Business

How AI-Powered Business Email Compromise Scams Are Stealing Billions

Date: August 8, 2026


The Business Email Compromise (BEC) is a scam perpetrated by scammers who use social engineering tactics to pose as company executives or trusted vendors to lure employees at their targeted companies to transfer funds to the scammers. I first reported to you about this scam in 2024. The FBI first began tracking this scam in 2013 and the scam has gotten worse each year since then. According to the FBI’s Internet Crime Complaint Center (IC3) most recent Annual Report, companies reported losing $3.046 billion in 2025 which represented an increase of $250 million in losses over the previous year.

In the past, as the name of the scam indicates, the Business Email Compromise would originate with an email to an employee who controlled payments at a targeted company. The email would appear to be from the CEO, company attorney or even a vendor with which the company did business requesting funds be wired to a phony company or person. At its essence, the scam is remarkably simple and relies more on psychology instead of sophisticated computer hacking or malware. Often the scammers will do significant research to not only learn the name of the key employees involved with payments within company but also will infiltrate the email accounts of company employees for a substantial period to learn the protocols and language used by the company in making payments. The scammers also gather information from the company’s website and social media accounts of its employees, all to adapt their message to seem more legitimate. AI has made the harvesting of such information quicker and easier for even unsophisticated scammers.

When the scam first started around 2013, the phony emails would often contain grammatical errors and were relatively easily recognized as scams. However, as the scam initially evolved, the scammers would hack into the email account of the CEO or other corporate executive whom they posed as to make their communications appear more legitimate. Now AI has enabled scammers to gather important information to craft believable emails and text messages as well as use deepfakes and voice cloning to make their scams even more believable.

An example of the older version of the BEC involved Barbara Corcoran, one of the stars of the “Shark Tank” television show whose company was scammed in 2020. According to Corcoran, “I lost the $388,700 as a result of a fake email chain sent to my company. It was an invoice supposedly sent by my assistant to my bookkeeper approving the payment for a real estate renovation. There was no reason to be suspicious as I invest in a lot of real estate.” In this case, the scammer didn’t even hack into the email account of Corcoran’s assistant but rather sent an email using an email address that appeared at first glance to be the email address of Corcoran’s assistant, but upon closer examination contained a single different letter, which mistake was not recognized by Corcoran’s bookkeeper who wired the money to pay the phony invoice to the scammers.

In recent years, like so many scams the BEC has evolved through the use of highly personalized emails, text messages and voice cloning phone calls which, through the use of a simple technique called “spoofing” appear as if they come from the CEO or some other legitimate source, and deepfake video meetings using deepfakes created from readily available video from the Internet of the CEO or others in senior positions in the targeted company.

FBI Warning

The FBI issued a warning in 2024 that scammers were increasingly using AI created voice cloning and deepfakes to commit these crimes. According to FBI Special Agent Robet Tripp, “As technology continues to evolve, so do cybercriminals’ tactics. Attackers are leveraging AI to craft highly convincing voice or video messages and emails to enable fraud schemes against individuals and businesses alike. These sophisticated tactics can result in devastating financial losses, reputational damage, and compromise of sensitive data.”

In perhaps the most noteworthy example of how the scam has evolved, in 2025 an employee in the Hong Kong office of the British engineering company Arup received a spear phishing email that appeared to come from the company’s CFO asking him to do a private transaction. Properly suspicious, the employee asked for a video conference call to confirm the legitimacy of the request. The phony CFO readily agreed and the employee was able to see and hear the CFO as well as other senior employees of the company and was then convinced to make the transfer of approximately $25 million. Unfortunately, what the employee saw was extremely convincing deepfake video and what he heard was AI created voice cloning.

More recently there have been reports of scammers targeting hedge funds with the BEC using deepfakes and voice cloning.

How Can Companies Protect Themselves

AI has made an already effective scam even more difficult to distinguish. All companies should institute strong security policies to defend themselves from these attacks. Defensive protocols may include:

  1. Requiring independent verification of wire transfers.
  2. Callback verification to secure phone numbers.
  3. Dual authorization for large payments.
  4. Training employees on deepfakes and voice cloning.
  5. Use of a code word for executive payment requests.

More like this