FBI: US victims lost nearly $21B to cybercrime in 2025, up 26% YoY, driven by investment scams, business email compromise, tech support fraud, and data breaches
U.S. victims lost nearly $21 billion to cyber-enabled crimes last year, driven primarily by investment scams, business email compromise …
Context & Ripple Effects
The reported total extends a multi-year escalation in FBI-reported losses: from $4.2B reported for 2020 to $6.9B in 2021, $12.5B in 2023, and a record $16.6B in 2024.
The composition also matters. Investment fraud had already become the largest reported loss category in 2023, while business email compromise was responsible for roughly half of estimated losses in the FBI's 2019 accounting. The latest report indicates that both enduring enterprise-payment fraud and consumer-facing scams remain material drivers.
First-order effects
- US victims and organizations absorb nearly $21B in reported losses, with investment scams, business email compromise, tech-support fraud, and data breaches concentrating the immediate harm.
- Companies exposed to payment-email fraud and breached data face more urgent pressure to verify transactions and contain compromised accounts, while the FBI receives a larger fraud-enforcement and reporting burden.
Second-order effects
- Banks, payment providers, email platforms, and security vendors will face greater demand for controls that interrupt impersonation, suspicious transfers, account takeover, and scam-driven customer support interactions.
- The persistence of business email compromise alongside investment scams broadens the market beyond a single consumer-fraud category: employers and their vendors must address payment-workflow risk as well as customer-facing social engineering.
Third-order effects
- If reported losses continue rising at this pace, cybercrime prevention will increasingly be treated as a financial-loss and operational-resilience problem, not solely an IT-security function.
- The recurring mix of investment fraud, impersonation, and data compromise points toward a more integrated fraud stack across identity, communications, payments, and incident response; how much this shifts industry practice will depend on whether reporting and enforcement translate into lower loss rates.
The trend: This is another data point in the convergence of cyber security and fraud prevention as online crime increasingly monetizes both compromised systems and human trust.