Cybercrime DB

Business Email Compromise Infrastructure Seizures

Losses hit $3 billion as actors got better at extraction, not enforcement.

Staff Writer · · 8 min read
Cover illustration for “Business Email Compromise Infrastructure Seizures”
cybercrime takedowns and seizures · September 12, 2026 · 8 min read · 1,831 words

Business Email Compromise cost victims $3.046 billion in 2025, up from $2.77 billion in 2024, according to FBI IC3 data analyzed by Abnormal AI and rexxfield.com. Complaint volume barely moved (24,768 versus 21,442), which means the actors got better at extraction, not more numerous. This is the second-largest fraud category the FBI tracks, and the cumulative number since 2015 sits at $17.1 billion. That's not a crime wave. That's an industry that solved its business model a decade ago and has been scaling it quietly ever since, largely because law enforcement keeps seizing the wrong layer.

What BEC actors actually build and why it is reusable across campaigns

No malware. No exploit kits, no zero-days, no ransomware payload sitting on a server waiting to detonate. The entire attack runs on impersonation, timing, and an email written well enough that someone in accounts payable decides today is not the day to double-check a wire request. People outside the field find that hard to believe, mostly because "sophisticated fraud" and "no code involved" don't sound like they belong in the same sentence.

That makes BEC infrastructure lighter than a ransomware crew's toolkit, and harder to fingerprint. Lighter doesn't mean empty, though. There's still a stack: lookalike domains, phishing kits, bulletproof hosting, compromised or synthetic email accounts, and mule networks that move the money once it lands. Each piece is separable. Each piece gets reused across dozens of victims before anyone notices the pattern repeating.

Most coverage of BEC treats the email as the crime. It isn't. The financial layer is where the crime actually happens, and it's the layer that gets the least attention. Bank accounts, crypto wallets, and the mules fronting them are where the money leaves the building. Seize a domain and an actor loses a costume. Seize the mule account holding the wire, and the payout freezes before it clears. Worth being precise here: this isn't botnet sinkholing. Nobody's redirecting command-and-control traffic to a research server. The closer comparison is a wire fraud task force, not a malware takedown.

Because the stack is modular, losing one piece just means rebuilding that piece. Arrest a mule, an actor recruits another. Seize a domain, an actor registers a fresh one from a stockpile sitting ready. Single-vector enforcement rarely knocks an operation over, and phishing feeds the whole pipeline directly: phishing losses jumped from $70 million in 2024 to $215.8 million in 2025, per SpyCloud's IC3 analysis. Phishing is the front door. BEC is what happens after someone's already inside the house, rifling through drawers.

How law enforcement maps BEC infrastructure before a seizure operation

Mapping starts with unglamorous work: domain registration patterns, registrar history, hosting ASNs tied to bulletproof providers who've hosted this traffic before, email header anomalies, early signs of an account takeover mid-progress. None of it looks dramatic alone. Stacked together, it draws a picture investigators can act on.

Mule networks get traced through financial intelligence instead of digital forensics: correspondent bank records, wire routing paths, crypto transaction graphs. Follow the money, except the money now runs through six intermediary accounts and a stablecoin swap before anyone can grab it.

Private-sector threat intelligence feeds a lot of this mapping through referral chains, and here's where the industry splits into two kinds of vendors. Firms that can point to a documented, verifiable role in that chain earn credibility with investigators. Firms that exaggerate their role lose it fast, because practitioners talk to each other constantly. That reputational math should scare vendors more than it currently does. The underreporting problem makes it worse: 24,768 IC3 complaints is a fraction of what's actually happening, so investigators working only from complaint data miss the reuse patterns across campaigns nobody bothered to report. Private-sector telemetry catches the detection signals that never make it into a complaint form. That's the real argument for why vendor data matters, not a sales pitch dressed up as one.

On the institutional side, the Secret Service runs a Global Investigative Operations Center built specifically around financial-layer intelligence, not malware analysis. Certifid.com credits it with over $2 billion in seized illicit proceeds across its operational history. That's the model that works: trace the money, not the code.

What seizure operations target at each layer and what that degrades

Diagram: The BEC Stack: What Each Layer Costs an Actor to Rebuild. Visualizes: Visualize the four disruption layers of a BEC operation ranked by rebuild difficulty and enforcement impact: (1) Domains — seized in hours, rebuilt in hours, 'delay tax…

Domain seizures pull the impersonation surface out from under an active campaign, but they don't touch an actor's ability to register the next one an hour later. Call it a delay tax, not a knockout blow.

Phishing kit takedowns hit harder, since a single kit often runs dozens of concurrent campaigns behind the scenes. Kill the kit and the damage spreads across every campaign built on it, not just the one somebody happened to notice.

Email account disruption, breaking into a synthetic account or a hijacked corporate mailbox used as a relay, rarely makes headlines. It might be the most damaging layer to lose anyway, because it breaks the trust chain that makes a BEC message convincing. Nobody wires money to a stranger. They wire it to what looks like their CFO, from an address that looks exactly right.

Mule network disruption, freezing bank accounts and seizing crypto wallets, is the only layer that stops loss before it becomes permanent. Per McDonald Hopkins's IC3 analysis, a BEC wire that clears before internal controls catch it is unrecoverable in most cases. That single fact explains why mule-layer seizure carries so much weight: it's the last stop before the money is simply gone, full stop, no undo button.

Real damage comes from hitting domains, accounts, and financial infrastructure together, in sequence, forcing an actor to rebuild three things at once instead of one. Worth flagging the limits of the record here: there's no confirmed 2024-to-2025 operation with public domain counts or arrest tallies to cite. What's described above is the operational model, not a specific case file. Historical reference points exist (Operation reWired in 2019, Operation Falcon in 2020), but nothing in the current data confirms a direct successor.

What the pace of actor recovery reveals about which disruptions actually hurt

Diagram: BEC Losses vs. Complaints: More Money, Same Actors. Visualizes: Show the contrast between 2024 and 2025 across two dimensions: total BEC losses ($2.77 billion in 2024 vs.

Losses climbing from $2.77 billion to $3.046 billion despite ongoing enforcement tells its own story. The current pace of seizures leaves the underlying activity intact, a speed bump on a highway that keeps getting wider lanes added to it.

Domains and hosting rebuild fast. An actor holding backup domains, or a standing relationship with a second bulletproof host, can get back online relatively quickly. Unless the seizure also hits the financial layer at the same time, the cost to the actor rounds down to nothing.

Mule networks are the opposite story, and this is the part enforcement should be leaning into harder than it currently does. Recruiting, vetting, and activating new mules is a slower and more operationally demanding process than rebuilding a domain, and it requires real tradecraft to avoid burning the new recruit the same way the last one got burned. That slower rebuild cycle is where a seizure operation leaves a mark that actually lasts past the news cycle.

One more wrinkle: AI-related BEC losses hit $30 million in 2025, per SpyCloud's IC3 analysis. Small slice of the total pie. But IC3 formalizing "AI-related" as its own crime descriptor is a signal by itself, suggesting AI-assisted impersonation is starting to professionalize into something closer to a service industry. Lower the skill floor for writing a convincing CEO email, and rebuild times after a seizure only shrink further. The 1,025% growth since 2015 says the model has outlasted every enforcement cycle thrown at it. What matters is whether seizures work in this specific context. It's whether they're aimed at the layer that actually costs criminals something to rebuild, and right now, most of them aren't.

How threat intelligence feeds into seizure operations and what vendors can legitimately claim

Private-sector intelligence earns its keep at the detection and attribution stage, long before a victim ever files an IC3 complaint: correlating domain registration patterns, spotting reused hosting infrastructure, fingerprinting mule account typologies across campaigns that look unrelated until someone lines them up side by side.

A handful of firms, Abnormal AI and SpyCloud among them, publish their own annual breakdowns of IC3 data layered with proprietary telemetry. That kind of analysis earns trust with practitioners for one plain reason: it doesn't need to inflate anything to be useful. It just shows the work.

The underreporting gap is the honest pitch, and it needs zero embellishment. 24,768 complaints represent a fraction of what's actually happening, so vendor telemetry catches signals complaint data never will. That's a specific, defensible claim, not a marketing flourish stapled onto a press release.

Framing BEC as an infrastructure problem, one with technical signals like header anomalies, lookalike domain patterns, account takeover precursors, and mule typologies, is what makes this relevant to a CISO's actual control surface. Treating it as a purely human social-engineering issue undersells the part a security team can actually instrument. Content studios building security narratives on live threat intelligence, rather than an editorial calendar chasing search volume, are the ones who get these claims right. Cyberou, a cybersecurity content studio, works from that premise: ground the narrative in operational intelligence first, let a vendor's actual contribution speak for itself instead of dressing it up. Overstating a role in a law enforcement referral chain is the fastest way to lose the exact audience whose trust makes the content worth publishing in the first place.

What seizure patterns tell defenders about where to build detection coverage

The layers seizure operations chase are the same layers defenders should already be watching: domain registration monitoring, header and routing anomaly detection, financial account behavior signals, mule typology matching. Law enforcement and internal security teams are running the same playbook from opposite ends of the same table.

The financial layer stays the hardest one to catch early and the most durable one to disrupt once caught. McDonald Hopkins's framing applies directly: nothing improves once the wire clears. Recovery and prevention both depend entirely on catching it before that moment, not after, and there is no version of this where "after" works out.

There's a regulatory deadline attached now, too. Nacha rule changes taking effect in 2026 aim to cut down successful BEC fraud and improve fund recovery after the fact, according to nacha.org. For banks and financial-sector defenders, that turns infrastructure detection from a nice-to-have into a line item auditors will ask about.

Total reported cybercrime losses hit $20.877 billion in 2025, a 26% jump from the year before, per McDonald Hopkins's IC3 analysis. Detection gaps are widening faster than enforcement can close them. Defenders who understand how the BEC stack gets built, and which layer actually hurts an actor when it's seized, can map that straight onto their own detection stack: which signal would have caught the domain, the account, or the mule before the wire ever went out. That's the whole game now. Not chasing headlines about takedowns, but building the sensor that fires before the money moves.

More in cybercrime takedowns and seizures