Tips & Insights

Small Business Cybersecurity Statistics: 2025 FBI Data

Contracting company owner at a cluttered back-office desk on the phone with his bank, looking at a laptop surrounded by invoices and a hard hat

Small business cybersecurity is mostly a fraud problem, not a hacking one, and the federal statistics show it. U.S. consumers and businesses filed 1,008,597 cybercrime complaints with the FBI's Internet Crime Complaint Center in 2025, reporting $20.877 billion in losses — a 26% rise on 2024 and the first year above $20 billion. The average reported loss was $20,699.

1,008,597
Cybercrime complaints filed with the FBI IC3 in 2025
FBI IC3 2025 Report
$20.877B
Total reported losses in 2025, up 26% on 2024
FBI IC3 2025 Report
$20,699
Average reported loss per complaint
FBI IC3 2025 Report
24,768
Business email compromise complaints in 2025
FBI IC3 2025 Report
$3.05B
Reported BEC losses, the second-largest category
FBI IC3 2025 Report
18%
Share of non-critical-sector ransomware reports from legal services
FBI IC3 2025 Report

How much does cybercrime cost U.S. businesses and consumers?

In 2025 the FBI's Internet Crime Complaint Center (IC3) received 1,008,597 complaints reporting $20.877 billion in losses, up 26% on the previous year. The average reported loss across all complaint types was $20,699, which for most small businesses is somewhere between a bad month and an existential one.

The losses are concentrated in fraud rather than in hacking. Cyber-enabled fraud accounted for 452,868 complaints and $17.697 billion in losses in 2025, which is 45% of all complaints but 85% of all losses. Investment fraud was the largest single category at $8.65 billion, followed by business email compromise at $3.05 billion and tech support scams at $2.13 billion.

One caveat belongs on every one of these figures: IC3 counts only what is reported to it. Businesses that quietly absorb a loss, handle it through insurance, or report to a local FBI field office instead never enter this dataset. The real totals are higher by an unknown margin.

Which cyber attacks actually hit small businesses?

Business email compromise is the one that empties a small business bank account. The FBI logged 24,768 BEC complaints in 2025 with reported losses of $3,046,598,558, the second-largest loss category of any crime type. It does not require anyone to break into your systems, which is exactly why it works against companies with no IT department.

The mechanism is mundane. An attacker either spoofs or gains access to a real email account in a chain you already trust, waits for a genuine invoice or closing to come up, and sends revised payment instructions. Nothing looks stolen, because nothing was. The money simply goes to a different account than intended. Phishing and spoofing were also the single largest category by complaint count in 2025, at 191,561 complaints, and phishing is usually the door BEC walks through.

Ransomware looks smaller in the data than it is. IC3 recorded 3,611 ransomware complaints in 2025 with just over $32.3 million in reported losses, but the FBI states plainly in the same report that this figure does not normally include lost business, time, wages, files or equipment, or third-party remediation services, which it says creates an artificially low overall ransomware loss rate. Read the complaint count, not the dollar figure.

Which small-business industries report the most ransomware?

Outside the 16 federally designated critical infrastructure sectors, the FBI received more than 1,400 ransomware complaints from businesses and organizations in 2025. These are ordinary small and mid-sized firms, and the industry breakdown is not the one most people expect: legal services at 18%, contracting services at 17%, engineering and architectural services at 10%, consulting services at 7%, and non-critical manufacturing at 5%.

Law firms, electricians, general contractors, land surveyors and marketing consultancies are not high-technology targets. What they share is a set of characteristics attackers like: client files that are useless to anyone else but indispensable to the owner, project and payment schedules that make downtime expensive by the day, little or no dedicated IT staff, and a strong incentive to resolve the problem quietly and fast.

If your business is in one of those categories, the practical takeaway is that you are in the reported population, not adjacent to it. Offline, immutable backups and multi-factor authentication on email and remote access are the two measures the FBI's own recommendations put first, and neither requires an IT department to implement.

What to do in the first hours after a fraudulent transfer

Speed decides whether the money comes back. The FBI's Recovery Asset Team, which works with banks to freeze fraudulent transfers, handled 3,574 domestic incidents in 2025 and froze $507,042,623. That process only starts when a victim reports quickly. Call your bank immediately and ask for a recall on the transfer, then file the complaint at ic3.gov with the account details.

Freezing is not the same as recovery, and the odds are far from certain. Across the 655 incidents reported by critical infrastructure organizations in 2025, the team froze $146,561,094 of $261,451,001 in reported losses, a 56% success rate among cases that reached it at all. That is a good outcome relative to doing nothing and a poor one relative to not having sent the money.

Then there is the part nobody plans for: even a well-handled incident leaves a hole in your cash position. Frozen funds take time to come back, forensic and legal help is not cheap, and payroll does not wait for either. This is what an emergency fund is for, and where working capital can bridge the gap if the reserve is not deep enough. The Broker Shop is a funding broker, not a funder: one 2-minute application goes to the funders in our network of 50+ whose guidelines your business meets, so you can compare real structures rather than take the first offer that arrives during a bad week. It is free to apply, and checking your options won't affect your credit score.

Frequently Asked Questions

How much do businesses lose to business email compromise?
The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025 with reported losses of $3,046,598,558, making it the second-largest loss category after investment fraud. BEC usually works by spoofing or compromising a real email account and changing the payment instructions on an invoice the business already expected to pay.
Can a cyber incident affect my ability to get business funding?
It can, indirectly. Most revenue-based funders read your recent bank statements, so a sudden drop in deposits, a run of negative days or an unexplained large transfer changes how an application reads. Being able to explain the gap in writing helps. Because The Broker Shop is a broker rather than a funder, one application shows which lenders' guidelines your business currently meets.

See what you qualify for

One 2-minute application is matched to the funders whose guidelines you meet. It's free, and checking your options won't affect your credit score.

See What I Qualify For →

The bottom line: Business email compromise, not hacking, is what costs U.S. businesses the most, and the small-business industries reporting the most ransomware are law firms and contractors rather than tech companies.

Source: Federal Bureau of Investigation — 2025 Internet Crime Complaint Center (IC3) Annual Report

Cite this research

Found these figures useful? You are welcome to cite or link to this page. Suggested attribution: “Small Business Cybersecurity Statistics: 2025 FBI Data”, The Broker Shop — thebrokershopinc.com/small-business-cybersecurity-statistics.html. Every figure links to its original primary source.