An official Admiresty Corporation service
How to verify
Official Admiresty services use admiresty.co

Admiresty Corporation operates ThreatGrid and its full service ecosystem from admiresty.co. All official platforms run from this domain or a verified subdomain. If you’re unsure, visit admiresty.co directly to confirm.

Secure Admiresty services always use HTTPS

A padlock and https:// in your address bar confirm a safe, encrypted connection. Never enter credentials or share sensitive data on any page without a valid HTTPS connection to an Admiresty domain.

Free security assessment for qualifying organizations — request yours →

Business email compromise hit $3 billion in 2025. Here’s what actually stops it

The FBI’s 2025 Internet Crime Report puts business email compromise losses at just over $3 billion, with complaints up 16% year over year. This analysis breaks down why BEC keeps working and the payment and identity controls that measurably reduce losses.

The FBI’s Internet Crime Complaint Center (IC3) published its 2025 annual report this spring, and the headline is hard to ignore: reported cybercrime losses reached roughly $20.9 billion, a 26% increase over 2024 and the highest total the FBI has recorded. Business email compromise (BEC) was the second-largest loss category behind investment fraud, at just over $3.04 billion from 24,768 complaints.

The numbers in context

BEC complaints rose about 16% from 2024 (21,442 complaints), and losses rose about 10% from roughly $2.77 billion. Divide the total by the complaint count and the average reported BEC loss is around $123,000, a figure that would be a serious event for most small and mid-sized organizations. These are only reported cases; the real number is higher.

2025 was also the first year the FBI tracked AI-related cybercrime as its own category, logging close to $900 million in losses across all crime types. For BEC specifically, AI shows up in the execution: polished messages in the right tone, convincing replies when a target pushes back, and in some cases cloned voices used to “confirm” a payment over the phone.

Why BEC keeps working

BEC is not a technical exploit. It works because it fits inside normal business processes. The typical pattern is familiar: an attacker compromises or impersonates a mailbox belonging to an executive, a vendor, or a title or escrow company, waits for a real transaction, then sends updated payment instructions at exactly the right moment. Nothing about the message looks malicious to a filter, because nothing in it is malicious, just a new bank account number.

The money usually moves by wire or ACH, and once it has been forwarded through a chain of accounts it is rarely recovered. That makes BEC a race: controls that slow down or verify a payment change are far more valuable than anything that helps after the fact.

Controls that measurably reduce losses

Out-of-band verification for any payment change. Any request to change bank details, or any first-time payment above a threshold, is confirmed by phone using a number already on file, never a number from the email requesting the change. This single control defeats most BEC attempts, including ones that use a compromised legitimate mailbox. With voice cloning now in play, make the call yourself rather than accepting an inbound call as confirmation.

A hold period on new or changed payees. A 24 to 48 hour delay before a changed account can receive funds gives time for the real vendor to notice. Most banks and AP platforms support this.

Phishing-resistant MFA on email. Many BEC cases start with a stolen Microsoft 365 or Google Workspace password. Attackers increasingly use adversary-in-the-middle kits that relay one-time codes, so passkeys or FIDO2 security keys for finance, executive, and admin accounts close the gap that SMS and app codes leave open.

Watch for mailbox rules and forwarding. After taking over a mailbox, attackers almost always create inbox rules that hide replies from the real owner or forward finance-related mail elsewhere. Alerting on new forwarding rules and unusual sign-in locations catches compromises before the payment request goes out.

Lookalike domain monitoring and DMARC enforcement. Register obvious misspellings of your own domain, monitor for new lookalikes, and move DMARC to p=quarantine or p=reject so attackers can’t send as your exact domain. TLINK PRO’s DNS checker and email deliverability tools show your current SPF, DKIM, and DMARC posture.

A rehearsed recall procedure. If money does go out, minutes matter. Finance staff should know to call the bank’s fraud line immediately to request a recall and to file with IC3 the same day. The FBI’s Recovery Asset Team has frozen funds in many cases where the report came in quickly.

Where managed security fits

Most of these controls are process, not tooling, but the detection piece, catching the mailbox takeover before the fraudulent invoice, is where analyst coverage pays off. ThreatGrid’s MDR service monitors identity and email signals for the patterns that precede BEC, and our legal and financial services programs include wire-fraud specific playbooks. To see where your organization stands, request an assessment.

Source: FBI Internet Crime Complaint Center, 2025 Internet Crime Report (ic3.gov), and published analyses of the report.


Take action

Request an assessment or start a conversation.

ThreatGrid works with organizations at every maturity level — from first MSSP evaluation through active monitoring and incident response.