Cyberattacks in 2019 Cost over $3.5 Billion in Victim Losses with Business Email Compromise Taking in Half

Stu Sjouwerman | Feb 14, 2020

Security concept Lock on digital screen, illustration-7The FBI’s annual year-in-review breaks down how 467,000 cyber attacks succeeded in taking consumers and businesses alike for billions of dollars.

The data provided by the FBI each year gives us an unfiltered glimpse into which kinds of attacks were most prevalent, how successful they were, and what was the damage. In their 2019 Internet Crime Report, the latest data provides some insight of where cybercriminals believe “the money is” and, thus, engage in the more lucrative attack types.

According to the report:

  • Business Email Compromise (BEC) only represented 5% of all attacks, but netted nearly $1.8 Billion in losses
  • Phishing/Vishing/Smishing/Pharming was the number one crime, representing 24% of all attacks
  • Spoofing attacks netted over $300 Million in losses
  • Of the top 20 crime types (based on total victim loss amount), 17 involved some form of social engineering

It’s evident from this data that email is the medium of choice, providing cybercriminals an unlimited opportunity to scam consumers and businesses using simple to sophisticated social engineering tactics.

The BEC number is staggering and should be seen as a very large flashing red warning light for every organization. The average scam took about $75,000 – and, while that may not be particularly newsworthy, it’s a material amount of money for most organizations.

User access to email must be done within the context of security; organizations need to educate users with Security Awareness Training so the user work with a sense of vigilance, always interacting with email with a security mindset, lowering the organization’s risk of a successful phishing attack.

Get Your CEO Fraud Prevention Manual

CEO-Fraud-Prevention-Manual-WP-FannedCEO fraud has ruined the careers of many executives and loyal employees, causing over $26 billion in losses. Don’t be the next victim. This manual provides a thorough overview of how executives are compromised, how to prevent such an attack and what to do if you become a victim.

Get Your Manual

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.