ScamsImpersonationBusiness email compromise and CEO fraud: one map of the scam family that cost $3 billion in 2025
High

Business email compromise and CEO fraud: one map of the scam family that cost $3 billion in 2025

A polite email from your 'CEO,' a trusted vendor, or 'HR' asks to wire funds, reroute payroll, buy gift cards, or send employee W-2s. It's all one scam — business email compromise — which the FBI ties to $3 billion in reported losses in 2025 and $55.5 billion in 2013–2023 cumulative exposed losses. Here's every major variant on one map, and the single verification rule that stops all of them.

Sources checked:FBI IC3IRSFTC

The most expensive scam a business will ever face doesn’t crash your systems or lock your files. It arrives as a normal email, from someone you know, asking for something that sounds like work. Business email compromise (BEC) — with its best-known variant, CEO fraud — is what the FBI calls “a sophisticated scam that targets both businesses and individuals who perform legitimate transfer-of-funds requests.” In 2025 alone, the FBI’s Internet Crime Complaint Center (IC3) logged 24,768 BEC complaints with just over $3.0 billion in reported losses — second only to investment fraud by dollars. Cumulatively, the IC3 counts $55.5 billion in exposed losses (actual and attempted) across 305,033 incidents reported from October 2013 through December 2023.

Here’s the whole defense, before the map: any request to move money, change where money goes, or release employee data gets confirmed by voice on a number you already had. Every variant below — and every variant that hasn’t been invented yet — dies at that one habit.

One engine, six costumes

Strip away the details and every BEC scheme is the same machine: a trusted identity + a plausible, work-shaped request + a new destination for money or data + a reason not to check. There’s usually no malware and often no link — nothing for a filter to catch, because the email is just words asking a competent employee to do their job slightly differently. What changes between variants is only the costume the trusted identity wears. Map the costumes and you’ll recognize all of them.

The variants, mapped

CEO / executive wire fraud. The classic. An email that appears to come from the CEO or CFO — often “in a meeting, can’t talk” — asks a finance employee for an urgent, confidential wire. The secrecy is load-bearing: it isolates the target from the one conversation that would collapse the scam. The video-call era upgraded the costume, not the engine — attackers now stage deepfake video calls of executives to bless the same transfer.

The gift card run. The small-dollar version of CEO fraud, aimed at any employee, not just finance. The “boss” needs gift cards for a client surprise — buy them, send the numbers on the back. The FTC’s January 2026 alert is blunt: “Only scammers will ask for gift card numbers and the PIN” — and its advice is to check with your boss first, using a number or email you know is real, not the one that contacted you. Full mechanics in our guide to gift card payment scams.

Vendor email compromise. The costliest costume in practice: a supplier you genuinely owe announces that “our bank details have changed,” often from the supplier’s real, compromised mailbox, inside a real thread. We take one of these apart line by line in the anatomy of a BEC invoice email. Its cousin — an invoice from a vendor that never existed at all — is a different con with a different fix; see fake invoices to small businesses.

Payroll diversion. Here the target is HR or the employee self-service portal. In a 2018 alert, the IC3 described criminals phishing employees’ login credentials, entering payroll accounts, and changing direct deposit information so paychecks flow to accounts they control — frequently prepaid cards — while adding account rules that block the alerts that would have warned the employee. Sometimes there’s no hacking at all: just an email to HR, “from” an employee, asking to update their banking details before Friday.

W-2 data theft. The variant that asks for data instead of dollars. The IRS warns that “cybercriminals use various spoofing techniques to disguise an email to make it appear as if it is from an organization executive,” sent to payroll or HR requesting all employees’ Forms W-2 — names, addresses, SSNs, wages in one file. The IRS classifies it as business email compromise, and the harvest feeds fraudulent tax returns filed in employees’ names.

The real estate closing. BEC pointed at the largest wire most people ever send. Criminals compromise a mailbox inside a transaction — agent, title company, attorney — then send the buyer “updated” wiring instructions days before closing. Per the IC3, BEC with a real estate nexus cost victims $446.1 million in 2022. The full play, and the one phone call that beats it, is in real estate wire fraud.

How the impersonation actually works

Four techniques carry every costume, in rising order of quality. Display name spoofing: the executive’s name over a random address — cheap, but effective on phones that hide the sender. Look-alike domains: a registered domain one character off the real one, so even a glance at the address passes. Thread hijacking: the attacker replies inside a stolen, genuine conversation, so everything above their message is real. Account takeover: the request comes from the actual mailbox — the FBI describes BEC as frequently carried out when a criminal compromises “legitimate business or personal email accounts through social engineering or computer intrusion,” which is why a phished login page is so often the first domino.

Generative AI has polished all four. The FBI’s 2025 report notes that “chat generators can quickly create official-sounding emails mimicking a company’s CEO or other officials,” and voice cloning now backs up the email with a phone call; in 2025, businesses reported more than $30 million in losses to BEC scams with an identified AI component. The broken-English tell is gone for good.

Why it beats smart, careful people

BEC doesn’t exploit gullibility — it exploits workflow. Paying invoices promptly, obeying executives, processing payroll changes: the scam rides the exact behaviors employees are hired for. Urgency and secrecy shrink the checking window; timing near deadlines, closings, and end-of-week banking hours does the rest. That’s why “be more careful” fails as a defense. The request is engineered to look exactly like the hundred legitimate requests around it — the fix has to be structural, not perceptual.

The one rule that kills every variant

This is Two-Channel Verification, written down as company policy. The FBI’s own protective guidance for BEC is to “use secondary channels and/or two-factor authentication to verify requests for changes in account information” — and the operational version fits on an index card:

  • Fix the trigger. Any request to send money, change bank/payroll/wiring details, or release employee data requires a voice confirmation on a number you already had. Not the number in the email signature. No exceptions for rank, urgency, or how real the thread looks.
  • Fix the process. Two approvers above a set threshold; vendor bank changes take effect only after the call-back; gift cards are never a business payment method, full stop.
  • Fix the doors. Multi-factor authentication on email, and a standing check for unauthorized mail-forwarding rules — the quiet tool attackers use to keep reading after a password reset. The broader small-company checklist is in the owner’s playbook.

Notice what’s not required: spotting the fake. The rule works even when the email is perfect, because it never argues with the email at all.

If money or data already moved

Speed decides everything. Call your bank now and ask for a wire recall, then file at ic3.gov with account numbers and the timeline — the IC3’s Recovery Asset Team runs a Financial Fraud Kill Chain with financial institutions, and per the FBI’s 2025 Internet Crime Report it covered 3,900 incidents with $1.16 billion in attempted transfers that year, freezing $679 million — a 58% success rate. The sequence is in Freeze & Report, and getting your money back by payment method covers the wire rail honestly. If W-2 data went out, email dataloss@irs.gov (“W2 Data Loss” in the subject) so the IRS can flag affected employees, forward the phish to phishing@irs.gov, and tell your people immediately.

Then close the loop the free way: put the call-back rule in writing, and run your team through the 60-second quiz — the variants change costumes, but the engine can be learned in an afternoon. The full set of free defenses is at defense moves.

Warning signs
  • An email from an executive, a vendor, or a colleague asks to move money, change bank or payroll details, buy gift cards, or send employee tax data — and adds a reason to hurry or keep it quiet.
  • The sender looks right: a real address that's been compromised, a look-alike domain a character or two off, or a familiar display name sitting on top of a stranger's address.
  • The request lands at a believable moment — mid-thread on a real invoice, during closing week, near a payroll cycle — because the attacker has been reading genuine email before writing any.
  • Every offer to confirm keeps you on email or chat: the one channel the attacker fully controls.
Defense move — Two-Channel Verification
  • Make one written rule: any request to send money, change where money goes, or release employee data gets confirmed by voice on a number you already had — never one supplied by the message. The FBI's guidance is to 'use secondary channels and/or two-factor authentication to verify requests for changes in account information.'
  • Trigger the rule on the request type, not on suspicion. A perfect-looking thread from a real address still gets the call — compromised mailboxes are the core of BEC, so nothing inside the email can clear the email.
  • Require two people to approve payments and account changes above a set threshold, so no single employee can be rushed into moving funds alone.
  • Treat gift cards as an automatic stop: per the FTC, only scammers tell you to buy gift cards and read them the numbers, and the check is to call your boss on a known number — not one from the message.
  • If a wire already went out, call your bank for a recall and file at ic3.gov immediately — in 2025 the FBI's Financial Fraud Kill Chain froze $679 million of $1.16 billion in attempted fraudulent transfers (a 58% success rate), and speed is what makes that possible.
Editor's note

Reading years of these cases, the pattern that stands out to me is that companies keep training people to recognize the last variant while the next one walks in wearing a different job title. The costume rotates — CEO, vendor, HR, title company — but the ask never does: move money or data somewhere new, fast, without talking to anyone. That's why I'd put the trigger on the event, not the sender. If a message changes where money or employee data goes, it gets a phone call. You don't have to out-think the impersonation; you just have to refuse to settle it on the channel it arrived on.

Frequently asked

Is BEC always about wire transfers, or can it ask for something else?

The money version is the biggest, but the same impersonation engine asks for whatever the target can hand over. Documented variants include wire transfers to new accounts, rerouted vendor invoice payments, employee direct deposits diverted to attacker-controlled accounts (often prepaid cards, per a 2018 FBI IC3 alert), gift card numbers texted or emailed back to a fake boss, and bulk employee data: the IRS documents a form of business email compromise in which a spoofed executive email asks payroll or HR for all employees' Forms W-2, which criminals then use to file fraudulent tax returns. If a message from an authority figure asks you to move money or hand over sensitive data, it belongs to this family — verify it on a second channel before acting.

How do scammers make the email genuinely look like it comes from our CEO or vendor?

Four main ways, in rising order of difficulty for you to catch. Display name spoofing puts the executive's name on top of an unrelated address, and wins on phones that hide the address. Look-alike domains swap or add a character so the address survives a quick glance. Thread hijacking replies inside a real, stolen conversation, so the history above the new message is genuine. And full account takeover sends the request from the real mailbox itself — the FBI describes BEC as frequently carried out by compromising legitimate business email accounts through social engineering or computer intrusion. The last two defeat inspection entirely, which is why the reliable defense is verifying the request out-of-band rather than examining the email harder.

We already acted on one of these — wired money or sent the W-2s. What now?

For money: call your bank immediately and ask for a wire recall, then file a complaint at ic3.gov with the account details and timeline. The FBI's Recovery Asset Team runs a Financial Fraud Kill Chain with banks to freeze fraudulent transfers — per the FBI's 2025 Internet Crime Report it covered 3,900 incidents with $1.16 billion in attempted transfers that year, freezing $679 million (a 58% success rate) — but it works on hours, not weeks. For W-2 data: the IRS asks employers to email dataloss@irs.gov with 'W2 Data Loss' in the subject line so it can help protect the affected employees from tax-related identity theft, and to forward the phishing email itself to phishing@irs.gov. Then tell your employees, because their names and SSNs are the loot.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›