Skip to content
NetarxImpact Database
Business Email CompromiseNo AI reportedConfirmedBenchmark

FBI: business email compromise exposed $43 billion in losses across 177 countries

Businesses, government entities and individuals worldwide (multi-victim campaign) · Financial Services · Global · May 4, 2022

Multi-victim total
$43,312,749,946
A total across many victims, or an agency-wide statistic. Overlaps with other entries by construction.
$43,312,749,946 in exposed domestic and international dollar loss reported to IC3 between June 2016 and December 2021 across 241,206 incidents. This is exposed loss, not confirmed net loss.
People or records affected
241,206
241K as reported

What happened

On 4 May 2022 the FBI's Internet Crime Complaint Center published an advisory titled Business Email Compromise: The $43 Billion Scam. Between June 2016 and December 2021 IC3 recorded 241,206 domestic and international incidents with a combined exposed dollar loss of $43,312,749,946. The scam has been reported in all 50 US states and 177 countries, and targets both businesses and individuals.

How the deception worked

BEC compromises a legitimate business or personal email account through social engineering or computer intrusion, then uses that account, or a convincing look-alike, to instruct an unauthorised transfer of funds. The attacker typically reads the mailbox first, learning payment cadence, vendor names, approval chains and the writing style of the person whose authority will be borrowed, then intervenes in a real transaction rather than inventing one. Variants substitute other assets for cash, targeting employee personally identifiable information, W-2 forms or cryptocurrency wallets. The action extracted is always a routine-looking finance operation performed by an authorised employee.

AI involvement · No AI reported

The 2022 advisory does not describe AI-enabled BEC.

The control that would have caught it· our reading, not a claim from the sources

Out-of-band verification of any payment or bank-detail change using contact details held on file, combined with phishing-resistant MFA on all mailboxes, addresses both the account takeover and the payment instruction.

Sources (1)

  1. Business Email Compromise: The $43 Billion Scam
    FBI Internet Crime Complaint Center·ic3.govOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.