This week, the Associated Press and PBS FRONTLINE published a major investigation into online scams in the U.S. It's long, and it's worth your time. Here's the short version, and what we think it means for your business.
The numbers are worse than you think
Americans reported a record $15.9 billion in scam losses to the Federal Trade Commission last year, a jump of more than $3 billion, over 25%, in a single year. The FTC believes the true figure is many times higher, because most victims are too embarrassed to report. Its estimate for 2024 was close to $200 billion, roughly $550 million a day.
In a companion AP-NORC poll, 98% of Americans said they believe they've been targeted by scammers. About three in ten said they've already lost money or personal information.
Businesses are squarely in the crosshairs. The FBI's Internet Crime Complaint Center logged more than $20 billion in reported losses in 2025, the most in its history. Business email compromise, in which a criminal impersonates an executive, vendor, or partner to redirect a payment, accounted for more than $3 billion of that, second only to investment fraud. For the first time, the FBI also tracked AI-related complaints as a category of their own: more than 22,000 of them, with nearly $900 million in losses.
This is not something that only happens to the naive. The reporters interviewed 58 victims between the ages of 32 and 90 who lost anywhere from a few thousand dollars to $4 million each. Among them were doctors, IT professionals, and academics with advanced degrees.
Why do smart people fall for it? Because scams are no longer a stranger with a misspelled email. They're an industry. AI writes flawless, personalized messages and clones voices in seconds. Cryptocurrency moves the money somewhere it can't be traced. Overseas scam compounds work thousands of victims at a time with scripts refined over years.
The part nobody warns you about
The most sobering finding in the investigation isn't the losses. It's what happens after.
Of the 58 victims, exactly one got any money back, and that came from a legal settlement with her bank, not from the criminals. For everyone else, the losses kept coming:
- The tax bill. Retirees who drained tax-deferred accounts still owed income tax on the withdrawals, and under a 2017 tax-law change, personal losses from many common scams can no longer be deducted. One retired nurse lost more than $200,000, then received an $80,000 bill from the IRS.
- The bank. Under U.S. law, banks are rarely liable when you authorize a transfer yourself, even if you were deceived into it, and business accounts generally have fewer protections than consumer accounts to begin with. Some victims had their accounts frozen or closed instead of getting help.
- The silence. Many victims filed police and FBI reports and never heard back. The FBI's online complaint portal receives nearly 3,000 reports a day.
- The second scam. Desperate victims are then targeted by fake "recovery services" claiming special access to the FBI or Secret Service, for a fee. One woman paid $23,000 to three such companies. None of them were real.
Erin West, a former prosecutor who founded the victim-support nonprofit Operation Shamrock, put it plainly to the AP: "What happens after the scam might even be worse than the scam itself."
Other countries are moving. The U.K., Australia, and Singapore now require banks and other companies to reimburse certain scam victims or face penalties. The U.S. does not. Congress is considering more than a dozen bills, but for now there is no safety net.
The conclusion is hard to avoid. For the overwhelming majority of victims, stolen money is never recovered, and no bank, agency, or statute now in place is positioned to return it. That leaves prevention as the only defense that reliably works.
What actually protects your business
None of this requires technical skill. It requires attention and diligence.
- Treat urgency as the red flag. Every scam manufactures pressure: the invoice that has to be paid before five o'clock, the executive who needs gift cards for a client "right now," the vendor whose bank account "just changed." Legitimate business doesn't run on panic. The feeling of being rushed is the alarm.
- Verify on a channel you control. Any request to send money, change payment details, or share credentials gets confirmed by phone, at a number you already have on file, never one supplied in the message. An email from a vendor with new account information, even one that looks perfect, is the setup for one of the costliest business scams in existence.
- Know the payment tells. No bank, government agency, or legitimate vendor will ask you to move money to a "safe account," or to pay with gift cards, cryptocurrency, or an urgent wire to an account you've never paid before. That request alone ends the conversation.
- Lock down email first. Your email account is the master key to your business, because it's where password resets go and where customers and vendors believe your voice comes from. A criminal who controls it can reset every other password you have, impersonate you to the people who trust you, and even walk off with your domain name. Give it a long, unique password (Bitwarden's free password generator will make one in seconds, and a password manager will remember it), then do the same for your domain registrar, banking, and payment-processor accounts.
- Turn on two-factor authentication today. Not next quarter. Today. It is the single most effective security measure available to you, and it's free. A Microsoft Research study of millions of accounts found that two-factor authentication cut the risk of compromise by more than 99%, and by more than 98% even for accounts whose passwords had already leaked. Enable it on every account that offers it, starting with email, and use an authenticator app or passkey rather than text-message codes wherever you can.
- Keep your website maintained. Neglected sites get hijacked to host phishing pages and malware aimed at your own customers, and Google flags your domain when it happens. Current software, valid TLS/SSL, strong hosting credentials, and someone actually watching the site all matter. (This is a large part of what we do for our clients, and it's the least glamorous, most important part of the job.)
- Make "slow down and verify" company policy. Most breaches start with one person acting on one email. A five-minute conversation with your team, repeated now and then, is the highest-return security investment you'll ever make.
We've laid out the complete set of steps, in priority order, in our Cybersecurity Essentials Checklist. If you haven't worked through it yet, this week is a good time.
If it has already happened
Call your bank immediately and file a report at IC3.gov. The first hours matter most: when a fraudulent wire is reported quickly, the FBI's Recovery Asset Team works with banks to try to freeze the funds before they move. Report it to the FTC at ReportFraud.ftc.gov as well, even if you don't expect a response, because reports are how patterns get identified and operations get shut down. Change any credentials that may have been exposed, and tell whoever manages your website and email so they can watch for follow-on attacks. And ignore anyone who contacts you offering to recover your money for a fee. That is the second scam.
One more thing
The FRONTLINE documentary from this investigation, Scammed, premieres on PBS on September 29. Watch it, and share it with your team. It will do more to make the risk real than any memo.
And if you'd like a second set of eyes on the security of your website, email, or domain setup, get in touch. It's a conversation we're always glad to have.
Sources
- Associated Press and FRONTLINE, "Scams in the US are at a record high. Yet most victims get no help and some end up losing even more" (September 2, 2026)
- Associated Press, AP-NORC poll on Americans' experiences with scams (2026)
- Federal Trade Commission, testimony before the Joint Economic Committee on the rising scam economy (March 25, 2026)
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report (PDF)
- Microsoft Research, "How effective is multifactor authentication at deterring cyberattacks?" (2023)
- Operation Shamrock
- Bitwarden Password Generator
- Risingline, Cybersecurity Essentials Checklist