Skip to Main Content

BEC Cost Calculator

Model what one business email compromise could cost you, using the FBI's 2025 Internet Crime Report as the per-incident figure. Every assumption stays visible and editable.

This is a model, not a forecast. IC3 publishes what victims reported. It does not publish the odds that any particular company is targeted, and neither does anyone else. The number of incidents below is your assumption, not evidence. The tool supplies one figure from the report and does the multiplication; it cannot tell you what will happen.

Your organization

Total headcount. Shown for context only. It does not scale the exposure figure, because IC3 publishes no loss-per-employee rate.

people

People who can initiate or approve a payment. This is the group BEC actually targets.

people

Your typical wire or supplier payment. Leave blank to use the IC3-derived average of $123,005 per reported incident.

USD

How many BEC attempts you assume would succeed in a year. There is no published base rate for this. It is a planning input, and the output is only as good as it is.

per year

Modeled exposure

Estimate, not a prediction

Modeled annual exposure $123,005, from 1 assumed incidents at $123,005 each.

Modeled annual exposure$123,005

1 assumed incident × $123,005 per incident

Loss per successful incident$123,005

Calculated from IC3 2025: $3,046,598,558 in reported BEC losses ÷ 24,768 complaints. IC3 does not publish this average itself.

Analyze these results with AI

Send this model, assumptions included, to your AI assistant to pressure-test it and talk through what reduces the exposure.

Assumptions behind that number

  • Incidents per year: 1. Your input, and no published source supports any particular value.
  • Loss per incident: $123,005. calculated from IC3 2025 totals.
  • Not included: recovery costs, legal fees, downtime, insurance excess, and reputational damage. IC3 records the reported loss only, so this model does too. The real cost of an incident is higher than the figure above.
  • Recovery is possible: IC3 operates a Recovery Asset Team that can freeze fraudulent wires when an incident is reported quickly. The model assumes no recovery, which makes it a gross figure, not a net one.

What IC3 actually published

From the 2025 IC3 Annual Report (April 2026). These are the figures as printed; the average is the only derived value on this page.

Reported business email compromise complaints and losses by year, from the IC3 annual reports
YearBEC complaintsReported losses
202321,489$2,946,830,270
202421,442$2,770,151,146
202524,768$3,046,598,558
  • BEC losses rose 10.0% between 2024 and 2025, against 1,008,597 complaints and $20.877 billion in total reported losses across all crime types.
  • BEC is not the costliest crime type by total losses. Investment fraud reported $8,648,617,756 in 2025, nearly three times BEC. What BEC leads on is the average per complaint: $123,005 against $118,500 for investment fraud and $8,950 for ransomware.
  • Wire transfer or ACH was the most frequently reported transaction type in BEC complaints, at 86%, which is why the average payment size in your finance process is the most useful number you can put into this model.
  • $30,256,592 of 2025 BEC losses were reported in complaints that referenced AI. IC3 applies that descriptor when the complaint text mentions AI, not when AI involvement is confirmed.

What the figures do and don’t cover

  • The figures are complaints voluntarily reported to a US federal channel, not measured losses. Incidents that were never reported to IC3 are not in them.
  • Each complaint is counted under exactly one crime type, so a BEC that also involved a data breach appears once.
  • IC3 describes its statistics as an assessment taken at a point in time, which may change.

Sources

Every dollar figure on this page comes from the 2025 IC3 Annual Report, published April 2026. The per-incident average is calculated from two figures in it and is labelled as such wherever it appears.

DMARC at enforcement closes one BEC route: mail sent as your exact domain

It won't stop a lookalike domain or a compromised mailbox, and no honest tool claims otherwise. What it does stop is someone putting your domain in the From line. Palisade's agent investigates every sender, drafts the fixes, and proposes each policy step. You approve before anything ships.

Get my domain to enforcement

1 domain free up to 1,000 emails/month

Related: score your domain’s authentication or check a suspicious link.

What is a BEC cost calculator?

Business email compromise is the attack where someone convinces a person who can move money to move it to the wrong account, usually by impersonating an executive, a supplier, or a colleague. Divide the FBI’s reported BEC losses by its complaint count and the average comes to about $123,005 per incident, higher than any other crime type in the report, though IC3 does not publish that average itself. This calculator turns that into a number you can put in front of a budget conversation: a per-incident loss taken from the FBI Internet Crime Complaint Center, multiplied by an incident count you set yourself. It is a model with its assumptions in the open, not a risk score, because nobody publishes the data a real risk score would need. On the controls side, the piece of this that authentication addresses is exact-domain spoofing: see where your domain stands with the email security score, or read how the attack works.

How much does business email compromise cost?

The FBI Internet Crime Complaint Center recorded 24,768 BEC complaints in its 2025 Internet Crime Report, with $3,046,598,558 in reported losses. Dividing one by the other gives roughly $123,005 per reported incident, which is a calculation rather than a figure IC3 publishes. That average is the highest of any crime type in the report, so while BEC is not the largest category by total losses, an individual incident costs more than one from any other category.

Where do the figures in this calculator come from?

One source: the FBI Internet Crime Complaint Center's 2025 Internet Crime Report, published in April 2026 and available as a PDF at ic3.gov. The complaint counts and loss totals for 2023, 2024 and 2025 are taken from its three-year comparison tables, and the comparisons with investment fraud and ransomware come from the same tables. Nothing on the page comes from a vendor survey or a secondary summary.

Is BEC the most expensive type of cybercrime?

Not by total losses. In the 2025 IC3 report, investment fraud accounted for $8,648,617,756 against BEC's $3,046,598,558, so investment fraud is nearly three times larger. Where BEC leads is the average loss per complaint, a figure calculated by dividing each category's losses by its complaint count rather than published by IC3: about $123,005 for BEC, against roughly $118,500 for investment fraud and around $8,950 for ransomware. Both statements are true, and they answer different questions. For an organization deciding what a single incident would cost, the average per complaint is the relevant one. For the ranking itself, see whether BEC is the most expensive cyberattack.

How is the exposure figure calculated?

Assumed successful incidents per year multiplied by the loss per incident. The loss figure defaults to the IC3-derived average and switches to your own number if you enter an average payment size, which is usually the better input because wire transfer or ACH was the most frequently reported transaction type in BEC complaints, at 86%. The incident count is entirely your assumption. IC3 publishes what victims reported, not the probability that any particular organization is targeted, so no published source can supply that number and the tool does not pretend to.

Why can this not tell me my actual risk?

Because the data does not support it. IC3 figures are complaints voluntarily reported to a US federal channel, not measured losses across all organizations, so incidents that were never reported are absent. Each complaint is counted under exactly one crime type, so a BEC that also involved a data breach appears once. IC3 itself describes its statistics as an assessment taken at a point in time that may change. A model built on those figures produces a planning estimate, not a prediction, which is why every assumption stays on screen.

What does the exposure figure leave out?

Recovery costs, legal fees, downtime, insurance excess, audit work, and reputational damage. IC3 records the reported loss, so a model built on it does the same. It also assumes no funds are recovered, which makes the output a gross figure. IC3 operates a Recovery Asset Team that can freeze fraudulent wires when an incident is reported quickly, so fast reporting genuinely changes the outcome even though the model cannot account for it.

Does DMARC stop business email compromise?

It closes one route. A DMARC policy at quarantine or reject stops mail that puts your exact domain in the From address, which is the cheapest version of the attack. It does not stop a lookalike domain, a compromised supplier mailbox, or a compromised account inside your own organization, and no honest tool claims otherwise. DMARC is worth doing because it removes the easiest option and gives you visibility into who sends as you. Pair it with payment verification controls that do not depend on email.

What should we do if we have been hit?

Contact your bank immediately and ask them to recall the transfer, then file a complaint at ic3.gov with the transaction details. Speed matters more than anything else: the IC3 Recovery Asset Team works with financial institutions to freeze fraudulent wires, and that window closes fast. Preserve the original emails with full headers, because the routing information is what an investigation works from.