TL;DR: The FBI’s 2025 IC3 report recorded $20.877 billion in cybercrime losses, with 85% tied to cyber-enabled fraud and $893 million linked to AI-related complaints, underscoring how AI is amplifying impersonation, BEC, and persistent fraud campaigns, according to Abnormal AI’s analysis of the report. Identity and access programmes now have to treat behavioural trust, not just technical compromise, as the primary control surface.
At a glance
What this is: Abnormal AI analyses the FBI’s 2025 IC3 data to show that AI is amplifying impersonation and fraud at scale, with cyber-enabled fraud dominating reported losses and AI-related complaints already reaching nine figures.
Why it matters: IAM and security teams need to treat trust, workflow context, and communication behaviour as part of the control plane, because AI is making social engineering more precise than signature-based defences can handle.
By the numbers:
- The FBI’s 2025 IC3 report recorded $20.877 billion in cybercrime losses, a 26% year-over-year increase.
- The report linked $893 million in losses to 22,364 AI-related complaints in 2025.
- Business Email Compromise drove $3.046 billion in losses in 2025.
Context
The primary issue is not that attackers have abandoned old fraud tactics. It is that AI has improved the quality, timing, and context of impersonation so that trusted workflows are easier to exploit. In identity terms, the control problem is shifting from message filtering to behavioural trust.
The FBI’s 2025 IC3 report gives that shift a measurable shape. Losses are concentrated in cyber-enabled fraud, where the attacker persuades a human to act rather than breaking a system first. That makes human identity, communication patterns, and workflow awareness part of the attack surface, not just the background environment.
Key questions
Q: How should security teams respond when AI makes business email compromise harder to spot?
A: Teams should move beyond message inspection and verify the requester, the channel, and the business context before allowing action. AI makes tone and wording unreliable signals, so the control point becomes workflow validation, out-of-band confirmation, and monitoring for abnormal approval patterns across finance, executive, and supplier interactions.
Q: What breaks when organisations only rely on static phishing detection?
A: They miss live proxy attacks that deliver the real website content through attacker infrastructure. There is no fixed template to fingerprint, so blocklists and page similarity tools lose their main signal. The failure mode is a valid-looking page with malicious session handling behind it, which requires behavioural detection instead.
Q: Why do impersonation attacks remain effective even when users are trained on phishing?
A: Training helps, but AI improves the quality of the impersonation itself. When the email, call, or message matches the target’s normal environment, the user sees fewer obvious cues to challenge it. That makes verification habits and approval controls more reliable than awareness alone.
Q: How can IAM teams tell whether fraud controls are actually working?
A: Look for fewer unverified high-risk requests, better challenge rates on abnormal approvals, and stronger separation between routine identity events and exceptional transactions. If users still complete sensitive actions based only on message urgency or apparent authority, the control is not working.
Technical breakdown
How AI changes business email compromise execution
Business Email Compromise succeeds when the attacker can imitate a legitimate request well enough to fit the organisation’s normal communication pattern. AI lowers the cost of that imitation by generating context-specific language, role-accurate tone, and timing that lines up with real business processes. That does not create a new attack class so much as it removes friction from an old one. The important technical shift is that the attacker now optimises for believability across sequence, content, and follow-up, not just the first message. Detection therefore has to compare message behaviour against historical workflow patterns, not just inspect for malicious artefacts.
Practical implication: build fraud detection around behavioural anomalies in identity and communication patterns, not only content filters.
Why impersonation scales beyond single-message phishing
Traditional phishing often depends on a one-off lure. AI-enabled impersonation is different because it can sustain consistency across multiple messages, multiple roles, and multiple targets without obvious degradation. That turns social engineering into a repeatable operation rather than a handcrafted event. The technical risk is not only better wording, but better operational continuity: attackers can maintain a storyline, adapt to responses, and continue pressure until the target complies. In security terms, the attacker is now exploiting the continuity of trust, which is much harder to model with static controls.
Practical implication: look for multi-step impersonation chains, not just single suspicious emails or calls.
Why behavioural context outperforms signature-based detection
Signature-based defences work best when malicious content repeats. AI-driven fraud reduces repeatability by varying wording, structure, and delivery while keeping the underlying intent the same. That makes identity behaviour, relationship history, and workflow alignment more reliable signals than known-bad phrases or domains. Behavioural models are useful here because they ask whether the interaction fits the normal pattern for that person, vendor, or finance process. This is especially relevant for human identity governance, where approval chains, payment requests, and executive communications are highly predictable and therefore easy to mimic.
Practical implication: tune controls to expected communication patterns, approval paths, and relationship histories.
Threat narrative
Attacker objective: The attacker aims to convert trust into action, typically to obtain money, sensitive information, or authorised transactions.
- Entry occurs through a believable email, call, or message that fits the victim’s normal communication context.
- Credential theft is not always required because the attacker’s goal is often to induce a wire transfer, disclosure, or approval action.
- Escalation happens through follow-up messages, voice cloning, or repeated impersonation that reinforces authority and urgency.
- Impact is financial loss, reputational damage, and in some cases wider enterprise fraud exposure across multiple workflows.
Breaches seen in the wild
- CoPhish OAuth phishing via Copilot Studio: Datadog showed Copilot Studio agents on a Microsoft domain can front OAuth consent phishing and forward stolen tokens; no victims reported.
- EmeraldWhale Git config credential theft: Tokens in exposed .git/config files let EMERALDWHALE clone private repositories and steal more than 15,000 cloud credentials.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Behavioural trust is now a core identity control surface: The FBI’s IC3 data shows that the dominant loss mode is not technical compromise but successful manipulation of human decision-making. That means identity programmes must treat communication patterns, workflow context, and approval behaviour as part of governance, not as soft signals. The practitioners who still anchor control design in content inspection alone are looking at the wrong layer.
AI-enabled fraud is collapsing the gap between social engineering and identity governance: The article shows that attackers can now imitate role, tone, and timing well enough to fit real business processes. That blurs the old separation between email security, user awareness, and IAM, because the abuse is happening in the trust relationship itself. The implication is that identity governance and fraud detection now overlap more than many programmes assume.
Human identity controls need behavioural proof, not just authentication proof: A verified login no longer guarantees a legitimate request, because AI can weaponise the post-authentication workflow. This makes transaction context, relationship history, and approval integrity more important than simple access state. Practitioners should assume that identity assurance can be true while request legitimacy is false.
Persistent fraud campaigns are a governance problem, not just a detection problem: The article’s emphasis on multi-step impersonation shows that attackers are now managing conversations over time, not firing isolated lures. That makes escalation paths, exception handling, and payment workflows part of the fraud surface. The practical conclusion is that governance must extend into the operational sequence where trust is repeatedly renewed.
Behavioural anomaly detection is becoming the decisive control layer for AI-driven fraud: The article’s central signal is that AI removes the imperfections that once exposed scams. In response, the strongest control is no longer content-based inspection but baseline-driven analysis of how people, vendors, and requests normally behave. That is a structural change in how organisations should think about identity assurance and fraud prevention.
What this signals
Behavioural trust is becoming the practical boundary of identity security: If attackers can sound like the right person and time the request to a real workflow, traditional identity assurance stops at the login screen. Programmes that want to stay effective need to observe how requests move through the business, not just whether a user authenticated.
AI-assisted impersonation makes long-running fraud campaigns more realistic across email, voice, and messaging channels. For practitioners, the result is a stronger case for out-of-band validation on high-risk actions and for treating approval chains as security controls rather than admin steps.
For practitioners
- Model behavioural trust signals Baseline normal communication patterns, approval routes, and vendor interaction histories so deviations are visible before the request is fulfilled.
- Harden executive request workflows Require out-of-band verification for high-risk requests that arrive through email, chat, or voice and match sensitive finance or access changes.
- Instrument finance and payroll exceptions Treat wire transfers, bank detail changes, and urgent vendor requests as governed identity events with extra validation and logging.
- Train for AI-assisted impersonation Update user awareness content to reflect cloned voices, context-aware messages, and multi-step fraud sequences rather than generic phishing examples.
- Review detection around workflow integrity Use behavioural analytics to flag requests that arrive from the right identity but outside the expected sequence, timing, or relationship context.
Key takeaways
- AI is making established fraud tactics more effective by improving impersonation quality, timing, and persistence.
- The strongest losses now come from cyber-enabled fraud that exploits human behaviour rather than technical compromise.
- Security teams should treat behavioural trust, workflow integrity, and transaction verification as core controls for identity and fraud defence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | The article centres on AI-assisted impersonation of human workflows and trust. |
| Recommendation — Control human-facing request channels and validate sensitive actions outside the message thread. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Identity assurance must extend into whether requests align with authorised workflow context. |
| Recommendation — Align approval paths and request validation with PR.AA-05 so abnormal actions are challenged before execution. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article’s fraud scenarios depend on weaknesses around credential and request validation discipline. |
| Recommendation — Use IA-5 to tighten credential and authenticator handling for high-risk identity workflows. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes impersonation and follow-on access abuse patterns seen in fraud operations. |
| Recommendation — Map impersonation-driven fraud campaigns to TA0006 and TA0008 to improve detection coverage. | ||
Key terms
- Behavioural Trust: Behavioural trust is the practice of judging message legitimacy by observed patterns such as timing, conversation history, and action sequence rather than by domain reputation alone. It is especially important when attackers operate through real accounts and authentic platforms.
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Impersonation: Impersonation is a controlled administrative action that lets an authorised operator assume a user context for debugging or support. In a well-governed setup it preserves audit logging, limits exposure of credentials, and keeps production authentication separate from local troubleshooting.
- Anomaly Detection: Anomaly detection is the use of rules, statistics, or behavioural models to identify access patterns that differ from the expected baseline. In identity programmes, it helps surface compromised credentials, misuse of service accounts, and suspicious changes in authentication or access behaviour.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org