TL;DR: Cybercrime losses exceeded $10 billion in 2022, with investment fraud leading and business email compromise close behind, while AI is expected to push losses higher in the short term, according to Abnormal AI’s webinar briefing and Secret Service predictions. The signal for identity teams is that email compromise is now an identity and trust problem, not just a messaging problem.
At a glance
What this is: Abnormal AI’s webinar summary argues that fraud losses are climbing because investment fraud and BEC are driving major losses, and AI is likely to worsen the trend.
Why it matters: For IAM, PAM, and email security teams, the issue is no longer only message filtering. It is the trust boundary around identity, impersonation, and delegated authority.
Context
Cybercrime losses are not just a law-enforcement metric. When losses exceed $10 billion and the leading drivers are investment fraud and business email compromise, the practical question for identity teams is where trust is being granted too easily across people, mailboxes, and delegated workflows.
This webinar material from Abnormal AI frames BEC as a growing identity problem because the attacker succeeds by exploiting trust signals, not by breaking cryptography. That matters to IAM because the control failure is often authorization by assumption, especially when users, finance teams, and mailbox workflows accept requests that should be independently verified.
Key questions
Q: How should teams reduce business email compromise risk in approval workflows?
A: Teams should treat approval workflows as identity checkpoints, not just communications channels. The most effective controls are out-of-band verification, role separation, and explicit confirmation for payment and account-change requests. If a mailbox can initiate and approve the same action path, BEC risk remains high even when authentication itself is strong.
Q: Why does AI make fraud losses harder to contain?
A: AI lowers the cost of producing convincing impersonation at scale. That means attackers can personalise messages, imitate internal language, and pressure targets faster than manual review can respond. The main impact is not that AI removes human judgement entirely, but that it overwhelms weak workflow controls and makes trust-based shortcuts more dangerous.
Q: What are the signs that an email fraud defence program is not working well enough?
A: A weak program usually shows up as repeated spoofing attempts, frequent impersonation of multiple identities, and a steady stream of urgent payment or request emails that reach users unchallenged. If finance, HR, and accounts payable are all being targeted, the organisation is likely seeing attackers move beyond single executive spoofing. That pattern means controls are not stopping reconnaissance, impersonation, or workflow abuse.
Q: Which teams are accountable for reducing BEC and investment fraud losses?
A: Accountability usually spans security, identity, finance, and business operations because the failure sits in the workflow, not a single tool. Security may monitor signals, but finance owns payment controls and business leaders own approval discipline. Frameworks that support this view are the ones that tie access, verification, and segregation of duties together.
Background and context
Why BEC is an identity trust failure
Business email compromise works because recipients treat the sender, mailbox, or message thread as a sufficient trust signal. The attacker does not need to break email systems if they can impersonate a known identity, hijack an account, or insert themselves into an existing business process. In identity terms, the failure sits at the point where human trust, mailbox legitimacy, and business authority are assumed to align. That is why BEC is more than phishing. It is a control bypass that exploits delegated decision-making, weak verification, and the speed of routine payment or account-change workflows.
Practical implication: treat high-risk email actions as identity verification events, not messaging events.
How AI changes fraud economics
AI changes fraud by reducing the cost of believable impersonation and scaling personalised deception. That does not mean every AI-enabled attack becomes autonomous. It means fraud actors can iterate faster, tailor lures better, and make social engineering harder to distinguish from legitimate business communication. In this article’s framing, AI is an accelerant that worsens the economics of fraud, especially where the target already relies on informal trust. For identity programmes, the key issue is that faster, more convincing impersonation compresses the time available for manual detection and human challenge.
Practical implication: harden high-trust workflows so that speed and realism do not become the attacker’s advantage.
Why investment fraud and BEC dominate loss data
Investment fraud and BEC dominate because both target decision points where identity trust converts directly into money movement or account control. Investment fraud abuses credibility and urgency, while BEC exploits authority and routine approvals. In both cases, the attack succeeds when a person accepts identity claims without independent confirmation. That pattern is relevant to human IAM because it shows that identity governance cannot stop at authentication. It must account for how authority is represented, inherited, and acted on inside business processes, especially in finance and executive communications.
Practical implication: add verification friction to payment, beneficiary, and account-change paths with the highest loss potential.
NHI Mgmt Group analysis
BEC is now an identity governance problem, not only an email security problem. The article’s core signal is that business email compromise succeeds where organisations allow trust in sender identity to stand in for proof. That is a governance failure because the business process accepts identity claims without an independent control layer. The practical conclusion is that email controls and IAM controls have to converge at the decision point, especially for financial workflows.
AI is compressing the window in which human verification can catch fraud. The article does not describe autonomous agent behaviour, so the correct lens is not agentic AI governance. The relevant shift is simpler and more immediate: AI lowers the cost of believable impersonation and increases fraud throughput. The implication is that manual review alone becomes a weaker compensating control when the volume and quality of deceptive requests both rise.
Cybercrime loss growth exposes where organisations still rely on implicit authority. When investment fraud and BEC account for major losses, the common factor is not just attacker creativity. It is the persistence of process designs that treat identity as sufficient evidence of legitimacy. That assumption is fragile across email, payments, and approvals, so practitioners should re-evaluate where authority is accepted without challenge.
Identity trust must be measured at the workflow level, not only at the authentication layer. Authentication can be strong while the business process around it remains easy to abuse. This article reinforces that fraud prevention depends on whether the right human or system is asked the right question at the right step. Teams should therefore look at where trust is granted, not only where access is granted.
From our research library:
- Businesses report a 200% surge in attempted deepfake-aided wire fraud in Q1 2025 alone.
What this signals
Identity trust is the real control surface in BEC: organisations should focus on where sender identity, mailbox legitimacy, and business authority are treated as interchangeable. That assumption breaks most visibly in finance, but the same pattern appears anywhere a request can become execution without a second check.
The most durable response is not more message inspection alone. Teams need workflow controls that make impersonation insufficient on its own, because fraud losses rise when trust and authorisation are collapsed into one step.
For practitioners
- Reclassify BEC as a trust-control problem Map the email-triggered workflows that can move money, change beneficiary data, or alter vendor payment details without independent verification.
- Add verification to high-risk approvals Require out-of-band confirmation for payment requests, bank detail changes, and urgent executive instructions before any downstream action is taken.
- Tighten mailbox and identity monitoring Correlate anomalous sender behaviour, unusual login context, and message-thread manipulation so fraud teams can spot identity abuse earlier.
- Reduce implicit authority in finance workflows Separate request, approval, and execution roles so a compromised mailbox cannot complete a transaction path on its own.
Key takeaways
- Cybercrime losses are climbing because fraud models increasingly exploit identity trust, not just technical compromise paths.
- Investment fraud and BEC account for much of the pressure in the article, and AI is expected to make those attacks harder to contain.
- The practical response is to move verification into the workflow, especially where email can trigger money movement or account change.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Workflow abuse here depends on trust and authority being granted too loosely. |
| GV.OC-01 — Organizational Context | The article shows fraud risk sitting inside business processes, not only security tooling. | |
| Recommendation — Review approval paths under PR.AA-05 so identity claims do not automatically become execution authority. Align fraud and identity controls to the business processes that move money or change account data. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | BEC impact grows when a mailbox or user can trigger too much authority in one workflow. |
| Recommendation — Apply AC-6 to restrict who can approve, execute, and override sensitive email-driven actions. | ||
| CIS Controls v8 | CIS-5 — Account Management | Compromised or abused accounts are the operating point for BEC-driven fraud. |
| Recommendation — Strengthen account governance so identity misuse is detected before it reaches finance workflows. | ||
| MITRE ATT&CK | TA0006 — Credential Access | The fraud pattern often begins with abused credentials or trusted mailbox access. |
| Recommendation — Map suspicious mailbox abuse to TA0006 and hunt for account takeover indicators around payment workflows. | ||
Key terms
- Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
- Identity trust: The set of assumptions an environment makes about how a user, device, or service proves who it is. When those assumptions are weak, attackers can enter through valid authentication instead of breaking infrastructure, which turns identity into the primary attack surface.
- Delegated Authority Model: A delegated authority model defines who is allowed to approve, review, or execute control-related decisions across the enterprise. It helps ensure requests reach the correct responsible party, especially when control owners, managers, and process owners sit in different teams, regions, or systems.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org