The $16.6 Billion Heist: How Cybercrime Quietly Became America’s Most Profitable Criminal Enterprise

The FBI's latest IC3 report reveals Americans lost a record $16.6 billion to cybercrime in 2024, a 33% increase over the prior year. Investment fraud, pig butchering scams, and business email compromise drove losses that may actually exceed $66 billion.
The $16.6 Billion Heist: How Cybercrime Quietly Became America’s Most Profitable Criminal Enterprise
Written by Maya Perez

Americans lost $16.6 billion to cybercrime in 2024. That figure — an all-time record — landed with a thud in the FBI’s latest Internet Crime Complaint Center report, released in late March. It represents a 33 percent jump from the prior year’s $12.5 billion and more than triples the losses recorded just five years ago. The numbers are staggering on their own. In context, they’re alarming.

The FBI’s IC3 annual report, which has tracked internet-facilitated crime since 2000, logged 859,532 complaints last year. But the bureau is quick to note that actual losses almost certainly dwarf what gets reported. Many victims — individuals and corporations alike — never file complaints, whether out of embarrassment, ignorance, or the quiet corporate calculus that disclosure does more reputational harm than the loss itself. As The Register reported, the FBI estimates real losses could be four to five times higher than the reported total — meaning the true cost of cybercrime in the United States may have exceeded $66 billion in a single year.

That’s not a rounding error. That’s a national security problem masquerading as a consumer protection issue.

The composition of these losses tells a story about who’s being targeted and how. Investment fraud remained the single most expensive category, accounting for $6.57 billion — up from $4.57 billion the year before. Much of this activity is driven by what law enforcement now calls “pig butchering” schemes, a term derived from the Chinese phrase “shā zhū pán.” The metaphor is brutal but accurate: scammers cultivate relationships with victims over weeks or months, building trust through dating apps, social media, or encrypted messaging platforms before steering them toward fraudulent cryptocurrency investment platforms. The victim watches fabricated returns climb on a slick dashboard. When they try to withdraw, the money’s gone. So is the person they thought they knew.

These aren’t low-effort Nigerian prince emails. They’re sophisticated, patient, and industrialized. According to the IC3 data, cryptocurrency-related fraud accounted for roughly $9.3 billion in reported losses across multiple crime categories in 2024. The infrastructure behind these operations frequently traces back to Southeast Asian compound operations — essentially forced-labor scam factories in countries like Myanmar, Cambodia, and Laos, where trafficked workers are coerced into running fraud campaigns at scale. The human rights dimensions of this criminal industry are as disturbing as the financial ones.

Business email compromise, or BEC, continued its reign as one of the most damaging attack vectors, generating $2.77 billion in losses. The mechanics are deceptively simple. An attacker compromises or spoofs a legitimate business email account and uses it to redirect wire transfers, alter payment instructions, or authorize fraudulent invoices. There’s no malware involved, no zero-day exploit. Just social engineering and the fundamental human tendency to trust familiar names in an inbox. BEC has been a top-tier threat for years now, and despite widespread awareness campaigns, the losses keep climbing.

Ransomware complaints rose 9 percent year over year, with 3,156 incidents reported to the IC3. But here again, the reported numbers understate reality. Many ransomware victims pay quietly and never contact law enforcement. The FBI noted that ransomware continued to be the most pervasive threat to critical infrastructure, with attacks hitting healthcare systems, school districts, municipal governments, and manufacturing operations. The median ransom demand has crept upward, and double-extortion tactics — where attackers both encrypt data and threaten to leak it — have become standard operating procedure.

One of the more troubling trends in the 2024 data is the disproportionate impact on older Americans. Individuals over 60 filed 147,127 complaints and reported $4.885 billion in losses, both figures the highest of any age group. That’s nearly 30 percent of total reported losses coming from a single demographic. The average loss per complaint for seniors exceeded $33,000. For some, it was their entire retirement savings.

This isn’t just about digital literacy gaps, though those exist. The schemes targeting older Americans are often deeply personal — romance scams, tech support fraud, government impersonation. Criminals know that isolation, trust, and unfamiliarity with digital financial systems make this population vulnerable. And the emotional devastation compounds the financial damage in ways that don’t show up in the IC3’s charts.

The geographic distribution of losses is predictable in some respects. California led with $2.55 billion, followed by Texas and Florida. These are the most populous states, so high absolute numbers are expected. But per-capita analysis reveals some surprises. Nevada, for instance, punches well above its population weight in fraud losses, likely driven by its concentration of cryptocurrency activity and transient population.

What should concern policymakers and corporate security leaders alike is the trajectory. In 2020, reported losses stood at $4.2 billion. By 2022, they’d reached $10.3 billion. Now $16.6 billion. The compounding isn’t slowing down — it’s accelerating. And the gap between reported and actual losses means the true growth curve is even steeper than it appears.

The FBI’s Recovery Asset Team, which works to freeze fraudulent wire transfers, managed to recover $561 million across 3,020 incidents in 2024, a success rate of about 66 percent on the cases it handled. That’s commendable work. But $561 million against $16.6 billion in losses — let alone the estimated $66 billion in actual losses — illustrates the fundamental asymmetry. Law enforcement is playing defense with a fraction of the resources that criminal enterprises deploy on offense.

International cooperation remains a persistent challenge. Many of the most prolific cybercrime operations sit in jurisdictions where local authorities are either unable or unwilling to act. Russia, North Korea, and China harbor state-linked or state-tolerated cybercriminal groups. Southeast Asian scam compounds operate in regions with weak governance and corruption. Even when U.S. law enforcement identifies perpetrators, extradition is often impossible.

The private sector’s response has been mixed. Financial institutions have invested heavily in fraud detection systems, and some have gotten meaningfully better at flagging suspicious transactions in real time. Cryptocurrency exchanges, under increasing regulatory pressure, have improved their compliance programs — though the decentralized and pseudonymous nature of blockchain transactions still provides substantial cover for illicit flows. Corporate cybersecurity spending continues to grow, with Gartner projecting global security and risk management spending to exceed $215 billion in 2025. But spending more hasn’t translated into losing less. Not yet.

Part of the problem is structural. Cybercrime is a distributed, adaptive, and increasingly professionalized industry. Criminal groups operate with the organizational sophistication of legitimate businesses — complete with HR departments, customer service teams for victims they’re defrauding, and R&D functions that develop new social engineering techniques. The barrier to entry has dropped as cybercrime-as-a-service platforms proliferate on dark web marketplaces. You don’t need to be a skilled hacker anymore. You just need to be willing to pay for the tools.

And the AI factor is only beginning to register. Generative AI has made phishing emails more convincing, deepfake audio and video more accessible, and automated scam operations more scalable. The IC3 report doesn’t break out AI-facilitated fraud as a separate category yet, but security researchers across the industry expect it to become a defining feature of the threat environment within the next two to three years. The same technology that’s transforming legitimate business is being weaponized by criminals who face no compliance department, no ethics board, and no quarterly earnings call.

So where does this leave us? The FBI’s data paints a picture of a problem that’s growing faster than the collective response. Reported losses have nearly quadrupled in four years. The criminal infrastructure is maturing. The victim pool is expanding. And the tools available to attackers are getting cheaper and more powerful.

None of this is inevitable. Better information sharing between the public and private sectors, stronger international law enforcement coordination, more aggressive takedowns of criminal infrastructure, and sustained investment in public education can all make a difference. But the scale of the challenge demands a proportional response — one that treats cybercrime not as a series of individual incidents but as a systemic threat to economic stability and public trust in digital systems.

The $16.6 billion figure will get attention for a news cycle. Then it’ll fade. The criminals won’t.

Subscribe for Updates

AISecurityPro Newsletter

A focused newsletter covering the security, risk, and governance challenges emerging from the rapid adoption of artificial intelligence.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us