alt
Mor Cohen-Tal September 18, 2026

U.S. States Where Businesses Are Most Exposed to Cybercrimes

Post image

A cyberattack against a business can reach well beyond the company that was initially targeted. A fraudulent payment can divert hundreds of thousands of dollars, ransomware can bring operations to a halt, and a data breach can expose information belonging to customers, employees, or business partners. The effects can also ripple through supply chains and other organizations that depend on the victim.

As businesses have become more reliant on digital systems to manage payments, communications, customer information, and day-to-day operations, cybersecurity has increasingly become a question of financial and operational resilience, not simply an IT concern.

That risk has moved higher on Washington’s agenda. In March 2026, the White House issued Executive Order 14390, calling for stronger financial and digital defenses against cybercrime and a more coordinated effort to disrupt transnational cybercriminal networks. Congress has also turned its attention to whether smaller companies have the resources to protect themselves, advancing the Small Business Cybersecurity Assistance Evaluation Act of 2026 and reinforcing a broader concern that cyberattacks can pose a greater risk to the economy than previously.

To assess where those risks are most concentrated, Opstream analyzed FBI Internet Crime Complaint Center records covering business email compromises, data breaches, ransomware, and intellectual property-related offenses. The findings show wide differences across states in both reported incidents and financial losses, offering a view into where businesses appear most exposed to some of the most costly forms of cybercrime.

Mor Cohen-Tal, Co-Founder and CTO, Opstream
By Mor Cohen-Tal, Co-Founder & CTO, Opstream
Previously Cloud CTO at Turbonomic (acq. IBM for nearly $2B). Holds 13 patents in cloud and AI infrastructure.
View LinkedIn profile →

Key Findings

Business email compromise (BEC) dominates both the frequency and financial cost of business cybercrime. Nearly 25,000 reported BEC victims accounted for more than $3 billion in losses in 2025.
Reported business cybercrime surged in 2025 after years of relative stability. Incidents increased 18% to 34,728, while reported losses topped $3.5 billion, up 74% from 2020.
California has the most corporate cybercrime victims, but Alaska has the highest concentration relative to its business population. California recorded 4,725 victims, while Alaska led on a relative basis at 47.3 victims per 10,000 businesses.
Western states are disproportionately represented among states with high rates of reported corporate cybercrime. Alaska, Arizona, Washington, Nevada, Colorado, Wyoming, and Utah all rank in the top 15 after accounting for the size of their business populations.

Which Types of Cybercrime Cause the Most Damage to U.S. Businesses?

Business email compromise (BEC) accounts for over $3 billion in corporate losses, far outpacing data breaches, ransomware, and IP theft combined

Business email compromise accounts for over 3 billion in corporate losses, far outpacing data breaches, ransomware, and IP theft combined

Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream

Business email compromise (BEC) was both the most prevalent and by far the most costly major cybercrime affecting U.S. businesses in 2025. A staggering 24,768 BEC incidents were reported nationwide, resulting in just over $3 billion in losses. These email scams account for nearly nine out of every 10 dollars lost to cybercrimes perpetrated against U.S. businesses when analyzed with business data breaches, ransomware, and intellectual property-related offenses. By comparison, data breaches resulted in about $435 million in losses, while reported losses associated with ransomware and intellectual property offenses were considerably smaller.

BEC can be so costly because the fraud often resembles an ordinary business transaction. A criminal might pose as a familiar vendor and email an employee about a legitimate-looking invoice but provide new banking instructions that send the payment to an account controlled by the scammer. In one FBI-documented case, criminals researched companies and posed as trusted vendors in emails instructing employees where to send payments. Two companies ultimately wired more than $120 million to fraudulent bank accounts. Other BEC schemes use similar tactics, including emails that appear to come from company executives or business partners requesting urgent payments or changes to payment instructions.

The other major threats work differently. A business data breach occurs when an intruder obtains confidential or protected information from corporate systems, while ransomware restricts access to systems or data and typically demands payment for their release. Intellectual property offenses target assets such as trade secrets, proprietary products, software, and copyrighted material. The number of reported incidents also varies sharply among these categories: BEC alone accounted for the large majority of incidents in 2025, while data breaches, ransomware, and intellectual property offenses made up a much smaller share. Importantly, these totals represent only incidents reported to the FBI. Cybercrimes that businesses discover but never report fall outside the figures entirely, meaning the tens of thousands of incidents and billions of dollars in losses documented each year represent only the known portion of a larger problem.

Opstream

Building Security Into the Procurement Process

Because many cyberattacks exploit routine purchasing and payment processes, businesses can benefit from greater visibility and control over how requests, approvals, and purchases move through the organization. A procurement orchestration platform can help centralize intake, standardize workflows, and provide greater oversight of enterprise spend activity.

How Much Are U.S. Businesses Losing to Cybercrime?

The reported number of corporate victims surged 18% in 2025 to nearly 35,000 while total losses exceeded $3.5 billion

Reported US business cybercrime victims surged 18 percent in 2025 to nearly 35,000 while total losses exceeded 3.5 billion

Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream

The financial burden of cybercrime on U.S. businesses has increased substantially since 2020, even though the number of reported incidents remained relatively stable for much of that period. Annual incidents hovered between roughly 28,800 and 29,500 from 2020 through 2024, before departing sharply from that pattern in 2025. Reported incidents increased 18% to nearly 34,700, the highest level in six years.

Financial losses had been rising well before the recent increase in reported incidents. Businesses lost about $2.0 billion in 2020, rising to $2.6 billion in 2021, $3.2 billion in 2022, and nearly $3.5 billion in 2023. Losses declined modestly to about $3.2 billion in 2024 before returning to roughly $3.5 billion in 2025. Overall, annual reported losses were 74% higher in 2025 than in 2020, despite relatively little change in the number of incidents during most of those years. The divergence suggests that the financial consequences of individual cybercrimes have become more severe over time.

Several changes in how businesses operate and how cybercriminals target them may be contributing to the rising financial toll. Companies now depend heavily on digital payments, cloud-based systems, and online communications for routine transactions, creating more opportunities for criminals to intercept payments, compromise business accounts, or disrupt operations. Those risks are evolving as well. The FBI has warned that criminals are using generative AI to create more convincing messages and impersonations, making fraud more difficult to recognize. As these tactics become more sophisticated, even a single successful attack can expose a business to substantial financial losses.

Opstream

Keeping a Closer Eye on Vendor Relationships

Third-party vendors can introduce additional security and financial risks, particularly when businesses regularly exchange sensitive information or make payments to outside partners. Vendor management software can help organizations centralize vendor information, streamline onboarding, and maintain better visibility into their supplier relationships.

Where Corporate Victims of Cybercrime Are Concentrated the Most

California leads the nation in overall corporate victims of cybercrime while Alaska reports the highest density

California leads the nation in overall corporate cybercrime victims while Alaska reports the highest concentration per 10,000 businesses

Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream

The states with the most corporate cybercrime victims tend to be among the nation’s largest business centers. California recorded 4,725 reported victims in 2025, more than any other state, followed by Texas with 3,027, Florida with 2,687, and New York with 2,322. Together, those four states accounted for more than one-third of reported victims nationwide. Their prominence is largely a reflection of scale, since each is home to a large number of businesses and, consequently, a larger pool of potential targets.

Adjusting for the number of businesses changes the geographic picture considerably. Alaska had the nation’s highest concentration, with 47.3 reported victims per 10,000 businesses, followed by Arizona at 36.9, Washington at 36.1, Texas at 35.3, and Nevada at 34.9. Western states are especially prominent near the top of the ranking, with Colorado, Wyoming, and Utah also reporting relatively high rates. This puts much of the West above the national average for reported corporate cybercrime exposure, even though the largest numbers of victims remain concentrated in the country’s biggest state economies.

Unlike burglary or other crimes that require proximity to a victim, cybercriminals can target a company from virtually anywhere, making the location of the attacker less important than the characteristics of the businesses being targeted. Business email compromise, which accounts for the majority of reported corporate cybercrime victims, is particularly illustrative. These schemes target businesses of all sizes and often exploit routine relationships with executives, vendors, and suppliers to redirect payments. As a result, a state does not need a large technology or financial sector to record substantial exposure. Businesses that regularly transfer money, rely heavily on email and other digital communications, or work with outside vendors can be targeted regardless of where they are headquartered. As companies become more dependent on third parties, evaluating and monitoring vendor risk has also become an important part of managing their broader security exposure.

Full Results

Methodology

About This Analysis

The cybercrime data used in this analysis is from the FBI Internet Crime Complaint Center’s (IC3) 2025 Internet Crime Report, with historical national figures drawn from IC3 reports dating back to 2020. Business-related cybercrime was defined to include business email compromise (BEC), data breaches, ransomware, and intellectual property rights/copyright and counterfeit offenses. Victim counts represent the total number of reported incidents across these categories and do not necessarily represent unique businesses, as the same organization may experience or report multiple cybercrimes during the year.

To determine the states where businesses are most exposed to cybercrime, researchers at Opstream calculated the number of reported corporate cybercrime victims per 10,000 businesses in each state. States were ranked according to this rate, with the state reporting the higher total number of corporate victims ranked higher in the event of a tie. Victim location corresponds to the headquarters of the affected business.

The FBI’s IC3 statistics include only cybercrimes reported to the agency, meaning unreported incidents are not reflected in the results. Additionally, the FBI’s ransomware figures are not limited exclusively to businesses and may include other types of victims. Ransomware was included because businesses and critical infrastructure organizations are primary targets of these attacks and can face significant financial and operational consequences when their systems are compromised.

See How Opstream Strengthens Procurement Controls

Reduce financial risk by centralizing intake, automating approvals, and gaining full visibility into every purchase before payment is made.

Book a Demo

About the Author

Mor Cohen-Tal
Mor Cohen-Tal
Co-Founder and CTO, Opstream

Mor Cohen-Tal is a visionary technology leader and the Co-Founder and Chief Technology Officer of Opstream, an intelligent procurement orchestration platform that is transforming the way companies buy. With a career marked by a relentless pursuit of innovation, Mor has earned 13 patents for her groundbreaking work. Notably, Mor was the Cloud CTO at Turbonomic, where she spearheaded the company’s successful transition from a datacenter-focused business to a cloud-centric model. Turbonomic was acquired by IBM for nearly $2B in 2021. As a leading thought leader in cloud and AI, Mor plays a critical role in cultivating partnerships with leading cloud providers such as AWS and Microsoft Azure, and has presented and keynoted at conferences around the world, including Microsoft Ignite and AWS re:Invent.

Connect on LinkedIn →

Want to see how it works?

Book a demo with our team or reach out at support@opstream.ai