.77 billion in 2024 and the second-largest loss of any crime type after investment fraud. Reported losses are a floor, because many victims never file a complaint.
How many BEC complaints did the FBI receive in 2025?
The FBI's Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025, up 15.5% from 21,442 in 2024 and the highest annual count in the 2016 to 2025 reports. BEC made up 2.5% of all 1,008,597 complaints but about 15% of reported losses (FBI IC3 2025).
What is the average loss from a BEC attack?
Across the 24,768 BEC complaints in the FBI's 2025 report, the average adjusted loss was about US$123,000 (Stingrai calculation), roughly six times the US$20,699 average for all complaints. Typical cases are smaller: the Verizon 2025 Data Breach Investigations Report says the median amount of money extracted from BEC victims "has settled around the $50,000 mark," and Coalition's average BEC insurance claim fell 28% to US$27,000 in 2025 while funds transfer fraud claims averaged US$141,000 (Coalition).
How is money stolen in BEC attacks usually paid out?
Mostly by wire transfer or ACH, which made up 86% of the payment methods named in BEC complaints in the FBI IC3 2025 report, with prepaid or gift cards at 7%. Attackers ask for gift cards more often than they get them: gift cards were the most requested BEC cash-out in Fortra's Q2 2026 data at 54%, against 17% for wires. In the AFP 2026 survey, 49% of organizations that experienced payments fraud said BEC used wire transfers in 2025, 34% said ACH debits and 33% said checks; respondents could name more than one method.
Which industries are most targeted by business email compromise?
It depends on the dataset. Arctic Wolf's incident response cases from November 2024 to November 2025 put finance and insurance first, then legal, education and nonprofit, manufacturing and business services (Arctic Wolf 2026 Threat Report), while Microsoft's BEC telemetry for January to June 2025 was led by research and academia at 49%, telecommunications at 11% and financial services at 7%. Real estate closings are a long-running target: FinCEN found 37% of real estate BEC incidents in 2020 and 2021 impersonated title and closing entities.
Can money lost to BEC be recovered?
Sometimes, if the bank and law enforcement move within hours. Across all the fraud cases in its Financial Fraud Kill Chain, historically mostly BEC, the FBI's Recovery Asset Team froze US$679 million of the US$1.16 billion it tried to stop in 2025, a 58% success rate, down from 82% in 2020 (FBI IC3 2025). Victims should ask their bank to recall the transfer immediately and file a complaint at ic3.gov, or with the Canadian Anti-Fraud Centre in Canada.
How big is business email compromise in Canada?
Spear phishing, the Canadian Anti-Fraud Centre category that includes BEC, cost C$67.9 million across 571 victims in 2025, the second-largest fraud loss after investment fraud (CAFC). That is about C$119,000 per victim (Stingrai calculation), and the RCMP estimates only 5 to 10% of fraud and cybercrime is reported. Our Canada cyber attack statistics cover the wider fraud picture.
What is the difference between BEC and phishing?
Phishing is a delivery technique; business email compromise is a fraud. The FBI defines BEC as a scam in which fraudsters compromise email accounts or other communications, such as phone numbers and virtual meeting applications, through social engineering or computer intrusion to conduct unauthorized transfers of funds. BEC often begins with phishing: Arctic Wolf traced 85% of BEC cases with a confirmed root cause to email phishing. Volume data on phishing itself is in our phishing statistics for 2026.
How can organizations reduce BEC losses?
Verify every new or changed payment instruction through a separate channel using contact details already on file, protect the mailboxes and identity systems BEC relies on, and rehearse a same-day recall with your bank. Speed matters: across all fraud types, the FBI's Recovery Asset Team froze 58% of the funds it targeted in 2025 (FBI IC3 2025). Stingrai's phishing campaigns and social engineering testing measure whether those controls hold when a realistic request reaches finance staff.
References
FBI Internet Crime Complaint Center (IC3). 2025 Internet Crime Report. April 2026. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf. Complaints and adjusted losses by crime type, BEC payment methods, Recovery Asset Team results, and AI, elder and cryptocurrency breakdowns for calendar 2025.
FBI Internet Crime Complaint Center (IC3). Internet Crime Reports, 2016 to 2024 editions. Published 2017 to 2025. https://www.ic3.gov/AnnualReport/Reports. Annual BEC complaint counts and adjusted losses, kill-chain results and case write-ups; each year cited from its own edition.
FBI Internet Crime Complaint Center (IC3). Business Email Compromise: The $55 Billion Scam (I-091124-PSA). September 11, 2024. https://www.ic3.gov/PSA/2024/PSA240911. Exposed losses and incidents from October 2013 to December 2023, countries and intermediary banks.
FBI Internet Crime Complaint Center (IC3). Business Email Compromise: The $50 Billion Scam (I-060923-PSA). June 9, 2023. https://www.ic3.gov/PSA/2023/PSA230609. Exposed losses to December 2022 and the real estate nexus trend from 2020 to 2022.
FBI Internet Crime Complaint Center (IC3). Business Email Compromise: The $43 Billion Scam (I-050422-PSA). May 4, 2022. https://www.ic3.gov/PSA/2022/PSA220504. Exposed losses to December 2021 and the definition of exposed loss as actual plus attempted loss.
FBI Internet Crime Complaint Center (IC3). Business Email Compromise: The $26 Billion Scam (I-091019-PSA). September 10, 2019. https://www.ic3.gov/PSA/2019/PSA190910. Exposed losses from June 2016 to July 2019 and early payroll diversion reporting.
FBI Internet Crime Complaint Center (IC3). Cyber Criminals Impersonating Employee Self-Service Websites to Steal Victim Information and Funds (I-042425-PSA). April 24, 2025. https://www.ic3.gov/PSA/2025/PSA250424. Search-ad impersonation of payroll and self-service portals used to redirect direct deposits.
FBI Internet Crime Complaint Center (IC3). Criminals Impersonating City and County Officials in Phishing Emails for Planning and Zoning Permits (I-030926-PSA). March 9, 2026. https://www.ic3.gov/PSA/2026/PSA260309. Fake permit-fee invoices sent to land-use permit applicants nationwide.
FBI Internet Crime Complaint Center (IC3). Protect Your Property from Illegal Sales Through Parcel Owner Impersonation (I-061626-PSA). June 16, 2026. https://www.ic3.gov/PSA/2026/PSA260616. Impersonation of vacant-parcel owners to realtors and title companies.
Financial Crimes Enforcement Network (FinCEN). Year in Review for Fiscal Year 2025. May 2026. https://www.fincen.gov/system/files/2026-05/FinCEN-Year-in-Review-2025.pdf. Rapid Response Program referrals, frozen and returned funds, and frozen funds by typology.
Financial Crimes Enforcement Network (FinCEN). Business Email Compromise in the Real Estate Sector: Threat Pattern and Trend Information, January 2020 to December 2021. March 30, 2023. https://www.fincen.gov/system/files/shared/Financial_Trend_Analysis_BEC_FINAL.pdf. Bank Secrecy Act filings on real estate BEC, impersonation targets, fund flows and recoveries.
Verizon. 2026 Data Breach Investigations Report. May 19, 2026. https://www.verizon.com/dbir. 31,861 incidents and 22,625 breaches from November 2024 to October 2025, including email gateway attack mix and pretexting data.
Verizon. 2025 Data Breach Investigations Report. April 2025. https://www.verizon.com/dbir. Median BEC amount and wire share of BEC proceeds from IC3 complaint data for 2024.
Microsoft. Microsoft Digital Defense Report 2025. October 16, 2025. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025. BEC share of threats and attack outcomes, BEC by sector and active BEC groups, July 2024 to June 2025.
Microsoft Threat Intelligence. Email threat landscape: Q1 2026 trends and insights. April 30, 2026. https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/. Quarterly BEC volume and message composition.
Microsoft Threat Intelligence. Email threat landscape: Q2 2026 trends and insights. July 23, 2026. https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/. Monthly BEC volume, request types and the June 1, 2026 automated campaign.
Microsoft Security Research. Protecting organizations from AI-assisted executive impersonation and invoice fraud. September 10, 2026. https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/. A million-message executive impersonation and invoice campaign from August 2026.
APWG. Phishing Activity Trends Report, 2nd Quarter 2026. September 2026. https://docs.apwg.org/reports/apwg_trends_report_q2_2026.pdf. Fortra's BEC wire-request averages, attack counts and cash-out methods; earlier quarters at https://apwg.org/trendsreports/.
Coalition. 2026 Cyber Claims Report. March 5, 2026. https://www.coalitioninc.com/claims-report/2026. 2025 claims frequency and severity for BEC and funds transfer fraud across more than 100,000 policyholders.
Arctic Wolf. 2026 Threat Report. February 2026. https://arcticwolf.com/resource/aw/arctic-wolf-threat-report-2026. Incident response caseload by category, BEC root causes and sectors, November 2024 to November 2025.
Association for Financial Professionals (AFP). 2026 AFP Payments Fraud and Control Survey Report. April 14, 2026. https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud. 465 treasury practitioners on 2025 payments fraud, BEC prevalence and payment methods.
Association for Financial Professionals (AFP). 2025 AFP Payments Fraud and Control Survey Report: Key Highlights. 2025. https://www.truist.com/content/dam/truist-bank/us/en/documents/info/cci/2025-afp-payments-fraud-control-survey-report-key-highlights.pdf. BEC prevalence from 2014 to 2024 and BEC types for 2024.
Canadian Anti-Fraud Centre (CAFC). Top 10 frauds in 2025. February 25, 2026. https://antifraudcentre-centreantifraude.ca/features-vedette/2026/02/top-fraud-2025-fraudes-plus-courantes-eng.htm. Reports, victims and losses by fraud type for 2025.
Canadian Anti-Fraud Centre (CAFC). Fraud Prevention Month 2025. February 2025. https://antifraudcentre-centreantifraude.ca/features-vedette/2025/02/month-prevention-mois-eng.htm. Top frauds by reports and dollar loss for 2024.
Canadian Anti-Fraud Centre (CAFC). Canadian Anti-fraud Centre and U.S. Secret Service freeze fraudulent transfer. February 21, 2024. https://antifraudcentre-centreantifraude.ca/news-nouvelles/2024/2024-02-21-eng.htm. 2023 spear phishing losses and a cross-border freeze.
Royal Canadian Mounted Police (RCMP). RCMP launches new National Cybercrime and Fraud Reporting System. November 6, 2025. https://rcmp.ca/en/news/2025/11/rcmp-launches-new-national-cybercrime-and-fraud-reporting-system. Estimate that only 5 to 10% of fraud and cybercrime is reported in Canada.
Royal Canadian Mounted Police (RCMP). Business Email Compromise. Updated November 6, 2025. https://rcmp.ca/en/federal-policing/cybercrime/cyber-features/business-email-compromise. BEC schemes observed in Canada and 2020 spear phishing losses.
Royal Canadian Mounted Police (RCMP). Fraud Prevention Month 2024: Fighting fraud in the digital era. February 29, 2024. https://rcmp.ca/en/news/2024/02/fraud-prevention-month-2024-fighting-fraud-digital-era. Top frauds by financial impact in 2023.
Canadian Centre for Cyber Security. National Cyber Threat Assessment 2025-2026. October 2024. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026. Assessment of fraud and spear phishing as cybercrime affecting Canadians.
Nacha. Risk Management Topics: Fraud Monitoring Phase 2. 2026. https://www.nacha.org/rules/risk-management-topics-fraud-monitoring-phase-2. False Pretenses definition and fraud monitoring requirements effective March 20 and June 19, 2026.



