FBI: Americans Lost $21 Billion to Cyber Crime in 2025 — AI-Assisted Fraud Is the New Normal
The FBI's IC3 2025 Annual Report records $21 billion in U.S. losses from cyber-enabled crime — a new record and the fifth consecutive year of growth. Investment fraud, BEC, and AI-powered social engineering drove the surge, while recovery rates remain below 3 cents on the dollar.
Americans lost nearly $21 billion to cyber-enabled crimes in 2025, according to the FBI’s Internet Crime Complaint Center Annual Report for 2025. That’s a record — and it marks the fifth consecutive year of growth, with losses more than doubling since 2021. The FBI received more than 880,000 complaints, averaging over 2,400 per day.
Investment fraud leads by dollar volume
Cryptocurrency investment scams — including pig butchering schemes, where victims are cultivated over weeks or months before being directed to fraudulent platforms — drove the largest share of total losses. These operations have industrialized. Scam compounds across Southeast Asia employ thousands of workers running coordinated campaigns against English, Spanish, and Mandarin-speaking targets simultaneously.
The pig butchering model is particularly efficient: the attacker builds trust before making any financial ask, which keeps platform fraud detection signals low and pushes victims to move funds proactively. By the time a victim understands what happened, the money has moved through multiple wallets across multiple chains.
BEC remains the most reliable enterprise threat
Business Email Compromise (BEC) ranked second in total losses. BEC attacks don’t require malware — they work by spoofing executive email addresses or compromising email accounts to redirect wire transfers and payroll. Despite being a documented threat for over a decade, BEC continues to generate billions in losses annually. Security controls exist. Enforcement at the process level — out-of-band wire transfer authorization, callback verification for payment changes — remains inconsistent.
AI is changing the cost structure of fraud
The 2025 report explicitly documents the expanded use of generative AI across multiple fraud categories: voice cloning in phone scams, deepfake video calls used in BEC attacks to impersonate executives, and AI-generated conversation scripts in romance and investment scam pipelines.
Two years ago, these attack types required skilled operators and substantial time investment per target. Generative AI has made them largely automatable. A single operator can now manage a pipeline that previously required a team.
Recovery is rare
The FBI’s financial fraud kill chain includes mechanisms to freeze wire transfers if reported within 72 hours of execution. In 2025, the IC3 managed to recover or freeze approximately $551 million of total reported losses — roughly 2.6 cents on the dollar.
That figure is both a testament to what the freeze mechanisms can do and a clear illustration of their limits. Most victims don’t report within 72 hours. Many don’t report at all.
What this means for organizations
The 2025 data reinforces that BEC and investment fraud are process failures as much as technical ones. Technical controls — email authentication, phishing detection, endpoint monitoring — are necessary but insufficient against attacks that target human decision-making at the wire transfer step.
The defensive measures that move the needle: mandatory out-of-band verification for any payment instruction received via email, established callbacks to known-good numbers for changes to banking details, and current training on AI-generated social engineering. These are controls. Implementing them requires process discipline, not additional software purchases.