Request access
RankShield Network · Financial · Payment Fraud

Payment Fraud Statistics 2026: The Numbers, Read Honestly

The payment-fraud figures people quote come from different sources measuring different things: US dollars lost, the share of companies hit, a global percentage of revenue, a forecast. Read each for what it is, and one number underneath all of them does not change.

Three brushed-steel instrument gauges on a dark console, one ringed with a teal indicator, representing payment fraud figures read as measured, instrument-grade data.
Key takeaways
  • The headline payment-fraud numbers come from different sources measuring different things: US dollars lost (FBI IC3), the share of companies targeted (AFP), a global percentage of revenue (ACFE), and a forecast (Deloitte). Quoting them interchangeably is the most common error.
  • Measured, US dollars: the FBI recorded $20.9 billion in total 2025 cybercrime losses, with business email compromise at $3.046 billion across 24,768 complaints and 86 percent of that money moving by wire or ACH. Because it counts only reported crime, it is a floor.
  • Measured, companies hit: the AFP 2026 survey found 76 percent of organizations faced attempted or actual payments fraud in 2025, with checks the most-targeted method at 58 percent. A share of companies is not a dollar total, and both are worth knowing.
  • Projected, not counted: Deloitte projects US generative-AI fraud losses reaching $40 billion by 2027 from $12.3 billion in 2023. That is a scenario model of a direction, and it should never be quoted as money already lost or stacked on the measured figures.
  • Every dataset, measured or projected, describes the same underlying event: an authorized payment sent to a payee that was switched or impersonated. That is the one number that does not change, and it is what verifying a payment before it settles is built to stop.

Payment fraud statistics are quoted everywhere, and the mistake most people make is treating numbers from different sources as if they measured the same thing. They do not. A dollar figure from the FBI counts reported US losses in one year; a percentage from a treasury survey counts how many companies were targeted, not how much they lost; a figure from a global fraud study measures something different again; and a headline like $40 billion is a projection of where losses are heading, not a count of money already gone. Each is useful once you read it for what it is. The FBI recorded $20.9 billion in total reported cybercrime losses in 2025, including $3.046 billion in business email compromise1; the Association for Financial Professionals found 76 percent of organizations faced attempted or actual payments fraud2; and the ACFE estimates the typical organization loses about 5 percent of revenue to fraud each year3. This guide collects the 2026 payment-fraud statistics that matter, labels each one by what it actually measures, separates the measured numbers from the projected ones, and ends on the single fact every dataset agrees on.

The measured scale: what the FBI actually counted in 2025

Start with the most solid numbers, because they count only crime that was actually reported. In its 2025 Internet Crime Report, the FBI recorded $20.877 billion in total losses across 1,008,597 complaints, a 26 percent increase over the prior year1. Within that, business email compromise accounted for $3.046 billion across 24,768 complaints, and 86 percent of the money stolen through BEC moved by wire or ACH. The FBI also recorded more than $893 million in losses across complaints with an artificial-intelligence nexus, the first time AI has been broken out at that scale. These are the numbers to trust most and inflate least: they describe reported losses, in one country, in one year, to one agency.

The honest caveat is that every one of these is a floor, not a ceiling. Payment fraud is heavily underreported, because a business that loses money to a spoofed vendor rarely files a public complaint, and many losses are absorbed quietly or run through insurance. So the measured total understates the real number by an unknown margin. That cuts against the instinct to treat a big reported figure as the whole problem; it is the visible part of a larger one. When a much larger figure appears elsewhere, the first question is always whether it is a count like this or a projection, because the two are not comparable and should never be added together.

What businesses actually face: the AFP 2026 survey

The FBI counts dollars; a treasury survey counts companies, and the distinction matters. The 2026 AFP Payments Fraud and Control Survey, conducted in January 2026 among 465 treasury practitioners, found that 76 percent of organizations experienced attempted or actual payments fraud in 20252, with business email compromise the most common method, affecting roughly 74 percent of those surveyed. On the payment methods themselves, paper checks remained the most-targeted at 58 percent, followed by ACH debits at 30 percent and wire transfers at 25 percent. Notably, only 17 percent of organizations reported using AI to help fight payments fraud, a gap between the tools attackers are adopting and the tools defenders have deployed.

Read this set for what it is: a measure of how widely fraud is attempted, not how much is lost. A 76 percent figure tells you exposure is nearly universal among mid-size and larger organizations, which is a different and complementary fact from the FBI dollar total. It also corrects a common misread of the headlines: checks, not wires, are still the single most-targeted instrument, even as the largest individual losses run through wire and ACH. Both things are true at once, because the method that is attacked most often is not the same as the method that loses the most per incident. A statistic about frequency and a statistic about severity answer different questions, and a serious read keeps them apart.

The internal side: what the ACFE measures globally

The FBI and AFP numbers describe fraud committed against organizations, largely by outsiders. The ACFE measures a different thing: occupational fraud, committed by the people inside. Its 2026 Report to the Nations, built on 2,402 real cases across 143 countries, estimates that the typical organization loses about 5 percent of its annual revenue to fraud3, with a median loss of $104,000 per case and an average above $1.4 million. Crucially for smaller businesses, organizations with fewer than 100 employees suffered the highest median loss of any size band, at $126,000, because they cannot separate the person who sets up a vendor from the one who approves the payment. Tips remain the single most common way these schemes are caught, and many run for a year or more before anyone notices.

Two honest qualifiers travel with these numbers. First, the 5-percent-of-revenue figure is a long-standing ACFE estimate, not a hard measured total like the FBI dollar count, so it belongs in the projection-adjacent category: a reasoned extrapolation, useful for scale, not a receipt. Second, this is global data, not US-specific, so it should not be blended with the US-only IC3 figures. What it adds to the picture is the reminder that not all payment fraud comes from outside: the same weak control, one person owning too much of the payment process, is what both an external impersonator and an internal fraudster exploit, which is why a verification step that is independent of any single employee addresses both at once.

The AI and deepfake numbers: measured, projected, and a single case

No area mixes the three kinds of number more than AI-enabled fraud, and keeping them straight is the whole discipline. The measured figure is the FBI’s: more than $893 million in losses across AI-nexus complaints in 2025. The projected figure is Deloitte’s: its Center for Financial Services projects US generative-AI fraud losses reaching $40 billion by 2027, from $12.3 billion in 20234, a 32 percent compound annual growth rate framed across adoption scenarios. And the single case is Arup, the engineering firm that lost about $25 million in one deepfake-video incident in 2024. Three numbers, three entirely different kinds of evidence: a count, a forecast, and an anecdote.

The disciplined way to use them is together but never interchangeably. The $893 million says AI is now a named, measured factor. The $40 billion says the trajectory is steep, as a model, not a fact about last year, and it should never be stacked on the measured total or quoted as money already stolen. The Arup $25 million proves the attack is real and can reach eight figures in a single event, but one landmark case is evidence that it works, not a measure of how often it happens. The companion guide on deepfake fraud statistics works through exactly this distinction in depth. If a source cites the $40 billion without noting it is a 2027 projection, that is a small signal to read the rest of its numbers carefully.

The instant-rail dimension: speed makes the losses final

One more number set explains why the trend is toward larger, faster losses: the rails themselves. In the United Kingdom, where reporting on authorized push payment fraud is more mature, UK Finance reported £450.7 million lost to APP fraud across 185,733 cases in 2024, with about 70 percent of cases starting online5. Authorized push payment fraud is the category where the victim is deceived into sending the money themselves, so it passes every control built to catch an intruder, and on an instant rail it settles in seconds with no reversal. The US instant rails, RTP and FedNow, are earlier in their adoption curve, which is precisely why building the verification habit now, before instant volume is dominant, matters.

This is the through-line connecting the datasets to a trend rather than a snapshot: as settlement gets faster and more final, the window to catch a fraudulent payment after it leaves shrinks toward zero. The FBI’s own recovery figures make the point from the other side, as the guide on wire fraud recovery details: clawback works only sometimes, and only when a loss is reported fast enough. Read alongside the rising totals, the finality numbers argue that the leverage is moving decisively from recovery after the fact to verification before settlement, because after settlement, on the rails the money increasingly travels, there is nothing left to reverse.

How to read any payment-fraud statistic honestly

Pulling it together, here is the short framework this whole guide applies, usable on any number you encounter. First, ask what kind it is: a measured count, a survey share, or a projection. A measured count of reported losses is a floor. A survey share tells you how common an attempt is, not how much was lost. A projection describes a modelled direction, not money gone. Second, ask about the denominator and scope: US or global, dollars or percentage of companies, one year or a multi-year forecast. Third, resist stacking: numbers from different sources measuring different things cannot be added, and a projection must never be piled on top of a measured total. Fourth, treat a single dramatic case as proof the attack works, not as evidence of its frequency.

Applied to the 2026 figures, that framework keeps the story straight. Measured US dollars: $20.9 billion total, $3.046 billion BEC. Measured company exposure: 76 percent hit, checks most-targeted. Global estimate: about 5 percent of revenue. Projected: $40 billion in US gen-AI fraud by 2027. One case: Arup at $25 million. None of these contradicts another once each is read for what it is, and the payment fraud by industry breakdown applies the same discipline to who gets hit hardest. The point of reading honestly is not to shrink the problem, which is genuinely large, but to know exactly what you know, which is what lets you choose a defense on evidence rather than on whichever figure is most alarming.

The one number that does not change

Underneath every statistic in this guide is a single event that all of them are counting in different ways: an authorized payment sent to a payee that was switched, spoofed, or impersonated. The FBI’s BEC billions, the AFP’s 76 percent, the deepfake case, the APP losses, even much of the internal ACFE data all describe money that moved because a real, authorized person released it to the wrong account. That is why these losses clear the controls built to stop intruders: there is no intruder, only a legitimate user acting on a convincing lie. And it is why the defense that addresses all of them is the same regardless of which number rises fastest, verifying the payee and the approval before the payment settles.

This is where RankShield Financial fits, and the honest framing matters after a guide about reading numbers honestly. It is a verification and attestation layer in the payment authorization path, not a bank, a fraud score, or a custodian of funds, and it never touches the money. What it does is verify the payee and a named approval and seal a checkable record before a payment settles, which acts on the exact event every one of these statistics is counting. The boundaries stay explicit: it verifies the payee and the approval and proves the decision, it does not catch every scam, and it is a design-partner-stage product that claims no network it has not built. If you want that verification in front of your payments, you can see how it works or request access. The statistics will keep climbing; the event they describe, and the point at which you can still stop it, will not.

Operate it

Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.

Conditions around this payment
PRE-SETTLEMENT VERDICTRANKSHIELD NETWORK

Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call

Downloadable · SVG
RANKSHIELD FINANCIAL // PAYMENT FRAUD, BY THE NUMBERS Four numbers, four different measurements MEASURED · US $ $20.9B total 2025 · $3.046B BEC Reported US losses, one year (FBI IC3). A floor: most fraud goes unreported. MEASURED · US ORGS 76% of organizations hit Share of companies targeted in 2025 (AFP). How common, not how much was lost. ESTIMATE · GLOBAL ~5% of revenue, per year Occupational fraud, global (ACFE). A reasoned estimate, not a hard count. PROJECTED · US $40B gen-AI fraud by 2027 A forecast from $12.3B in 2023 (Deloitte). A modelled direction, not money lost. The one number underneath all of them: an authorized payment to a switched payee. That is what verifying before settlement stops. rankshieldfinancial.com READ EACH FOR WHAT IT IS

The 2026 payment-fraud figures come from four different measurements: the FBI counts reported US dollars lost ($20.9B total, $3.046B BEC), the AFP counts the share of companies hit (76%), the ACFE estimates a global percentage of revenue (~5%), and Deloitte projects a 2027 forecast ($40B). Read each for what it is, and the one event underneath all of them is an authorized payment to a switched payee.

FAQ

Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.

JAMIE KLONCZ · RANKSHIELD FINANCIAL ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →
Self-check

How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

  1. 01Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
  2. 02Can one person both change a vendor’s bank details and approve the payment?
  3. 03Do you always confirm a bank-detail change on a number from your own files, not the request?
  4. 04Is the first payment to a new or changed payee held for verification before it goes out?
  5. 05Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5

Jamie Kloncz
About the author

Jamie KlonczFounder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

  • Primary sources only: each figure links to the original filing
  • Honest boundaries: what verification can and cannot do is stated plainly
  • Last verified August 18, 2026
Verify, then settle

See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.

Request accessHow it works