Most small-business cybersecurity spending targets ransomware, but business email compromise and payment fraud generate nearly 100 times the reported financial losses. Here’s how to close the gap.
The FBI’s Internet Crime Complaint Center published its annual report a few months ago, and one number in it deserves more attention than it has received. Reported losses directly attributed to ransomware came to $32.3 million. Meanwhile, reported losses from business email compromise (BEC) in 2025 came to $3.046 billion.
Read those two numbers again. BEC generated roughly ninety-four times the reported losses that ransomware did.
A necessary caveat about that shockingly low ransomware number. The figure excludes the costliest components of a ransomware attack, which include business disruption, downtime, remediation, and recovery. It can only capture what victims voluntarily reported, and the FBI acknowledges that many entities report no dollar amount at all or report directly to field offices rather than through the IC3. We can safely assume that true economic toll of ransomware is orders of magnitude larger. Estimates from IBM and Sophos put the average cost of a single ransomware incident in the millions.
But the caveat cuts both ways. BEC losses are also underreported, and the FBI’s $3 billion figure captures only what victims filed through the same voluntary system. Most importantly, the broader IC3 data tells a story that can’t be explained away by methodology. Investment fraud generated $8.6 billion in reported losses in 2025. Tech support scams generated $2.1 billion. Even phishing, as a standalone category, generated nearly seven times the reported losses that ransomware did. Cyber-enabled fraud as a whole accounted for 85 percent of all losses reported to the FBI. The pattern is consistent across every fraud category: the threats that work by manipulating people into sending money are generating far more financial damage than the threats that work by locking systems and demanding payment.
And the World Economic Forum’s Global Cybersecurity Outlook 2026 reinforces the point from a different angle. The report found that 73 percent of respondents said someone in their professional network had been personally affected by cyber-enabled fraud over the course of 2025. Fraud and impersonation, not ransomware, now sit at the top of CEO-level cybersecurity concerns according to the WEF’s analysis.
So why are most small businesses still budgeting as though ransomware were the primary financial risk?
Why Does Ransomware Get All the Attention?
The answer isn’t complicated. Ransomware incidents are dramatic. Screens go dark and files are mysteriously locked. Employees end up standing in the hallway with their coats on because there is nothing they can do. The recovery is painful, can be highly public, and makes for a compelling story at every cybersecurity conference in the country.
Fraud, by contrast, works in the other direction. A successful business email compromise may not be discovered for weeks. There’s no ransom note, no moment of crisis that forces everyone into a conference room. Someone in your accounting department wires money to what they believe is a legitimate vendor, using updated banking details that arrived via email from what appeared to be a trusted contact. The email came from a real address, or one close enough to pass a glance. By the time anyone realizes what happened, the money has vaporized into a outside accounts that law enforcement may or may not be able to reach.
What this means, ultimately, is that budget allocations tend to reflect the vividness of the threats rather than their true financial weight. Walk into most small and midsize businesses that take cybersecurity seriously and you will find endpoint detection and response tools, backup infrastructure with immutable storage, maybe a ransomware-specific insurance rider. These are sensible investments. But ask those same businesses what procedures they have in place for verifying payment instructions received via email? You’re likely to get a long pause.
What Fraud Actually Costs a Small Business
A typical BEC scenario in a small business doesn’t start with a dramatic breach. It starts with patience. Attackers compromise a mailbox, often through a credential that was phished or harvested from a previous data breach. Then, they wait. They read email threads. They learn who handles payments, who approves wires, who is traveling, and what the internal language looks like when someone requests a transaction. They set up forwarding rules to monitor specific conversations without the account holder noticing. Then they look for the right moment: a real invoice from a real vendor, a real closing on a real property, a real payment cycle that is already in motion.
When they strike, the email looks routine. Maybe it’s updated banking details for an existing vendor. Or a request from the CEO, who just happens to be out of town, to expedite a payment. An invoice from a contractor that matches the format of every previous invoice except for the account number at the bottom. The amounts are calibrated to be large enough to matter and small enough not to trigger the instinct to double-check.
What makes this particularly punishing for SMBs is the recovery math. Ransomware, for all its damage, has a defined remediation path: restore from backups, rebuild affected systems, notify as required, move on. But the money lost to a successful wire fraud is simply gone. The FBI’s Recovery Asset Team achieves a roughly 66 percent success rate on freezing fraudulent transfers, but only when the victim reports quickly, and “quickly” means hours, not days. Most small businesses don’t discover the fraud in time.
And then there is the legal dimension, which is still evolving. Courts have increasingly had to decide who bears the loss when a BEC attack tricks one party in a legitimate transaction into wiring money to a fraudulent account. The answers have been inconsistent. Some courts apply an “imposter rule” analysis that asks who was in the best position to prevent the fraud. Others look at whether either party failed to exercise reasonable care. For a small business that wired money in good faith based on a compromised email, the possibility exists that a court might assign some or all of the loss to them, rather than the party whose email was compromised. That’s a risk that doesn’t appear on most cybersecurity dashboards.
Building a Fraud-Aware Security Posture
The good news is that the most effective fraud prevention controls aren’t expensive. Several cost nothing at all! What they require is a willingness to treat payment verification as a security discipline rather than an administrative inconvenience.
Implement a callback policy for payment changes.
This is the single highest-return control we can recommend. Write a one-page policy that requires a phone call to a known, pre-established number before any wire transfer is initiated, any banking details are changed, any new vendor is added to the payment system, or any payroll routing is modified. The callback number must come from your own records or a published directory. Never use a phone number from the email that is requesting the change.
This one procedure, consistently followed, would have prevented the majority of the BEC losses reported to the FBI last year.
It costs nothing. It takes two minutes. But too many businesses don’t do it.
Set up dual authorization for outbound payments above a defined threshold.
Pick a dollar figure that makes sense for your business, whether that is five thousand dollars or fifty thousand, and require two people to approve any payment above that amount. This eliminates the scenario in which a single employee, acting on a convincing email, can send a six-figure wire without anyone else in the building knowing about it.
Deploy DMARC on your email domain.
Domain-based Message Authentication, Reporting, and Conformance prevents attackers from sending emails that appear to come from your domain. To be fair, it won’t stop an attacker who has compromised a real mailbox, and it won’t not catch a lookalike domain with a single letter changed. But it eliminates the most basic spoofing attacks and is increasingly an underwriting requirement for cyber insurance. If you haven’t implemented DMARC at enforcement level, start there.
Refocus your security awareness training.
Most SMB security training programs, to the extent they exist, emphasize phishing links and malicious attachments. That is useful stuff, but it’s incomplete. The fraud scenarios that cost businesses the most money don’t involve clicking a link. They involve a convincing email from what appears to be a known sender, requesting a routine action. Make sure you’re training your finance team specifically on payment fraud scenarios: last-minute changes to wire instructions, urgency cues, requests that bypass normal approval channels. Run tabletop exercises where someone role-plays a BEC attempt and the accounting team has to identify it in real time.
Review your cyber insurance for social engineering coverage.
Many cyber policies cover ransomware and data breaches but exclude or cap losses from social engineering and wire fraud. If your policy has a social engineering sublimit (and many do, often at a fraction of the overall policy limit), you may be carrying far less protection than you think. Review the policy language with your broker and understand exactly what is covered and what attestations you have made about your payment verification procedures.
Keeping Resources Aligned with Risk
We’re not suggesting that ransomware is a solved problem or that SMBs should stop investing in endpoint protection and backup infrastructure. Those investments are absolutely necessary. Ransomware appeared in 88 percent of SMB breaches in the most recent Verizon Data Breach Investigations Report, and any business without immutable backups and a tested restoration process is taking a serious gamble.
But what we’re seeing “on the ground,” as it were, is that the typical allocation of attention and resources has drifted out of proportion to the actual financial risk. The threats that make headlines and the threats that drain bank accounts just aren’t the same.
A two-minute phone call to a known number before approving a wire transfer is, dollar for dollar, probably the most valuable cybersecurity control a small business can implement in 2026. The fact that it requires no software, no vendor, and no budget line item may be precisely the reason it gets overlooked. We have been trained to think of cybersecurity as a technology problem. Sometimes the fix is a phone call and a policy that says you have to make it.