Business email compromise (BEC) never needed malware, a breached network, or a single line of code to succeed. It needs one thing: a payment approver who believes the request in front of them is real. That’s exactly why the numbers below should matter to anyone in finance or operations with wire transfer authority, not just to IT.
In 2025 alone, BEC cost businesses $3.04 billion in reported losses, according to the FBI’s Internet Crime Complaint Center (IC3), up from $2.77 billion the year before. Eighty-six percent of that money left through wire transfer or ACH, the fastest and hardest-to-reverse payment rails a company has. And the attacks generating those losses are no longer the broken-English, obviously-fake emails your team learned to spot years ago.
What increasing AI usage means
Security firm VIPRE’s Email Threat Trends research found that 40% of detected BEC emails are now AI-generated, with some created entirely by AI from prompt to send. AI is being used to write phishing lures that mimic the tone, structure, and internal shorthand of legitimate executive and vendor communications, at scale, in the recipient’s own language and context. The same report found BEC now accounts for 49% of all detected spam and flagged a 74% year-over-year jump in malicious URLs feeding these campaigns.
The IC3’s own 2025 data adds a pointed detail: businesses reported more than $30 million in losses specifically tied to AI-enabled BEC schemes, a category that barely existed in official reporting a few years ago.
Here’s the practical business email compromise 2026 reality this creates: the training most finance teams received was built to catch typos, mismatched sender domains, and stiff, formal phrasing. Those cues are disappearing. An AI-generated request from “your CFO” or “your vendor’s AP department” can now match the real thing in tone, formatting, and even reference specific project names or invoice numbers pulled from a prior breach or a scraped email thread. If your verification process still depends on an employee’s ability to notice something feels off, you are relying on a control that AI is specifically designed to defeat.
Why Wire Transfer Fraud Verification Has to Change
The IC3’s decade-of-data figure is worth sitting with $55.5 billion in BEC losses reported between October 2013 and December 2023, most of it moved through a small handful of payment methods and laundered through intermediary accounts in a predictable set of countries before recovery became impossible. The pattern hasn’t changed. What’s changed is how convincing attackers can now trigger that first transfer.
This means BEC fraud prevention can no longer live entirely in employee judgment. It has to live in process, specifically, in a verification step that happens the same way, every time, regardless of how urgent or legitimate the request sounds. That’s what a callback verification protocol is for.
A Callback Verification Protocol You Can Implement This Week
This isn’t a technology purchase. It’s a five-step procedure your finance and AP teams can adopt immediately, before any larger security investment.
- Treat every payment change or new-payee request as unverified by default. Any email, message, or call asking to change bank details, redirect a payment, or approve a new or urgent wire should be treated as unconfirmed until independently verified, no matter who it appears to be from or how much internal detail it includes.
- Call back using a number you already have on file, never one provided in the request. Pull the phone number from your vendor management system, your internal directory, or the company’s official website, not from the email signature, the letterhead, or a number texted to you moments before. This single rule defeats the majority of callback bypass attempts, since attackers routinely provide a “confirmation number” that simply rings back to them.
- Have someone other than the original recipient make the call. Segregating duties between the person who received the request and the person who verifies it removes the social pressure and urgency the attacker built into the original message. A second set of eyes, working from a different starting point, is far harder to manipulate.
- Verify the details, don’t just confirm them. Ask the person on the other end of the callback to state the banking information and amount themselves, and compare it against source documentation, rather than reading the numbers aloud and asking “does this sound right?” Attackers can confirm details they already planted; they can’t produce ones they don’t have.
- Require dual authorization above a defined dollar threshold.No single employee, regardless of seniority or how convincing the request, should be able to unilaterally approve a large wire. A second, independently reached approver is the backstop for every case where steps one through four still get talked around.
Set this protocol in writing, apply it without exceptions for “urgent” requests, and revisit the dollar thresholds annually. Manual callbacks do have real limits, they take time, they don’t scale cleanly across thousands of vendors, and a rushed or poorly trained callback can still be talked past. That’s precisely why this protocol is the immediate fix, not the complete one.
The Scalable Fix: Training That Keeps Up With the Threat
A written callback protocol stops individual transactions. It doesn’t change how your organization recognizes the next AI-generated lure, the next spoofed executive request, or the next vendor impersonation that doesn’t hit your AP team at all but lands somewhere else in the business. That takes an ongoing awareness program, not a one-time policy memo.
CyberClan’s Cybersecurity Awareness, Education, and Training program is built around exactly this gap. It runs on a continuous Evaluate-Communicate-Fortify-Measure cycle: assessing how your finance and operations staff actually respond to social engineering attempts, delivering targeted training on the specific tactics showing up in BEC campaigns today (including AI-generated lures and deepfake-enabled requests), closing the gaps that testing reveals, and tracking measurable improvement over time. It’s paired with realistic phishing simulations that show exactly where your organization’s risk is concentrated, and tabletop exercises that walk your finance team through a live wire-fraud attempt before a real one happens.
A callback protocol protects the transaction in front of you. Ongoing awareness training protects every transaction after it, and adjusts as attackers do.
Ready to see how your finance and operations team would perform against today’s AI-generated BEC tactics? Talk to CyberClan about building a wire transfer fraud verification and awareness program designed for 2026, not 2023.


