The Federal Bureau of Investigation (FBI) maintains the Internet Crime Complaint Center (IC3) and issues an annual report. The latest Internet Crime Report, issued in 2025, presents some concerning statistics.
Cyber-Enabled Crime Continues to Rise
Fraud conducted through the internet and other electronic communications has grown into one of the most significant financial crime problems facing American consumers and businesses. The IC3 2025 Annual Report stated that 1,008,597 complaints were filed, which resulted in approximately $20.9 billion in losses. That represents a 26% increase in reported losses from 2024 and amounts to an average reported loss of approximately $20,699 per complaint.
IC3 is now receiving nearly 3,000 complaints every day.
Those figures are striking not simply because they are large, but because of how rapidly the financial consequences of fraud are increasing. The FBI reported approximately $16.6 billion in losses in 2024, compared with $20.9 billion in 2025.
Cyber-Enabled Fraud Accounts for Most Financial Losses
The report distinguishes general cybercrime complaints from what it describes as cyber-enabled fraud, a category of schemes in which criminals use the internet or other technology to steal money, information or identities or to facilitate fraudulent transactions.
In 2025, IC3 received 452,868 cyber-enabled fraud complaints, representing approximately 45% of all complaints submitted to the center. Those cases were responsible for an extraordinary $17.7 billion in losses, or approximately 85% of all reported IC3 losses for the year.
That disparity illustrates an important feature of modern fraud. The schemes that produce the most complaints are not necessarily the ones causing the largest financial losses.
Of all cyber-enabled crimes, phishing and spoofing remained the most frequently reported crime category, generating 191,561 complaints. Extortion followed with 89,129 complaints, while investment-related schemes generated 72,984 complaints.
Investment Fraud
According to the graphic above, investment fraud was by far the most financially damaging category reported to IC3 in 2025. Victims reported approximately $8.65 billion in investment fraud losses. That single category accounted for more than 40% of all losses reported to IC3.
Business email compromise (BEC) ranked second with approximately $3.05 billion in losses, followed by tech and customer-support scams at approximately $2.13 billion. Personal data breach-related complaints were associated with approximately $1.31 billion in losses, while confidence and romance scams resulted in approximately $929 million in reported losses. Government impersonation scams caused another $798 million in losses.
The three-year comparison contained in the IC3 report is particularly revealing. Investment fraud complaints increased from 39,570 in 2023 to 47,919 in 2024 and 72,984 in 2025. Government impersonation complaints also climbed dramatically, from 14,190 in 2023 to 17,367 in 2024 and 32,424 in 2025. Tech-support complaints increased from 36,002 in 2024 to 47,794 in 2025.
These trends show that fraudsters continue to refine schemes that rely less on technically sophisticated computer intrusions and more on manipulating victims into voluntarily transferring money.
Cryptocurrency Has Become a Major Vehicle for Fraud
IC3 received 181,565 cryptocurrency-related complaints in 2025, a 21% increase over 2024. Those complaints were associated with approximately $11.37 billion in losses, an increase of 22%. The average loss among cryptocurrency-related complainants was approximately $62,604, and 18,589 complainants reported losses exceeding $100,000.
Cryptocurrency does not necessarily constitute a separate type of fraud. Instead, it increasingly serves as the mechanism for money transfers to investment scams, impersonation schemes, romance fraud and other crimes.
The age distribution is especially noteworthy. Individuals aged 60 and older reported approximately $4.43 billion in cryptocurrency-related losses, substantially more than any other age group. People between 50 and 59 reported another $2.14 billion.
These numbers help explain why cryptocurrency has become attractive to organized fraud operations. Transfers can occur rapidly, victims may have difficulty reversing transactions, and criminals can move proceeds through numerous accounts, wallets and jurisdictions.
Older Americans Are Suffering Disproportionate Losses
One of the most troubling findings in the 2025 report involves Americans aged 60 and older. IC3 received 201,266 complaints from individuals aged 60 or older, an increase of 37% from 2024. Reported losses for this group reached approximately $7.75 billion, a 59% increase in a single year. The average reported loss was $38,500, and 12,444 complainants over the age of 60 reported losses exceeding $100,000.
By comparison, individuals between 50 and 59 reported approximately $3.68 billion in losses. Those ages 40 to 49 reported about $2.96 billion; ages 30 to 39 reported $1.74 billion; and ages 20 to 29 reported approximately $563 million. Victims under age 20 reported approximately $67 million in losses.
Among older victims, investment fraud was the greatest financial threat, producing approximately $3.52 billion in losses. Tech-support scams caused more than $1.04 billion in losses among people 60 and older, while confidence and romance scams resulted in approximately $584 million. BEC and government impersonation scams accounted for another $568 million and $413 million, respectively.
Fake Banking Websites
One of the ways criminals can so easily perpetrate cyber-enabled fraud is the proliferation of fake banking websites. With the help of AI, cybercriminals can create a look-alike domain and site in just a few minutes, complete with security controls for authentication and a fake accounting ledger. Criminals use such websites for everything from creating demand deposit accounts and certificates of deposit (CDs) to cryptocurrency trading.
The fake CD websites are particularly difficult to address because the individuals tricked into sending their money to a fake website are often not looking for the money for six, 12, or 24 months. By the time the investor seeks repayment, the website is often gone, the perpetrators have moved on, the accounts to which the original investment was sent are empty or closed, and there are fewer leads or the leads are harder to follow due to the passage of time.
Common steps taken by banks is to (1) monitor their own domain and search for look-alike domains; (2) educate customers as to how to spot and identify the correct domain banking website; (3) talk to customers on a regular basis either using email campaigns, old-fashioned letter campaigns, or hosting educational sessions for customers; and (4) if a fake domain is identified notify the domain registrar to immediately take it down.
As an example of fake domains, a search for the domain of “capitalone” returned domains such as:
- CAAPITALONE.COM
- CABITALONE.COM
- CACPITALONE.COM
- CAIPITALONE.COM
- CAITALONE.COM
- CAJPITALONE.COM
- CALITALONE.COM
- CALPITALONE.COM
- CAMPITALONE.COM
- CANPITALONE.COM
A search for “citi” produced numerous spoofed names such as:
- EITI.COM
- BITI.COM
- CETI.COM
- C-ITI.COM
- XITI.COM
- C1TI.COM
- ICTI.COM
- ITI.COM
- CITI.IO
- CLTI.COM
In addition to banking sites, there are numerous fake cryptocurrency investment sites actively targeting and soliciting vulnerable individuals.
Conclusion
In the last year alone, the IC3 report showed more effective efforts by fraudsters to exploit individuals in the modern era of online banking, investing and cryptocurrencies. Such schemes are disproportionately affecting older individuals in communities and take many forms, making a blanket defense difficult to provide. Cyber-enabled schemes pose the greatest threat and cause most of the overall losses attributable to fraud. Greater access to technology does not necessarily mean more sophisticated schemes, but it does create a greater volume of schemes, making it difficult to slow the growth of fraud and protect consumers.
Banks can help thwart the frauds by (1) monitoring domains similar to their own, and when such domains are discovered quickly notify the registrars to request takedown; (2) educating customers with presentations and regular fraud awareness campaigns through email, letters, account statements, webinars and branch events; and (3) helping customers identify and implement security controls appropriately for products and services such as CDs, new deposit accounts, wire transfers and cryptocurrency-related transactions, especially when customers are moving large sums to unfamiliar sites.



