Business Email Compromise Statistics
Business Email Compromise by Industry
Latest Statistics
10% of reported cybercrime cases in Africa in 2025 involved Business Email Compromise (BEC).
Malicious links are identified as the initial threat in 47% of incidents, malicious attachments in 46%, credential harvesting in 36%, and Business Email Compromise in 35%.
Business Email Compromise is identified as the initial threat in 35% of ransomware incidents.
35.9% of IT and security professionals report experiencing business email compromise (BEC) resulting in financial or data loss in the past 12 months.
54.7% of IT and security professionals in the U.S. report experiencing BEC incidents, nearly 19 percentage points above the overall average.
Confirmed business email compromise (BEC) losses range from $140,000 to $1.5 million, compared to an average of roughly $40,000 in early 2025.
Billing account update requests have a 26.5% compromise rate.
Routine invoice inquiries have a compromise rate of less than 1%.
33% of all business email compromise in higher education is lateral.
28% of organizations experience business email compromise.
10% of intrusions investigated involved Business Email Compromise (BEC), with actors targeting banking details for wire and deposit fraud.
Business Email Compromise and Funds Transfer Fraud accounted for 58% of cyber incidents.
Among 2025 funds transfer fraud claims, 52% originated from business email compromise.
BEC claims frequency rose 15% year-over-year in 2025 while severity decreased 28% year-over-year to an average loss of $27,000.
In Q4 2025, CEOs and senior executives accounted for 50% of impersonation-based BEC emails and 41% of total BEC incidents.
Impersonation made up 82% of all BEC incidents in Q4 2025.
Diversion tactics (fraudulent invoices, fake payroll requests) accounted for 18% of BEC incidents in Q4 2025.
Business Email Compromise (BEC) accounted for 21% of successful cyber attacks, surpassing ransomware at 16%.
31% of leaders at financial services firms say they are unprepared to recover effectively from a Business Email Compromise.
In 2022, 64% of respondents from healthcare organizations said their organizations were very or highly vulnerable to BEC/spoofing/impersonation attacks.
52% of healthcare organizations were vulnerable or highly vulnerable to a BEC/spoofing/impersonation incident in 2024.
53% of healthcare organizations believe their organizations are vulnerable or highly vulnerable to a BEC/spoofing/impersonation incident.
56% of organizations noted preparedness for business email compromise.
Swedish and Norwegian targets comprise a combined 19% of BEC targets.
The strategic use of Danish language in BEC scams is 11.9%.
Swedish language use in BEC scams is 3.8%.
Non-Business Email Compromise (BEC) incidents rose by 214%.
Conversely, EMEA organisations show the highest reporting rate for BEC, at 4.22%
Repeat engagement with VEC in EMEA is the highest of any region, over twice that of BEC.
Email-based BEC attacks surged 70% year-over-year.
The majority of 2024 cyber insurance claims (60%) originated from business email compromise (BEC) and funds transfer fraud (FTF) incidents.
29% of BEC events resulted in funds transfer fraud in 2024.
BEC claims severity increased by 23% in 2024.
The FBI received 21,442 complaints about business email compromise scams in 2024 (versus 21,489 in 2023 and 21,832 in 2022).
Wire transfers were the payment method most frequently targeted by BEC scammers in 2024, reported by 63% of respondents, up from 39% in the previous survey.
ACH credits saw more BEC scam activity in 2024 than in the prior year, rising to 50% from 47% of respondents reporting incidents.
Third-party impersonations, reported by 63% of respondents, remained the most frequent type of BEC scam.
Vendor email compromise accounts for 61% of all business email compromise attacks.
In Q4 2025, Business Email Compromise accounted for 51% of all email fraud cases.
For Business Email Compromise (BEC) attacks, English-speaking executives remain the most targeted at 42%.