How Generative AI Is Supercharging Business Email Compromise Attacks
According to Forbes, citing the FBI's Internet Crime Complaint Center's most recent Annual Report, businesses hemorrhaged more than $3 billion to Business Email Compromise scams in 2025 — a $250…

According to Forbes, citing the FBI's Internet Crime Complaint Center's most recent Annual Report, businesses hemorrhaged more than $3 billion to Business Email Compromise scams in 2025 — a $250 million jump year over year, and the steepest toll since the FBI began tracking the scheme back in 2013.
The con itself is almost embarrassingly old-school. A finance lead gets an email that looks like it's from the CEO, the general counsel, or a long-time vendor. Wire this amount, today, to this account. No malware, no zero-days — just psychology. What changes the math now is what AI does to that psychology.
What AI puts on the table
The early iterations were easy to spot. Awkward phrasing, weird formatting, the kind of grammar any sharp-eyed employee could flag before clicking reply. As Forbes recounts, scammers responded by hijacking the actual inbox of an executive so their messages carried the real voice of the company. Generative AI compresses that whole arc into minutes.
Large language models can scrape a company website, scan LinkedIn profiles, and parse months of inbox traffic to learn how a CFO actually phrases a payment approval. They draft the message in that voice. They fix the grammar. And — the part that should keep a founder up at night — they generate the deepfake video and the voice-cloned phone call that confirm the wire with eerie confidence.
Barbara Corcoran, the Shark Tank personality, has described losing $388,700 in 2020 after a fake email chain, supposedly sent by her assistant, instructed her bookkeeper to release a real-estate payment. That was the pre-AI version. The post-AI version is the same play with a perfect mask.
The price tag, and what it actually buys
The $3.046 billion in 2025 losses reported to IC3 isn't a one-off spike. The FBI has watched the number climb every single year for more than a decade. That trajectory matters more than the headline figure: each improvement in generative tools gives scammers a cheaper way to scale research, personalization, and impersonation simultaneously.
For a founder sitting across from their CFO, the trade-off has shifted. The old control — "spot the typo, catch the impersonator" — is eroding fast. The new control has to assume the message looks right, sounds right, and arrives on a channel the company already trusts.
What to actually watch
A few friction points worth building into the payment workflow before the next attempt lands:
- Out-of-band confirmation on any wire that changes destination, beneficiary, or amount. A phone call to a number already on file — never one inside the email itself.
- A second human approver who wasn't on the original thread, so the social pressure of a "quick" request has somewhere to dissipate.
- Delay-by-default on first-time vendor payments, giving verification a window outside the urgent tone the scam depends on.
The scammers aren't hacking the network. They're hacking the urgency. AI just handed them a much better pen.