Ransomware gets the headlines. The frozen screen, the countdown clock, the demand for Bitcoin, it makes for a great news segment. Business email compromise doesn’t have any of that drama. There’s no lock screen, no ransom note, no dramatic IT team racing to restore from backup while the clock ticks down. It’s just an email that looks exactly like it should, asking for something that seems completely normal.
And yet, dollar for dollar, business email compromise is quietly outpacing ransomware as the more expensive threat facing small and midsize businesses. According to the FBI’s 2025 Internet Crime Report, BEC accounted for more than 3 billion dollars in reported losses last year. Ransomware, by comparison, accounted for just over 32 million dollars in direct reported losses. That’s not a typo. BEC losses were nearly one hundred times higher than ransomware losses in the same reporting period.
If that number surprises you, you’re not alone. Most business owners still picture ransomware as the “big” cyber threat and BEC as a lesser cousin, an annoying phishing email that gets caught by spam filters most of the time. The reality is the opposite, and understanding why matters just as much as knowing the statistic.
Ransomware Has a Recovery Path. BEC Often Doesn’t.
When ransomware hits, there’s a process. It’s a painful, expensive, disruptive process, but it’s a process. You isolate the infected systems, you assess the damage, you restore from backup if you have one, and in a worst case scenario you negotiate. Insurance often covers part of it. There’s a beginning, middle, and end.
Business email compromise doesn’t work that way. Once a fraudulent wire transfer clears, that money is typically gone within minutes. There’s no decryption key to buy, no system to restore, no technical fix that brings the funds back. The FBI’s Recovery Asset Team can sometimes freeze fraudulent transfers if a business reports the incident within hours, but that window closes fast, and most SMBs don’t even realize what happened until days later when a vendor calls asking where their payment is.
The Insurance Safety Net Has Holes in It
A lot of business owners assume cyber insurance will make them whole if something like this happens. In practice, BEC claims are some of the hardest to get paid. Insurers increasingly treat social engineering fraud as a separate coverage category with its own sublimits, meaning a policy that looks robust on paper might only cover a fraction of an actual BEC loss. We wrote about this shift in detail in why cyber insurance is making it harder to get a claim paid, and BEC is exactly the kind of incident where that gap shows up. If your policy hasn’t been reviewed in the last year or two, there’s a good chance you’re less covered than you think.
It Starts Quietly, Long Before the Wire Goes Out
The other reason BEC is so costly is that it rarely starts with the fraudulent email itself. It starts with a compromised credential, an exposed password sitting on a data broker site, or a login that was scraped in a breach nobody ever reported. Attackers sit in an inbox for weeks, learning who approves invoices, how your finance team talks, when your CFO travels. By the time the fraudulent request goes out, it’s been written with your own company’s rhythm and tone. This is exactly why ongoing credential exposure checks matter so much. We break down what that actually looks like in what SMBs would find if they actually looked at dark web monitoring, and it’s worth a read if you’ve never had that visibility into your own exposure.
Why Tools Alone Won’t Fix This
Ransomware is largely a technical problem with technical defenses: patching, backups, endpoint detection. BEC is a human problem wearing a technical disguise. No firewall stops an employee from wiring money to an account because the email genuinely looked like it came from the owner. This is where a verification mindset matters more than any single piece of software. Every payment change, every urgent request, every “quick favor” from an executive needs a second channel of confirmation before money moves. That’s the practical core of a zero trust approach, and we explain what that actually means for non-technical teams in zero trust explained for business owners who aren’t technical. Verify first, every time, no exceptions for “urgent.”
The Real Cost Is Bigger Than the Wire Transfer
There’s also a cost to BEC that doesn’t show up in any FBI report. When an employee gets fooled into wiring money to a fraudster, they often carry the guilt of that mistake for a long time, and the trust between finance staff and leadership can take a real hit. Vendors who never got paid start asking uncomfortable questions. None of that shows up in a dollar figure, but all of it drains time, morale, and credibility that a business needs to keep running.
The businesses that fare best against BEC aren’t the ones with the most expensive security stack. They’re the ones that have built a culture where a phone call to confirm a wire transfer isn’t seen as slow or distrustful, it’s just how things get done. That habit costs nothing and it’s the single most effective defense against a threat that, dollar for dollar, is proving far more expensive than the ransomware everyone’s still bracing for.
If you’re not sure where your business stands against BEC, whether that’s email authentication, credential exposure, or your actual insurance coverage, Helixstorm can walk through it with you. It’s a lot cheaper to find the gap now than after a wire transfer clears.
