Payment Fraud / Research

Working paper 01. August 2026. Research into wire, invoice and business email compromise fraud.

Who actually gets hit by invoice and wire fraud

Business email compromise, invoice fraud, payment diversion, vendor impersonation — one problem with several names, and the same ending every time: a legitimate payment goes to an account the attacker controls.

$3.05B
Reported to the FBI in 2025
24,768 BEC complaints, averaging $123,005 each. This is the number everyone quotes. observed
$8.9B
Modeled US business loss
Gross dollars diverted before recovery across US businesses above $10M in revenue, roughly 2.9× what gets reported. Built by summing the grid below across firm counts. modeled
39%
Highest modeled exposure
Chance a $1B+ construction organization sees at least one diverted payment in a year, converted from a modeled incident count. Public sector is close behind at 33%. modeled
18.7×
Relative burden, small against large
Expected annual loss as a share of revenue is an order of magnitude heavier under $10M than over $1B. modeled

Every public dataset on business email compromise reports one number at a time: a national total, an average claim, an industry anecdote. None of them answer the question a CFO actually asks — what is the chance this happens to a company like mine, and what does it cost when it does? This is an attempt at that cross-tab.

Every figure on this page is tagged observed when it comes from a named published source and modeled when it comes from ours. The model is published in full at the bottom — parameters, arithmetic, limitations, and the corrections we have made against our own earlier drafts.

01

How it works

Three ways the money actually leaves

None of these require malware, a breach of your network, or any technical sophistication at all. They require patience and an email account. The composites below are drawn from the documented pattern of these attacks; they are illustrations, not case files.

Vendor impersonation

The lookalike domain

01An attacker compromises a mailbox at your supplier — not at your company. Often a small firm with no multi-factor authentication.
02They read quietly for weeks. They learn you pay this supplier monthly, roughly how much, who signs off, and what the invoices look like.
03They register a domain one character off the real one — a hyphen added, an rn for an m — and set up a mailbox on it.
04Days before the real invoice is due, "the supplier" writes: they have changed banks, here are updated remittance details, please use these going forward. The tone, the signature block and the invoice format are all correct, because they were copied.
05Accounts payable updates the vendor record and pays. Nobody notices until the real supplier calls about a missed payment — typically thirty to sixty days later.
What would have caught itA single call to the phone number already on file for that supplier — not the number in the email. Everything else in the message was designed to survive inspection.
Thread hijack

The reply that was always going to come

01The attacker is inside a real mailbox and can see a live conversation — a project manager and a subcontractor eight weeks into a job.
02They wait for the moment payment is discussed, then reply inside the existing thread. The message history below their reply is genuine.
03They add a forwarding rule so the real party never sees the replies, and answer any follow-up questions themselves.
04The request goes to the person who owns the relationship, not to the accounts payable inbox — so it arrives already carrying that person's authority when it reaches finance.
Why this one is hardThere is no spoofed domain to spot and no first contact to be suspicious of. The sender address is real. The only anomaly is that banking details changed.
Transaction interception

The closing, the payoff, the draw

01Some payments are enormous, one-off, and scheduled in advance — a property closing, a mortgage payoff, a construction draw, a settlement disbursement.
02The attacker only needs to know the date and the parties, which are often a matter of public record or sit in a mailbox with weak protection.
03Wiring instructions arrive shortly before the deadline, with urgency built in: the closing is tomorrow, the rate lock expires, the crew is waiting.
04The payer has no established banking relationship with this counterparty to compare against — it is the first and only payment they will ever make to them.
The scale hereMedian losses in real-estate wire fraud run $239,850 for a buyer's cash-to-close and $389,125 for a mortgage payoff. Often the money belongs to a household, not a company.

Every one of these turns on a single moment: somebody accepts new banking details over email. That is the whole attack. Everything before it is preparation and everything after it is recovery.

02

The exposure map

Who gets hit, how often, and what it costs

The question every finance leader asks — what is the chance this happens to a company like mine, and what does it cost — has no published answer. No dataset cross-tabulates industry against revenue. So we built one. Everything in this grid is modeled, from published inputs, with every parameter listed in § Method. Argue with the parameters; the arithmetic is simple enough to redo.

Payment-diversion exposure by revenue band and industry
Expected annual loss — likelihood × severity × the share that never comes back. The number an underwriter prices. Rows are ranked by the metric shown.

How to read it

Expected annual loss is the number that matters. It is not a prediction that you will lose that amount this year — it is what the risk is worth annually once you account for how often it lands and how much never comes back. It is the figure to compare against a premium, a control budget, or an insurance retention. A $120M construction firm carrying roughly $34,000 a year in expected loss is carrying a risk most companies that size have never priced.

Incidents per year is not a probability. A figure of 0.15 means the model expects one successful diversion roughly every seven years — but these are not evenly spaced, and a company that pays one fraudulent invoice is a documented soft target for the next one.

03

Where two datasets disagree

Construction is attacked the most and shows up in the claims data the least

Construction sits at the top of the only published cross-sector comparison of attack targeting we could find, and near the bottom of the insurer claims data. Both are real measurements of real things. The distance between them is the finding.

Start with the targeting. In one email-security vendor's customer base, 76% of construction and engineering organizations received at least one vendor-impersonation attack in a six-month window — the highest share of any sector that vendor measured. Three caveats travel with that number, and we would rather set them out than lean on it. It counts the customers of a single vendor rather than the sector. It records whether a firm received any attack, not how many, so the gap to the next sector is ten points rather than an order of magnitude. And it covers July to December 2023, which makes it the oldest figure on this page.

Being attacked is not the same as losing money. What moves construction from a high attack rate to genuine exposure is what a loss costs once one lands. Net margins in the sector run roughly 2 to 8 percent, among the thinnest of any major industry — undercut mainly by grocery and agriculture. A loss comes out of profit rather than revenue, so at a 5% margin, replacing a $34,000 diverted payment takes $673,000 of additional work. A professional services firm at a 25% margin replaces the same loss with a fifth of that.

Revenue required to replace one year of expected loss
Expected annual loss ÷ net profit margin, at $50M–$250M revenue. Commercial sectors only.
Modeled loss over published margin benchmarks. Public sector and nonprofits are excluded here — they have no profit margin, and the equivalent measure for them is programme spending displaced, which is worse still. modeled Margins from source 7.

A note on the grid above. On raw dollars the exposure map puts construction sixth, below legal services, the public sector and professional services. That ordering is driven by the severity input, which comes from insured claims — and insured claims are the single place construction is most under-counted, for the reasons set out below. Switch the grid to incidents per year and construction goes to the top of it, because targeting and control gap are what drive frequency. It leads on how often it is attempted, on how often it succeeds, and on what a loss costs to replace. It trails only on the dollar size of an insured claim. We are showing you both rather than picking the one that suits the argument.

Why construction, structurally

The payee list churns constantly. A general contractor pays a different set of subs, suppliers and equipment vendors on every project. New payees are normal, so a new payee is not a signal. In a manufacturing business paying the same forty suppliers every month, it would be.

Payment authority is decentralised by necessity. Project managers and site supervisors approve work and confirm invoices because they are the only ones who know the work was done. That authority sits outside the finance function, and the fraudulent request lands with them, not with accounts payable.

The relationships are public. Bid tabulations, awarded-contract notices, lien filings and permit records tell an attacker who is working for whom, on what, and roughly for how much. No breach required to write a convincing invoice.

The payments are large and scheduled. Progress draws and retainage releases are six figures, expected, and time-pressured. Urgency is native to the process, which is exactly the cover these attacks need.

What the claims data says, and why we still say this

Insurer claims data does not put construction near the top. In one carrier's 2025 book construction indexes at 42 against a 100 benchmark on financial-fraud claim frequency, and $186,000 on average amount stolen — both below average. That is a real number and we are not hiding it.

We think it measures insurance, not fraud. A claim exists only when a loss exceeds a retention, falls inside cover, and gets notified. Construction has low cyber-insurance penetration, social-engineering cover is frequently a sublimit rather than full cover, and a contractor who absorbs a $180,000 hit and keeps working never appears in anyone's claims data. The sector that tops every targeting dataset and bottoms the claims data is the sector whose losses are least visible — which is an argument for looking harder, not for relaxing.

If you hold construction payment or loss data that settles this either way, we would rather see it than keep inferring.

For construction CFOs and owners: the exposure is not that you will be attacked — on the one published targeting dataset, the odds are that you already have been. It is that a diverted progress payment costs you the profit on roughly two more jobs, and that nothing in your current stack is checking whether the bank details on that sub's invoice changed.
04

The cliff

Crossing $25M in revenue multiplies your expected loss by five

One carrier publishes both claim frequency and average dollars stolen by revenue band, from the same book of business. Multiply them and you get relative expected loss. The gap between the smallest band and the next one up is not a slope — it is a step.

Relative expected loss by revenue band
Claim frequency × average funds stolen, indexed to the smallest band = 100. Published data. The modeled extension into larger revenue bands is shown separately below.
Modeled extension beyond the published series
Frequency rises 2.9× and severity 1.8× across the first boundary; together they compound to 5.1×. The published series stops at $500M — the two hatched bars are our model's extension and carry the wider uncertainty that implies. Source 1; model in § Method.

The mechanism is not mysterious. Below $25M, a company usually pays a handful of known vendors and an owner sees most of what leaves. Above it, the payee list grows faster than the finance team, new suppliers appear monthly, and approval gets delegated to someone who has never met the vendor they are paying. Attack surface scales with payee count. Controls scale with headcount budget. Those two curves separate right here.

The same carrier reports the $25M–$100M band had the steepest year-on-year frequency increase of any segment in its book. The cliff is getting steeper, not flatter.

What one average incident costs, as a share of annual revenue
The same event, scaled to the organization absorbing it.
Modeled. Absolute losses rise with size, but revenue rises much faster — so the damage inverts. A single diverted payment is a rounding error at the top of the market and a solvency event at the bottom, which is exactly backwards from where verification controls are usually deployed. modeled
If you are between $25M and $250M in revenue: you are in the segment with the fastest-growing fraud frequency in the published data, you are large enough that a single payment is worth six figures, and you are statistically unlikely to have payee-verification controls in place. That combination is the finding.
05

The clock

Recovery is a cliff too — and it is over by day fourteen

Everyone knows speed matters after a wire goes out. The data is sharper than that: there is no such thing as slow recovery. Whatever comes back comes back early, and the curve is flat after two weeks.

Share of victims recovering any funds, by notification delay
Financial-fraud claims, 2024–2025. Published data — not modeled.
The 15–30 day and 30+ day outcomes are one percentage point apart. After the second week, waiting longer costs you almost nothing more — because there is almost nothing left to lose. Across the whole book only about one victim in five recovers in full. Source 1

Read the drops rather than the levels. Days 0–3 to days 4–14 costs 17 points. Days 4–14 to days 15–30 costs another 25. Then the curve dies: 28% to 27%. The money has been layered through mule accounts and converted, and no amount of diligence brings it back.

One more number worth sitting with. Of the 24,768 business email compromise complaints filed with the FBI in 2025, only 3,900 reached the Financial Fraud Kill Chain — the process that actually contacts the receiving bank and asks it to freeze the funds. Filing a complaint is a record. The kill chain is an intervention. Most victims do the first and believe they have done the second.

What this is worth: the difference between reporting on day two and day twenty is roughly 43 points of recovery probability. There is no control you can buy this year with that kind of return — and it costs nothing except knowing, in advance, exactly who to call.

Take this bit with you

The first 72 hours

Print it. Put it next to whoever approves payments. The single most valuable control in this entire report costs you nothing.

Hour 0–1

Call your bank's fraud line — not your relationship manager

Ask explicitly for a SWIFT recall or ACH return and get a case reference. Relationship managers route through channels that take days. Fraud lines are staffed to act in minutes, and the receiving bank can only freeze what is still sitting there.

Hour 1–4

File at IC3.gov and flag it for the Financial Fraud Kill Chain

Include the exact amount, the date, both banks' names, the receiving account number, and any SWIFT or wire reference. Incomplete filings do not trigger the kill chain. This is the step five in six victims miss.

Hour 4–24

Notify your insurer, and preserve the mailbox

Social engineering is often a sublimit rather than full cover — check the number before you assume you are covered. In parallel, stop anyone from "cleaning up" the compromised mailbox: forwarding rules and login records are what establish how the attack worked, and they are frequently deleted by well-meaning IT staff on the first day.

Day 1–3

Check whether the same payee touched other payments

Payee-change fraud is rarely a single transaction. Pull every payment to that vendor for the preceding ninety days, and every bank-detail change made across the vendor master in the same window. A second diverted invoice sitting unnoticed is common.

Day 3–14

Keep pushing while the window is open

Recovery does not stop at day three, it just gets harder — 53% of victims reporting in the 4–14 day window still recovered something. Chase the receiving bank through your own bank's fraud team, and keep the IC3 case updated with anything new. After day fourteen the odds are what they are going to be.

Before it happens

Write down the three phone numbers now

Bank fraud line, insurer's incident line, and whoever will do your forensics. Taped inside the AP cabinet or pinned in the finance channel. Every hour spent finding a phone number on the day is spent inside the steepest part of the recovery curve.

The gap between a bad day and a catastrophic one is not a security product. It is whether somebody knows which number to call before they need it.

06

Method

The model, published in full

Two layers. A published layer — every figure attributed to a named source and quoted as reported. A modeled layer — the exposure grid, which produces the industry-by-revenue cross-tab the published layer cannot. Everything below describes the modeled layer. If you disagree with a parameter, the arithmetic is simple enough to redo with your own.

Severity — how much a successful diversion costs

Mean loss per successful incident is fitted by least squares to one carrier's three published mean-stolen-by-revenue points, giving mean = 3,117 × revenue^0.2615 with R² = 0.93. The sublinear exponent is the fitted result, not an assumption: attackers take what a single plausible payment is worth, not what the company is worth. Per-incident dispersion is lognormal with σ = 1.35, so the mean sits 2.49× the median. Because the fit is to insured claims, it excludes losses below a retention and is therefore an upper bound at the smallest firm sizes.

Frequency — how often it succeeds

Expected successful diversions per year is E[K] = N × p₀ × g, where N is a size-scaled attempt count multiplied by the sector's targeting multiplier, p₀ = 0.022 is the per-attempt success rate against an organization with no verification controls, and g is the residual control gap. We use the expected number of successes rather than the probability of at least one, because an organization can be hit more than once in a year and expected loss must be built on a count. N and p₀ are the two parameters with the least observational support, and they are why this section reports expected loss rather than a headline probability.

Recovery — how much comes back

One carrier's observed victim-level curve (70 / 53 / 28 / 27%) is converted to dollar-weighted recovery of 60 / 30 / 12 / 9%, discounted because recovering some funds is not recovering all of them — the same source reports only one victim in five recovers fully. Weighted by an assumed market reporting mix, this gives a 34% blended recovery, close to but below that carrier's observed 42% overall rate, which reflects a book receiving active carrier-led recovery support the wider market does not get.

Margin adjustment

Revenue required to replace a loss is expected annual loss divided by the sector's net profit margin, using published industry benchmarks at the midpoint of each stated range. This is deliberately crude — margins vary enormously within any sector — but the ranking it produces is driven by margin differences far larger than the within-sector spread.

The national aggregate

The $8.9B in the summary is the sum of modeled expected annual loss across every cell of the grid, multiplied by the number of US firms in each revenue band and grossed back up by the 34% blended recovery rate: roughly $5.9B net, $8.9B before recovery. It excludes firms under $10M in revenue, where the severity fit is least reliable and most likely to be an overstatement. It also assumes firms are distributed evenly across the ten sectors within each band, because no firmographic source we have splits revenue by sector — that assumption is the weakest part of the calculation. Read the aggregate as an order of magnitude to set against the $3.05B reported to the FBI, not as an estimate of the true national figure.

Why one probability appears in the summary

This section reports expected loss rather than probability, for the reasons given above. The single exception is the 39% in the summary, which converts the modeled incident count for the largest construction band into the chance of at least one incident in a year, under a Poisson assumption. It inherits every weakness of N and p₀ and belongs in the same category as the rest of the grid: a scale for comparing segments, not a forecast for any individual organization. It is the only probability on the page and we would not defend it as anything more.

Every parameter in the model
Change any of these and the map changes. Tagged by whether the value is published or ours.
Revenue bandMidpoint revenueAttempts / yrControl indexUS firms
SectorTargeting ×Control gap ×Severity ×Net marginBasis
Attempt counts and control indices are modeled throughout. Severity multipliers are taken from published per-sector claims data for the seven sectors one carrier breaks out, and modeled for the three it does not. Firm counts are commercial firmographics for businesses above $1M in revenue.

What this cannot tell you

Your firm's absolute annual probability of being hit. No public dataset contains the denominator that question needs — attempts per organization per year — and we would rather say so than publish a number that looks precise and is not.

The single largest limitation is that most sector-level severity evidence comes from insurance claims, which exclude losses below a retention, outside cover, or never notified. Sectors with low insurance uptake or typically small payments look safer in this data than they are. Construction is the clearest case, and we have said so above rather than quietly benefiting from it.

Two smaller ones. The revenue bands above $500M extend past the published series and inherit wider uncertainty. And the model treats a year as independent draws, which understates repeat victimisation — a company that pays one fraudulent invoice is a documented soft target for the next.

Corrections against earlier drafts

An earlier version of this analysis ranked sectors using severity multipliers we had assigned ourselves, producing a ranking that echoed our own assumptions rather than a finding; that ranking is withdrawn and this edition uses published per-sector figures wherever they exist. We also previously computed expected annual loss from the probability of at least one incident rather than the expected number, understating it by up to 17% in the highest-exposure cells. And we reported the FBI's 2025 mean loss per complaint as $122,935 — it is $123,005, and it is adjusted losses divided by all complaints including those with no loss and including individual consumers, not an average per successful diversion.

Sources

  1. At-Bay, 2026 InsurSec Report — financial fraud 30% of claims; average theft $285K; funds stolen and claim frequency by revenue band and by industry; recovery by notification delay; 42% overall recovery, one in five recovering in full; email the initial vector in 82% of financial-fraud claims. at-bay.com
  2. FBI Internet Crime Complaint Center, 2025 Internet Crime Report — 24,768 BEC complaints, $3,046,598,558 in losses; the Financial Fraud Kill Chain ran on 3,900 incidents, freezing $679,013,183 of $1,163,919,846 in attempted theft. ic3.gov
  3. Abnormal Security, H1 2024 Email Threat Report — 76% of construction and engineering customers received at least one vendor email compromise attack, the highest of any sector measured; retail and consumer goods 66%. Measures July–December 2023 and is the oldest figure used here. abnormal.ai
  4. Coalition, 2026 Cyber Claims Report — BEC claims $27K average; funds transfer fraud $141K; funds transfer fraud originating as BEC $112K; 52% of transfer-fraud claims began as BEC; BEC and transfer fraud together 58% of cyber claims. coalitioninc.com
  5. CertifID, 2026 State of Wire Fraud Report — median real-estate transaction losses of $239,850 (buyer cash-to-close), $343,497 (seller proceeds), $389,125 (mortgage payoff). certifid.com
  6. Association for Financial Professionals, 2026 Payments Fraud and Control Survey — 74% of organizations affected by BEC; 48% of firms under $1B and 66% above $1B reported actual losses; 30% recovered more than three-quarters, 20% recovered nothing. financialprofessionals.org
  7. Crestmont Capital, Profit Margin Benchmarks by Industry, 2026 — net margin ranges by sector; midpoints used. crestmontcapital.com
  8. NAICS Association, US business counts by annual sales range — firm counts by revenue band. naics.com