Security

The FBI Started Counting AI Fraud. The Number Is Nothing Like What You've Been Sold

For the first time there is an authoritative figure rather than a vendor estimate — and AI-involved business email compromise comes to just over $30 million against a $3 billion category. It is also an undercount, by the FBI's own admission. Both are true, and together they point somewhere useful.

Disclosure, up front

We sell automation and security work, so the incentive here runs toward telling you the threat is enormous. This article argues that the numbers being used to sell you AI-fraud protection do not match the only authoritative count that exists, and that the defences worth having are cheap and boring. Every figure below is read from the FBI's own 2025 Internet Crime Report, and where we quote something we could not verify, we say so.

In its 2025 annual report, the FBI's Internet Crime Complaint Center did something it had never done before: it added "AI Related" as a formal descriptor and counted it.

That matters because until now, every claim about the scale of AI-enabled fraud came from companies selling protection against AI-enabled fraud. There was no denominator. Now there is one, published by the organisation that actually receives the complaints.

The number is much smaller than what you have probably been told. It is also, by the FBI's own explicit admission, an undercount. Both of those are true at once, and the gap between them is where the useful thinking lives.

The headline figures, from the report itself

  • All cybercrime in 2025: 1,008,597 complaints, $20.877 billion in losses — up 26% on 2024.
  • Everything flagged AI-related: 22,364 complaints, $893,346,472. That is about 4% of total losses.
  • Business email compromise overall: $3,046,598,558 from 24,768 complaints — the second most costly category after investment fraud.
  • BEC where AI was involved: businesses reported just over $30 million. Against $3.05 billion of BEC, that is roughly 1%.

01What the FBI actually counted

The 2025 report breaks the AI-related total down by scam type. Setting each against the total for that whole category is the part nobody quotes.

FBI IC3 2025: losses with a reported AI nexus, against total losses for each category
Scam type Losses with a reported AI nexus Total losses for that category
Investment fraudover $632 millionover $8 billion
Business email compromiseover $30 million$3,046,598,558
Confidence / romanceover $19 million
Employment scamsalmost $13 million
Distress / "grandparent" scams (voice cloning)over $5 million
All AI-related complaints$893,346,472 across 22,364 complaints$20.877 billion across 1,008,597 complaints

Read from the FBI IC3 2025 Annual Report, section "Artificial Intelligence (AI) Used in Cybercrime", on 9 September 2026. Dashes mark categories where the report gives the AI-nexus figure but we did not extract a comparable category total; do not infer a ratio for those rows. All figures are victim-reported and adjusted by IC3.

The row that should stop a small business owner is the second one. Business email compromise — the fake-invoice, changed-bank-details, urgent-wire-transfer family of fraud — is the thing most likely to actually happen to you. It is a three-billion-dollar problem. The portion where a victim reported AI involvement is about one percent of it.

02Why that clashes with what you are being sold

Search this topic and you will find figures in wide circulation that are difficult to reconcile with the above: that around 40% of business email compromise attacks now include AI-generated voice or video, up from under 5% in 2023; and that the average AI-augmented BEC loss exceeds $4.1 million against roughly $1.3 million for traditional BEC.

We could not trace either to a primary source. They appear on vendor blogs and in security-marketing content, usually without a named dataset, sample size or method. That does not make them invented. It does mean nobody reading them can check them.

Run the arithmetic, though. If 40% of BEC attacks involved AI, and AI-involved incidents cost several times more, then AI-involved BEC would account for the majority of a $3 billion problem. The FBI's own count says just over $30 million. Those cannot both describe the same world.

The question to ask any AI-threat statistic

Who counted, how, and among whom? "The FBI received 22,364 complaints referencing AI totalling $893 million" is answerable. "40% of attacks now use deepfakes" is not, unless someone names the sample. This is the same discipline we would apply to a pricing claim, and it matters more here, because fear is a more effective sales tool than value.

03The honest half: this is a floor, not a ceiling

It would be easy to stop there and conclude AI fraud is hype. That would be the wrong conclusion, and the report says so itself.

The "AI Related" tag is a descriptor. The report is explicit that it is applied when the information reported contains a reference to artificial intelligence, and that descriptors exist "for tracking purposes only". In other words, it counts complaints where somebody mentioned AI. It does not count incidents where AI was used and nobody realised.

That distinction is enormous, and the FBI draws attention to it directly. On investment fraud, having noted more than $632 million with a reported AI nexus, the report observes that overall investment losses exceeded $8 billion, "demonstrating that many victims do not realize the extent AI may be involved in scams".

Think about what that means for BEC in particular. If you receive a convincing email from a supplier and wire the money, you have no way of knowing whether a machine wrote it. If you take a call from someone who sounds like your bookkeeper, you cannot tell a cloned voice from a decent impersonation. The victim is structurally the worst-placed person to know whether AI was involved, which makes a victim-reported AI figure close to useless as a measure of actual prevalence.

So the honest position is narrow and, we think, more useful than either extreme:

  • $893 million is a real, authoritative floor, and the first one that has ever existed.
  • The true figure is certainly higher, and unknowable with current reporting.
  • Neither of those justifies the specific unsourced multiples being used to sell products.

04Why the distinction barely changes what you should do

Here is the part that makes the whole argument practical. Whether the voice on the phone was cloned or merely a good impersonation does not change a single control you should have.

The defences against a fake payment instruction are identical either way, because they defend the process rather than trying to detect the artefact:

  • Call back on a number you already had. Not a number in the email, not one the caller gives you. From your own records. This one control defeats voice cloning and ordinary impersonation equally, and it costs nothing.
  • Treat any change of bank details as a separate, verified event. New account details are the single highest-risk message your business receives. Verify out of band, every time, no exceptions for urgency or seniority.
  • Two people on payments above a threshold you set. Pick a number that would hurt and require a second pair of eyes above it.
  • Kill the urgency lever. Almost every one of these frauds requires the target to skip a step because it is urgent and someone senior is impatient. Say out loud, in advance, that nobody will ever be criticised for verifying — that sentence is the control.
  • Agree a verification word for phone requests involving money, if you are small enough that this is practical. Low-tech, effective against a cloned voice, and free.

Note that none of these mention AI. That is the point. A business with these controls is protected against the version of this fraud that existed in 2015 and the version that exists now. A business without them is exposed to both, and no detection product closes that gap.

05What not to buy

  • Deepfake detection, as a first purchase. If you have no callback rule, a detection tool is protecting a process that has no floor. Fix the process; it is free and it works on more attacks.
  • Anything sold on the unsourced multiples. A vendor quoting "40% of BEC" without a dataset is either not checking their own marketing or hoping you will not. That is a reasonable thing to judge a security supplier on.
  • Staff training that teaches spotting fakes. Training people to detect artefacts in audio is training for a task that gets harder every quarter. Train the procedure instead: what you do when money is requested, regardless of how convincing the request is.
  • A separate "AI security" budget line. This is BEC with better grammar. It belongs with your existing payment controls and your existing fraud awareness, not in a new category.

06The honest summary

For the first time there is an authoritative number: 22,364 complaints and $893 million in 2025, roughly 4% of all reported cybercrime losses, with AI-involved business email compromise at just over $30 million against a $3 billion category. That is dramatically less than the figures circulating in security marketing, and those figures cannot be traced to a primary source.

It is also an undercount, by design and by the FBI's own statement, because the person filing the complaint is the last person able to tell whether a machine was involved.

Both things being true is not a contradiction, and it resolves into something simple: do not buy the panic, and do not skip the callback. The controls that stop this are a phone call to a number you already had, a rule about changed bank details, and permission for your staff to slow down. None of it is about AI at all.

07Common questions

How much money is actually lost to AI-enabled fraud?

In 2025 the FBI's Internet Crime Complaint Center recorded 22,364 complaints carrying an AI-related descriptor, with adjusted losses of $893,346,472. Total reported cybercrime losses that year were $20.877 billion across 1,008,597 complaints, so AI-flagged losses were roughly 4% of the total. This was the first year IC3 tracked AI as a formal descriptor, so it is the first authoritative figure that exists.

How much of business email compromise involves AI?

Less than most coverage suggests. The FBI reported that in 2025 businesses lost just over $30 million to BEC scams involving AI. Total BEC losses were $3,046,598,558 across 24,768 complaints, making AI-involved BEC roughly 1% of the category by value. BEC overall remains the second most costly crime type after investment fraud.

Is the FBI's AI fraud number an undercount?

Yes, and the report says so. The AI tag is a descriptor applied when the information reported contains a reference to artificial intelligence, used for tracking purposes only — so it counts complaints where someone mentioned AI, not incidents where AI was used. Discussing investment fraud, the report notes over $632 million with a reported AI nexus against more than $8 billion in total investment losses, demonstrating that many victims do not realise the extent AI may be involved.

Why do vendor statistics about AI fraud look so much bigger?

Widely circulated claims — that around 40% of BEC attacks now include AI-generated voice or video, or that AI-augmented BEC averages over $4.1 million per incident — could not be traced to a primary source with a named dataset, sample size or method. They may be real, but they cannot be checked. They are also hard to reconcile arithmetically with the FBI's count: if 40% of BEC involved AI and cost several times more, AI-involved BEC would dominate a $3 billion category rather than accounting for about $30 million of it.

What actually stops voice cloning and deepfake fraud?

Process controls, not detection. Call back on a number you already held rather than one supplied in the message. Treat any change of bank details as a separate event verified out of band, every time. Require two people on payments above a threshold. Remove the urgency lever by stating in advance that nobody will be criticised for verifying. If you are small enough, agree a verification word for money requests by phone. None of these mention AI, which is precisely why they work on both cloned voices and ordinary impersonation.

Should I buy deepfake detection software?

Not as a first purchase. If you have no callback rule and no bank-detail verification step, a detection tool is defending a process with no floor beneath it, and the process fix is free and covers far more attacks. Be particularly wary of vendors quoting the unsourced multiples, since a security supplier that does not check its own marketing statistics is telling you something useful about its rigour.

Is AI fraud growing?

Reported AI-related crime is being counted for the first time, so there is no prior year to compare against and any growth rate you see quoted for it is inferred rather than measured. What is measured is that overall cybercrime losses rose 26% in 2025 to $20.877 billion, and that BEC losses rose from $2.77 billion in 2024 to $3.05 billion in 2025. The category is growing; the AI-specific slice cannot yet be trended honestly.

Should staff be trained to spot deepfakes?

Train the procedure rather than the detection. Teaching people to spot artefacts in synthetic audio or video is training for a task that gets measurably harder every few months, and a staff member who fails to spot a good fake will then trust it. Training what to do whenever money or bank details are involved — verify out of band regardless of how convincing or urgent the request is — does not degrade as the technology improves.

Tell us how a payment gets approved

Describe the path a payment takes in your business — who can request one, who approves it, and what happens when a supplier emails to say their bank details have changed. We will tell you which of the five controls above you already have and which are missing. It is a short conversation and usually ends with a free fix rather than a quote.

Ask for a payment process check

Sources: the FBI IC3 2025 Annual Report, read directly from the published PDF on 9 September 2026 — every dollar figure, complaint count and quoted phrase about descriptors and victim awareness comes from that document and is first-party. The circulating vendor claims described in section 02 are quoted as we found them and are explicitly unverified; we could not locate a primary source, sample size or method for either, and we are not asserting they are false. The five controls in section 04 are ordinary payment-fraud practice, not our invention. Figures are victim-reported and adjusted by IC3, which means they exclude unreported crime entirely. Related: An AI Agent Breached a Real Company and Which Decisions You Should Never Hand to an AI Agent.

Hero image from Unsplash, used under the Unsplash License.