The number that changed the risk conversation this year
The FBI Internet Crime Complaint Center published its 2025 Annual Report in April 2026, and the business email compromise line is the one every Hawaii owner should read. IC3 logged 24,768 BEC complaints in 2025 with $3.046 billion in reported losses, up from $2.77 billion in 2024 — a 9.9% year-over-year increase in a category that is already the largest business-facing cybercrime loss. The average complaint carried $122,000-$123,000 in direct loss, and 86% of that money moved by wire transfer or ACH. Ransomware, for comparison, drove $32.3 million in reported IC3 losses the same year.
BEC is not a technical attack. There is no malware, no exploit, no zero-day. There is an email that convinces one person to move money to the wrong account. AI-generated text and voice cloning have compressed the time to craft a convincing lure from around 16 hours to about 5 minutes, and BEC has now been IC3's costliest cybercrime category for seven consecutive years. The controls that stop BEC are boring, procedural, and cheap. The cost of not having them is on the previous paragraph.
What a BEC actually costs a Hawaii small business, line by line
Reference scenario: a Kakaako professional services firm with 22 employees receives an email that appears to come from the managing partner directing the bookkeeper to wire $148,000 to a "new vendor" for a project closing that week. The bookkeeper wires the money. The partner sees the confirmation the next morning at 9am and calls the bank at 9:03am — roughly 18 hours after the transfer. Full cost:
- Direct wire loss: $148,000. RAT is engaged same day; funds are partially recovered ($62,000 frozen at the receiving bank, $86,000 lost). Net direct loss $86,000.
- Incident response and forensics: $28,000 (Microsoft 365 mailbox forensics, session and OAuth token review, mail-rule audit, credential rotation).
- Outside legal counsel: $14,000 (privilege analysis, disclosure obligations to affected clients, insurance coordination).
- Cyber insurance retention: $25,000 (policy pays $150,000 under Social Engineering Fraud endorsement, capped at $250,000 with $25,000 retention).
- Client notification and credit monitoring: $8,000 (18 affected client contacts, one-year monitoring).
- Internal finance-team time: ~120 hours across 6 weeks reconciling vendor payables, re-negotiating three payment schedules, rebuilding the callback policy, and re-training. Loaded cost approximately $9,000.
- Reputational and banking relationship costs: the firm's operating bank required a compliance letter and additional review before restoring wire authority to the bookkeeper account. Not directly billable but real.
Total cost of this Kakaako incident: about $170,000 above the insurance recovery, on a wire that netted the attacker $86,000. The wire is the visible number; the wire is not the total cost. If the partner had noticed the same transfer four hours later instead of 18 hours later, RAT recovery odds would have been meaningfully higher, and the outcome would have looked different.
The four-hour freeze window most Hawaii businesses don't know about
The FBI IC3 Recovery Asset Team (RAT) exists precisely for the moment described above. In 2025, RAT initiated 3,900 Financial Fraud Kill Chain incidents covering $1.164 billion in attempted theft and successfully froze $679 million — a 58% recovery rate on incidents that were reported quickly. The word "quickly" in the FBI's own framing means hours, not days. The path is:
- Call the sending bank's fraud line immediately, state a fraudulent wire has been sent, request a formal freeze and recall.
- File a complaint at ic3.gov and explicitly request FFKC activation, including the receiving bank routing number, account number, transfer amount, and any known contact information for the recipient.
- For international wires, ask your correspondent banking team to initiate a SWIFT gpi recall through your SWIFT BIC same-day.
- Notify your cyber insurance carrier within 24 hours to preserve coverage.
- Preserve email evidence: pull the original malicious email as raw .eml or .msg (never a forward), capture headers, screenshot the mail rules and forwarding config before anything is remediated.
The 58% recovery number is a headline, not a promise. It weights toward the incidents reported in the first hours, before the receiving bank releases funds, before the receiving account layers the money through mule accounts, and before conversion to cryptocurrency. Recovery odds on incidents reported after 72 hours drop dramatically.
How BEC actually lands at a Hawaii small business
Three patterns account for most Hawaii BEC incidents:
- Vendor invoice fraud. A legitimate vendor's email account is compromised elsewhere; the attacker studies the real email history, then sends a genuine-looking follow-up on an outstanding invoice with new banking instructions. The Hawaii business updates the vendor record and pays the next legitimate invoice to the attacker's account. Defense: callback verification to a known phone number from your own records — not from the email — before any banking-detail change.
- Executive impersonation. The attacker registers a lookalike domain (using a zero for an O, or a similar TLD) and emails a bookkeeper or controller "from the CEO" with urgency framing. Defense: dual authorization on outbound payments above a threshold, plus a policy that the CEO does not initiate wires by email under any circumstance.
- Payroll diversion. An employee's mailbox is compromised; the attacker sends HR a request to update direct deposit routing to a new bank. Defense: HR requires in-person or verified-phone confirmation of direct deposit changes, plus an alert on any external mail-forward rule created in the previous 30 days.
None of these require technical sophistication. All three are defeated by an out-of-band verification step and phishing-resistant MFA on the finance-team's email. The controls cost less than the average incident.
Related insights and recovery guidance
For the M365 mailbox forensic steps referenced above, see the first 72 hours after a Microsoft 365 compromise. For phishing-resistant MFA options on finance email, see passkeys and phishing-resistant MFA. For the broader Hawaii SMB compliance and disclosure landscape, see the Hawaii SMB compliance calendar for 2026-2027. For downtime-cost framing on a parallel business risk, see the real cost of IT downtime for a Hawaii small business.
What a Hawaii business should do this week
Five decisions to make by Friday of next week:
- Write a one-page callback verification policy that covers every payment change, new vendor onboarding, wire request above a threshold, and direct-deposit change. Post it where the bookkeeper and controller can see it.
- Confirm the finance team is on phishing-resistant MFA. If they're on SMS one-time codes, migrate to passkeys or FIDO2 hardware keys this quarter.
- Ask your cyber insurance broker in writing: does the policy cover BEC-triggered wire fraud, what is the sub-limit, what is the retention, and does it require callback verification as a condition of coverage.
- Set a monthly Exchange Online mailbox rule audit that alerts on any new external auto-forward rule and any inbox rule that filters legitimate finance-team mail to trash or archive.
- Bookmark ic3.gov and put the FBI Honolulu field office fraud line into the bookkeeper's phone contacts. When the moment comes, four hours is the window.
Why HI Tech Hui is publishing this
HI Tech Hui has been the managed IT and cybersecurity provider for Hawaii businesses since 2014, operating from 401 Kamakee Street in Kakaako with a Cyberuptive-run security operations capability. Business email compromise is the incident we get called into most often after the wire has already left. Reading the FBI numbers side-by-side with the ransomware line makes the picture obvious: for a Hawaii small business the risk is not the ransomware headline — it's a bookkeeper acting on a convincing email at 4:53pm on a Friday. The controls above cost less than the average loss. Publishing them plainly is the right thing to do.
Frequently asked questions
What does business email compromise actually cost a Hawaii small business in 2026?
For a Hawaii small business, a business email compromise (BEC) in 2026 costs an average of $122,000 in direct wire loss (FBI IC3 2025 Annual Report), plus $40,000-$120,000 in incident response, forensic, and legal work, plus a cyber insurance retention of $10,000-$50,000, plus 2-6 weeks of finance-team disruption. If the fraudulent transfer is reported to the FBI Recovery Asset Team within four hours, there is roughly a 58% chance of freezing the funds; after 72 hours the recovery rate collapses.
How common is business email compromise in 2026?
The FBI IC3 logged 24,768 BEC complaints in 2025 with reported losses of $3.046 billion, up from $2.77 billion in 2024. BEC is the second-largest category of reported cybercrime losses after investment fraud and the largest category of business-facing loss. The average complaint involves $122,000-$123,000 and 86% of stolen funds move by wire transfer or ACH. Most incidents are never reported, so actual losses are higher.
What is the FBI Recovery Asset Team and how does it work?
The FBI IC3 Recovery Asset Team (RAT) coordinates with financial institutions to freeze fraudulent transfers through the Financial Fraud Kill Chain (FFKC). In 2025, RAT initiated 3,900 FFKC incidents covering $1.164 billion in attempted theft and successfully froze $679 million, a 58% recovery rate. To trigger RAT, a Hawaii business must file a complaint at ic3.gov quickly — hours, not days — and explicitly request FFKC activation with the receiving bank routing and account numbers.
How much time does a Hawaii business have to recover a fraudulent BEC transfer?
The practical window is four hours. RAT's 58% recovery rate is heavily weighted toward incidents reported within hours of transfer, before the receiving bank releases the funds. After 24-72 hours, recovery odds drop sharply as funds move through mule accounts or convert to cryptocurrency (86% of BEC funds now move by wire or ACH before conversion). International wires give an extra window if a SWIFT gpi recall is initiated same-day; domestic ACH is faster to freeze but only if reported within the ACH return window.
What are the full downstream costs of a BEC beyond the wire loss?
For a Hawaii small business, downstream costs typically add $80,000-$220,000 on top of the wire loss: incident response and forensics ($15,000-$60,000), outside legal counsel ($8,000-$35,000), cyber insurance retention ($10,000-$50,000), customer or vendor notification and credit monitoring ($3,000-$25,000), 40-160 hours of internal finance-team time on remediation, and reputational recovery with major banking partners and vendors. Ransom is not a factor in BEC — the loss is the transferred funds.
Does cyber insurance cover BEC losses for a Hawaii small business?
It depends on the policy. Traditional cyber coverage often excludes social engineering fraud unless a specific Social Engineering Fraud endorsement is added, typically capped at $100,000-$250,000 with a separate deductible. Fund transfer fraud coverage in a Crime policy is a separate rider. Ask your broker in writing: (1) does the policy cover BEC-triggered wire fraud, (2) what is the sub-limit, (3) does it require callback verification of payment changes, and (4) what is the retention. Coverage disputes are common.
How can a Hawaii small business prevent business email compromise?
Six controls, in order of impact: (1) callback verification policy for every payment-change or new-vendor request using a phone number from your own records — never from the email, (2) dual authorization for outbound payments above a threshold, (3) phishing-resistant MFA (passkeys or FIDO2) on the finance team's email, (4) DMARC enforcement on your sending domain, (5) mailbox rule audit that alerts on external auto-forward rules, and (6) quarterly finance-team tabletop exercise. All six together cost less than a single average BEC loss.
What is the first phone call a Hawaii business should make after a suspected BEC?
Call your bank's fraud line first, not IT, not the CEO, not the lawyer. State clearly: a fraudulent wire has been sent, request an immediate freeze and formal recall, and provide the destination routing and account. Then file at ic3.gov requesting FFKC activation. Then notify your cyber insurance carrier within 24 hours to preserve coverage. Only after those three calls does the internal incident response start. The bank call is the four-hour window.
Bottom line
Business email compromise cost US businesses $3.046 billion in 2025 across 24,768 FBI complaints, at an average of $122,000-$123,000 per incident. The FBI Recovery Asset Team recovered 58% of what it engaged on, but recovery depends on reporting within hours — not days. A Hawaii small business's realistic all-in cost after downstream forensics, legal, insurance retention, and finance-team disruption typically lands $170,000-$350,000. The six preventive controls above cost less than one average incident. If a wire has already gone: call the bank first, ic3.gov second, insurance third. Four hours is the window.