What this covers:
- What the Florida business cybercrime numbers actually say
- Why Florida business cybercrime clusters in email scams
- Where Florida business cybercrime losses come from
- Density matters more than state size
- The cost of Florida business cybercrime beyond the dollars
- 5 controls that cut your exposure
- FAQ
Florida business cybercrime reached 2,687 reported business victims in 2025, with $237,842,777 in reported losses — about $88,516 per affected organization. The figures come from an Opstream analysis of FBI Internet Crime Complaint Center (IC3) data and place Florida third nationally for corporate victims, behind California (4,725) and Texas (3,027). Those four leading states account for more than a third of all reported business victims in the country.
For a South Florida company, the ranking matters less than the mechanics. Which attacks land, what they cost, and which controls change the odds — that is what a business can act on.
What the Florida business cybercrime numbers actually say
The state figure sits inside a trend that has not slowed. The FBI’s 2025 IC3 Annual Report logged more than one million complaints and over $20.9 billion in reported losses — a 26% increase over 2024. Cyber-enabled fraud accounted for 452,868 complaints and $17.7 billion, or 85% of all reported losses, with business email compromise alone driving $3.05 billion across 4,566 complaints. Statewide, Florida reached 71,843 complaints and roughly $1.6 billion, third in the nation in both categories.
For local companies the pattern is consistent: email scams dominate by victim count, a few categories drive nearly all the losses, and the money usually leaves as a payment rather than as a ransom.
Why Florida business cybercrime clusters in email scams
Of Florida’s 2,687 reported business victims, 2,025 — about 75% — reported an email-based scam such as business email compromise. Data breaches accounted for 283 victims, ransomware attacks 195, and counterfeiting and intellectual property theft 184. That distribution is the most useful fact in the dataset for a business deciding where to spend.
Email wins because it needs no exploit and no malware. A lookalike domain, a spoofed display name, and a payment-change request arriving in a busy week is enough. The FBI describes these schemes as targeting businesses of every size and leaning on routine relationships with executives, vendors and suppliers to make the request look ordinary — an invoice update, a new bank account, a rush wire before month end. The failure is rarely technical. It is a request that should have been verified by phone and was approved by reply.
Where Florida business cybercrime losses come from
Reported losses totaled $237,842,777, an average of about $88,516 per victim company — a figure that hides the range, since a redirected $9,000 invoice and a seven-figure wire each count once.
Speed is what makes payment fraud expensive. IC3’s recovery team froze more than $507 million in domestic incidents in 2025 by intercepting funds while they were still in transit, and that leverage disappears the moment a transfer settles.
Density matters more than state size
Florida’s 2,687 victims work out to 31.0 victims per 10,000 businesses. By raw count that is top three; by density it sits mid-pack among the most exposed states, behind Alaska (47.3), Arizona (36.9), Washington (36.1), Texas (35.3) and Nevada (34.9).
That gap separates a big state from an exposed one. Attacks need no physical proximity, so risk tracks the target’s habits — does the company move money by wire, live in email, depend on outside vendors — far more than it tracks a state ranking.
The cost of Florida business cybercrime beyond the dollars
The reported total is a floor. IC3 counts complaints that were filed, and businesses under-report, especially when a bank quietly recovered the funds or the incident is embarrassing. Treat $237.8 million as what Florida companies were willing to report, not what they lost.
The costs that never reach the dataset are the ones that hurt operating businesses most:
- Downtime. Ransomware and data theft stop invoicing, scheduling and shipping for days.
- Recovery labor. Rebuilding endpoints and restoring data pulls staff off revenue work.
- Insurance consequences. Claims and renewals get harder, and carriers increasingly ask for proof of specific controls.
- Relationship damage. When a vendor’s mailbox is used to defraud a customer, the customer remembers whose name was on the email.
5 controls that cut your exposure
Nothing here is novel, and all five cost less than a single redirected wire:
- Phishing-resistant MFA. App-based or hardware multifactor authentication on email, remote access, finance systems and cloud administration — and remove SMS-only fallback where a business-critical account can still use it.
- Out-of-band payment verification. Any change to bank details or payment amounts gets confirmed by phone to a number already on file. Never use contact details supplied in the same email.
- Quarterly phishing simulation with real feedback. The person clicking is still the weakest link, which is why phishing email attacks keep working. Frequent short tests beat an annual compliance video.
- Layer the email path. Link inspection and DMARC enforcement give you a second chance after a message reaches an inbox — the approach covered in secure email for business.
- Tested offline backups and a written recovery plan. Backups that have never been restored are a hope, not a control — the production impact we documented in ransomware targets South Florida manufacturers.
If outside vendors can reach your systems or data, add vendor review to the list. Attackers often reach the smaller supplier first and use that relationship to get upstream.
FAQ: Florida business cybercrime
How serious is Florida business cybercrime for a smaller company?
An average of about $88,516 per victim company understates the risk for a business with tight cash flow. A single redirected wire can exceed a year of IT spending, and the recovery work lands on the same small team that runs daily operations.
What is the most common attack on Florida businesses?
Email-based scams. Of 2,687 reported business victims in 2025, 2,025 involved email scams such as business email compromise, compared with 283 data breach victims and 195 ransomware victims.
Should a business report an incident, and where?
The FBI asks victims to notify the financial institutions involved immediately, file a complaint at ic3.gov, contact the nearest FBI field office, and notify local law enforcement. Reporting fast is the only realistic path to freezing funds still in transit.
Next step
If your business has never mapped which controls would have stopped a six-figure payment redirect, that is a two-hour conversation rather than a project. Our team reviews email security, payment approval process, identity controls and backup recovery for South Florida organizations, and tells you which gaps matter first. Talk to Nextek IT or call the office to schedule that review.
Sources: FBI 2025 IC3 Annual Report; Opstream state analysis (APG state wire); FBI IC3 reporting guidance.