Australians reported $2.18 billion in combined scam losses in 2025, up 7.8% on 2024, with payment redirection, the category covering business email compromise, second only to investment scams at $166.8 million. That is the National Anti-Scam Centre's reconciled figure across five reporting channels; ASD and the FBI count differently, and the differences matter.
Three official channels publish Australian scam and business email compromise (BEC) statistics: the National Anti-Scam Centre's annual Targeting Scams report, ASD's Annual Cyber Threat Report built on ReportCyber data, and the FBI's Internet Crime Complaint Center (IC3). They measure different populations over different periods with different counting rules, so most articles that quote one channel as "the" Australian figure get the total wrong. This page sets out what each channel actually says, why they disagree, and which Microsoft 365 controls address the scam type behind most of the business losses. Every figure below has been checked against its primary source, and one widely repeated claim that could not be traced to a primary has been left out.
Key statistics at a glance
- Combined scam losses reported to Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC reached $2.18 billion in 2025, up 7.8% on 2024 (NASC Targeting Scams report, published March 2026).
- Payment redirection scams, the National Anti-Scam Centre's category for business email compromise, cost a reported $166.8 million in 2025, up 9.3% on 2024's $152.6 million and second only to investment scams at $837.7 million (NASC, 2026).
- Australians lodged 481,523 scam reports across the five combined channels in 2025, a 2.3% decrease on 2024 even as total losses rose (NASC Targeting Scams report, 2026).
- Self-reported BEC losses to ReportCyber were almost $84 million in FY2023-24, across more than 1,400 reports involving a financial loss, an average above $55,000 per confirmed incident (ASD Annual Cyber Threat Report 2023-24).
- Total self-reported financial losses from BEC for large Australian businesses rose 138% in FY2024-25, a movement ASD itself cautions may be skewed by a small number of outlier reports (ASD Annual Cyber Threat Report 2024-25).
- Email compromise without financial loss (19% of business cybercrime reports) and BEC fraud with financial loss (15%) were the two most-reported cybercrime types for Australian businesses in FY2024-25 (ASD, 2025).
- False billing was the most reported scam type by Australian small businesses in 2025, both with and without financial loss, and the NASC links these scams to business email compromise (NASC Targeting Scams report, 2026).
- The FBI recorded US$55.5 billion in exposed BEC losses across 305,033 incidents worldwide between October 2013 and December 2023 (IC3 public service announcement, September 2024).
How much is business email compromise costing Australian businesses?
The best national figure is the National Anti-Scam Centre's: payment redirection scams cost a reported $166.8 million in calendar 2025, up 9.3% on 2024. That moved the category from third to second place among scam types by loss, behind investment scams at $837.7 million and ahead of romance scams at $139.9 million. The NASC number is the broadest available because it combines five channels, Scamwatch, ReportCyber, IDCARE, the Australian Financial Crimes Exchange and ASIC, and removes duplicates where the same victim reported to more than one of them. It still only counts what victims chose to report.
ASD's ReportCyber data tells the per-incident story. In FY2023-24, the most recent year for which ASD published a national BEC loss total, self-reported BEC losses were almost $84 million across more than 1,400 reports involving a financial loss, an average above $55,000 per confirmed incident, with Queensland lodging the most confirmed reports. The FY2024-25 edition reports movements rather than a headline BEC dollar total: email compromise without financial loss (19%) and BEC fraud with financial loss (15%) were the two most-reported cybercrime types for business, and total self-reported BEC losses for large business rose 138%. Over the same year, the average self-reported cost of cybercrime of any type was $56,600 per report for small businesses, $97,200 for medium and $202,700 for large.
What does each official channel actually count?
NASC and Scamwatch: the widest net
The National Anti-Scam Centre's Targeting Scams report, published each March for the prior calendar year, combines Scamwatch's voluntary public reports with ReportCyber, IDCARE, the Australian Financial Crimes Exchange (bank fraud data) and ASIC. Because the same scam is often reported to several of these bodies, the NASC applies an explicit adjustments row to the totals to strip out double counting. Its headline: $2.18 billion in combined 2025 losses from 481,523 reports. This is the only channel that attempts a deduplicated national total, which is why Frontrow treats it as the anchor figure.
ASD ReportCyber: the law-enforcement lens
ReportCyber is the Australian Government's cybercrime reporting portal, and reports are referred to state and territory police. ASD's Annual Cyber Threat Report summarises it by financial year: over 84,700 cybercrime reports in FY2024-25, down 3%, roughly one every six minutes. It captures cybercrime specifically rather than all scams, so a phone-based investment scam that never touched a computer sits in Scamwatch's data but may never appear in ASD's. Its BEC figures are self-reported and, as ASD states plainly, the vast majority of cybercrime goes unreported.
FBI IC3: the global yardstick, not an Australian one
The FBI's Internet Crime Complaint Center publishes the largest BEC dataset in the world: US$55.5 billion in exposed losses across 305,033 domestic and international incidents between October 2013 and December 2023, per its September 2024 public service announcement, with identified global exposed losses up 9% between December 2022 and December 2023. But IC3 is a United States reporting channel. Australians lodged just 1,533 complaints of all crime types with IC3 in 2024, the sixth-highest foreign country behind the United Kingdom, Canada, India, France and the Philippines (IC3 2024 Annual Report). IC3 numbers describe the global and American picture; they say almost nothing about Australian totals.
Why do the three channels disagree?
Because they count different people, over different periods, with different rules. Scamwatch takes voluntary reports from anyone; ReportCyber skews toward victims seeking a police response; the banks' fraud exchange sees transactions rather than stories; IC3 mostly hears from Americans. The NASC deduplicates across its five feeds precisely because one victim often reports to three of them, so quoting Scamwatch and ReportCyber side by side and adding them double counts, while quoting either alone undercounts. Periods differ too: the NASC and FBI report calendar years while ASD reports financial years, so "2025" means two different twelve-month windows depending on the source. Finally, the FBI reports exposed losses, which include attempted transfers as well as money actually gone, a broader measure than the realised losses in Australian reports. None of these figures is wrong; each is an honest count of a different thing, and the double-digit disagreements between them are a measurement artefact, not a mystery.
Which scams hit Australian small businesses hardest?
False billing was the most reported scam type by small businesses in 2025, both with and without financial loss, and the NASC links these scams to business email compromise: a fake or altered invoice is the payload, a compromised or impersonated mailbox is the delivery mechanism. Small businesses (0 to 19 employees) lodged 2,228 Scamwatch reports in 2025 and reported more scams, more reports with loss and higher aggregate losses than medium and large businesses combined. By dollar value their top categories were investment scams at $6.2 million, false billing at $2.0 million and phishing at $0.6 million (NASC Targeting Scams report, 2026).
ASD's data adds the cost dimension: the average self-reported cost of cybercrime per report for small businesses was $56,600 in FY2024-25, up 14% year on year, against $36,633 across all reporters. And the Australian Institute of Criminology's 2024 Australian Cybercrime Survey, cited in ASD's report, found 22% of surveyed SME owners said their business was impacted by cybercrime in 2024. For a business turning over less than a million dollars, one successful payment redirection at the FY2023-24 average of $55,000 per incident is not an IT line item; it is the year's margin.
How does Australia compare globally?
BEC is the same crime everywhere, and the FBI's decade of data shows its scale: US$55.5 billion in exposed losses, incidents reported in all 50 US states and 186 countries, and fraudulent transfers sent to over 140 countries, with banks in the United Kingdom and Hong Kong the most common first stop, followed by China, Mexico and the UAE (IC3, September 2024). In IC3's 2024 annual data, BEC generated US$2.77 billion in reported losses from 21,442 complaints, the second-costliest crime type behind investment fraud in a dataset dominated by US victims. A caution for readers comparing sources: several Australian roundups assert a specific Australian ranking among global BEC victim counts and cite the FBI's BEC announcement for it, but that announcement contains no country ranking, so this page does not repeat the claim.
Which Microsoft 365 controls actually stop BEC?
Almost every BEC incident follows the same path: an attacker phishes a mailbox password or registers a lookalike domain, watches real invoice traffic, then sends a payment-detail change that looks routine. Each step has a specific, unglamorous control in Microsoft 365, and none of them requires a security product beyond what most business licences already include.
- SPF, DKIM and DMARC with an enforced policy stop criminals sending mail as your exact domain, and stop your invoices being spoofed to your customers. Frontrow's separate SPF, DKIM and DMARC setup guide for Microsoft 365 walks through the records step by step; the point here is that unauthenticated domains are the raw material of false billing.
- Multi-factor authentication removes the most common entry point, a phished password. Phishing-resistant methods such as Windows Hello for Business, FIDO2 security keys and passkeys matter increasingly, because attacker-in-the-middle phishing kits can relay one-time codes and approval prompts in real time.
- External sender tagging in Exchange Online labels mail arriving from outside the organisation, which makes display-name impersonation of a director or supplier visible at a glance, including on phones where sender addresses are hidden.
- A payment-change verification process: no bank-detail change is actioned on email alone, ever; someone phones the supplier on a number already on file before a dollar moves. ASD's ReportCyber mitigation advice for BEC says the same thing in fewer words.