TL;DR: The FBI’s 2025 IC3 report recorded $20.877 billion in cybercrime losses, with 85% tied to cyber-enabled fraud and $893 million linked to AI-related complaints, underscoring how AI is amplifying impersonation, BEC, and persistent fraud campaigns, according to Abnormal AI’s analysis of the report. Identity and access programmes now have to treat behavioural trust, not just technical compromise, as the primary control surface.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “$893M in Losses: What the 2025 IC3 Report Reveals About AI-Driven Cybercrime”.
By the numbers:
- The FBI’s 2025 IC3 report recorded $20.877 billion in cybercrime losses, a 26% year-over-year increase.
- The report linked $893 million in losses to 22,364 AI-related complaints in 2025.
- Business Email Compromise drove $3.046 billion in losses in 2025.
Key questions
Q: How should security teams respond when AI makes business email compromise harder to spot?
A: Teams should move beyond message inspection and verify the requester, the channel, and the business context before allowing action.
Q: What breaks when organisations only rely on static phishing detection?
A: They miss live proxy attacks that deliver the real website content through attacker infrastructure.
Q: Why do impersonation attacks remain effective even when users are trained on phishing?
A: Training helps, but AI improves the quality of the impersonation itself.
Practitioner guidance
- Model behavioural trust signals Baseline normal communication patterns, approval routes, and vendor interaction histories so deviations are visible before the request is fulfilled.
- Harden executive request workflows Require out-of-band verification for high-risk requests that arrive through email, chat, or voice and match sensitive finance or access changes.
- Instrument finance and payroll exceptions Treat wire transfers, bank detail changes, and urgent vendor requests as governed identity events with extra validation and logging.
Bottom line: AI is making established fraud tactics more effective by improving impersonation quality, timing, and persistence.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Behavioural trust is now a core identity control surface: The FBI’s IC3 data shows that the dominant loss mode is not technical compromise but successful manipulation of human decision-making. That means identity programmes must treat communication patterns, workflow context, and approval behaviour as part of governance, not as soft signals. The practitioners who still anchor control design in content inspection alone are looking at the wrong layer.
A question worth separating out:
Q: How can IAM teams tell whether fraud controls are actually working?
A: Look for fewer unverified high-risk requests, better challenge rates on abnormal approvals, and stronger separation between routine identity events and exceptional transactions. If users still complete sensitive actions based only on message urgency or apparent authority, the control is not working.
👉 Read our full editorial: AI-enabled fraud is reshaping cybercrime losses and identity trust