Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI’s widely reported $43.3 billion Business Email Compromise (BEC) figure is a historical total of exposed losses reported for June 2016 through December 2021—not a current annual loss estimate. The FBI says exposed loss includes both actual and attempted losses, so the figure should not be read as $43.3 billion in confirmed, realized victim losses. A later FBI/IC3 cumulative tally reached $55.5 billion through December 2023, but it covers a longer period that starts earlier.

What the FBI’s $43 billion figure means

In a May 4, 2022 public service announcement, the FBI’s Internet Crime Complaint Center (IC3) reported $43,312,749,946 in domestic and international exposed dollar loss associated with BEC records from June 2016 through December 2021. The underlying records included filings from FBI/IC3, law-enforcement agencies, and financial institutions. Read the FBI/IC3 announcement.

“Exposed loss” is not synonymous with money definitively taken from victims. The FBI’s measure includes actual and attempted losses. It does not, by itself, establish how much was ultimately transferred, recovered, or left unrecovered. The figure is a reported-data measure, not a guaranteed count of every BEC incident.

How the later FBI total compares

On September 11, 2024, the FBI/IC3 reported $55,499,915,582 in domestic and international exposed dollar loss for October 2013 through December 2023. This is a later cumulative BEC tally, but it should not be described as a like-for-like increase over the $43.3 billion figure: its reporting window begins earlier and ends later. Read the 2024 FBI/IC3 announcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
FBI/IC3 figure Measure and period How to read it
$43,312,749,946 Domestic and international exposed dollar loss; June 2016–December 2021 (2022 PSA) Includes actual and attempted loss; not a net realized-loss figure.
$55,499,915,582 Domestic and international exposed dollar loss; October 2013–December 2023 (2024 PSA) A later cumulative tally with a longer, earlier-starting window.
21,489 complaints; adjusted losses over $2.9 billion BEC complaints and adjusted losses during calendar year 2023 (2023 Internet Crime Report) An annual complaint measure, distinct from cumulative PSA exposed-loss totals.
$2,770,151,146 BEC complaint losses during calendar year 2024 (2024 IC3 Annual Report, published 2025) An annual complaint-loss figure, not the cumulative exposed-loss series.

The annual figures come from FBI/IC3’s 2023 Internet Crime Report and 2024 IC3 Annual Report. Complaint counts, adjusted losses, and exposed losses describe different measures and periods; they should not be combined as if they were one continuous annual total.

What business email compromise is

The FBI describes BEC—also called Email Account Compromise (EAC)—as a sophisticated scam aimed at businesses and individuals who make legitimate requests to transfer funds. Criminals commonly compromise a real business or personal email account, using social engineering or computer intrusion to make an unauthorized payment request appear trustworthy. Some schemes instead seek employees’ personally identifiable information or access to related accounts. The FBI’s 2024 overview of BEC/EAC explains the threat and its variations.

Common BEC scenarios

  • Vendor or supplier email compromise: A criminal uses or imitates a trusted supplier’s account to redirect an invoice payment or change payment instructions.
  • Real-estate transaction redirection: A fraudulent message attempts to divert funds involved in a property transaction.
  • W-2 information requests: An employee is asked to send sensitive payroll or tax information.
  • Gift-card requests: An employee is asked to buy large quantities of gift cards and share their codes.

Payment destinations can also vary. The FBI has warned that schemes increasingly use custodial accounts at financial institutions associated with cryptocurrency exchanges or third-party payment processors, or transfer funds directly to those platforms, where money may be dispersed quickly. The 2023 IC3 report describes these patterns.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the risk of BEC wire fraud

BEC exploits normal trust and payment workflows, so account security and payment verification serve different purposes. Multifactor authentication can make account access harder to compromise; a separate verification channel can help catch a fraudulent payment change even when an email looks convincing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Verify payment changes independently. If an email changes bank details or asks for an urgent transfer, call a known, independently verified number for the supplier, employee, or business contact. Do not use a phone number or other contact detail supplied in the suspicious message.
  • Use two-factor or multifactor authentication. Add an extra authentication layer to email and other relevant accounts, as recommended by the FBI. The recommendation is for MFA generally; the FBI does not require or endorse a particular product or hardware key.
  • Check the full sender address and links. Look for mismatches, subtle misspellings, or URLs that differ from the expected domain rather than relying only on a familiar display name.
  • Do not send credentials or personal information by email. Treat unexpected requests for passwords, account access, or sensitive employee information as a reason to verify through another channel.
  • Monitor financial accounts. Check for irregularities that could indicate an unauthorized transfer or account change.

These safeguards reflect FBI/IC3 guidance in its 2022 BEC announcement, 2024 BEC announcement, and 2023 Internet Crime Report.

What to do after a fraudulent transfer

  1. Contact your financial institution immediately. Ask it to recall the funds. Procedures vary by institution, and a recall request does not guarantee recovery.
  2. File a complaint with IC3 promptly. The FBI says prompt reporting can help financial institutions and law enforcement pursue possible recovery efforts, but recovery is not assured. Use the FBI/IC3 guidance for reporting information.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.