Skip to Content
listen live
Home

U.S. States Where Businesses Are Most Exposed to Cybercrimes

U.S. States Where Businesses Are Most Exposed to Cybercrimes

Photo Credit: FaceStock / Shutterstock



A cyberattack against a business can reach well beyond the company that was initially targeted. A fraudulent payment can divert hundreds of thousands of dollars, ransomware can bring operations to a halt, and a data breach can expose information belonging to customers, employees, or business partners. The effects can also ripple through supply chains and other organizations that depend on the victim. As businesses have become more reliant on digital systems to manage payments, communications, customer information, and day-to-day operations, cybersecurity has increasingly become a question of financial and operational resilience, not simply an IT concern.

That risk has moved higher on Washington’s agenda. In March 2026, the White House issued Executive Order 14390, calling for stronger financial and digital defenses against cybercrime and a more coordinated effort to disrupt transnational cybercriminal networks. Congress has also turned its attention to whether smaller companies have the resources to protect themselves, advancing the Small Business Cybersecurity Assistance Evaluation Act of 2026 and reinforcing a broader concern that cyberattacks can pose a greater risk to the economy than previously.

To assess where those risks are most concentrated, Opstream—an AI-native procurement orchestration software platform for enterprises—analyzed FBI Internet Crime Complaint Center records covering business email compromises, data breaches, ransomware, and intellectual property-related offenses. The findings show wide differences across states in both reported incidents and financial losses, offering a view into where businesses appear most exposed to some of the most costly forms of cybercrime.

Here are the key takeaways from the analysis:

  • Business email compromise (BEC) dominates both the frequency and financial cost of business cybercrime. Nearly 25,000 reported BEC victims accounted for more than $3 billion in losses in 2025.
  • Reported business cybercrime surged in 2025 after years of relative stability. Incidents increased 18% to 34,728, while reported losses topped $3.5 billion, up 74% from 2020.
  • California has the most corporate cybercrime victims, but Alaska has the highest concentration relative to its business population. California recorded 4,725 victims, while Alaska led on a relative basis at 47.3 victims per 10,000 businesses.
  • Western states are disproportionately represented among states with high rates of reported corporate cybercrime. Alaska, Arizona, Washington, Nevada, Colorado, Wyoming, and Utah all rank in the top 15 after accounting for the size of their business populations.

Which Types of Cybercrime Cause the Most Damage to U.S. Businesses?

Business email compromise (BEC) accounts for over $3 billion in corporate losses, far outpacing data breaches, ransomware, and IP theft combined


Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream

Business email compromise (BEC) was both the most prevalent and by far the most costly major cybercrime affecting U.S. businesses in 2025. A staggering 24,768 BEC incidents were reported nationwide, resulting in just over $3 billion in losses. These email scams account for nearly nine out of every 10 dollars lost to cybercrimes perpetrated against U.S. businesses when analyzed with business data breaches, ransomware, and intellectual property-related offenses. By comparison, data breaches resulted in about $435 million in losses, while reported losses associated with ransomware and intellectual property offenses were considerably smaller.

BEC can be so costly because the fraud often resembles an ordinary business transaction. A criminal might pose as a familiar vendor and email an employee about a legitimate-looking invoice but provide new banking instructions that send the payment to an account controlled by the scammer. In one FBI-documented case, criminals researched companies and posed as trusted vendors in emails instructing employees where to send payments. Two companies ultimately wired more than $120 million to fraudulent bank accounts. Other BEC schemes use similar tactics, including emails that appear to come from company executives or business partners requesting urgent payments or changes to payment instructions.

The other major threats work differently. A business data breach occurs when an intruder obtains confidential or protected information from corporate systems, while ransomware restricts access to systems or data and typically demands payment for their release. Intellectual property offenses target assets such as trade secrets, proprietary products, software, and copyrighted material. The number of reported incidents also varies sharply among these categories: BEC alone accounted for the large majority of incidents in 2025, while data breaches, ransomware, and intellectual property offenses made up a much smaller share. Importantly, these totals represent only incidents reported to the FBI. Cybercrimes that businesses discover but never report fall outside the figures entirely, meaning the tens of thousands of incidents and billions of dollars in losses documented each year represent only the known portion of a larger problem.

How Much Are U.S. Businesses Losing to Cybercrime?

The reported number of corporate victims surged 18% in 2025 to nearly 35,000 while total losses exceeded $3.5 billion


Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream

The financial burden of cybercrime on U.S. businesses has increased substantially since 2020, even though the number of reported incidents remained relatively stable for much of that period. Annual incidents hovered between roughly 28,800 and 29,500 from 2020 through 2024, before departing sharply from that pattern in 2025. Reported incidents increased 18% to nearly 34,700, the highest level in six years.

Financial losses had been rising well before the recent increase in reported incidents. Businesses lost about $2.0 billion in 2020, rising to $2.6 billion in 2021, $3.2 billion in 2022, and nearly $3.5 billion in 2023. Losses declined modestly to about $3.2 billion in 2024 before returning to roughly $3.5 billion in 2025. Overall, annual reported losses were 74% higher in 2025 than in 2020, despite relatively little change in the number of incidents during most of those years. The divergence suggests that the financial consequences of individual cybercrimes have become more severe over time.

Several changes in how businesses operate and how cybercriminals target them may be contributing to the rising financial toll. Companies now depend heavily on digital payments, cloud-based systems, and online communications for routine transactions, creating more opportunities for criminals to intercept payments, compromise business accounts, or disrupt operations. Those risks are evolving as well. The FBI has warned that criminals are using generative AI to create more convincing messages and impersonations, making fraud more difficult to recognize. As these tactics become more sophisticated, even a single successful attack can expose a business to substantial financial losses.

Where Corporate Victims of Cybercrime Are Concentrated the Most

California leads the nation in overall corporate victims of cybercrime while Alaska reports the highest density


Source: Opstream analysis of the FBI’s Internet Crime Complaint Center data | Image Credit: Opstream

The states with the most corporate cybercrime victims tend to be among the nation’s largest business centers. California recorded 4,725 reported victims in 2025, more than any other state, followed by Texas with 3,027, Florida with 2,687, and New York with 2,322. Together, those four states accounted for more than one-third of reported victims nationwide. Their prominence is largely a reflection of scale, since each is home to a large number of businesses and, consequently, a larger pool of potential targets.

Adjusting for the number of businesses changes the geographic picture considerably. Alaska had the nation’s highest concentration, with 47.3 reported victims per 10,000 businesses, followed by Arizona at 36.9, Washington at 36.1, Texas at 35.3, and Nevada at 34.9. Western states are especially prominent near the top of the ranking, with Colorado, Wyoming, and Utah also reporting relatively high rates. This puts much of the West above the national average for reported corporate cybercrime exposure, even though the largest numbers of victims remain concentrated in the country’s biggest state economies.

Unlike burglary or other crimes that require proximity to a victim, cybercriminals can target a company from virtually anywhere, making the location of the attacker less important than the characteristics of the businesses being targeted. Business email compromise, which accounts for the majority of reported corporate cybercrime victims, is particularly illustrative. The FBI says these schemes target businesses of all sizes and often exploit routine relationships with executives, vendors, and suppliers to redirect payments. As a result, a state does not need a large technology or financial sector to record substantial exposure. Businesses that regularly transfer money, rely heavily on email and other digital communications, or work with outside vendors can be targeted regardless of where they are headquartered. As companies become more dependent on third parties, evaluating and monitoring vendor risk has also become an important part of managing their broader security exposure.

For more information about how the study was conducted, see the methodology section below. For complete results, see the original report on Opstream: U.S. States Where Businesses Are Most Exposed to Cybercrimes

Methodology


Photo Credit: FaceStock / Shutterstock

The cybercrime data used in this analysis is from the FBI Internet Crime Complaint Center’s (IC3) 2025 Internet Crime Report, with historical national figures drawn from IC3 reports dating back to 2020. Business-related cybercrime was defined to include business email compromise (BEC), data breaches, ransomware, and intellectual property rights/copyright and counterfeit offenses. Victim counts represent the total number of reported incidents across these categories and do not necessarily represent unique businesses, as the same organization may experience or report multiple cybercrimes during the year.

To determine the states where businesses are most exposed to cybercrime, researchers at Opstream calculated the number of reported corporate cybercrime victims per 10,000 businesses in each state. States were ranked according to this rate, with the state reporting the higher total number of corporate victims ranked higher in the event of a tie. Victim location corresponds to the headquarters of the affected business.

The FBI’s IC3 statistics include only cybercrimes reported to the agency, meaning unreported incidents are not reflected in the results. Additionally, the FBI’s ransomware figures are not limited exclusively to businesses and may include other types of victims. Ransomware was included because businesses and critical infrastructure organizations are primary targets of these attacks and can face significant financial and operational consequences when their systems are compromised.

For complete results, see U.S. States Where Businesses Are Most Exposed to Cybercrimes on Opstream.