Payment fraud statistics are quoted everywhere, and the mistake most people make is treating numbers from different sources as if they measured the same thing. They do not. A dollar figure from the FBI counts reported US losses in one year; a percentage from a treasury survey counts how many companies were targeted, not how much they lost; a figure from a global fraud study measures something different again; and a headline like $40 billion is a projection of where losses are heading, not a count of money already gone. Each is useful once you read it for what it is. The FBI recorded $20.9 billion in total reported cybercrime losses in 2025, including $3.046 billion in business email compromise1; the Association for Financial Professionals found 76 percent of organizations faced attempted or actual payments fraud2; and the ACFE estimates the typical organization loses about 5 percent of revenue to fraud each year3. This guide collects the 2026 payment-fraud statistics that matter, labels each one by what it actually measures, separates the measured numbers from the projected ones, and ends on the single fact every dataset agrees on.
The measured scale: what the FBI actually counted in 2025
Start with the most solid numbers, because they count only crime that was actually reported. In its 2025 Internet Crime Report, the FBI recorded $20.877 billion in total losses across 1,008,597 complaints, a 26 percent increase over the prior year1. Within that, business email compromise accounted for $3.046 billion across 24,768 complaints, and 86 percent of the money stolen through BEC moved by wire or ACH. The FBI also recorded more than $893 million in losses across complaints with an artificial-intelligence nexus, the first time AI has been broken out at that scale. These are the numbers to trust most and inflate least: they describe reported losses, in one country, in one year, to one agency.
The honest caveat is that every one of these is a floor, not a ceiling. Payment fraud is heavily underreported, because a business that loses money to a spoofed vendor rarely files a public complaint, and many losses are absorbed quietly or run through insurance. So the measured total understates the real number by an unknown margin. That cuts against the instinct to treat a big reported figure as the whole problem; it is the visible part of a larger one. When a much larger figure appears elsewhere, the first question is always whether it is a count like this or a projection, because the two are not comparable and should never be added together.
What businesses actually face: the AFP 2026 survey
The FBI counts dollars; a treasury survey counts companies, and the distinction matters. The 2026 AFP Payments Fraud and Control Survey, conducted in January 2026 among 465 treasury practitioners, found that 76 percent of organizations experienced attempted or actual payments fraud in 20252, with business email compromise the most common method, affecting roughly 74 percent of those surveyed. On the payment methods themselves, paper checks remained the most-targeted at 58 percent, followed by ACH debits at 30 percent and wire transfers at 25 percent. Notably, only 17 percent of organizations reported using AI to help fight payments fraud, a gap between the tools attackers are adopting and the tools defenders have deployed.
Read this set for what it is: a measure of how widely fraud is attempted, not how much is lost. A 76 percent figure tells you exposure is nearly universal among mid-size and larger organizations, which is a different and complementary fact from the FBI dollar total. It also corrects a common misread of the headlines: checks, not wires, are still the single most-targeted instrument, even as the largest individual losses run through wire and ACH. Both things are true at once, because the method that is attacked most often is not the same as the method that loses the most per incident. A statistic about frequency and a statistic about severity answer different questions, and a serious read keeps them apart.
The internal side: what the ACFE measures globally
The FBI and AFP numbers describe fraud committed against organizations, largely by outsiders. The ACFE measures a different thing: occupational fraud, committed by the people inside. Its 2026 Report to the Nations, built on 2,402 real cases across 143 countries, estimates that the typical organization loses about 5 percent of its annual revenue to fraud3, with a median loss of $104,000 per case and an average above $1.4 million. Crucially for smaller businesses, organizations with fewer than 100 employees suffered the highest median loss of any size band, at $126,000, because they cannot separate the person who sets up a vendor from the one who approves the payment. Tips remain the single most common way these schemes are caught, and many run for a year or more before anyone notices.
Two honest qualifiers travel with these numbers. First, the 5-percent-of-revenue figure is a long-standing ACFE estimate, not a hard measured total like the FBI dollar count, so it belongs in the projection-adjacent category: a reasoned extrapolation, useful for scale, not a receipt. Second, this is global data, not US-specific, so it should not be blended with the US-only IC3 figures. What it adds to the picture is the reminder that not all payment fraud comes from outside: the same weak control, one person owning too much of the payment process, is what both an external impersonator and an internal fraudster exploit, which is why a verification step that is independent of any single employee addresses both at once.
The AI and deepfake numbers: measured, projected, and a single case
No area mixes the three kinds of number more than AI-enabled fraud, and keeping them straight is the whole discipline. The measured figure is the FBI’s: more than $893 million in losses across AI-nexus complaints in 2025. The projected figure is Deloitte’s: its Center for Financial Services projects US generative-AI fraud losses reaching $40 billion by 2027, from $12.3 billion in 20234, a 32 percent compound annual growth rate framed across adoption scenarios. And the single case is Arup, the engineering firm that lost about $25 million in one deepfake-video incident in 2024. Three numbers, three entirely different kinds of evidence: a count, a forecast, and an anecdote.
The disciplined way to use them is together but never interchangeably. The $893 million says AI is now a named, measured factor. The $40 billion says the trajectory is steep, as a model, not a fact about last year, and it should never be stacked on the measured total or quoted as money already stolen. The Arup $25 million proves the attack is real and can reach eight figures in a single event, but one landmark case is evidence that it works, not a measure of how often it happens. The companion guide on deepfake fraud statistics works through exactly this distinction in depth. If a source cites the $40 billion without noting it is a 2027 projection, that is a small signal to read the rest of its numbers carefully.
The instant-rail dimension: speed makes the losses final
One more number set explains why the trend is toward larger, faster losses: the rails themselves. In the United Kingdom, where reporting on authorized push payment fraud is more mature, UK Finance reported £450.7 million lost to APP fraud across 185,733 cases in 2024, with about 70 percent of cases starting online5. Authorized push payment fraud is the category where the victim is deceived into sending the money themselves, so it passes every control built to catch an intruder, and on an instant rail it settles in seconds with no reversal. The US instant rails, RTP and FedNow, are earlier in their adoption curve, which is precisely why building the verification habit now, before instant volume is dominant, matters.
This is the through-line connecting the datasets to a trend rather than a snapshot: as settlement gets faster and more final, the window to catch a fraudulent payment after it leaves shrinks toward zero. The FBI’s own recovery figures make the point from the other side, as the guide on wire fraud recovery details: clawback works only sometimes, and only when a loss is reported fast enough. Read alongside the rising totals, the finality numbers argue that the leverage is moving decisively from recovery after the fact to verification before settlement, because after settlement, on the rails the money increasingly travels, there is nothing left to reverse.
How to read any payment-fraud statistic honestly
Pulling it together, here is the short framework this whole guide applies, usable on any number you encounter. First, ask what kind it is: a measured count, a survey share, or a projection. A measured count of reported losses is a floor. A survey share tells you how common an attempt is, not how much was lost. A projection describes a modelled direction, not money gone. Second, ask about the denominator and scope: US or global, dollars or percentage of companies, one year or a multi-year forecast. Third, resist stacking: numbers from different sources measuring different things cannot be added, and a projection must never be piled on top of a measured total. Fourth, treat a single dramatic case as proof the attack works, not as evidence of its frequency.
Applied to the 2026 figures, that framework keeps the story straight. Measured US dollars: $20.9 billion total, $3.046 billion BEC. Measured company exposure: 76 percent hit, checks most-targeted. Global estimate: about 5 percent of revenue. Projected: $40 billion in US gen-AI fraud by 2027. One case: Arup at $25 million. None of these contradicts another once each is read for what it is, and the payment fraud by industry breakdown applies the same discipline to who gets hit hardest. The point of reading honestly is not to shrink the problem, which is genuinely large, but to know exactly what you know, which is what lets you choose a defense on evidence rather than on whichever figure is most alarming.
The one number that does not change
Underneath every statistic in this guide is a single event that all of them are counting in different ways: an authorized payment sent to a payee that was switched, spoofed, or impersonated. The FBI’s BEC billions, the AFP’s 76 percent, the deepfake case, the APP losses, even much of the internal ACFE data all describe money that moved because a real, authorized person released it to the wrong account. That is why these losses clear the controls built to stop intruders: there is no intruder, only a legitimate user acting on a convincing lie. And it is why the defense that addresses all of them is the same regardless of which number rises fastest, verifying the payee and the approval before the payment settles.
This is where RankShield Financial fits, and the honest framing matters after a guide about reading numbers honestly. It is a verification and attestation layer in the payment authorization path, not a bank, a fraud score, or a custodian of funds, and it never touches the money. What it does is verify the payee and a named approval and seal a checkable record before a payment settles, which acts on the exact event every one of these statistics is counting. The boundaries stay explicit: it verifies the payee and the approval and proves the decision, it does not catch every scam, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of your payments, you can see how it works or request access. The statistics will keep climbing; the event they describe, and the point at which you can still stop it, will not.
