Business Email Compromise Statistics
Business Email Compromise by Industry
Latest Statistics
79% of chief information security officers report at least one e-mail phishing, spear-phishing, or business e-mail compromise incident in the last 12 months.
10% of reported cybercrime cases in Africa in 2025 involved Business Email Compromise (BEC).
Malicious links are identified as the initial threat in 47% of incidents, malicious attachments in 46%, credential harvesting in 36%, and Business Email Compromise in 35%.
Business Email Compromise is identified as the initial threat in 35% of ransomware incidents.
35.9% of IT and security professionals report experiencing business email compromise (BEC) resulting in financial or data loss in the past 12 months.
54.7% of IT and security professionals in the U.S. report experiencing BEC incidents, nearly 19 percentage points above the overall average.
Confirmed business email compromise (BEC) losses range from $140,000 to $1.5 million, compared to an average of roughly $40,000 in early 2025.
Billing account update requests have a 26.5% compromise rate.
Routine invoice inquiries have a compromise rate of less than 1%.
33% of all business email compromise in higher education is lateral.
28% of organizations experience business email compromise.
10% of intrusions investigated involved Business Email Compromise (BEC), with actors targeting banking details for wire and deposit fraud.
Business Email Compromise and Funds Transfer Fraud accounted for 58% of cyber incidents.
Among 2025 funds transfer fraud claims, 52% originated from business email compromise.
BEC claims frequency rose 15% year-over-year in 2025 while severity decreased 28% year-over-year to an average loss of $27,000.
In Q4 2025, CEOs and senior executives accounted for 50% of impersonation-based BEC emails and 41% of total BEC incidents.
Impersonation made up 82% of all BEC incidents in Q4 2025.
Diversion tactics (fraudulent invoices, fake payroll requests) accounted for 18% of BEC incidents in Q4 2025.
Business Email Compromise (BEC) accounted for 21% of successful cyber attacks, surpassing ransomware at 16%.
31% of leaders at financial services firms say they are unprepared to recover effectively from a Business Email Compromise.
In 2022, 64% of respondents from healthcare organizations said their organizations were very or highly vulnerable to BEC/spoofing/impersonation attacks.
52% of healthcare organizations were vulnerable or highly vulnerable to a BEC/spoofing/impersonation incident in 2024.
53% of healthcare organizations believe their organizations are vulnerable or highly vulnerable to a BEC/spoofing/impersonation incident.
56% of organizations noted preparedness for business email compromise.
Impersonation is the most common technique in BEC scams, with 82% of attempts targeting CEOs and executives.
Swedish and Norwegian targets comprise a combined 19% of BEC targets.
The strategic use of Danish language in BEC scams is 11.9%.
Non-Business Email Compromise (BEC) incidents rose by 214%.
Conversely, EMEA organisations show the highest reporting rate for BEC, at 4.22%
Repeat engagement with VEC in EMEA is the highest of any region, over twice that of BEC.
Email-based BEC attacks surged 70% year-over-year.
29% of BEC events resulted in funds transfer fraud in 2024.
The majority of 2024 cyber insurance claims (60%) originated from business email compromise (BEC) and funds transfer fraud (FTF) incidents.
BEC claims severity increased by 23% in 2024.
The FBI received 21,442 complaints about business email compromise scams in 2024 (versus 21,489 in 2023 and 21,832 in 2022).
"Classic" BEC scams, saw a significant decline, with 49% of respondents reporting incidents in 2024 compared to 57% in 2023.
Wire transfers were the payment method most frequently targeted by BEC scammers in 2024, reported by 63% of respondents, up from 39% in the previous survey.
ACH credits saw more BEC scam activity in 2024 than in the prior year, rising to 50% from 47% of respondents reporting incidents.
Vendor email compromise accounts for 61% of all business email compromise attacks.
In Q4 2025, Business Email Compromise accounted for 51% of all email fraud cases.