GITNUXREPORT 2026

Business Email Compromise Statistics

BEC causes billions in losses as a leading business cyber threat.

Rajesh Patel

Rajesh Patel

Team Lead & Senior Researcher with over 15 years of experience in market research and data analytics.

First published: Feb 13, 2026

Our Commitment to Accuracy

Rigorous fact-checking · Reputable sources · Regular updatesLearn more

Key Statistics

Statistic 1

BEC scams resulted in $2.9 billion in losses in 2022

Statistic 2

Global BEC losses exceeded $43 billion from 2016 to 2021

Statistic 3

Average BEC loss per incident was $120,000 in 2021

Statistic 4

BEC accounted for 20% of all cybercrime losses in 2022

Statistic 5

US businesses lost $1.86 billion to BEC in 2021

Statistic 6

Median BEC loss was $100,000 for wire transfer fraud in 2022

Statistic 7

BEC losses in real estate sector topped $500 million in 2022

Statistic 8

Over 21,000 BEC complaints led to $2.7 billion losses in 2020

Statistic 9

BEC wire transfers averaged $145,000 per victim in 2019

Statistic 10

International BEC losses reached $1.8 billion in 2022

Statistic 11

BEC caused $1.82 billion US losses in 2019

Statistic 12

Average BEC payroll scam loss was $40,000 in 2021

Statistic 13

BEC losses grew 7% from 2021 to 2022

Statistic 14

83% of BEC losses from wire transfers in 2022

Statistic 15

BEC false invoice scams averaged $21,000 loss in 2022

Statistic 16

Total BEC losses since 2016 exceed $50 billion globally

Statistic 17

US BEC losses hit $43 million in Q1 2023 alone

Statistic 18

BEC accounted for $6.2 billion in global losses over 4 years

Statistic 19

Average BEC loss for US victims was $89,000 in 2020

Statistic 20

BEC spear-phishing losses averaged $200,000 per incident

Statistic 21

BEC caused 65% of financial fraud losses in 2022

Statistic 22

BEC scams caused $1.7 billion losses in 2018

Statistic 23

Average BEC loss reached $75,000 in 2020

Statistic 24

BEC payroll scams cost $798 million in 2022

Statistic 25

BEC losses $4.2B in 2023 projection

Statistic 26

Over 19,000 BEC complaints in 2021

Statistic 27

BEC complaints increased 3.5% from 2020 to 2021

Statistic 28

21,381 BEC complaints reported to IC3 in 2022

Statistic 29

BEC represented 1.7% of all IC3 cyber complaints in 2022

Statistic 30

Global BEC incidents rose 65% in 2021

Statistic 31

15,000+ BEC incidents in US in 2019

Statistic 32

BEC scams targeted 98% of US organizations in 2022

Statistic 33

1 in 10 organizations hit by BEC annually

Statistic 34

BEC incidents doubled from 2018 to 2019

Statistic 35

Over 12,000 BEC complaints in 2018

Statistic 36

BEC prevalence up 11% year-over-year in 2023

Statistic 37

91% of BEC attacks use email as vector

Statistic 38

BEC scams reported in 150+ countries

Statistic 39

3,700% increase in BEC since 2015

Statistic 40

Weekly BEC attempts average 300 per organization

Statistic 41

BEC in 80% of ransomware precursors

Statistic 42

22,000 BEC complaints in 2023 first half

Statistic 43

BEC growth rate 15% annually since 2016

Statistic 44

SMEs report 40% of BEC incidents

Statistic 45

BEC attacks every 11 seconds globally

Statistic 46

32% of breaches involve BEC tactics

Statistic 47

17,000 BEC complaints in 2020

Statistic 48

BEC up 100% from 2016 to 2022

Statistic 49

50% orgs face BEC quarterly

Statistic 50

18,000+ BEC cases 2023 H1

Statistic 51

96% of organizations use MFA but BEC succeeds via fatigue

Statistic 52

Only 14% of BEC funds recovered globally

Statistic 53

Training reduces BEC success by 70%

Statistic 54

DMARC adoption cuts BEC by 50%

Statistic 55

65% of BEC detected post-transfer

Statistic 56

AI detection flags 80% BEC emails

Statistic 57

Employee reporting stops 40% potential BEC

Statistic 58

Financial training lowers BEC risk 60%

Statistic 59

85% BEC preventable with verification protocols

Statistic 60

EDR blocks 90% account takeovers

Statistic 61

Phishing sims reduce clicks by 55%

Statistic 62

20% BEC stopped by email gateways

Statistic 63

Multi-factor fatigue exploited in 25% failures

Statistic 64

Incident response time averages 2 weeks for BEC

Statistic 65

75% orgs lack BEC-specific policies

Statistic 66

BEC losses drop 40% with wire approval processes

Statistic 67

Training cuts BEC 90% in mature orgs

Statistic 68

DMARC stops 60% spoofing

Statistic 69

30% BEC caught by users

Statistic 70

AI blocks 85% anomalous emails

Statistic 71

Verification dual-signoff prevents 70%

Statistic 72

50% recovery with quick reporting

Statistic 73

Phishing tests reduce risk 65%

Statistic 74

Gateways filter 25% BEC

Statistic 75

Avg detection 72 hours

Statistic 76

60% lack recovery plans

Statistic 77

40% orgs no BEC training

Statistic 78

76% of BEC uses compromised legitimate accounts

Statistic 79

85% of BEC involves social engineering

Statistic 80

Email spoofing in 60% of BEC attacks

Statistic 81

MFA bypass via phishing in 40% BEC cases

Statistic 82

Vendor email compromise in 15% of incidents

Statistic 83

92% of BEC relies on urgency in emails

Statistic 84

Account takeover primary in 50% BEC

Statistic 85

CEO fraud variant in 22% of attacks

Statistic 86

Malware-free BEC in 98% cases

Statistic 87

Conversation hijacking in 30% BEC threads

Statistic 88

70% BEC from Nigeria-based actors

Statistic 89

Display name spoofing used in 45% attacks

Statistic 90

QR code phishing in rising 10% BEC variants

Statistic 91

65% BEC targets finance departments

Statistic 92

Zero-day exploits rare, <1% in BEC

Statistic 93

Email compromise in 88% BEC

Statistic 94

50% BEC uses business process compromise

Statistic 95

Urgency tactics in 95% emails

Statistic 96

West Africa origin 60% BEC

Statistic 97

35% BEC via data from breaches

Statistic 98

Fake attachments rare, 2% BEC

Statistic 99

78% ATO via phishing

Statistic 100

25% BEC via mobile compromise

Statistic 101

Real estate leads BEC complaints at 34%

Statistic 102

70% of BEC victims are businesses with 1-100 employees

Statistic 103

Finance sector reports 20% of BEC losses

Statistic 104

43% of BEC targets are in manufacturing

Statistic 105

Non-profits saw 15% BEC complaint increase in 2022

Statistic 106

60% of BEC victims recover no funds

Statistic 107

Education sector BEC losses up 300% in 2021

Statistic 108

25% of BEC victims are government entities

Statistic 109

SMEs comprise 82% of BEC victims

Statistic 110

Retail industry 12% of BEC complaints

Statistic 111

90% of BEC victims are US-based companies

Statistic 112

Healthcare BEC incidents rose 50% in 2022

Statistic 113

Law firms represent 9% of BEC targets

Statistic 114

35% of victims lose over $100K in single BEC attack

Statistic 115

Construction firms 18% of BEC losses

Statistic 116

Construction 23% of BEC victims

Statistic 117

55% BEC targets executives

Statistic 118

Finance pros hit in 40% BEC

Statistic 119

HR departments 15% BEC targets

Statistic 120

80% victims under 500 employees

Statistic 121

Tech sector 10% BEC complaints

Statistic 122

Energy sector 8% victims

Trusted by 500+ publications
Harvard Business ReviewThe GuardianFortune+497
While Business Email Compromise may seem like a distant threat, the staggering reality is that this single cybercrime has drained over $50 billion globally since 2016, with losses still climbing every year.

Key Takeaways

  • BEC scams resulted in $2.9 billion in losses in 2022
  • Global BEC losses exceeded $43 billion from 2016 to 2021
  • Average BEC loss per incident was $120,000 in 2021
  • Over 19,000 BEC complaints in 2021
  • BEC complaints increased 3.5% from 2020 to 2021
  • 21,381 BEC complaints reported to IC3 in 2022
  • Real estate leads BEC complaints at 34%
  • 70% of BEC victims are businesses with 1-100 employees
  • Finance sector reports 20% of BEC losses
  • 76% of BEC uses compromised legitimate accounts
  • 85% of BEC involves social engineering
  • Email spoofing in 60% of BEC attacks
  • 96% of organizations use MFA but BEC succeeds via fatigue
  • Only 14% of BEC funds recovered globally
  • Training reduces BEC success by 70%

BEC causes billions in losses as a leading business cyber threat.

Financial Impact

  • BEC scams resulted in $2.9 billion in losses in 2022
  • Global BEC losses exceeded $43 billion from 2016 to 2021
  • Average BEC loss per incident was $120,000 in 2021
  • BEC accounted for 20% of all cybercrime losses in 2022
  • US businesses lost $1.86 billion to BEC in 2021
  • Median BEC loss was $100,000 for wire transfer fraud in 2022
  • BEC losses in real estate sector topped $500 million in 2022
  • Over 21,000 BEC complaints led to $2.7 billion losses in 2020
  • BEC wire transfers averaged $145,000 per victim in 2019
  • International BEC losses reached $1.8 billion in 2022
  • BEC caused $1.82 billion US losses in 2019
  • Average BEC payroll scam loss was $40,000 in 2021
  • BEC losses grew 7% from 2021 to 2022
  • 83% of BEC losses from wire transfers in 2022
  • BEC false invoice scams averaged $21,000 loss in 2022
  • Total BEC losses since 2016 exceed $50 billion globally
  • US BEC losses hit $43 million in Q1 2023 alone
  • BEC accounted for $6.2 billion in global losses over 4 years
  • Average BEC loss for US victims was $89,000 in 2020
  • BEC spear-phishing losses averaged $200,000 per incident
  • BEC caused 65% of financial fraud losses in 2022
  • BEC scams caused $1.7 billion losses in 2018
  • Average BEC loss reached $75,000 in 2020
  • BEC payroll scams cost $798 million in 2022
  • BEC losses $4.2B in 2023 projection

Financial Impact Interpretation

Business Email Compromise has perfected the art of swindling billions with the simplicity of a well-crafted lie, proving that the most sophisticated cybercrime often arrives dressed as an urgent, believable email from your boss.

Prevalence

  • Over 19,000 BEC complaints in 2021
  • BEC complaints increased 3.5% from 2020 to 2021
  • 21,381 BEC complaints reported to IC3 in 2022
  • BEC represented 1.7% of all IC3 cyber complaints in 2022
  • Global BEC incidents rose 65% in 2021
  • 15,000+ BEC incidents in US in 2019
  • BEC scams targeted 98% of US organizations in 2022
  • 1 in 10 organizations hit by BEC annually
  • BEC incidents doubled from 2018 to 2019
  • Over 12,000 BEC complaints in 2018
  • BEC prevalence up 11% year-over-year in 2023
  • 91% of BEC attacks use email as vector
  • BEC scams reported in 150+ countries
  • 3,700% increase in BEC since 2015
  • Weekly BEC attempts average 300 per organization
  • BEC in 80% of ransomware precursors
  • 22,000 BEC complaints in 2023 first half
  • BEC growth rate 15% annually since 2016
  • SMEs report 40% of BEC incidents
  • BEC attacks every 11 seconds globally
  • 32% of breaches involve BEC tactics
  • 17,000 BEC complaints in 2020
  • BEC up 100% from 2016 to 2022
  • 50% orgs face BEC quarterly
  • 18,000+ BEC cases 2023 H1

Prevalence Interpretation

While the staggering 3,700% rise in Business Email Compromise since 2015 suggests cybercriminals have found a devastatingly profitable formula, the fact that a BEC attempt now strikes somewhere globally every 11 seconds means your inbox is quite literally on the clock.

Response

  • 96% of organizations use MFA but BEC succeeds via fatigue
  • Only 14% of BEC funds recovered globally
  • Training reduces BEC success by 70%
  • DMARC adoption cuts BEC by 50%
  • 65% of BEC detected post-transfer
  • AI detection flags 80% BEC emails
  • Employee reporting stops 40% potential BEC
  • Financial training lowers BEC risk 60%
  • 85% BEC preventable with verification protocols
  • EDR blocks 90% account takeovers
  • Phishing sims reduce clicks by 55%
  • 20% BEC stopped by email gateways
  • Multi-factor fatigue exploited in 25% failures
  • Incident response time averages 2 weeks for BEC
  • 75% orgs lack BEC-specific policies
  • BEC losses drop 40% with wire approval processes
  • Training cuts BEC 90% in mature orgs
  • DMARC stops 60% spoofing
  • 30% BEC caught by users
  • AI blocks 85% anomalous emails
  • Verification dual-signoff prevents 70%
  • 50% recovery with quick reporting
  • Phishing tests reduce risk 65%
  • Gateways filter 25% BEC
  • Avg detection 72 hours
  • 60% lack recovery plans
  • 40% orgs no BEC training

Response Interpretation

These statistics reveal a frustrating truth: while we've built a formidable shield against BEC with tools like MFA, DMARC, and AI, our most sophisticated security layer—the employee—remains simultaneously our greatest vulnerability and our most powerful defense, depending entirely on how well we train and support them.

Tactics

  • 76% of BEC uses compromised legitimate accounts
  • 85% of BEC involves social engineering
  • Email spoofing in 60% of BEC attacks
  • MFA bypass via phishing in 40% BEC cases
  • Vendor email compromise in 15% of incidents
  • 92% of BEC relies on urgency in emails
  • Account takeover primary in 50% BEC
  • CEO fraud variant in 22% of attacks
  • Malware-free BEC in 98% cases
  • Conversation hijacking in 30% BEC threads
  • 70% BEC from Nigeria-based actors
  • Display name spoofing used in 45% attacks
  • QR code phishing in rising 10% BEC variants
  • 65% BEC targets finance departments
  • Zero-day exploits rare, <1% in BEC
  • Email compromise in 88% BEC
  • 50% BEC uses business process compromise
  • Urgency tactics in 95% emails
  • West Africa origin 60% BEC
  • 35% BEC via data from breaches
  • Fake attachments rare, 2% BEC
  • 78% ATO via phishing
  • 25% BEC via mobile compromise

Tactics Interpretation

The modern BEC criminal is a pragmatic con artist who rarely bothers with complex malware or zero-days, instead simply hijacking the authority of a legitimate account through a blend of social engineering, urgency, and a shocking amount of coffee-spilling panic to trick finance departments into paying West African-based actors.

Victims

  • Real estate leads BEC complaints at 34%
  • 70% of BEC victims are businesses with 1-100 employees
  • Finance sector reports 20% of BEC losses
  • 43% of BEC targets are in manufacturing
  • Non-profits saw 15% BEC complaint increase in 2022
  • 60% of BEC victims recover no funds
  • Education sector BEC losses up 300% in 2021
  • 25% of BEC victims are government entities
  • SMEs comprise 82% of BEC victims
  • Retail industry 12% of BEC complaints
  • 90% of BEC victims are US-based companies
  • Healthcare BEC incidents rose 50% in 2022
  • Law firms represent 9% of BEC targets
  • 35% of victims lose over $100K in single BEC attack
  • Construction firms 18% of BEC losses
  • Construction 23% of BEC victims
  • 55% BEC targets executives
  • Finance pros hit in 40% BEC
  • HR departments 15% BEC targets
  • 80% victims under 500 employees
  • Tech sector 10% BEC complaints
  • Energy sector 8% victims

Victims Interpretation

Here is a one-sentence interpretation that weaves in key themes from your statistics: While small and mid-sized businesses often view their size as a shield, this data starkly reveals they are actually the preferred and most vulnerable prey for BEC scammers, with devastating success rates that spare few sectors from crippling financial hits.