Executive Summary
In 2025, the FBI's Internet Crime Complaint Center (IC3) reported that Americans lost nearly $21 billion to cyber-enabled crimes, marking a 26% increase from the previous year. The most prevalent incidents included phishing attacks, extortion, and investment scams, with cryptocurrency-related fraud accounting for over $11 billion in losses. Notably, individuals over the age of 60 were disproportionately affected, reporting $7.7 billion in losses, a 37% rise from 2024. Additionally, the FBI highlighted the emergence of AI-driven scams, which resulted in 22,300 complaints and $893 million in losses, involving tactics such as voice cloning and deepfake videos.
This surge underscores the evolving sophistication of cybercriminals, who are increasingly leveraging advanced technologies like artificial intelligence to enhance the effectiveness of their schemes. The significant financial impact on older adults highlights the urgent need for targeted education and robust cybersecurity measures to protect vulnerable populations from these emerging threats.
Why This Matters Now
The rapid escalation in cybercrime losses, particularly through AI-driven scams and cryptocurrency fraud, emphasizes the critical need for enhanced cybersecurity awareness and proactive defense strategies to safeguard individuals and organizations against increasingly sophisticated digital threats.
Attack Path Analysis
The adversary initiated the attack by sending phishing emails to employees, leading to the compromise of email accounts. Using the compromised accounts, they escalated privileges to access sensitive systems. They then moved laterally within the network to identify and access critical data. Established command and control channels allowed them to maintain persistent access. The adversary exfiltrated sensitive data to external servers. Finally, they leveraged the stolen data to conduct financial fraud, resulting in significant monetary losses.
Kill Chain Progression
Initial Compromise
Description
The adversary sent phishing emails to employees, leading to the compromise of email accounts.
MITRE ATT&CK® Techniques
Phishing
Financial Theft
Impersonation
Phishing for Information
Spearphishing via Service
Phishing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for detecting and responding to failures are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
DORA – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Implement robust identity and access management controls.
Control ID: Identity and Access Management
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Investment scams and cryptocurrency fraud drove $19.6 billion in losses, requiring enhanced egress security and anomaly detection for transaction monitoring.
Health Care / Life Sciences
Healthcare identified as most targeted critical infrastructure sector, needing zero trust segmentation and encrypted traffic protection for patient data.
Information Technology/IT
IT sector faces multi-vector attacks including ransomware and data breaches, requiring comprehensive cloud firewall and threat detection capabilities.
Government Administration
Government facilities targeted in critical infrastructure attacks, necessitating secure hybrid connectivity and multicloud visibility for sensitive operations protection.
Sources
- FBI: Americans lost a record $21 billion to cybercrime last yearhttps://www.bleepingcomputer.com/news/security/fbi-americans-lost-a-record-21-billion-to-cybercrime-last-year/Verified
- FBI Releases Annual Internet Crime Reporthttps://www.fbi.gov/news/press-releases/fbi-releases-annual-internet-crime-reportVerified
- Internet Crime Complaint Center (IC3) | Threat Actors Spoofing the FBI IC3 Website for Possible Malicious Activityhttps://www.ic3.gov/PSA/2025/PSA250919Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it embeds security directly into the cloud infrastructure, potentially limiting the adversary's ability to move laterally and exfiltrate data. By enforcing identity-aware controls and dynamic segmentation, CNSF could likely reduce the attacker's reach and minimize the blast radius of the breach.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While CNSF primarily focuses on intra-cloud security, its comprehensive visibility into network traffic could potentially aid in identifying and mitigating unauthorized access resulting from compromised credentials.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation could likely constrain the adversary's ability to escalate privileges by enforcing strict access controls and limiting lateral movement within the network.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security could likely limit the adversary's lateral movement by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control could likely detect and disrupt command and control channels by providing comprehensive monitoring across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement could likely prevent data exfiltration by controlling and monitoring outbound traffic.
By potentially limiting the adversary's ability to exfiltrate sensitive data, CNSF could likely reduce the risk of financial fraud and associated monetary losses.
Impact at a Glance
Affected Business Functions
- Financial Transactions
- Customer Data Management
- Email Communications
- Technical Support Services
Estimated downtime: N/A
Estimated loss: $21,000,000,000
Personal and financial information of victims, including PII and sensitive financial data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement advanced email filtering and anti-phishing solutions to detect and block malicious emails.
- • Enforce multi-factor authentication (MFA) to prevent unauthorized access even if credentials are compromised.
- • Deploy Zero Trust Segmentation to limit lateral movement within the network.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound data transfers.
- • Establish comprehensive Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious activities promptly.



