FBI says “CEO fraud” attacks, where scammers often scrape email addresses and impersonate execs to target employees, have cost organizations $2.3B+ since 2013
Brian Krebs / Krebs on Security :
Context & Ripple Effects
This 2016 report is the early baseline for a fraud category that kept compounding: FinCEN's later tracking shows attempted business email compromise thefts rising from $110M per month in 2016 to $301M per month in 2018, and IC3's global tally put actual and attempted BEC losses above $43B from mid-2016 through mid-2019.
Krebs' figure matters because it names the mechanism — scraped addresses, executive impersonation, wire-transfer requests aimed at employees — that FBI reporting has since treated as a top loss driver year after year.
First-order effects
- Finance and treasury staff at targeted organizations face immediate pressure to add out-of-band verification before executing exec-requested wire transfers, since the scam's entry point is ordinary corporate email rather than malware.
- The FBI's $2.3B+ aggregate gives prosecutors and cyber-insurance underwriters a quantified loss base for a crime that previously looked like isolated incidents.
Second-order effects
- Email security vendors and payment-process controls become procurement priorities as BEC scales — FinCEN's monthly-attempt figures show attackers industrializing faster than perimeter defenses alone can absorb.
- Cyber insurers begin pricing social-engineering and funds-transfer-fraud coverage as a distinct line item rather than folding it into general breach risk.
Third-order effects
- If FBI and FinCEN reporting holds its trajectory, BEC cements itself as a standing loss category measured in tens of billions globally, pushing banks and corporates toward shared verification standards for high-value transfers.
- Sustained aggregate losses give regulators a data case for treating executive-impersonation fraud as systemic financial-crime infrastructure rather than consumer nuisance fraud.
The trend: Business email compromise is scaling from a niche impersonation scam into one of the costliest reported cybercrime categories, with FBI and FinCEN tallies documenting the climb.