A cyberattack against a business can reach well beyond the company that was initially targeted. A fraudulent payment can divert hundreds of thousands of dollars, ransomware can bring operations to a halt, and a data breach can expose information belonging to customers, employees, or business partners. The effects can also ripple through supply chains and other organizations that depend on the victim.
As businesses have become more reliant on digital systems to manage payments, communications, customer information, and day-to-day operations, cybersecurity has increasingly become a question of financial and operational resilience, not simply an IT concern.
That risk has moved higher on Washington’s agenda. In March 2026, the White House issued Executive Order 14390, calling for stronger financial and digital defenses against cybercrime and a more coordinated effort to disrupt transnational cybercriminal networks. Congress has also turned its attention to whether smaller companies have the resources to protect themselves, advancing the Small Business Cybersecurity Assistance Evaluation Act of 2026 and reinforcing a broader concern that cyberattacks can pose a greater risk to the economy than previously.
To assess where those risks are most concentrated, Opstream analyzed FBI Internet Crime Complaint Center records covering business email compromises, data breaches, ransomware, and intellectual property-related offenses. The findings show wide differences across states in both reported incidents and financial losses, offering a view into where businesses appear most exposed to some of the most costly forms of cybercrime.
Key Findings
Business email compromise (BEC) accounts for over $3 billion in corporate losses, far outpacing data breaches, ransomware, and IP theft combined
Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream
Business email compromise (BEC) was both the most prevalent and by far the most costly major cybercrime affecting U.S. businesses in 2025. A staggering 24,768 BEC incidents were reported nationwide, resulting in just over $3 billion in losses. These email scams account for nearly nine out of every 10 dollars lost to cybercrimes perpetrated against U.S. businesses when analyzed with business data breaches, ransomware, and intellectual property-related offenses. By comparison, data breaches resulted in about $435 million in losses, while reported losses associated with ransomware and intellectual property offenses were considerably smaller.
BEC can be so costly because the fraud often resembles an ordinary business transaction. A criminal might pose as a familiar vendor and email an employee about a legitimate-looking invoice but provide new banking instructions that send the payment to an account controlled by the scammer. In one FBI-documented case, criminals researched companies and posed as trusted vendors in emails instructing employees where to send payments. Two companies ultimately wired more than $120 million to fraudulent bank accounts. Other BEC schemes use similar tactics, including emails that appear to come from company executives or business partners requesting urgent payments or changes to payment instructions.
The other major threats work differently. A business data breach occurs when an intruder obtains confidential or protected information from corporate systems, while ransomware restricts access to systems or data and typically demands payment for their release. Intellectual property offenses target assets such as trade secrets, proprietary products, software, and copyrighted material. The number of reported incidents also varies sharply among these categories: BEC alone accounted for the large majority of incidents in 2025, while data breaches, ransomware, and intellectual property offenses made up a much smaller share. Importantly, these totals represent only incidents reported to the FBI. Cybercrimes that businesses discover but never report fall outside the figures entirely, meaning the tens of thousands of incidents and billions of dollars in losses documented each year represent only the known portion of a larger problem.
Opstream
Building Security Into the Procurement Process
Because many cyberattacks exploit routine purchasing and payment processes, businesses can benefit from greater visibility and control over how requests, approvals, and purchases move through the organization. A procurement orchestration platform can help centralize intake, standardize workflows, and provide greater oversight of enterprise spend activity.
The reported number of corporate victims surged 18% in 2025 to nearly 35,000 while total losses exceeded $3.5 billion
Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream
The financial burden of cybercrime on U.S. businesses has increased substantially since 2020, even though the number of reported incidents remained relatively stable for much of that period. Annual incidents hovered between roughly 28,800 and 29,500 from 2020 through 2024, before departing sharply from that pattern in 2025. Reported incidents increased 18% to nearly 34,700, the highest level in six years.
Financial losses had been rising well before the recent increase in reported incidents. Businesses lost about $2.0 billion in 2020, rising to $2.6 billion in 2021, $3.2 billion in 2022, and nearly $3.5 billion in 2023. Losses declined modestly to about $3.2 billion in 2024 before returning to roughly $3.5 billion in 2025. Overall, annual reported losses were 74% higher in 2025 than in 2020, despite relatively little change in the number of incidents during most of those years. The divergence suggests that the financial consequences of individual cybercrimes have become more severe over time.
Several changes in how businesses operate and how cybercriminals target them may be contributing to the rising financial toll. Companies now depend heavily on digital payments, cloud-based systems, and online communications for routine transactions, creating more opportunities for criminals to intercept payments, compromise business accounts, or disrupt operations. Those risks are evolving as well. The FBI has warned that criminals are using generative AI to create more convincing messages and impersonations, making fraud more difficult to recognize. As these tactics become more sophisticated, even a single successful attack can expose a business to substantial financial losses.
Opstream
Keeping a Closer Eye on Vendor Relationships
Third-party vendors can introduce additional security and financial risks, particularly when businesses regularly exchange sensitive information or make payments to outside partners. Vendor management software can help organizations centralize vendor information, streamline onboarding, and maintain better visibility into their supplier relationships.
California leads the nation in overall corporate victims of cybercrime while Alaska reports the highest density
Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream
The states with the most corporate cybercrime victims tend to be among the nation’s largest business centers. California recorded 4,725 reported victims in 2025, more than any other state, followed by Texas with 3,027, Florida with 2,687, and New York with 2,322. Together, those four states accounted for more than one-third of reported victims nationwide. Their prominence is largely a reflection of scale, since each is home to a large number of businesses and, consequently, a larger pool of potential targets.
Adjusting for the number of businesses changes the geographic picture considerably. Alaska had the nation’s highest concentration, with 47.3 reported victims per 10,000 businesses, followed by Arizona at 36.9, Washington at 36.1, Texas at 35.3, and Nevada at 34.9. Western states are especially prominent near the top of the ranking, with Colorado, Wyoming, and Utah also reporting relatively high rates. This puts much of the West above the national average for reported corporate cybercrime exposure, even though the largest numbers of victims remain concentrated in the country’s biggest state economies.
Unlike burglary or other crimes that require proximity to a victim, cybercriminals can target a company from virtually anywhere, making the location of the attacker less important than the characteristics of the businesses being targeted. Business email compromise, which accounts for the majority of reported corporate cybercrime victims, is particularly illustrative. These schemes target businesses of all sizes and often exploit routine relationships with executives, vendors, and suppliers to redirect payments. As a result, a state does not need a large technology or financial sector to record substantial exposure. Businesses that regularly transfer money, rely heavily on email and other digital communications, or work with outside vendors can be targeted regardless of where they are headquartered. As companies become more dependent on third parties, evaluating and monitoring vendor risk has also become an important part of managing their broader security exposure.
About This Analysis
The cybercrime data used in this analysis is from the FBI Internet Crime Complaint Center’s (IC3) 2025 Internet Crime Report, with historical national figures drawn from IC3 reports dating back to 2020. Business-related cybercrime was defined to include business email compromise (BEC), data breaches, ransomware, and intellectual property rights/copyright and counterfeit offenses. Victim counts represent the total number of reported incidents across these categories and do not necessarily represent unique businesses, as the same organization may experience or report multiple cybercrimes during the year.
To determine the states where businesses are most exposed to cybercrime, researchers at Opstream calculated the number of reported corporate cybercrime victims per 10,000 businesses in each state. States were ranked according to this rate, with the state reporting the higher total number of corporate victims ranked higher in the event of a tie. Victim location corresponds to the headquarters of the affected business.
The FBI’s IC3 statistics include only cybercrimes reported to the agency, meaning unreported incidents are not reflected in the results. Additionally, the FBI’s ransomware figures are not limited exclusively to businesses and may include other types of victims. Ransomware was included because businesses and critical infrastructure organizations are primary targets of these attacks and can face significant financial and operational consequences when their systems are compromised.
Reduce financial risk by centralizing intake, automating approvals, and gaining full visibility into every purchase before payment is made.
Book a Demo