The FBI's Internet Crime Complaint Center (IC3) is the single richest longitudinal dataset on US cybercrime, precisely because it is the one federal agency that citizens and organisations are asked to report to directly. Every reported wire-fraud, BEC, ransomware, romance scam, tech support scam and investment fraud complaint lands here. The 2024 annual report, published April 2025, logs the largest annual loss total in the program's history.
Total reported losses across all internet crime categories in 2024: $16.6 billion. Total complaints: 859,532. The subset attributed to business email compromise: 21,442 cases, roughly $2.79 billion in reported losses ( FBI IC3 2024 Annual Report, retrieved 2026-09-03).
The BEC number, taken in isolation, understates the risk. Taken alongside the reporting methodology, the trend, and the industry cross-references, it is the floor of a substantially larger real figure. This piece walks through both the reported data and the reasoning about what it doesn't capture.
The headline numbers
From the 2024 IC3 report ( ic3.gov PDF, retrieved 2026-09-03):
- $16.6B — total reported losses (up from $12.5B in 2023, a 33% year-over-year increase)
- 859,532 — total complaints filed
- $19,372 — median loss per complaint
- $6.6B — losses attributed to investment fraud (largest category by dollar)
- $2.79B — losses attributed to business email compromise
- $470M — losses attributed to tech support fraud
- $150M+ — losses attributed to reported ransomware (widely believed to be a small fraction of the true figure)
- 60+ — age group with highest total losses; the oldest cohort loses the largest per-capita amount to online fraud
Investment fraud — largely crypto scams and pig-butchering schemes — passed BEC as the largest dollar category in 2022 and has widened the gap since. BEC remains the second-largest category and is materially more concentrated on organisations rather than individuals, which changes the risk calculus for anyone building corporate controls.
The BEC cut — $2.79B across 21,442 cases
Dividing $2.79B across 21,442 reported BEC cases gives a mean per-incident loss of roughly $130,000. That is the number a mid-sized organisation should size a control against — not the median across all crime types, not the outlier at the top of the distribution.
The BEC category in IC3's taxonomy covers five distinct sub-patterns:
- Fake vendor invoice. The Rimasauskas playbook. A criminal impersonates a vendor already in the AP system and requests payment to a new bank account.
- Fake executive wire request. The "CEO fraud" variant. An urgent email from "the CFO" instructs finance to wire funds for a confidential acquisition.
- Fake payroll change. An impersonated employee requests HR redirect their salary to a new bank account. Individual amounts are smaller but the volume is high.
- Attorney impersonation. A fake law-firm email demands wire transfer for time- sensitive litigation costs.
- Real-estate wire fraud. Interception of closing instructions; the buyer wires the down payment to the criminal's account.
Vendor-invoice and executive-wire cases account for the bulk of the total dollar volume. Payroll and real-estate cases account for the bulk of the case count. Both patterns matter, but the dollar-volume patterns are what determine how much a control is worth.
The three-year cumulative: ~$8.5B
IC3's rolling three-year BEC totals:
- 2022 — approximately $2.74B across 21,832 reported BEC cases
- 2023 — approximately $2.95B across 21,489 cases
- 2024 — approximately $2.79B across 21,442 cases
- Cumulative 2022–2024 — roughly $8.5B
The case count has been remarkably stable — about 21,500 reported incidents per year — while the average per-incident loss has fluctuated modestly. Neither the total nor the case count is trending down. Every year for the last three years, a US business has been hit with a reported BEC and lost roughly $130,000 on average.
Why the reported figure is a fraction
Every credible cross-reference points the same direction: the reported IC3 figure is a floor, not a ceiling.
- Under-reporting rate is high. IC3 itself notes in the 2024 report that many organisations decline to file — the reputational hit of a public BEC filing, plus scepticism about recovery, keeps the reporting rate low. Industry estimates of the reporting rate range from 15% to 40% depending on the sample. Applied even at the 40% upper bound, the true 2024 BEC loss figure sits above $7B.
- Nacha's payment-network data is broader. Nacha, the operator of the ACH network, tracks fraud losses across the domestic wire system independently. Its aggregate fraud-loss data for 2024 is materially higher than IC3's — some of the delta is BEC not reported to IC3.
- Verizon DBIR corroborates prevalence, not dollars. The Verizon 2025 Data Breach Investigations Report ( verizon.com/business/resources/reports/dbir, retrieved 2026-09-03) confirms pretexting (the phishing subset that includes BEC) as one of the most-observed action types in confirmed breaches — meaning the incidents happen even when the dollar loss doesn't get reported to law enforcement.
- IBM Cost of a Data Breach 2024 confirms the per-incident math. IBM's report puts the average total cost of a phishing-initiated data breach at $4.88M when all downstream costs (regulatory, remediation, brand) are included ( ibm.com/reports/data-breach, retrieved 2026-09-03). That is well above IC3's per-incident BEC mean, which counts only the wire itself.
Anatomy of a typical BEC case
The 2024 IC3 report and multiple DOJ press releases from the year converge on a consistent mechanic. A typical mid-market BEC case in 2024 looked like this:
- Week 0 — Attacker identifies target organisation via LinkedIn or a public vendor directory. Registers a lookalike domain of a known vendor. Obtains a Let's Encrypt cert in minutes. Sets up mailbox.
- Week 1 — Attacker sends a "we've updated our banking details" email from the lookalike domain to the target's AP inbox. Attaches a forged letterhead PDF for the "new" account.
- Week 2 — Legitimate vendor invoice arrives on schedule. Target's AP team, remembering the banking-update note, pays to the new (criminal) account.
- Week 3 — Real vendor emails asking about the unpaid invoice. Target discovers the fraud. Files IC3 complaint. Attempts wire recall — usually too late.
- Week 4+ — Money moves through 2–4 intermediary accounts, typically ending in a jurisdiction with limited cooperation on recovery. Recovery rate is well below 50% at the total dollar level.
Two structural facts matter here. First, the attacker's investment is roughly a domain registration ($10) plus a few hours of setup. Second, the reason it works is that the lookalike domain plus a plausible pretext plus an existing vendor relationship satisfies every check most AP workflows actually run. See the typosquatting deep-dive for the six lookalike families and the Rimasauskas $121M case for the fully-scaled version of the same playbook.
What preventing one incident is worth
Take the IC3 mean per-incident BEC loss (~$130,000) and layer the downstream cost from IBM Cost of a Data Breach 2024 for phishing-initiated incidents ($4.88M average total) and you get a defensible expected-value range for one prevented BEC:
- Direct wire loss — $130K mean, $500K–$1M for cases in the top quartile
- Recovery costs — investigation, forensic, legal, filing — typically 15–30% of the direct loss
- Regulatory and disclosure — variable by jurisdiction; SOC 2 and PCI reporting obligations can be triggered
- Brand and churn — hard to quantify but present in every disclosed case
- Executive time — 40–200 hours of C-level attention per material incident
One prevented BEC pays for a decade of DMARC tooling, lookalike-domain monitoring, and AP out-of-band verification training combined. This is the calculation every security-team budget request against BEC controls needs to walk through, and one the CFO on the receiving side of the pitch actually understands.
Controls that actually move the number
IC3's own recommendations align tightly with what disclosed post-mortems say worked:
- DMARC at
p=rejectwithsp=reject. Both on your own domain (protects your customers) and enforced on inbound (protects your AP inbox from exact-spoof BEC). See what is DMARC and the DMARC enforcement gap analysis for the mechanics and the 30-day migration path. - Lookalike-domain monitoring. Continuous generation and DNS-resolution of the six typosquat families across your brand and top-25 vendors. Alert on new registrations with live MX records.
- Out-of-band verification for payment changes. Any invoice with a new bank account triggers a mandatory phone call to a pre-verified vendor contact. This is a workflow change, not a tooling change, and it is the single highest-impact BEC prevention control.
- Quarterly AP tabletop. Run a mock BEC once per quarter. The failure modes surface fast — usually a workflow gap, occasionally a training gap, rarely a tooling gap.
- Wire-recall playbook. Have your bank's fraud line and IC3 filing URL in a shared runbook. Recovery windows are hours, not days. Pre-authenticated escalation channels shave minutes off the recovery attempt.
- Track vendor DMARC posture. A quarterly report of your top-25 vendors' DMARC enforcement grades makes vendor risk visible in the same way SOC 2 attestations do. A vendor at
p=noneis a vendor whose invoices can be spoofed at zero cost.
FAQ
Where does IC3 get its numbers?
IC3 aggregates complaints filed directly at ic3.gov by victims (individuals and organisations). The FBI verifies and categorizes each complaint; losses reported are self-reported dollar figures. The annual report publishes the aggregate. The methodology, sample scope, and category definitions are documented in the report's appendix.
Why is investment fraud higher than BEC in 2024?
Investment fraud in IC3's taxonomy covers crypto scams, pig-butchering (relationship-then- investment schemes), and similar high-return-promise fraud aimed at individuals rather than organisations. Its 2024 total of $6.6B primarily reflects individual victims sending life savings to fake crypto platforms. BEC targets corporate AP workflows, which have more scrutiny per transaction — hence lower per-victim losses but wider organisational impact.
Why doesn't IC3 include the true recovery rate?
It does, in aggregate: the FBI's Recovery Asset Team publishes an annual figure for funds frozen and returned. In 2024 the team froze roughly $500M-plus of the year's total fraudulent wires. The recovery rate on BEC specifically is not broken out cleanly but is widely understood to be well below 50% at the total dollar level and lower for cross- border wires.
Is filing an IC3 complaint worth it if recovery is unlikely?
Yes, for two reasons. First, timely filing is what activates the FBI's Recovery Asset Team — the window is measured in hours, and the sooner the wire is on their radar the higher the chance of a bank-level recall. Second, aggregate data drives federal policy and international cooperation; not filing keeps the reported figure artificially low, which slows the response.
How does the IC3 BEC number compare internationally?
UK Action Fraud, Australia's ACSC, and Canada's CAFC publish equivalents. The US figure is the largest in absolute terms; per-capita figures vary. The FBI IC3 is the single most complete public dataset available, which is why security research and industry reports index against it.
What is the fastest way to gauge my own BEC exposure?
Three quick checks: (1) confirm your own DMARC record is at p=reject; sp=reject; — see the DMARC primer; (2) run a lookalike-domain scan against your brand and top vendors; (3) audit your AP workflow for the "new bank account = mandatory out-of-band call" rule. If any of those three is missing, your exposure is above the median for your organisation size.