Business email compromise, or BEC, is still one of the principal causes of losses from cybercrime in the United States.
According to the FBI’s Internet Crime Complaint Center (IC3), people suffered losses of more than $3 billion as a result of BEC schemes in 2025, and there were almost 25,000 complaints received across the country ([1], [2]).
Nowadays, criminals are employing artificial intelligence, for example voice cloning and AI-generated emails, in order to make their scams appear genuine ([3]).
It is important to act within the first 72 hours if a fraudulent wire transfer is discovered.
The FBI states that swift action can enable large amounts of stolen money to be frozen, and FinCEN points out that reporting the fraud immediately offers the best opportunity for recovery ([4], [5]).
How the Fraud Occurs
BEC scams usually begin when an individual’s email account has been hacked.
The hacker then reads the emails as they are being sent, monitors any payments, and waits until the time comes for a scheduled transaction.
At that moment the hacker sends new bank transfer details either from the compromised email account or from an email address that looks similar to the real one.
When the false wire transfer is sent, the attacker could already have been watching the emails for weeks and they usually set up forwarding rules, delete messages, or alter their mailbox settings in order to conceal their activity ([6]).
You should be cautious about any requests that appear to be urgent, secret, or that involve last-minute changes to the payment instructions ([7]).
Immediate Response
Start by contacting your bank and ask them to see if they can remember the wire transfer and to get in touch with the receiving bank right away.
Every minute is important because stolen money can pass through multiple accounts within just a few hours, making recovery more difficult at each subsequent step ([8]).
You should file a complaint with IC3 as soon as you can and include all of the banking details, the transaction information, and any other identifiers associated with the transfer.
Quickly reporting the matter may enable law enforcement to use special tools to recover the fraudulent wire transfers ([9], [10]).
It is just as crucial to retain all evidence, since many companies erroneously reset their devices or alter their systems prior to a forensic examination.
You should immediately save email headers, login records, forwarding rules, wire confirmations, and any messages sent to banks.
Should the evidence be lost, it may then be impossible to determine how the breach took place or to establish who is to blame ([11], [12]).
Assessing Responsibility
In any BEC case the first issue to consider is who had their system hacked, since this answer usually influences the course of the investigation and may have an impact on insurance matters, contracts, and any possible legal claims.
Forensic experts typically examine mailbox activity, login history, forwarding rules, and security controls and often discover that the attacker had already gained access to the email account before the fake payment instructions were sent ([13]).
The person or organisation that sends the wire transfer isn’t necessarily to blame for the loss.
In different circumstances, claims could be brought against a hacked counterparty, a bank, or some of the other parties involved in the transaction.
Moreover, banks are obliged to report any suspicious activity and to comply with the rules concerning payment security ([14], [15]). It will be the specifics of each case that determine what solutions are available.
How Dilendorf Law Firm Assists
The Dilendorf Law Firm has assisted victims in more than 130 cases of cybercrime both in the United States and overseas.
Our approach is to act swiftly by contacting banks and the authorities, preserving crucial evidence and carrying out an investigation into the hacked accounts and devices.
We assist our clients with filing IC3 complaints, have conversations with both the sending and receiving banks, attempt to get the funds back, and look at any possible claims against those who are responsible.
If necessary, we work together with forensic experts and ex-members of law enforcement to discover how the breach took place and to preserve the evidence for use in court or arbitration.
If your company has just discovered a fraudulent transfer, the first 72 hours matter most. Contact us immediately.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 4, 8. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI IC3, 2025 Internet Crime Report, pp. 25–26. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[3] FBI IC3, 2025 Internet Crime Report, pp. 39–42. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[4] FBI IC3, 2025 Internet Crime Report, p. 17 (Recovery Asset Team / Financial Fraud Kill Chain). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[5] FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, p. 2. https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[6] FBI IC3, PSA I-040620, Cyber Criminals Conduct Business Email Compromise Through Exploitation of Cloud-Based Email Services, Apr. 6, 2020. https://www.ic3.gov/PSA/2020/PSA200406
[7] U.S. Secret Service, Understanding Business Email Compromise. https://www.secretservice.gov/investigations/bec
[8] FBI IC3, Business Email Compromise (victim guidance); FBI IC3, 2025 Internet Crime Report, p. 17. https://www.ic3.gov/CrimeInfo/BEC
[9] FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, p. 2 (information required in the complaint). https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[10] FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, p. 1; FBI IC3, 2025 Internet Crime Report, p. 17. https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[11] NIST SP 800-86, Guide to Integrating Forensic Techniques into Incident Response, §§ 3.1.2, 8.2. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-86.pdf
[12] U.S. Secret Service, Understanding Business Email Compromise (preserve evidence; engage incident response). https://www.secretservice.gov/investigations/bec
[13] FinCEN Advisory FIN-2019-A005, Updated Advisory on Email Compromise Fraud Schemes, July 16, 2019, p. 10. https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf
[14] FinCEN Advisory FIN-2019-A005, July 16, 2019, p. 9 (suspicious activity reporting). https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf
[15] Uniform Commercial Code §§ 4A-202, 4A-204 (Cornell Legal Information Institute). https://www.law.cornell.edu/ucc/4A/4A-202

