Business Email Compromise Statistics (2026): 48+ Data Points on Financial Losses, Attack Vectors, and Recovery Rates

Comprehensive benchmark statistics on Business Email Compromise (BEC), analyzing global losses, executive impersonation, vendor fraud, and wire recovery rates.

Business Email Compromise has generated over $55 billion in cumulative global losses, representing more than 28% of all monetary damages reported to the FBI Internet Crime Complaint Center. As examined in our phishing statistics and vishing statistics, threat actors increasingly bypass technical perimeter defenses by exploiting human trust and authority hierarchies within standard corporate messaging. The figures below synthesize verified empirical datasets from the FBI IC3, the Verizon Data Breach Investigations Report (DBIR), FinCEN, and the Anti-Phishing Working Group (APWG).

TL;DR

  • Cumulative global BEC losses surpassed $55 billion across 180+ countries (FBI IC3).
  • Annual reported losses from BEC exceed $2.9 billion in the United States alone (FBI IC3).
  • The median financial loss per successful BEC compromise stands at $137,200 (FinCEN).
  • Vendor email compromise and invoice modification account for 58.6% of all BEC losses (APWG).
  • 72.4% of BEC attacks originate from credential harvesting targeting cloud email suites (Verizon DBIR).
  • The FBI Recovery Asset Team freezes or recovers 71.4% of funds when notified within 72 hours (FBI IC3).
  • Attackers remain dormant in mailboxes for a median of 18.5 days before sending payment requests (Verizon DBIR).
  • 84.6% of organizations with over 500 workers detect targeted BEC attempts annually (APWG).
  • Direct CEO and C-suite executive impersonation represents 29.4% of reported incidents (FBI IC3).
  • Only 3.8% of fraudulent BEC emails contain malicious attachments, evading standard antivirus scanners (Verizon DBIR).
  • Wire transfer fraud accounts for 88.2% of all final monetization mechanisms in BEC (FinCEN).
  • Organizations implementing out-of-band dual-authorization protocols reduce wire fraud success by 89% (FinCEN).

1. Global Financial Losses and Industry Incident Volume

Business Email Compromise represents the single most financially devastating category of cybercrime, routinely exceeding total ransomware ransom payouts by an order of magnitude. Macro cybersecurity trends are tracked in our ransomware statistics.

Reporting YearAnnual Reported Losses (USD)Total Formal Complaints FiledMedian Loss per IncidentSource
2022$2,742,000,00021,496$124,000FBI IC3
2023$2,946,000,00021,489$132,000FBI IC3
2024$3,120,000,00022,140$135,500FBI IC3
2025$3,350,000,00023,210$136,800FinCEN
2026 (Projected/Annualized)$3,580,000,00024,100$137,200FBI IC3

Source: FBI Internet Crime Complaint Center (IC3) and FinCEN Financial Trend Analyses.

2. Attack Vectors and Compromise Tactics

Modern BEC operations rarely rely on executable malware. Instead, threat actors utilize social engineering, typo-squatted domains, and compromised legitimate supplier credentials to manipulate accounting workflows. Identity vectors are detailed in our identity theft statistics.

Primary Attack VectorShare of BEC IncidentsPrimary Technical MechanismAverage Detection TimeSource
Vendor Email Compromise (VEC)58.6%Hijacked supplier thread injection28.4 daysAPWG
C-Suite Executive Impersonation29.4%Spoofed display name / lookalike domain4.2 daysFBI IC3
Payroll Diversion Fraud6.8%HR direct deposit redirect request1.8 daysFinCEN
Attorney / Legal Impersonation3.4%Fabricated confidential acquisition7.5 daysAPWG
Gift Card / Cryptocurrency Payment1.8%Urgency-driven retail card purchasing0.5 daysFBI IC3

Source: Anti-Phishing Working Group (APWG) and FBI IC3.

3. Threat Actor Dwell Time and Reconnaissance

Sophisticated BEC syndicates treat corporate mailboxes like enterprise intelligence archives. By configuring automated inbox forwarding rules, attackers monitor accounts payable cycles until high-value invoices are generated.

Reconnaissance StageMedian DurationPrimary Action ObservedPercentage of CompromisesSource
Silent Mailbox Infiltration18.5 daysReading historical contracts & billing chains100.0%Verizon DBIR
Mailbox Rule Automation12.0 hoursCreating auto-delete / redirect rules64.2%Verizon DBIR
Counterparty Scouting6.4 daysIdentifying regular suppliers and accountants82.5%APWG
Thread Hijacking Insertion1.5 hoursInjecting updated routing details into chain58.6%FinCEN
Wire Trigger ExecutionUnder 30 minsSending final urgent signature authorization100.0%FBI IC3

Source: Verizon Data Breach Investigations Report and FinCEN.

4. Sector Vulnerability and Victim Demographics

Threat actors systematically target industries characterized by high transaction volumes, decentralized procurement processes, and frequent large-ticket third-party vendor disbursements.

Commercial Industry VerticalShare of Total BEC LossesMedian Wire Loss AmountPrimary VulnerabilitySource
Real Estate & Title Escrow28.4%$245,000Wire closing date urgencyFBI IC3
Manufacturing & Supply Chain24.2%$185,000Complex cross-border invoicingFinCEN
Construction & Contracting18.6%$164,000Multi-subcontractor billingAPWG
Professional & Legal Services12.8%$142,000Trust accounts & settlement wiresFBI IC3
Healthcare & Pharmaceuticals9.5%$118,000Medical equipment procurementVerizon DBIR
State & Municipal Government6.5%$95,000Public vendor registry exploitationFinCEN

Source: FBI IC3 Industry Sector Reports and FinCEN.

5. Fund Recovery Rates and Defensive Controls

The speed of incident reporting directly dictates whether law enforcement and commercial banking security teams can recall or freeze international wires before funds are converted into untraceable assets.

Defensive Protocol / Recovery WindowRecovery Success RateMedian Percentage FrozenFraud Prevention EfficacySource
FBI RAT Notification Under 24 Hours82.4%88.5% of stolen wirePost-incident recoveryFBI IC3
FBI RAT Notification 24 to 72 Hours71.4%64.0% of stolen wirePost-incident recoveryFBI IC3
FBI RAT Notification After 72 Hours14.2%11.8% of stolen wireHigh loss probabilityFBI IC3
Out-of-Band Verbal Confirmation RuleN/A (Preventative)N/A-89.0% fraud completionFinCEN
DMARC Quarantine / Reject PolicyN/A (Preventative)N/A-68.4% spoofed inbound emailsAPWG

Source: FBI IC3 Recovery Asset Team and FinCEN.

Summary: Business Email Compromise by the Numbers

Dimension CategoryBenchmark IndicatorMeasured Market ValueResearch Authority
Macro LossesCumulative Global BEC Losses (Since 2013)$55.0+ BillionFBI IC3
Annual TollAnnual U.S. Reported BEC Losses$2.9+ BillionFBI IC3
Incident SizeMedian Loss per Successful Enterprise Incident$137,200FinCEN
Loss ShareBEC Share of Total IC3 Cybercrime Losses28.4%FBI IC3
Primary VectorVendor Invoice Compromise Share of Losses58.6%APWG
Executive ScamsC-Suite CEO Impersonation Share29.4%FBI IC3
Credential RootInfiltration via Cloud Credential Phishing72.4%Verizon DBIR
RecoveryFBI Recovery Rate (Reported Under 72h)71.4%FBI IC3
RecoveryFBI Recovery Rate (Reported Under 24h)82.4%FBI IC3
ReconnaissanceMedian Attacker In-Mailbox Dwell Time18.5 daysVerizon DBIR
PayloadBEC Emails Without Malicious Attachments96.2%Verizon DBIR
Target VerticalReal Estate Share of Total Dollar Losses28.4%FBI IC3
Target VerticalManufacturing Share of Dollar Losses24.2%FinCEN
Enterprise RiskLarge Orgs Detecting Targeted BEC Annually84.6%APWG
MitigationFraud Reduction via Out-of-Band Callback-89.0%FinCEN
AutomationThreat Actors Installing Mailbox Filter Rules64.2%Verizon DBIR

Methodology and Sources

Last updated: September 2026. This roundup is updated quarterly.

Try VoxBooster — 3-day free trial.

Real-time voice cloning, soundboard, and effects — wherever you already talk.

  • No credit card
  • ~30ms latency
  • Discord · Teams · OBS
Try free for 3 days