Mark Beare, Head of Consumer, Malwarebytes.

In March, the world’s largest police organization, INTERPOL, released its 2026 Global Financial Fraud Threat Assessment. Among the findings was this startling figure: The global scam economy generated an estimated $442 billion in losses in 2025. That’s just shy of the economic output of Denmark.

By INTERPOL’s own assessment, scamming is now an industry in its own right, in the same league as the global drug trade or human trafficking as a source of organized crime revenue.

The report warned that financial fraud represents a growing global threat, with losses expected to rise significantly over the coming years.

Most executives will read that and come to the same conclusion: It’s unfortunate, but largely a consumer problem.

I think that’s becoming an increasingly risky—and expensive—assumption.

The Disappearing Line Between Consumer Fraud And Enterprise Risk

I lead the consumer business at Malwarebytes, which gives me an inside view of how online fraud is evolving. Not only are scams continuing to get more sophisticated, but the line between consumer fraud and enterprise risk is disappearing.

Companies have traditionally focused on protecting the business itself from threats like ransomware, data breaches, business email compromise and attacks on corporate systems. Scams targeting individuals—fake online stores, romance scams, investment fraud and impersonation schemes—have generally been viewed as a separate problem.

But criminals are no longer making that distinction.

The same scammers targeting individuals are now using similar techniques against employees, vendors and businesses. For instance, information stolen from consumers becomes intelligence for attacks on companies, trusted brands become tools for impersonation campaigns and employees become targets at work and at home, often using identical tactics. ​

That’s why scams deserve far more attention in boardrooms than they receive today. According to the World Economic Forum, in 2025, some 77% of business leaders around the world reported an increase in fraud over the past year.

The Dominant Attack Vector

Brand impersonation is one example of how this change is playing out. The Federal Trade Commission (FTC) reported that Americans lost $3.5 billion to imposter scams in 2025, nearly triple what was reported five years earlier, with business and government impersonators alone accounting for close to $2 billion of that total.

Meanwhile, business email compromise caused more than $3 billion in reported losses last year, found the FBI. Rather than relying on malware, this type of scam operates by convincing someone to trust an email, approve an invoice or authorize a payment that looks legitimate. According to the World Economic Forum’s most recent identity fraud analysis, payment fraud has surpassed identity document fraud for the first time as the dominant attack vector.

In other words, rather than breaching the gate, criminals are embedding themselves inside of legitimate transactional flows, where the money already is. This puts the onus of protection back on employees and their ability to discern the real from the fake—a vulnerability that no firewall addresses.

Google and Facebook learned this firsthand. A scammer posing as a legitimate hardware supplier collected more than $100 million from the two companies by sending fraudulent invoices, according to the Department of Justice. The attack worked because someone approved an invoice that appeared to come from a trusted supplier. ​

While the financial loss is significant, the reputational damage to the targeted company can cause even greater harm in the form of customer churn, increased support costs as victims seek resolution and long-term erosion of the conversion rates that marketing budgets are designed to help grow.

What customers who have been scammed remember is pretty simple: Interacting with your brand ended badly. Every successful impersonation campaign erodes trust that organizations spend years and significant marketing budgets building.

The Rise Of AI-Driven Scams​

AI is making a bad situation worse. INTERPOL’s assessment found that AI-enhanced fraud is already 4.5 times more profitable than traditional methods. The same technologies companies use to improve customer service, automate communications and personalize marketing are also making it cheaper for criminals to produce convincing emails, realistic voice calls, polished websites and highly targeted scams at scale. The cost of executing a fraud campaign that would have required a criminal organization five years ago is now within reach of anyone with a laptop and a subscription.

And awareness hasn’t kept pace with the technology. Malwarebytes’ own research has found that roughly half of people feel unprepared for AI-driven scams.

What Executives Should Be Doing Today

This changes how organizations should think about risk. As scams become more sophisticated and pervasive, leaders should rethink how their organizations identify, measure and respond to cybercrime as an enterprise-wide business risk.

1. Measure Scam Exposure The Way You Measure Other Enterprise Risks​

For companies, the impact extends well beyond the victim. Revenue, customer trust, payment systems and brand reputation are all on the line. How often is your brand being impersonated? How many customer support requests stem from fraud? What does a successful impersonation campaign cost in lost customers or diminished trust?

Start by being transparent with your own customers about how you communicate. Publish which email addresses and phone numbers are legitimately yours, and be explicit about what you will and will not ask for by email. That will help someone distinguish a genuine message from a fake one.

2. Focus Your Defenses Where The Risk Is Highest​

Many of today’s biggest frauds begin with an email, an invoice or a payment request that looks completely legitimate. Finance, procurement and anyone responsible for approving payments or managing vendors are on the front line of these attacks. They need training that’s tailored to the scams they’re most likely to encounter, ideally using real examples of how criminals operate. The investment is relatively small compared with the cost of a single successful fraud.

3. Stop Treating Consumer Security And Enterprise Security As Separate Conversations

Customers, employees and businesses all operate in the same digital ecosystem, and criminals move easily between them using information gathered in one place to launch attacks somewhere else.

The Bottom Line​

A scam targeting one of your customers today can become an attack on one of your employees tomorrow. ​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version