How AI-Powered BEC Scams Are Stealing Billions
· investing
How AI-Powered Business Email Compromise Scams Are Stealing Billions
The Business Email Compromise (BEC) scam has been a persistent threat to businesses for over a decade, with losses reaching $3.046 billion in 2025 alone. According to the FBI’s Internet Crime Complaint Center (IC3), this represents a significant increase of $250 million compared to the previous year.
The BEC scam relies on social engineering tactics to trick employees into transferring funds to scammers posing as company executives or trusted vendors. While this may seem straightforward, the level of sophistication and personalization has increased exponentially due to AI-powered tools. Scammers now use AI-generated voice cloning and deepfakes to craft highly convincing emails, text messages, and even video meetings that can fool even vigilant employees.
One notable case involved Barbara Corcoran’s company being scammed out of $388,700 in 2020 through a fake email chain sent to her bookkeeper. The scam was so convincing it went unnoticed until after the funds had been transferred. This incident highlights the level of research and planning that goes into these scams, with scammers often infiltrating email accounts and gathering information from company websites and social media profiles.
The use of AI in BEC scams has made it increasingly challenging for companies to defend themselves. Scammers can create highly personalized attacks tailored to each company’s specific protocols and language, making it difficult for employees to distinguish between legitimate and fake communications. As FBI Special Agent Robert Tripp noted, “As technology continues to evolve, so do cybercriminals’ tactics.”
A recent example of this trend came in 2025 when an employee at the British engineering company Arup received a spear phishing email from what appeared to be their CFO. The scam was convincing enough to include a deepfake video meeting with AI-generated voice cloning. Incidents like these underscore the need for companies to take proactive measures to protect themselves against these types of attacks.
To defend against BEC scams, companies must implement strong security policies that require independent verification of wire transfers, callback verification using secure phone numbers, dual authorization for large payments, employee training on deepfakes and voice cloning, and the use of a code word for executive payment requests. These measures address the root cause of these scams: human vulnerabilities.
In an era where technology is rapidly advancing and becoming increasingly intertwined with our daily lives, it’s essential to recognize both the benefits and risks associated with AI-powered advancements. While AI has the potential to revolutionize numerous industries, its misuse can have devastating consequences for individuals and companies alike. The BEC scam serves as a stark reminder of this reality and highlights the need for greater awareness and cooperation between businesses, law enforcement agencies, and technology providers to combat these threats.
The success of these scams hinges on human psychology rather than technical expertise. As long as there are vulnerabilities in employee behavior and company protocols, scammers will continue to exploit them using AI-powered tools. It’s imperative that companies take proactive steps to educate their employees about these risks and implement robust security measures to prevent such attacks from succeeding.
Ultimately, it’s not just about updating cybersecurity software or investing in AI-powered detection systems; it’s about acknowledging the darker side of technological advancements and taking concrete actions to mitigate them. As we continue to push the boundaries of what is possible with technology, we must also remain vigilant against its misuse.
Reader Views
- LVLin V. · long-term investor
The AI-powered BEC scam is a perfect storm of sophistication and deceit, where scammers use social engineering and machine learning to infiltrate even the most secure networks. What's striking about these scams is their ability to adapt and evolve in real-time, making traditional security measures almost obsolete. Companies need to rethink their cybersecurity strategies to account for this new threat landscape.
- TLThe Ledger Desk · editorial
The BEC scam's AI-powered evolution is a ticking time bomb for companies without robust cybersecurity measures in place. While the article highlights the staggering financial losses, it glosses over the long-term consequences of these scams: compromised employee trust and systemic vulnerabilities that leave organizations exposed to future attacks. As companies continue to invest in AI-driven security solutions, they must also prioritize training their employees on identifying subtle phishing tactics and implementing zero-trust policies to prevent insider threats from arising.
- MFMorgan F. · financial advisor
The BEC scam's reliance on AI-powered tactics has turned what was once a straightforward financial heist into a sophisticated and personalized attack on corporate security. What's striking is how these scams are not just about duping employees, but also exploiting their faith in company protocols. In many cases, scammers infiltrate email accounts to gather intel, which they then use to craft convincing messages that blend seamlessly with internal communications. Companies must start thinking of their own systems as potential vulnerabilities, and take proactive steps to limit the damage – including segmenting sensitive data and imposing stricter controls on employee access.