Is business email compromise the most expensive cyberattack?
In brief
Business email compromise ranks second by total losses in the FBI's 2025 figures, behind investment fraud, but leads every category on loss per complaint.

No. By the most widely cited loss figures, the FBI's Internet Crime Complaint Center, business email compromise ranks second, not first. IC3's 2025 report records $3,046,598,558 in BEC losses against $8,648,617,756 for investment fraud. BEC does lead on one measure: average loss per complaint, at roughly $123,000, the highest of any crime type IC3 tracks. "Most expensive" may mean total reported losses, loss per incident, recovery cost, or business disruption, and those measures rank attacks differently. See the broader email threats and impersonation hub for related security topics.
At a glance
Quick takeaways
- In the FBI's 2025 figures, BEC losses were $3.05 billion, second to investment fraud at $8.65 billion.
- The average BEC complaint reported about $123,000 in losses, the highest of any crime type IC3 tracks.
- Reported losses do not necessarily equal total losses, incident response costs, or operational disruption.
- A single large breach and a category of fraud cannot be ranked together without a stated methodology.
- "Largest cyberattack" has no single answer unless the measurement is defined first.
- Claims that a percentage of incidents begin with email require a source that defines both "incident" and its sample.
- An email-security review can identify controls to examine, but it does not prove that BEC is prevented.
How an "most expensive" claim works
The phrase "most expensive cyberattack" combines two decisions that must be explicit: what counts as the attack category, and what counts as cost.
A category-level claim compares many events over a reporting period. A single-event claim compares one incident against another. A loss claim may count money reported by victims, while an operational-cost claim may include investigation, recovery, legal work, downtime, or other impacts. Without the same measurement across every item being compared, the ranking is not reliable.
A quotable statement should therefore include all of the following:
- The source that collected the data.
- The reporting period.
- The definition of BEC used by that source.
- The loss metric.
- The attack categories included in the comparison.
- Any stated limits, such as underreporting or incomplete cost capture.
Likewise, Darktrace describes its platform as providing "Unified visibility, continuous behavioral monitoring, and autonomous response across your entire enterprise." That product description does not rank cyberattack categories by financial loss. Darktrace's product overview is not evidence for a BEC cost comparison.
When the answer changes
The answer can change only when a source makes the ranking testable.
Use this decision rule:
- If an official report compares BEC with other attack categories using the same reported-loss metric and period, describe BEC's rank exactly as that report states it.
- If a source reports BEC losses without comparing categories, say that it reports BEC losses. Do not add a rank.
- If a source identifies one expensive incident, describe it as a single incident. Do not use it to rank an attack category.
- If a source uses a different measure, such as records exposed, affected people, downtime, or ransom demand, keep that measure separate from financial loss.
- If the source does not define its population or method, treat its ranking as unsupported.
Do not turn a headline, vendor marketing statement, or isolated incident figure into an industry-wide ranking. The comparison method must be available to readers.

What the FBI's 2025 figures actually show
The IC3 annual report is the source that makes this ranking testable, because it publishes losses and complaint counts for every crime type it tracks, over the same period, using the same self-reported metric.
For 2025 it records $3,046,598,558 in BEC losses across 24,768 complaints, inside a total of $20.877 billion across 1,008,597 complaints. Ranked by total reported losses, investment fraud is far larger at $8,648,617,756. The report states the order plainly: investment-related fraud was the largest component of losses, followed by business email compromise and tech support scams.
So the popular claim fails on total losses. It holds on a different measure. Dividing IC3's published losses by its published complaint counts gives an average reported loss per complaint:
| Crime type | Average reported loss per complaint |
|---|---|
| Business email compromise | $123,005 |
| Investment fraud | $118,500 |
| Data breach | $109,826 |
| Tech and customer support scams | $44,664 |
| Ransomware | $8,950 |
| Phishing and spoofing | $1,127 |
BEC has the highest average of any category, and roughly fourteen times the average of a ransomware complaint. IC3 does not publish these averages, so treat them as calculated from its figures rather than quoted from the report.
Three caveats travel with every number above. The data is self-reported complaints to a United States federal channel, not measured losses. Each complaint is counted under a single crime type, so a phishing email that ends in a fraudulent wire appears once, not twice. And IC3 describes its own statistics as an assessment taken at a point in time, which may change.
The honest published claim is therefore one of these: BEC is the second-costliest crime type in the FBI's 2025 figures; or the average BEC complaint reports the largest loss of any category; or BEC is the most expensive attack on business email, which is a narrower class than "cyberattack."
Worked evidence rule for a BEC cost claim
Use a claim only when it can be expressed with the source's own scope and metric.
Publishable claim shape:
[Official source] reports [amount or rank] for [defined BEC category]
during [reporting period], measured as [defined loss metric], compared with
[defined attack categories or population].
Do not publish:
"Business email compromise is the most expensive cyberattack."
unless the cited source explicitly supports that exact comparison.
The first shape gives readers a way to assess the claim. The second omits the source, period, metric, and comparison class.
The same rule applies to statements such as "90% of cyber incidents begin with email" or "a stated percentage of cyberattacks use email." Those figures need a primary study that defines what counted as an incident or attack, who was measured, and how the percentage was calculated. A percentage without those details cannot establish a general fact about all organizations.
What to check before using a BEC cost claim
Start with the source named in the statement. Look for the report itself, rather than a summary page, and record the reporting period and definition of loss. Then check whether it compares BEC against other categories under the same method.
If the evidence concerns your own organization rather than an industry-wide ranking, keep the question operational:
- Identify the business process that handles payment, supplier, payroll, or account-change requests.
- Record which verification step is required before that process releases money or changes details.
- Review the organization’s broader email security controls alongside the approval process.
- Preserve the relevant evidence for incident response and follow the organization’s reporting procedure when fraud is suspected.
That check does not detect every BEC attempt, prove that a payment request is legitimate, monitor a production environment continuously, or establish the cost of any attack category.
Evidence
Sources and further reading
- FBI IC3 annual reports. The 2025 Internet Crime Report is the source for every loss and complaint figure above.
- APWG Phishing Activity Trends Report, Q1 2026. Attack volume and BEC delivery methods.
- CISA, NSA, FBI and MS-ISAC phishing guidance. The recommended control set, including DMARC at reject.
- Palisade email security guide
- Palisade email security score checker
Questions readers ask
Frequently asked questions
What do business email compromise attacks rely most heavily on?
Business email compromise relies most heavily on ordinary email accounts rather than technical exploits. Fortra's data in the APWG Q1 2026 report found 72% of BEC attacks were launched from a free webmail domain, with Gmail accounting for 53% of those. The most common payout method was gift cards at 48%, ahead of wire transfers at 19%, and the average wire request was $42,663. Those figures describe attempted attacks observed by one vendor, not confirmed losses.
What is the largest cyberattack in history?
The answer changes with the measure you pick, because "largest" can mean reported financial loss, people affected, records exposed, duration, or business disruption. Measured by money reported to the FBI in 2025, investment fraud leads at $8,648,617,756, with business email compromise second at $3,046,598,558. Name your metric first, then use a source that compares events under that same metric.
Where do 90% of all cyber incidents begin?
The usual answer given is email, but nobody publishes the study behind the 90% figure, so it works as a slogan rather than a statistic. A number worth citing would define what counts as an incident, name the population measured, state the period, and explain how the percentage was calculated. Until you can find that source, call email a common starting point and leave the number off.
What percent of cyber attacks use email?
There is no dependable single percentage, because threat reports, incident datasets, and security telemetry each define "cyberattack" differently and count email's role differently. The FBI's IC3 files each complaint under one crime type, so a phishing email that ends in a fraudulent wire is counted once, not twice. Quote a percentage only when the source states its definition, sample, and period.
Does an email-security score prove a company is protected from BEC?
No, an email-security score cannot prove that, because it reviews public domain evidence rather than the payment and approval steps that BEC targets. Most BEC attempts succeed through a convincing request sent to a person, not a flaw in DNS. Use the score to open a control review, then check how your team verifies payment, supplier, and account-change requests.

Written by
Ian BussieresCTO & Co-Founder, Palisade
Ian Bussieres is the CTO and co-founder of Palisade, agentic DMARC software for IT teams and MSPs.
More from Ian →


