{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"},"incident":{"title":"FBI: business email compromise exposed $43 billion in losses across 177 countries","date":"2022-05-04","date_precision":"day","victim_org":"Businesses, government entities and individuals worldwide (multi-victim campaign)","sector":"Financial Services","country":"Global","primary_vector":"Business Email Compromise","secondary_vectors":["Vendor / Supply Chain Impersonation","Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"The 2022 advisory does not describe AI-enabled BEC.","outcomes":["Wire Fraud / Financial Loss","Data Breach","Cryptocurrency Theft"],"loss_usd":43312749946,"loss_note":"$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.","records_affected":241206,"threat_actor":null,"summary":"On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.","how_it_worked":"BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.","lessons":"Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.","confidence":"Confirmed","sources":[{"title":"Business Email Compromise: The $43 Billion Scam","url":"https://www.ic3.gov/PSA/2022/PSA220504","publisher":"FBI Internet Crime Complaint Center"}],"entry_type":"benchmark","slug":"2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co","year":2022,"loss_kind":"aggregate","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-fbi-business-email-compromise-exposed-43-billion-in-losses-across-177-co"}}