Criminals impersonate executives, vendors, employees and trusted institutions to convince legitimate recipients to send money or disclose sensitive information.
Artificial intelligence is making these scams faster, cheaper and more convincing. However, the underlying vulnerability remains unchanged: a professional-looking communication does not prove who sent it.
How Much Money Do Americans Lose to Online Fraud?
The FBI’s Internet Crime Complaint Center received 1,008,597 complaints involving nearly $21 billion in reported losses in 2025.
The costliest reported categories included:
| Fraud category | Reported losses |
|---|---|
| Investment fraud | Approximately $8.6 billion |
| Business email compromise | Approximately $3 billion |
| Technology and customer-support fraud | Approximately $2.1 billion |
The FBI also recorded:
- 22,364 complaints with an AI-related descriptor
- Nearly $893 million in associated losses
These figures do not capture every AI-assisted scam. Victims may never know whether artificial intelligence generated or modified the email, voice, photograph, profile or video used against them.
Source: FBI 2025 Internet Crime Report summary and FBI IC3 fraud overview.
What Is Business Email Compromise?
Business email compromise, or BEC, is a targeted fraud in which a criminal impersonates a trusted executive, employee, vendor or professional to manipulate a business transaction. The scammer typically requests a wire transfer, invoice payment, payroll change, banking update or release of confidential information.
A BEC email may contain no suspicious attachment or malicious link. Its purpose is to persuade the recipient to take an apparently legitimate action.
Common examples include:
- A fake CEO requesting an urgent wire transfer
- A vendor submitting fraudulent banking details
- A lawyer sending altered closing instructions
- An employee requesting a payroll-account change
- A supplier replacing a legitimate invoice
- A criminal continuing a conversation from a compromised mailbox
Case study
How Did Ubiquiti Lose $46.7 Million to an Employee-Impersonation Scam?
In 2015, Ubiquiti Networks disclosed that an outside entity had impersonated company employees and sent fraudulent requests to its finance department.
A company subsidiary transferred $46.7 million to third-party accounts overseas.
Ubiquiti reported the incident in a filing with the US Securities and Exchange Commission. The filing described criminal fraud involving employee impersonation but did not identify a related intrusion into the company’s information systems.
Source: Ubiquiti Networks SEC filing.
What weakness did the attackers exploit?
The finance team needed to determine whether an authorized employee had approved the transfers. The communications instead demonstrated only that someone could present the employee’s identity convincingly.
Names, titles, writing styles and email signatures can be copied. None independently proves that the person with the corresponding authority issued the instruction.
What can businesses learn from the Ubiquiti fraud?
High-value transfers should never depend exclusively on instructions received within a single email conversation.
The safest approval process confirms:
- Who requested the payment
- Whether that person has the necessary authority
- Whether the request was independently approved
- Whether the destination account belongs to the intended recipient
Case study
How Were More Than $120 Million in Vendor Payments Redirected?
Between approximately 2013 and 2015, a fraudster registered a Latvian company with the same name as a legitimate Asian computer-hardware manufacturer.
Two US multinational technology companies regularly purchased goods and services from the real manufacturer. Employees received phishing emails instructing them to send legitimate vendor payments to accounts controlled by the imitation company.
The scheme included forged:
- Invoices
- Contracts
- Corporate letters
- Company stamps
- Supporting payment documents
The victims transferred more than $120 million to accounts in Latvia and Cyprus. The money was subsequently moved through several jurisdictions.
The US Department of Justice secured a conviction. The defendant was ordered to forfeit approximately $49.7 million and pay approximately $26.5 million in restitution.
Source: US Department of Justice vendor-impersonation case.
What made the fake vendor appear legitimate?
The victims evaluated documents supplied by the identity they were attempting to verify.
The email appeared to support the invoice. The invoice matched the contract, and the contract appeared to confirm the company. Every document was consistent because the same criminal controlled all of them.
The attacker did not need to compromise the genuine manufacturer. He constructed a parallel corporate identity around an existing commercial relationship.
What can businesses learn from this vendor scam?
A professional invoice does not verify the company that issued it. Neither does a matching logo, corporate stamp or familiar business name.
Before accepting new payment instructions, a business should independently verify:
- The supplier’s legal identity
- The sender’s authority
- The requested bank-account change
- The connection between the destination account and contracted supplier
- The request through contact information already held by the business
What Is a Fake Vendor Email Scam?
A fake vendor email scam occurs when a criminal impersonates a trusted supplier and asks a business to send an invoice payment to a fraudulent account. The message may claim that the vendor has changed banks, provide a replacement invoice or continue an existing email conversation.
Fake vendor emails are particularly dangerous because the underlying payment may be legitimate. The criminal changes only its destination.
Warning signs can include:
- Unexpected changes to banking information
- Urgent requests to bypass normal approval procedures
- Slightly altered email domains
- New contact details supplied inside the request
- Payment accounts registered in an unexpected country
- Resistance to independent confirmation
These signs should prompt additional verification, but their absence does not prove that a request is authentic.
How Much Do US Consumers Lose to Impersonation Scams?
The Federal Trade Commission received 2.6 million consumer fraud reports involving $12.5 billion in losses during 2024.
| Consumer fraud category | Reported losses |
|---|---|
| Investment scams | $5.7 billion |
| Imposter scams | $2.95 billion |
| Government impersonation | $789 million |
| Job and employment scams | $501 million |
Consumers reported losing more through bank transfers and cryptocurrency than through all other payment methods combined.
Source: FTC Consumer Sentinel findings for 2024.
Criminals frequently impersonate:
- Government and law-enforcement agencies
- Banks and technology companies
- Customer-support departments
- Employers and recruiters
- Investment professionals
- Family members
- Romantic partners
Older adults are not necessarily more likely to report fraud, but their financial losses can be much larger. Among people aged 60 and older, reported losses of more than $100,000 increased from $55 million in 2020 to $445 million in 2024.
Source: FTC analysis of high-loss impersonation scams targeting older adults.
How Is AI Making Phishing and Impersonation Scams More Convincing?
AI-assisted impersonation uses generated text, cloned voices, synthetic images or manipulated video to imitate a trusted person. It allows criminals to produce personalized scams at scale while removing many of the spelling, language and visual mistakes that previously exposed fraudulent communications.
The FBI has warned that criminals use generative AI to create:
- Personalized phishing emails
- Cloned voices
- Synthetic identification documents
- Fake professional profiles
- Realistic photographs and videos
- Live video representations of executives or officials
A familiar voice is no longer reliable proof of identity. Correct grammar does not establish that an email is legitimate, and seeing an executive on a video call does not guarantee that the real executive is present.
Can AI Voice Detection Stop Executive-Impersonation Scams?
AI detection may flag suspicious audio, images or video, but it generally produces an estimate rather than proof of identity.
Detection also creates an ongoing contest: generation tools improve, detection systems respond and criminals change their methods. Businesses should therefore verify the authority behind a sensitive request instead of relying exclusively on determining whether the content was artificially generated.
How Can a Business Verify a Vendor’s Banking Change?
A vendor bank-account change should be treated as a high-risk request because it can redirect legitimate payments without changing the invoice amount or commercial relationship.
Before updating payment details:
- Do not use the phone number or link supplied in the request.
- Contact the vendor using information already stored in company records.
- Confirm the change with an authorized vendor representative.
- Verify the legal name attached to the destination account.
- Require a second internal approval.
- Document who requested, confirmed and approved the change.
- Apply a temporary hold when the information cannot be independently verified.
A reply within the same email thread is insufficient if the vendor’s mailbox has been compromised.
How Can Companies Prevent Business Email Compromise?
No single security control stops every BEC scam. Effective prevention combines technical protection with independent payment authorization.
Protect company email accounts
Use multifactor authentication, strong access controls, suspicious-login alerts and monitoring for mailbox-forwarding rules.
Authenticate company domains
Configure SPF, DKIM and DMARC to reduce unauthorized use of corporate domains. These standards help detect spoofing but cannot prove who is operating a compromised legitimate account.
Require independent payment approval
Confirm wire transfers, bank-account changes and payroll updates outside the original message. Use contact details stored before the request arrived.
Separate request and approval authority
The person who receives or enters a payment change should not be the only person who approves it.
Verify the person, not the presentation
Do not rely on logos, caller ID, email signatures, writing style, voices or video appearances as proof of identity.
Train employees around specific decisions
Training should focus on high-risk actions such as changing banking details, sending urgent transfers, releasing credentials and bypassing established approval procedures.
Why Don’t Email Security and Employee Training Stop Every BEC Scam?
Email filters are designed to identify technical threats and known malicious patterns. A carefully written message from a compromised account may contain no malware, unusual link or detectable payload.
Other controls also have limitations:
- SPF, DKIM and DMARC may pass when the real mailbox is compromised.
- Multifactor authentication does not prevent an employee from being persuaded to authorize a payment.
- Transaction monitoring may approve a transfer that resembles normal vendor activity.
- Employees may call a number supplied by the impersonator.
- Security training depends on people noticing increasingly subtle inconsistencies.
The unresolved question is often not whether the message appears suspicious. It is whether the person behind it has the authority being claimed.
What Should a Business Do After Sending Money to a Scammer?
Immediately contact the sending bank and request a recall or freeze. Preserve the emails, headers, invoices, account details and transaction records. Report the incident to the FBI’s Internet Crime Complaint Center and relevant law-enforcement authorities. Recovery becomes harder as the money moves through additional accounts.
The FBI’s Recovery Asset Team shows why speed matters. In 2022, it initiated the Financial Fraud Kill Chain for 2,838 selected domestic BEC complaints involving more than $590 million. Approximately $433 million was frozen—a 73% success rate for that eligible group.
This was not the recovery rate for every US fraud case. It applied to selected incidents reported quickly enough for intervention.
Source: FBI 2022 Internet Crime Report.
How Could Verified Digital Identity Help Prevent Impersonation?
Most fraud controls analyze the communication, protect the account or monitor the resulting transaction. An identity-verification layer addresses a different question:
Can the communication be connected to the accountable person or organization it claims to represent?
A verification system could allow organizations to register:
- Their legal identities
- Official domains and communication channels
- Authorized employees and departments
- Approved business purposes
- Payment-change procedures
- Representatives permitted to authorize sensitive requests
Recipients could check those facts before sending money, releasing information or granting access.
For high-risk transactions, verifying the email address alone would not be enough. The system would also need to confirm that an authorized person approved the specific request.
How Does Gemisis Approach Communication Verification?
Gemisis is building a cross-platform verification and traceability layer for digital communications.
When a recipient receives a supported email, call or message, Gemisis is intended to determine whether it corresponds with the legal organization, authorized representative and official channel registered by the claimed sender.
For a sensitive business request, Gemisis could evaluate whether:
- The claimed organization is legally identifiable.
- The communication channel belongs to that organization.
- The sender is authorized to act in the claimed role.
- The particular request received the necessary independent approval.
The verification result would appear where the interaction occurs, allowing the recipient to check the claimed identity before acting.
Gemisis would complement—not replace—email security, multifactor authentication, payment controls, banking safeguards and law enforcement.
What If a Scammer Compromises a Real Email Account?
A real email address proves that the account belongs to an organization. It does not prove that the authorized owner is currently operating it.
If a criminal controls a vendor’s genuine mailbox, the message may pass SPF, DKIM and DMARC. A registry may also correctly recognize the address as belonging to the vendor.
Sensitive actions must therefore receive request-level authorization through a separate trusted process. A wire transfer, banking change or release of confidential information should be connected to an approved person, device and workflow—not merely a familiar email account.
Frequently Asked Questions
What is the difference between phishing and business email compromise?
Phishing commonly sends similar messages to many recipients to steal credentials, install malware or obtain money. Business email compromise is typically more targeted. The criminal researches a particular organization or commercial relationship and impersonates someone the recipient already trusts.
How much did business email compromise cost the US in 2025?
The FBI recorded approximately $3 billion in reported business email compromise losses during 2025, making BEC one of the country’s costliest forms of cyber-enabled fraud.
What is CEO fraud?
CEO fraud is a business email compromise scam in which a criminal impersonates a senior executive and pressures an employee to send money or confidential information. The request often uses urgency, secrecy or executive authority to discourage normal verification.
Can a fake vendor email come from the vendor’s real account?
Yes. Criminals can compromise a legitimate vendor mailbox and continue existing conversations. In that situation, the email address and authentication checks may appear valid. Banking changes should therefore be confirmed through an independent contact method and approved workflow.
What is the safest way to confirm wire-transfer instructions?
Contact the authorized person through a trusted channel already held in company records. Do not use contact information contained only in the new request. High-value transfers should also require a separate internal approval.