Sitemap

Analysis | FBI Releases the 2025 Internet Crime Report

--

Press enter or click to view image in full size

On April 7, 2026, the Federal Bureau of Investigation (FBI) released the 2025 Internet Crime Report. The report coincides with the 25th anniversary of the FBI Internet Crime Complaint Center (IC3). Based on over 1 million complaints collected in 2025, it provides an in-depth analysis of the historic loss scale exceeding $20.8 billion, victim profiles, and core crime categories such as investment fraud, while also placing special emphasis on the evolution of artificial intelligence (AI) in online scams and breakthroughs by law enforcement in asset recovery.

This article provides an interpretation of the core contents of the report, helping readers quickly grasp the evolving dynamics of global cybersecurity threats in 2025, and improve their awareness of and ability to defend against complex online scams and AI-driven threats.

Press enter or click to view image in full size

Key Point 1: IC3 Complaint Data in 2025

1. Overall Situation

In 2025, IC3 received a total of 1,008,597 complaints, with total reported losses reaching $20.877 billion, a 26% increase compared to 2024. The average loss per incident was approximately $20,699. Among these, 85% of losses were caused by online fraud.

Press enter or click to view image in full size

2. Cryptocurrency-related Situation

There were a total of 181,565 cryptocurrency-related complaints, resulting in cumulative losses of $11.366 billion, a 22% increase compared to 2024. Among these complaints, 18,589 investors suffered losses exceeding $100,000. Across all complainants, individuals aged over 60 accounted for the largest proportion.

Press enter or click to view image in full size

Key Point 2: Analysis of Victim Groups

1. Overall Age Distribution

  • Aged 60 and above: 201,266 complaints, with losses of approximately $7.75 billion.
  • Aged 50–59: 124,820 complaints, with losses of approximately $3.68 billion.
  • Aged 40–49: 167,066 complaints, with losses of approximately $2.96 billion.
  • Aged 30–39: 153,293 complaints, with losses of approximately $1.74 billion.
  • Aged 20–29: 112,069 complaints, with losses of approximately $560 million.
  • Under 20: 31,254 complaints, with losses of approximately $67.1 million.
Press enter or click to view image in full size

2. Cryptocurrency Victim Groups

In cryptocurrency investment scams, individuals aged 60 and above accounted for the highest number of complaints (13,685 complaints), with total losses reaching $2.76 billion, far exceeding other age groups. This cohort was also the most heavily affected in cryptocurrency ATM/kiosk scams, with 6,188 related complaints and losses of approximately $257 million. Due to limited familiarity with emerging financial technologies and payment methods (such as cryptocurrency ATMs and QR-code transfers), as well as relatively weaker fraud awareness, individuals over 60 have become a primary target for scammers.

It is also worth noting that many victims, after being defrauded once, were subsequently targeted again through so-called “fund recovery services.” In these “recovery scams,” this same age group again ranked first, recording 2,529 complaints and losses exceeding $540 million.

Press enter or click to view image in full size

3. Main Crime Types Affecting Individuals Aged 60 and Above

  • Crime types with the highest number of complaints: :phishing /spoofing, tech /customer support, investment, personal data breach, and confidence / romance.
  • Crime types causing the highest financial losses:investment , tech / customer support, confidence/ romance , business email compromise (BEC), and government impersonation.
Press enter or click to view image in full size

Key Point 3: Analysis of Crime Types

1. By Number of Complaints

  • Phishing / Spoofing:191,561 complaints.
  • Extortion:89,129 complaints .
  • Investment:72,984 complaints.
  • Personal data breach:67,456 complaints .
  • Non-payment / non-delivery:56,478 complaints .
Press enter or click to view image in full size

2. By Amount of Losses

  • Investment: approximately $8.649 billion.
  • Business Email Compromise (BEC): approximately $3.047 billion.
  • Tech / Customer Support: approximately $2.135 billion.
  • Personal Data Breach: approximately $1.315 billion.
  • Confidence / Romance: approximately $929 million.
Press enter or click to view image in full size

3. Cryptocurrency-related Crimes

  • Most reported: investment (61,559 complaints), extortion (23,797 complaints).
  • Highest losses: investment (approximately $7.28 billion), tech / customer support (approximately $1.23 billion).

Key Point 4: Online Fraud and Law Enforcement Outcomes

1. Overall Situation of Online Fraud

In 2025, IC3 received 452,868 online fraud complaints, resulting in $17.697 billion in losses, accounting for 85% of the total annual losses.

Press enter or click to view image in full size

The transaction types with the highest number of complaints include cryptocurrency, wire transfer / ACH, debit card / credit cards, peer-to-peer transfer, gift card / prepaid card, check / cashier’s check, and cash.

Press enter or click to view image in full size

2. Typical Fraud Methods

  • Account takeover: approximately 4,700 complaints, with losses of $359.7 million.
  • Gold courier scams: approximately 725 complaints, with losses of $311.8 million.
  • Investment club scams: approximately 1,600 complaints, with losses of $160 million.
  • Government impersonation: approximately 32,000 complaints, with losses of $798 million.
Press enter or click to view image in full size

3. Cyber Threats

In 2025, the types of cyber threats reported to IC3 included:

  • Data breach: accounting for 39%, the most reported type.
  • Ransomware:accounting for 36%, ranking second.
  • SIM swap:accounting for 10%.
  • Malware:accounting for 9%.
  • Botnet:accounting for 7%.
Press enter or click to view image in full size

Among these, 3,600 ransomware complaints resulted in more than $32 million in losses. Major ransomware variants included Akira, Qilin, INC./Lynx/Sinobi, BianLian, Play, RansomHub, LockBit, DragonForce, SAFEPA, and Medusa.

Press enter or click to view image in full size

In response to the frequent occurrence of ransomware attacks, the FBI recommends that businesses and organizations adopt the following key protective measures:

  • Create offsite or offline backups, and regularly maintain backup and recovery mechanisms;
  • Remove default passwords and credentials when installing software;
  • Disable and remove unnecessary protocols by default;
  • Enable multi-factor authentication (MFA) for all services whenever possible;
  • Protect initial access entry points;
  • Implement network segmentation to prevent ransomware from spreading;
  • Timely update all operating systems, software, and firmware.

4. Asset Recovery Achievements

  • In 2025, the FBI RAT, through FFKC, intercepted 3,900 cases and froze $679 million in funds, achieving a 58% interception success rate.
  • “Operation Level Up” issued alerts to more than 8,000 victims and helped prevent over $500 million in potential losses for these victims.
  • In cooperation with Indian law enforcement agencies, the FBI targeted call center scams, resulting in more than 475 arrests through 27 joint operations.
  • In financial fraud initiatives, multiple large-scale funds were successfully frozen and recovered.

Key Point 5: The Use of Artificial Intelligence (AI) in Cybercrime

1. Overall Situation

In 2025, IC3 received more than 22,000 complaints involving AI-related information. These complaints resulted in total losses exceeding $893 million.

Press enter or click to view image in full size

2. By Number of Complaints

  • Investment : 4,356 complaints.
  • Extortion: 1,764 complaints.
  • Personal Data Breach: 1,204 complaints.
  • Phishing / Spoofing: 803 complaints.
  • Harassment / Stalking: 763 complaints.
Press enter or click to view image in full size

3. By Amount of Losses

  • Investment: approximately $632.04 million.
  • BEC: approximately $30.26 million.
  • Tech / customer support: approximately $19.46 million.
  • Romance / Confidence: approximately $19.04 million.
  • Personal Data Breach: approximately $18.77 million.
Press enter or click to view image in full size

4. Specific Applications of AI in Typical Scam Scenarios

According to the report, AI has been widely used in the following typical scam scenarios:

  • Business Email Compromise (BEC): AI is used to generate emails that mimic the tone of senior executives, or to produce voice-cloned instructions for fund transfers. In 2025, related losses exceeded $30 million.
  • Romance / Confidence: AI is used to generate fake identities and scripted conversations, and even to simulate family members in distress through voice cloning. Related losses exceeded $19 million.
  • Employment : Voice spoofing or deepfake technology is used during remote interviews to gain access to internal corporate systems, with losses approaching $13 million.
  • Investment : AI is used to mass-generate personalized communication content and to create fake celebrity or authority endorsements in videos and audio. Related losses exceeded $632 million.

Overall, AI is lowering the barrier to fraud while significantly enhancing its scalability and deception capabilities.

Conclusion

The FBI’s 2025 Internet Crime Report further reveals the deep structural evolution of today’s cybercrime ecosystem: on one hand, the scale of fraud continues to rise, with cryptocurrencies remaining a key vehicle for fund transfers and money laundering; on the other hand, criminal tactics are rapidly shifting from traditional “opportunistic fraud” toward more precise and industrialized operations. This is especially evident in the high-intensity targeting of elderly populations and the proliferation of “recovery scams,” both of which reflect attackers’ deep exploitation of victims’ psychology and behavioral patterns. At the same time, the introduction of artificial intelligence has significantly lowered the barrier to fraud while amplifying attack efficiency, pushing cyber fraud toward a complex threat system characterized by automation and large-scale deployment.

Although law enforcement agencies have achieved incremental progress in fund interception and cross-border cooperation, the overall scale of losses and upward trend indicate that the risk landscape remains severe. For everyday users, developing basic risk awareness and anti-fraud literacy has become an essential skill in the digital era. For industry participants and regulators, the key challenge ahead lies in enhancing the ability to identify fund flows, behavioral patterns, and anomalous signals through technological means, while strengthening cross-regional coordination — an essential step in addressing the next generation of cybercrime.

About SlowMist

SlowMist is a threat intelligence firm focused on blockchain security, established in January 2018. The firm was started by a team with over ten years of network security experience to become a global force. Our goal is to make the blockchain ecosystem as secure as possible for everyone. We are now a renowned international blockchain security firm that has worked on various well-known projects such as HashKey Exchange, OSL, MEEX, BGE, BTCBOX, Bitget, BHEX.SG, OKX, Binance, HTX, Amber Group, Crypto.com, etc.

SlowMist offers a variety of services that include but are not limited to security audits, threat information, defense deployment, security consultants, and other security-related services. We also offer AML (Anti-money laundering) software, MistEye (Security Monitoring), SlowMist Hacked (Crypto hack archives), FireWall.x (Smart contract firewall) and other SaaS products. We have partnerships with domestic and international firms such as Akamai, BitDefender, RC², TianJi Partners, IPIP, etc. Our extensive work in cryptocurrency crime investigations has been cited by international organizations and government bodies, including the United Nations Security Council and the United Nations Office on Drugs and Crime.

By delivering a comprehensive security solution customized to individual projects, we can identify risks and prevent them from occurring. Our team was able to find and publish several high-risk blockchain security flaws. By doing so, we could spread awareness and raise the security standards in the blockchain ecosystem.

--

--

SlowMist
SlowMist

Written by SlowMist

SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.