Manav.id
Research ยท 18 min read

The $20.9 billion re-read: which cybercrime losses a signature would actually have stopped

Every April, the FBI publishes a number that goes straight onto a slide in a hundred thousand budget meetings. In 2026 that number was $20.877 billion. Nobody has re-read the report by control instead of by crime type, so nobody can tell you which of those dollars a given security purchase would have saved. We did the re-read. Most of the money is out of reach, and saying so is the only way to be trusted about the part that is not.

A budget meeting that goes wrong in a very specific way

Picture the third Tuesday in May. A security director is presenting next year's budget to a finance committee that has already sat through two hours of headcount. Slide four is the one everyone remembers: a bar chart from the FBI's Internet Crime Complaint Center, the 2025 bar towering over 2024, one line of text underneath. Twenty point nine billion dollars.

The CFO does the thing CFOs do. She looks at the number, looks at the ask, and asks the only question that matters. "Of that twenty billion, how much would the thing you are asking me to buy have prevented?"

And here is the uncomfortable part. The security director cannot answer, and neither could you. Not for lack of preparation, but because the question has never been answered for any control, anywhere. The IC3 report is organized by crime type. Vendor category sheets are organized by product. Neither is organized by the question the CFO just asked, which is a question about causation: at which step did this money leave, who performed that step, and would the control have made that step impossible?

So the director says what everyone says, which is that the threat is growing and the budget should grow with it. The committee approves something. The next year the bar is taller and nobody has learned anything, because the number was never a measurement of anything a control can act on. It was a measurement of harm, and harm is not a control taxonomy. This piece is an attempt to fix that, with a method published in full so you can disagree with us line by line.

Short answer. Of the $20.877 billion in losses the FBI reported for 2025, only a minority sits in categories where an attacker acted as somebody else and could have been stopped by requiring a fresh, action-bound signature from the real human's enrolled device. Using published category figures, that slice is roughly $3.6 billion, about 17 percent. The rest is dominated by losses the victim authorized on purpose, where no signature helps, because the failure was judgment, not authentication.

What does the FBI's 2025 Internet Crime Report actually say?

Start with the raw material, because the analysis is only as good as the numbers underneath it. The IC3 received 1,008,597 complaints in 2025, the first time the annual count has crossed a million, up from 859,532 the year before. Total reported losses reached $20.877 billion, an increase of roughly 26 percent year over year (FBI IC3 2025 Internet Crime Report).

Inside that total, several categories are broken out with enough precision to work with:

Two notes before we build on it. These are reported losses, so the real figures are larger: most fraud is never reported to the IC3, and corporate victims often route incidents through counsel and insurers instead. And the categories overlap, since a ransomware incident that began with a social-engineered credential reset appears under ransomware while the money that later left by wire appears under BEC. Both problems return in the limits section.

Why is "total losses" the wrong number to budget against?

The headline number has one job in the wild, which is to establish that the problem is big. It does that job well. What it cannot do is tell you where a specific control pays, and the reason is structural rather than sloppy.

Crime type is a description of the attacker, not of the gap

"Investment fraud" tells you what the attacker said. "Business email compromise" tells you which channel they used. Neither tells you what was missing when the money moved. Two incidents under different crime types can share an identical control gap, and two under the same crime type can have nothing in common to a defender. Payroll diversion and vendor bank-change fraud are both filed as BEC and share a gap. A romance scam and a deepfaked CFO call both involve impersonation and share no gap at all, for reasons we make precise below.

Vendor categories are a description of the market, not of the loss

The other taxonomy in common use is the product category: email security, identity threat detection, transaction risk scoring. It has an obvious flaw, which is that it was drawn by the people selling into it. No vendor benefits from publishing a map showing their category cannot touch most of the losses it is marketed against, so nobody publishes one, and buyers infer coverage from adjacency: this loss involves email, we bought an email product, presumably that helps.

Existing frameworks answer adjacent questions

MITRE ATT&CK catalogues attacker techniques and deliberately says nothing about dollars. The NIST Cybersecurity Framework catalogues defender functions and deliberately says nothing about specific losses. Neither was built to answer "would this control have made this dollar impossible to steal", and it is unfair to criticize them for a job they never claimed. But the job is unfilled, and it is exactly the one the CFO was asking about.

What is the difference between a loss of authentication and a loss of judgment?

Here is the single distinction the whole re-read rests on. Take your time with it, because everything downstream is arithmetic once this is clear.

Imagine a bank branch in 1975. There are exactly two ways for your money to walk out of that branch without your consent, and they are not variations on a theme. They are different failures with different fixes.

In the first, someone forges your signature on a withdrawal slip. The teller compares it to the signature card, is fooled, and hands over the cash. This is a loss of authentication. The bank believed a document came from you and it did not. Every improvement to the signature, better cards, a second comparison, a countersignature, ultraviolet ink, makes this attack harder. In the limit, if the signature became genuinely impossible to forge, this loss goes to zero.

In the second, someone telephones you for six weeks, becomes your friend, explains that your grandson is in jail in another state, and you walk into the branch yourself and sign a real withdrawal slip with your real hand. This is a loss of judgment. The signature is perfect. It is genuinely yours. Making it harder to forge accomplishes precisely nothing, because nothing was forged. The bank did exactly what you asked it to do, and what you asked it to do was the harm.

Hold those two branches side by side, because the industry conflates them constantly. Both end with your money gone. Both get filed under "fraud". Both appear in the same annual total. Only one of them is a signature problem, and only one of them improves when you improve signatures.

Translate to 2026 and the distinction survives intact. An attacker with a stolen session cookie clicking "release payment" in your treasury console is the forged slip: the system believed the request came from your approver and it did not. A person in a pig-butchering scheme transferring their savings to a wallet they have been groomed for four months to trust is the second branch: every cryptographic control performs exactly as designed, and the money is gone, because the human meant to send it.

This is why "total cybercrime losses" is such a poor budgeting instrument. It sums two categories that respond to completely different interventions, in a ratio nobody has published, and hands you the sum.

What is a wedge-fit score?

A wedge-fit score answers one question about a category of loss, on a scale from 0 to 5:

If the authorizing step had required a fresh cryptographic signature, produced on an enrolled device belonging to the accountable human and bound to the exact details of the action, would the loss have been impossible?

The rubric is deliberately narrow. It does not ask whether a loss was preventable in general, because almost everything is given unlimited friction. It asks about one specific control, so the answer means something. Here is the full scale, published before the scores so you can check our work rather than take our word for it.

ScoreNameDefinitionWhat the control achieves
0Victim-authorizedThe accountable human performed the act, knew the payee, and intended the transfer.Nothing. The signature is produced correctly and the money still goes.
1Evidence onlyVictim-authorized, but a signed record of what was displayed would help a later dispute.Better forensics and liability position. No loss prevented.
2Friction-sensitiveVictim-authorized, but the loss depends on speed and on the victim not pausing.Some losses avoided through the pause, none deterministically.
3Partially structuralMixed population: some incidents involve impersonation, others a willing victim.The impersonation slice is prevented. The willing slice is not.
4Structural with a gapAn attacker performed or induced the act, but a residual path remains such as coercion or compromised enrollment.Most of the loss removed. A named residual remains.
5Deterministically preventableAn attacker performed the act while impersonating the accountable human, and could not have produced the signature.The loss becomes impossible without also compromising the enrolled device.

Written as code, so that the judgement calls are visible rather than hidden in prose:

def wedge_fit(category):
    # Who actually performed the step that moved the money or granted access?
    if category.authorizing_actor == "attacker":
        # Could the attacker have produced a signature from the
        # accountable human's enrolled device? If not, the loss stops.
        return 4 if category.has_residual_path else 5

    if category.authorizing_actor == "victim":
        if category.victim_knew_and_intended_the_payee:
            # Judgment loss. A perfect signature changes nothing.
            return 1 if category.dispute_evidence_matters else 0
        if category.victim_acted_on_attacker_supplied_details:
            # The victim signed, but signed the attacker's payload.
            # Binding the signature to verified payee details helps.
            return 4
        return 2  # speed-dependent, a pause helps some of the time

    return 3  # mixed population, score the slices separately

Two decisions in that function deserve argument. Treating "the victim signed the attacker's payload" as a 4 rather than a 2 rests on the payee details themselves being bindable to an enrolled counterparty, so the victim is no longer free to sign an arbitrary destination. The residual-path deduction that turns a 5 into a 4 is usually coercion: a signature proves a human signed, not that they were free when they did it.

How does each loss category score?

Scores below use the published figures listed earlier. Where the IC3 does not separately break out a category in the headline set we are working from, the loss column says so rather than guessing, and that category is excluded from the arithmetic in the next section.

CategoryReported 2025 lossWho performed the authorizing actWedge-fit
Business email compromise$3.046BAttacker, impersonating an executive, employee, or vendor5
Account takeover$262MAttacker, inside the victim's authenticated account5
SIM swap$17.4MAttacker, after seizing the phone number used for recovery5
Real estate wire fraud$275MVictim, on payee details supplied by the attacker4
Elder fraud, AI voice-cloning slice$352MVictim, believing they are helping a specific relative3
AI-related schemes, all types$893MMixed: impersonation of institutions and of individuals3
Employment fraud$363MMostly victim, depositing their own money into a task scheme2
Elder fraud, remainderBalance of $7.7BOverwhelmingly victim, in investment and confidence schemes1
Cryptocurrency-linked losses$11.366BOverwhelmingly victim, in investment schemes1
RansomwareNot in the headline set used hereAttacker, usually after an identity-based initial access4 (entry vector only)
Investment fraudNot separately used hereVictim, intentionally, over weeks or months0
Tech support fraudNot separately used hereVictim, granting access and moving money themselves0

Note that the two largest slices of the report score a 1 and a 0. That is not an accident of our method, it is the finding.

How much of the $20.9 billion is actually addressable?

Add up only the categories scoring 4 or 5 with a published figure:

CategoryScoreLoss
Business email compromise5$3.046B
Real estate wire fraud4$275M
Account takeover5$262M
SIM swap5$17.4M
Totalapproximately $3.60B

That is about 17 percent of the $20.877 billion headline. Roughly $17.3 billion, or 83 percent, is either victim-authorized or not separately broken out in the figures we are willing to publish.

Treat $3.6 billion as a floor, not an estimate of the true addressable total. Several high-scoring categories are folded inside larger lines and never surface separately: payroll diversion sits inside BEC, and the credential-reset social engineering that opens most enterprise ransomware sits inside ransomware. Both would raise the number. The categories that would lower it, investment fraud and the confidence schemes dominating the crypto and elder lines, already score 0 and 1 and contribute nothing. We would rather publish a defensible floor than a flattering estimate. If you want a bigger number, the honest route is better category breakouts from the IC3, not a more generous rubric.

What do the zeros teach us?

This is the section that will annoy our own sales team, and it is the reason the rest of the analysis is worth reading.

The largest single line in the report, cryptocurrency-linked losses at $11.366 billion, is overwhelmingly investment fraud: people persuaded over weeks or months to move real money into a scheme that looked like a return. They logged in correctly. They approved correctly. They typed the destination address themselves, often several times, often after being warned. No cryptographic control prevents this, ours included, because at no point did a machine believe something false about who was acting. The same holds for most of the $7.7 billion reported by people over 60, and for tech support schemes where the victim installs the remote access tool with their own hands.

If a vendor claims their product addresses these categories, ask them to walk you through the exact step at which their control would have said no. The answer usually collapses into risk scoring, which is a probability that a transfer is unusual, not a fact about who authorized it.

What does help here is a different family of interventions, worth naming so the section is not purely negative: mandatory delay on first-time payees, payee-name checking at the receiving bank, reimbursement regimes that give banks a reason to slow down, and opt-in arrangements where a second trusted person must approve unusual transfers. That last one is genuinely a signature control, and it is why the AI voice-cloning slice scores 3 rather than 1. A cloned voice cannot produce a second enrolled signature from an adult child's phone, so the impersonation is defeated even though the parent's judgment was successfully attacked. We covered that shape in how to prove a human is present in 2026.

What do the fives teach us?

Every category scoring 4 or 5 shares one shape, and once you see it you cannot stop seeing it: an attacker performed an action while a system believed the accountable human was performing it.

In BEC, the attacker sends the instruction from a mailbox the system trusts. In account takeover, they operate inside a session issued to someone else. In SIM swap, they receive a recovery code addressed to the victim's number. In real estate wire fraud, the buyer signs a real instruction whose destination was written by someone else. In every case the system's belief about the actor is wrong, and the wrongness is the loss.

These are all, in the strict sense, identity failures, though only one of them is filed that way. That reclassification is the practical payoff of the exercise: four apparently unrelated budget lines share one gap, which means one control covers all four, which makes the buying decision far simpler than the category sheets suggest.

It also says something about phishing-resistant multi-factor authentication that the marketing does not. Every one of these losses happened after a successful authentication, or in a flow where authentication was never the disputed step. Tycoon 2FA, a single adversary-in-the-middle phishing kit, reached more than 96,000 victims across 330 domains before Microsoft, Europol, and partners disrupted it in March 2026 (Microsoft Security blog, 4 March 2026). Its entire product was harvesting live sessions from users who had authenticated correctly, MFA included. Strong login was not the missing control, because login was not where the money moved.

Worked example: scoring business email compromise, step by step

Take the largest 5 in the table and run the rubric properly, since a method you cannot reproduce is just an opinion in a table.

Step one, identify the authorizing act. Not the phishing email, not the mailbox compromise, not the fake invoice. It is the moment a payment is released or a vendor's bank details change in the master file, the step at which the money becomes unrecoverable. Everything before it is preparation.

Step two, identify who performed it. In the vendor-change variant, the attacker performs it directly from a compromised mailbox. In the deepfaked-executive variant, a finance employee performs it on the attacker's instruction with no independent knowledge of the payee. Either way, the accountable human did not knowingly approve this payment to this account.

Step three, ask what would have been required. A signature over the canonical bytes of the action, not over a random challenge. Concretely, something with this shape:

{
  "action":       "payment.release",
  "amount":       "42150.00",
  "currency":     "USD",
  "beneficiary":  "Northwind Fabrication LLC",
  "account_last4":"8812",
  "routing":      "021000021",
  "invoice":      "INV-2026-4471",
  "requested_by": "ap-clerk-114",
  "timestamp":    "2026-09-03T14:22:07Z"
}

The approver's device hashes that object, displays the amount and beneficiary on its own screen, and signs the hash. The resulting receipt says one thing precisely: this enrolled human confirmed this payload at this moment. It verifies later against a published key with no callback to anyone.

Step four, ask whether the attacker could produce it. The attacker holds the mailbox, the session, the invoice, and in the worst case a convincing video likeness of the CFO. They do not hold the approver's enrolled device. The signature cannot be produced. The release fails. Score: 5.

Step five, look for the residual. Enrollment. If the attacker controls the process by which a device is first bound to a human, they control everything downstream, which is why we score 4 rather than 5 whenever the enrollment path is routinely exposed to the same attacker. For BEC in a functioning enterprise, enrollment happens at onboarding under separate controls, so the 5 holds. The full flow is in the signing demo and the payload and receipt formats in the developer documentation.

What are the limits of this method?

Four, and they are real. We would rather list them than have a reviewer find them.

The underlying data is self-reported and undercounts. Large corporate losses often go to counsel, insurers, and regulators rather than the IC3, so both the numerator and the denominator in our 17 percent are understated, not necessarily by the same factor. The ratio is more reliable than either absolute number, but it is not exact.

Categories overlap. A ransomware event that began with a help-desk credential reset and ended with an extortion payment touches three lines. We handled this by excluding categories we cannot separate cleanly, which biases the addressable figure downward. Anyone rerunning the method should state which overlaps they resolved and how.

A signature-required step can still be socially engineered. The control makes it impossible for the attacker to produce the signature, not impossible for them to convince the real approver to produce it. What changes is the attack's cost and shape: the attacker must reach a specific person, get them to confirm a screen showing the real amount and the real beneficiary, and do it inside the signature's validity window. Much narrower than sending an email, but not closed. Coercion defeats every cryptographic control ever built.

Scoring is a judgement, not a measurement. We assigned these numbers. Someone applying the same rubric could reasonably score employment fraud a 3 rather than a 2, on the grounds that a verified-employer signature would collapse the fake-job funnel. We would listen. That is precisely why the rubric is published above the scores rather than below them.

What should you do with this on Monday?

The point of an analysis is a different decision, so here is the shortest path to one.

  1. Write down your five highest-value actions, not your five biggest systems. Payment release, vendor bank-detail change, payroll bank-detail change, privileged access grant, and data export is a good starting list for most organizations.
  2. For each one, answer a single question: if an attacker held a valid session for the person who normally performs it, what would stop them? Write the answer down. If the answer is "an alert would fire", that is detection, and it fires after the fact.
  3. Score your own incident history with the rubric above, including near misses from the last two years. The distribution tells you more about your exposure than any industry report.
  4. Separate your authentication metric from your authorization metric. "Percent of logins on phishing-resistant MFA" is a real number and you should keep it. Add a second one: "percent of high-value actions requiring an action-bound signature". Most organizations discover the second number is zero.
  5. Stop buying against the headline total. When a vendor cites $20.9 billion, ask which of their covered categories score 4 or 5 by this rubric and which score 0. A vendor who cannot name their own zeros is describing a market, not a control.
  6. Ask your insurer what they will price. A control producing an offline-verifiable receipt is unusually easy for an underwriter to audit, because they can check it without trusting you or us.
  7. Fix enrollment before you fix anything else. Every control in the 4 and 5 categories rests on the binding between a human and their device. If that binding can be established by someone with a stolen mailbox, you have moved the attack rather than stopped it.

Why this becomes an annual series

The 2025 report is the first with a dedicated line for AI-enabled schemes, so 2026 gives the first comparison. Agentic commerce, where software buys and moves money on a person's behalf, will start appearing as its own kind of dispute, and "who authorized this" gets harder to answer, not easier. We covered that shape in agentic commerce and chargeback liability and how to prove an agent is authorized. So this repeats annually, same rubric, same order: method, scores, arithmetic, zeros. If the addressable percentage moves, that movement is the finding. If somebody publishes a better rubric, we will use theirs.

Frequently asked questions

How much of the FBI's 2025 internet crime losses were preventable? By a human-intent signature at the moment of authorization, roughly $3.6 billion of the $20.877 billion total, about 17 percent, using published category figures. That covers business email compromise, account takeover, SIM swap, and real estate wire fraud. The remainder is dominated by investment and confidence schemes the victim authorized deliberately, where no cryptographic control applies.

What were the total IC3 losses in 2025? The FBI's Internet Crime Complaint Center reported $20.877 billion in losses across 1,008,597 complaints for 2025, the first year complaints exceeded one million and roughly a 26 percent increase in reported losses over 2024. Cryptocurrency-linked losses were the largest slice at $11.366 billion.

What is a wedge-fit score? A 0 to 5 rating of whether requiring a fresh signature from the accountable human's enrolled device, bound to the exact details of the action, would have made a loss impossible. Zero means the victim knowingly authorized the payment. Five means an attacker acted as someone else and could not have produced the signature.

Which cybercrime categories does multi-factor authentication not stop? Any loss occurring after a successful login. Business email compromise, account takeover via stolen session cookies, payroll and vendor diversion, and help-desk credential resets all happen inside authenticated sessions or through recovery flows. Adversary-in-the-middle kits harvest live sessions from users who authenticated correctly, MFA included.

Why do investment fraud and romance scams score zero? The victim performed the authorizing act deliberately, knew the payee, and intended the transfer. Nothing was forged, so improving signatures changes nothing. These categories respond to delay, payee verification at the receiving bank, and reimbursement regimes, not to authentication.

Does a required signature stop someone tricked into signing? No. It stops the attacker acting as that person, a different and larger share of losses. Someone deceived into confirming a payment on their own device produces a valid signature. That residual is why coercion and social engineering keep several categories at 4 rather than 5.

Sources

  1. FBI Internet Crime Complaint Center, 2025 Internet Crime Report. ic3.gov/AnnualReport/Reports
  2. FBI press release on the 2025 report, cryptocurrency and AI scheme figures. fbi.gov
  3. FBI IC3 public service announcement on account takeover fraud, 25 November 2025. ic3.gov/PSA
  4. Microsoft Threat Intelligence, Inside Tycoon2FA: how a leading AiTM phishing kit operated at scale, 4 March 2026. microsoft.com
  5. CertifID, 2026 State of Wire Fraud Report. certifid.com
  6. MITRE ATT&CK. attack.mitre.org
  7. NIST Cybersecurity Framework. nist.gov/cyberframework
The headline number measures harm. Budgets are spent on controls. Until somebody scores one against the other, every security purchase is an argument from adjacency.