Business email compromise cost U.S. victims $3 billion in 2025 alone, and it rarely involves malware. Someone impersonates an executive or vendor by email, creates urgency, and asks for a wire transfer. No virus. No exploit. Just a well-timed lie.
Every other threat covered in VJNetworks’ cybersecurity work involves some piece of malicious code somewhere. Ransomware, a phishing link, a vulnerable server. Business email compromise doesn’t. It’s one message, written well, sent at the right moment, asking the right person to move money. Nothing to detect. Nothing to patch. Just timing and a plausible story doing all the work.
How the Scam Actually Works
Two flavors show up constantly. In the first, the criminal registers a lookalike domain, something like “vjnetwork5.com” instead of “vjnetworks.com,” and sends an email that looks close enough at a glance. In the second, and the more dangerous one, they’ve actually broken into a real account, a vendor’s, a CEO’s, an attorney’s, and they’re emailing from inside it. Real signature. Real history in the thread. Real trust already built.
Either way, the target is almost never the CEO himself, since the real goal is whoever inside the company can actually move money, an accounts payable clerk, a bookkeeper, someone in HR with access to payroll routing. The FBI’s own data shows this scam hitting all 50 states and 186 countries, small local businesses right alongside large corporations. Nobody’s too small to be worth the email.

What a Fake CEO Email Actually Looks Like
Picture the pattern, not a specific case. Friday afternoon, right before a long weekend or right when the real CEO happens to be traveling. An email lands in the controller’s inbox, display name reading “Jim Mutone,” reply-to address one character off from the real one. Subject line: something routine. “Quick favor.” The body is short. Confidential vendor payment, needs to go out today, can’t talk right now, I’m in a meeting. A wire amount that’s large enough to matter but not so large it triggers a second look. That’s the whole scam. No attachment. No link. Just pressure and a deadline.
The version aimed at vendors works almost the same way, except the criminal poses as your own accounts payable department and asks a real supplier to update their banking details “before the next invoice.” The invoice gets paid. Just to the wrong account.
The Real Numbers Behind This
The FBI’s 2025 Internet Crime Report logged 24,768 business email compromise complaints and $3,046,598,558 in reported losses for the year, the second-highest loss total of any crime category the Bureau tracks, trailing only investment fraud. Zoom out further and the number gets harder to ignore. Between October 2013 and December 2023, the FBI’s IC3 identified over $55 billion in global exposed losses tied to this scam. Fifty-five billion, from an attack that needs nothing more than an email account and a plausible story.
| Crime Type (FBI IC3, 2025) | Reported U.S. Losses |
|---|---|
| Investment fraud | $8,648,617,756 |
| Business email compromise | $3,046,598,558 |
| Tech/customer support fraud | $2,134,675,818 |
| Confidence/romance fraud | $929,287,469 |
| Government impersonation | $797,943,193 |
AI is starting to show up in this scam too. The FBI’s report attributes more than $30 million of 2025’s BEC losses specifically to attacks with a confirmed AI component, cloned voices and generated emails included. That’s a small slice of $3 billion today. Worth watching. Not the main story yet.

Why This Keeps Working
Spam filters look for malicious links, infected attachments, known-bad senders. A BEC email usually has none of that. It’s plain text from a domain that looks right, or from an account that actually is right. Nothing for the filter to catch. The only thing standing between a criminal and a wire transfer is a human being pausing long enough to ask, wait, should I verify this first.
Urgency does the rest. Confidential, time-sensitive, don’t discuss it with anyone else, and I’m unreachable right now if you try to check, four phrases doing the same job of shutting down verification before it starts. The fix here has less to do with any IT tool or service and more to do with a habit your team either has or doesn’t.
What Actually Stops This
- Verify any payment or banking-detail change through a second channel. Call a phone number you already had on file, never one from the email itself.
- Set a dollar threshold where any wire, regardless of who supposedly requested it, needs a second sign-off before it goes out.
- Turn on full email address display for your team, not just the sender’s display name. The mismatch is often visible if anyone bothers to look.
- Register close variants of your own domain before someone else does, and put DMARC, SPF, and DKIM in place so spoofed mail from your domain gets rejected elsewhere.
- Require MFA on every email account. A compromised account is the more dangerous version of this scam, and MFA is what usually stops the compromise in the first place.

If a Wire Already Went Out
Move fast. Call your bank immediately and request a recall along with any indemnification paperwork they need. Every financial institution handles this a little differently, so find out your bank’s actual process now, while you’re calm, rather than trying to learn it for the first time in the middle of a panic. File a report at ic3.gov regardless of the dollar amount. The FBI’s recovery program has clawed back funds in cases reported within hours. Reported a day later, the odds drop fast.
Where to Start
- Write a payment-verification policy today, even a short one. Any change to bank details gets a callback, no exceptions.
- Check whether MFA is actually enforced on every email account, not just available on some of them.
- Ask your bank now what their wire recall process looks like, before you’re calling them in a panic.
- Walk your finance team through what a real BEC attempt looks like. Most have never seen one described plainly.
Questions We Actually Get About This
Isn’t this just phishing with a different name?
How would a criminal even know who to email and what to ask for?
Can the bank get the money back if we catch it quickly?
We’re a small company. Does this actually target businesses our size?
Wouldn’t a spam filter already catch something like this?
Twenty-two years running VJNetworks out of Rockland has taught me that the scams costing businesses the most money are rarely the flashy ones. A fake CEO email is about as low-tech as fraud gets, and it’s outpacing almost every other cybercrime category the FBI tracks. Email security is one piece of VJNetworks’ broader threat protection work, and a lot of what stops this scam is process, not software. If your team has never walked through what a real attempt looks like, that’s worth an hour before it costs you a wire transfer. VJNetworks also covered why “too small to target” doesn’t hold up for ransomware either. Same logic applies here.
The same blind spot shows up with unapproved apps and tools employees adopt on their own without telling IT. VJNetworks broke down how to actually find out what’s running across a network in a companion piece on shadow IT.
Further reading: the FBI’s Business Email Compromise overview covers reporting steps directly from the source.
A free assessment checks your email security setup and your team’s actual verification habits, not just the tools you already have installed. No obligation, no sales pitch.
