# Payment Fraud Statistics 2026: What the Numbers Show | RankShield Financial

> Payment fraud statistics for 2026 from the FBI, AFP, and ACFE, read honestly: what was measured, what was projected, and the one number that does not change.
>
> Source: https://rankshieldfinancial.com/resources/payment-fraud-statistics-2026/ · RankShield Financial (verifiable pre-settlement payment security)

RankShield Network · Financial · Payment Fraud
# Payment Fraud Statistics 2026: The Numbers, Read Honestly

The payment-fraud figures people quote come from different sources measuring different things: US dollars lost, the share of companies hit, a global percentage of revenue, a forecast. Read each for what it is, and one number underneath all of them does not change.
   By  Jamie Kloncz  Founder, RankShield Financial    August 18, 2026 · 12 min read               Key takeaways
- The headline payment-fraud numbers come from different sources measuring different things: US dollars lost (FBI IC3), the share of companies targeted (AFP), a global percentage of revenue (ACFE), and a forecast (Deloitte). Quoting them interchangeably is the most common error.
- Measured, US dollars: the FBI recorded $20.9 billion in total 2025 cybercrime losses, with business email compromise at $3.046 billion across 24,768 complaints and 86 percent of that money moving by wire or ACH. Because it counts only reported crime, it is a floor.
- Measured, companies hit: the AFP 2026 survey found 76 percent of organizations faced attempted or actual payments fraud in 2025, with checks the most-targeted method at 58 percent. A share of companies is not a dollar total, and both are worth knowing.
- Projected, not counted: Deloitte projects US generative-AI fraud losses reaching $40 billion by 2027 from $12.3 billion in 2023. That is a scenario model of a direction, and it should never be quoted as money already lost or stacked on the measured figures.
- Every dataset, measured or projected, describes the same underlying event: an authorized payment sent to a payee that was switched or impersonated. That is the one number that does not change, and it is what verifying a payment before it settles is built to stop.

Payment fraud statistics are quoted everywhere, and the mistake most people make is treating numbers from different sources as if they measured the same thing. They do not. A dollar figure from the FBI counts reported US losses in one year; a percentage from a treasury survey counts how many companies were targeted, not how much they lost; a figure from a global fraud study measures something different again; and a headline like $40 billion is a projection of where losses are heading, not a count of money already gone. Each is useful once you read it for what it is. The FBI recorded $20.9 billion in total reported cybercrime losses in 2025, including $3.046 billion in business email compromise 1 ; the Association for Financial Professionals found 76 percent of organizations faced attempted or actual payments fraud 2 ; and the ACFE estimates the typical organization loses about 5 percent of revenue to fraud each year 3 . This guide collects the 2026 payment-fraud statistics that matter, labels each one by what it actually measures, separates the measured numbers from the projected ones, and ends on the single fact every dataset agrees on.

## The measured scale: what the FBI actually counted in 2025

Start with the most solid numbers, because they count only crime that was actually reported. In its 2025 Internet Crime Report, the FBI recorded $20.877 billion in total losses across 1,008,597 complaints, a 26 percent increase over the prior year 1 . Within that, business email compromise accounted for $3.046 billion across 24,768 complaints, and 86 percent of the money stolen through BEC moved by wire or ACH. The FBI also recorded more than $893 million in losses across complaints with an artificial-intelligence nexus, the first time AI has been broken out at that scale. These are the numbers to trust most and inflate least: they describe reported losses, in one country, in one year, to one agency.

The honest caveat is that every one of these is a floor, not a ceiling. Payment fraud is heavily underreported, because a business that loses money to a spoofed vendor rarely files a public complaint, and many losses are absorbed quietly or run through insurance. So the measured total understates the real number by an unknown margin. That cuts against the instinct to treat a big reported figure as the whole problem; it is the visible part of a larger one. When a much larger figure appears elsewhere, the first question is always whether it is a count like this or a projection, because the two are not comparable and should never be added together.

## What businesses actually face: the AFP 2026 survey

The FBI counts dollars; a treasury survey counts companies, and the distinction matters. The 2026 AFP Payments Fraud and Control Survey, conducted in January 2026 among 465 treasury practitioners, found that 76 percent of organizations experienced attempted or actual payments fraud in 2025 2 , with business email compromise the most common method, affecting roughly 74 percent of those surveyed. On the payment methods themselves, paper checks remained the most-targeted at 58 percent, followed by ACH debits at 30 percent and wire transfers at 25 percent. Notably, only 17 percent of organizations reported using AI to help fight payments fraud, a gap between the tools attackers are adopting and the tools defenders have deployed.

Read this set for what it is: a measure of how widely fraud is attempted, not how much is lost. A 76 percent figure tells you exposure is nearly universal among mid-size and larger organizations, which is a different and complementary fact from the FBI dollar total. It also corrects a common misread of the headlines: checks, not wires, are still the single most-targeted instrument, even as the largest individual losses run through wire and ACH. Both things are true at once, because the method that is attacked most often is not the same as the method that loses the most per incident. A statistic about frequency and a statistic about severity answer different questions, and a serious read keeps them apart.

## The internal side: what the ACFE measures globally

The FBI and AFP numbers describe fraud committed against organizations, largely by outsiders. The ACFE measures a different thing: occupational fraud, committed by the people inside. Its 2026 Report to the Nations, built on 2,402 real cases across 143 countries, estimates that the typical organization loses about 5 percent of its annual revenue to fraud 3 , with a median loss of $104,000 per case and an average above $1.4 million. Crucially for smaller businesses, organizations with fewer than 100 employees suffered the highest median loss of any size band, at $126,000, because they cannot separate the person who sets up a vendor from the one who approves the payment. Tips remain the single most common way these schemes are caught, and many run for a year or more before anyone notices.

Two honest qualifiers travel with these numbers. First, the 5-percent-of-revenue figure is a long-standing ACFE estimate, not a hard measured total like the FBI dollar count, so it belongs in the projection-adjacent category: a reasoned extrapolation, useful for scale, not a receipt. Second, this is global data, not US-specific, so it should not be blended with the US-only IC3 figures. What it adds to the picture is the reminder that not all payment fraud comes from outside: the same weak control, one person owning too much of the payment process, is what both an external impersonator and an internal fraudster exploit, which is why a verification step that is independent of any single employee addresses both at once.

## The AI and deepfake numbers: measured, projected, and a single case

No area mixes the three kinds of number more than AI-enabled fraud, and keeping them straight is the whole discipline. The measured figure is the FBI’s: more than $893 million in losses across AI-nexus complaints in 2025. The projected figure is Deloitte’s: its Center for Financial Services projects US generative-AI fraud losses reaching $40 billion by 2027, from $12.3 billion in 2023 4 , a 32 percent compound annual growth rate framed across adoption scenarios. And the single case is Arup, the engineering firm that lost about $25 million in one deepfake-video incident in 2024. Three numbers, three entirely different kinds of evidence: a count, a forecast, and an anecdote.

The disciplined way to use them is together but never interchangeably. The $893 million says AI is now a named, measured factor. The $40 billion says the trajectory is steep, as a model, not a fact about last year, and it should never be stacked on the measured total or quoted as money already stolen. The Arup $25 million proves the attack is real and can reach eight figures in a single event, but one landmark case is evidence that it works, not a measure of how often it happens. The companion guide on [deepfake fraud statistics](https://rankshieldfinancial.com/resources/deepfake-fraud-statistics-2026/) works through exactly this distinction in depth. If a source cites the $40 billion without noting it is a 2027 projection, that is a small signal to read the rest of its numbers carefully.

## The instant-rail dimension: speed makes the losses final

One more number set explains why the trend is toward larger, faster losses: the rails themselves. In the United Kingdom, where reporting on authorized push payment fraud is more mature, UK Finance reported £450.7 million lost to APP fraud across 185,733 cases in 2024, with about 70 percent of cases starting online 5 . Authorized push payment fraud is the category where the victim is deceived into sending the money themselves, so it passes every control built to catch an intruder, and on an instant rail it settles in seconds with no reversal. The US instant rails, RTP and FedNow, are earlier in their adoption curve, which is precisely why building the verification habit now, before instant volume is dominant, matters.

This is the through-line connecting the datasets to a trend rather than a snapshot: as settlement gets faster and more final, the window to catch a fraudulent payment after it leaves shrinks toward zero. The FBI’s own recovery figures make the point from the other side, as the guide on [wire fraud recovery](https://rankshieldfinancial.com/resources/wire-fraud-recovery-first-72-hours/) details: clawback works only sometimes, and only when a loss is reported fast enough. Read alongside the rising totals, the finality numbers argue that the leverage is moving decisively from recovery after the fact to verification before settlement, because after settlement, on the rails the money increasingly travels, there is nothing left to reverse.

## How to read any payment-fraud statistic honestly

Pulling it together, here is the short framework this whole guide applies, usable on any number you encounter. First, ask what kind it is: a measured count, a survey share, or a projection. A measured count of reported losses is a floor. A survey share tells you how common an attempt is, not how much was lost. A projection describes a modelled direction, not money gone. Second, ask about the denominator and scope: US or global, dollars or percentage of companies, one year or a multi-year forecast. Third, resist stacking: numbers from different sources measuring different things cannot be added, and a projection must never be piled on top of a measured total. Fourth, treat a single dramatic case as proof the attack works, not as evidence of its frequency.

Applied to the 2026 figures, that framework keeps the story straight. Measured US dollars: $20.9 billion total, $3.046 billion BEC. Measured company exposure: 76 percent hit, checks most-targeted. Global estimate: about 5 percent of revenue. Projected: $40 billion in US gen-AI fraud by 2027. One case: Arup at $25 million. None of these contradicts another once each is read for what it is, and the [payment fraud by industry](https://rankshieldfinancial.com/resources/payment-fraud-by-industry-data/) breakdown applies the same discipline to who gets hit hardest. The point of reading honestly is not to shrink the problem, which is genuinely large, but to know exactly what you know, which is what lets you choose a defense on evidence rather than on whichever figure is most alarming.

## The one number that does not change

Underneath every statistic in this guide is a single event that all of them are counting in different ways: an authorized payment sent to a payee that was switched, spoofed, or impersonated. The FBI’s BEC billions, the AFP’s 76 percent, the deepfake case, the APP losses, even much of the internal ACFE data all describe money that moved because a real, authorized person released it to the wrong account. That is why these losses clear the controls built to stop intruders: there is no intruder, only a legitimate user acting on a convincing lie. And it is why the defense that addresses all of them is the same regardless of which number rises fastest, verifying the payee and the approval before the payment settles.

This is where RankShield Financial fits, and the honest framing matters after a guide about reading numbers honestly. It is a verification and attestation layer in the payment authorization path, not a bank, a fraud score, or a custodian of funds, and it never touches the money. What it does is verify the payee and a named approval and seal a checkable record before a payment settles, which acts on the exact event every one of these statistics is counting. The boundaries stay explicit: it verifies the payee and the approval and proves the decision, it does not catch every scam, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of your payments, you can [see how it works](https://rankshieldfinancial.com/how-it-works/) or [request access](https://rankshieldfinancial.com/contact/). The statistics will keep climbing; the event they describe, and the point at which you can still stop it, will not.
        Operate it
## Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.
      Pay to     Amount (USD)     Conditions around this payment      Bank details changed by email       First-time payee       Amount over approval policy       Approver signature verifies       PRE-SETTLEMENT VERDICT  RANKSHIELD NETWORK
Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call
        Downloadable · SVG
The 2026 payment-fraud figures come from four different measurements: the FBI counts reported US dollars lost ($20.9B total, $3.046B BEC), the AFP counts the share of companies hit (76%), the ACFE estimates a global percentage of revenue (~5%), and Deloitte projects a 2027 forecast ($40B). Read each for what it is, and the one event underneath all of them is an authorized payment to a switched payee.
      FAQ
## Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.
           JAMIE KLONCZ · RANKSHIELD FINANCIAL           ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
      REQUEST ACCESS →           Self-check
## How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

- 01 Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
- 02 Can one person both change a vendor’s bank details and approve the payment?
- 03 Do you always confirm a bank-detail change on a number from your own files, not the request?
- 04 Is the first payment to a new or changed payee held for verification before it goes out?
- 05 Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5
        References
- [FBI IC3, 2025 Internet Crime Report ($20.877B total; BEC $3.046B / 24,768 complaints / 86% wire or ACH; $893M+ AI-nexus)](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
- [Association for Financial Professionals, 2026 AFP Payments Fraud and Control Survey (76% hit; BEC most common; checks 58%, ACH debits 30%, wire 25%; 17% use AI)](https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud)
- [ACFE, Occupational Fraud 2026: A Report to the Nations (2,402 cases / 143 countries; ~5% of revenue; median $104K; under-100-employee orgs $126K, highest)](https://www.acfe.com/fraud-resources/report-to-the-nations)
- [Deloitte Center for Financial Services, Generative AI and fraud in banking (US gen-AI fraud projected to reach $40B by 2027, from $12.3B in 2023)](https://www.deloitte.com/us/en/insights/industry/financial-services/deepfake-banking-fraud-risk-on-the-rise.html)
- [UK Finance, 2025 Annual Fraud Report (APP fraud £450.7M across 185,733 cases in 2024; ~70% of cases started online)](https://www.ukfinance.org.uk/news-and-insight/press-release/fraud-report-2025-press-release)

         About the author
## [Jamie Kloncz](https://rankshieldfinancial.com/about/) Founder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

- Primary sources only: each figure links to the original filing
- Honest boundaries: what verification can and cannot do is stated plainly
- Last verified August 18, 2026

  How RankShield Financial verifies →  Request access →            Verify, then settle
## See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.
  Request access  How it works

## Frequently asked questions

### What are the key payment fraud statistics for 2026?

The most-cited measured figures come from the FBI’s 2025 Internet Crime Report: $20.877 billion in total reported US cybercrime losses across more than a million complaints, including $3.046 billion in business email compromise, with 86 percent of BEC money moving by wire or ACH, plus more than $893 million in AI-nexus losses. The 2026 AFP Payments Fraud survey adds that 76 percent of organizations faced attempted or actual payments fraud in 2025, with checks the most-targeted method at 58 percent. The ACFE estimates the typical organization loses about 5 percent of revenue to fraud globally. These measure different things, US dollars lost, share of companies hit, and a global revenue estimate, so they should be quoted separately, not combined.

### Is business email compromise still the biggest payment fraud threat?

By reported dollars among payment-specific scams, yes. The FBI put business email compromise at $3.046 billion in 2025, one of the largest single loss categories, and the AFP survey found BEC was the most common fraud method reported by organizations, affecting roughly 74 percent of respondents. The nuance is that the most-targeted payment instrument is still the paper check, at 58 percent in the AFP data, even though the largest per-incident losses travel by wire and ACH. Frequency and severity are different measures: checks are attacked most often, while BEC-driven wire and ACH fraud loses the most money per event. Both facts belong in an honest summary.

### Is the $40 billion AI fraud statistic real?

It is a real projection, but it is a projection, not a count. Deloitte’s Center for Financial Services projects that generative AI could push US fraud losses to about $40 billion by 2027, from $12.3 billion in 2023, a compound annual growth rate near 32 percent, framed across adoption scenarios. It is useful for understanding trajectory and for planning, but it should never be quoted as money already lost, and it should not be stacked on top of the FBI’s measured figures as if the two were additive. The disciplined way to use it is as a modelled direction paired with the measured FBI number, which was more than $893 million in AI-nexus losses in 2025, as the current floor.

### Why do payment fraud statistics vary so much between sources?

Because they measure different things. The FBI counts reported dollar losses in the US in one year, which is a floor because most fraud goes unreported. The AFP surveys treasury teams and reports the share of organizations that were targeted, which measures how common attempts are, not how much was lost. The ACFE studies occupational fraud globally and estimates losses as a percentage of revenue. Deloitte publishes a multi-year projection. A dollar total, a percentage of companies, a percentage of revenue, and a forecast are four different kinds of number, so they naturally differ, and the mistake is treating them as interchangeable or adding them together. Read each for its scope, its denominator, and whether it is measured or projected.

### What do all the payment fraud statistics have in common?

They describe the same underlying event: an authorized payment released to a payee that was switched, spoofed, or impersonated. Business email compromise, vendor impersonation, deepfake executive requests, and most authorized push payment fraud all work by getting a legitimate, authorized person to send real money to the wrong account, which is why they defeat controls built to catch intruders. This is also why the defense does not need to be re-chosen every time a number rises: verifying the payee and the approval before a payment settles acts on the one event every statistic is counting. Recovery after the fact works only sometimes and only on rails that still allow it, so as settlement gets faster and more final, the leverage moves to verification before the money moves.
