$3 billion was stolen from American businesses through email last year
September 23, 2026

$3 BILLION
That's what American businesses reported losing to one specific scam last year. The FBI's Internet Crime Complaint Center logged almost 25k complaints about it - an average complaint of $123k. Holy moly.
The scam is called business email compromise and it’s so unsophisticated it’ll make you scream.
Where the number comes from
The FBI's Internet Crime Complaint Center, usually written as IC3, publishes an annual report on everything the public reports to it. The 2025 edition came out on April 6, 2026.
It counted 1,008,597 complaints across every crime type it tracks, up from 859,532 the year before, with nearly $21 billion in total reported losses.
Business email compromise came second by money lost, at $3.05 billion. Investment fraud was bigger, at $8.65 billion. Tech and customer support scams came third, at $2.13 billion.
Two caveats about this data:
It's voluntary. These are complaints people chose to file at ic3.gov. Nobody is required to report anything. Plenty of businesses that got hit never told the FBI, because they were embarrassed, or because they didn't know the site existed. The real total sits above $3 billion and nobody really knows by how much.
It's already old. These are complaints filed during calendar year 2025, published in April 2026, and you're reading about them in September. The most current national figure available is well over a year behind the thing it measures. That's just how annual reporting works unfortunately.
What business email compromise actually looks like
Here’s how the scam plays out IRL.
Someone emails the person who pays your bills. The email looks like it came from a supplier you use, about an invoice you were likely expecting. It says the company has changed banks, and gives new account details for this month's payment.
Your bookkeeper pays it, because that's the job and the invoice looked right.
Sometimes there's a lot more work behind it. Attackers sit inside a compromised mailbox for weeks, reading real threads, learning who approves what and how your people write. Then they insert themselves into a conversation that was already running. By the time anyone questions anything, the money has moved through 2 accounts and left the country. Ouch…
The fix costs nothing
One rule, written down, stops most of this:
Any change to payment details gets verified by a phone call, to a number you already had on file. Never the number in the email.
That's it. The attacker owns the email thread. They don't own the phone number sitting in your accounting system.
Two things make that rule work in practice.
Write it down somewhere, so it survives the person who currently does the paying moving on. And tell whoever pays your bills, out loud, that they'll never be in trouble for holding a payment to make that call.
That second part is the one people skip, and it's the one that decides whether the rule holds. These scams run on urgency. The email says the payment is overdue, or the account is on hold, or the supplier is about to stop shipping. If your bookkeeper is worried about getting told off for slowing things down, the scam has already won the argument.
Two more things worth doing this month
Decide in advance the dollar figure above which a payment needs a second person to approve it. Whatever number makes your stomach tighten is about the right number. Write that one down too.
Then switch on multi-factor authentication for every email account in the business. Most of the elaborate versions of this scam start with somebody quietly reading a mailbox they shouldn't have access to, and multi-factor authentication is what keeps them out of it.
If it already happened to you
Report it at ic3.gov, and do it quickly. The FBI's figures only exist because people file, and a fraudulent transfer reported early has a far better chance of being frozen before the money moves on again.
Call your bank in the same hour. Banks run their own recall processes and those work on hours, not days. Then tell the supplier whose name was used, because odds are you aren't the only customer of theirs who got the same email.
If you'd rather work through this properly, with other owners in the same position and someone to ask questions to, my live workshops are here.
More like this, weekly.
One email a week on operations, systems and where AI actually helps.
KEEP READING



