EXECUTIVE SUMMARY
The findings in this report come from the results of active defense engagements with BEC threat actors. Every month, Fortra Intelligence & Research Experts (FIRE) conducts hundreds of these engagements to collect comprehensive intelligence about BEC tactics and trends to help better understand how the BEC threat landscape is evolving.
The primary findings for September 2026 detailed in this report include the following:
• During September 2026, FIRE observed an increase of 76% in overall attack volume in comparison to the prior month.
- Gift cards was the most common cash-out method in September, totaling 46.9% of all cash-out methods.
- Apple Store was the most requested of all gift card types, making up 53.3% of total gift card requests.
- FIRE identified 12 cryptocurrency-related scams and recorded 9 unique wallets used by scammers.
- The average amount requested from BEC wire transfer attackers was $102,201 in September compared to $52,268 in August 2026.
- 60% of BEC attacks were sent from email addresses hosted on free webmail providers compared to 40% of attacks sent from maliciously registered domains.
BEC Attack Trends
During the month of September 2026, FIRE observed an increase of 76% in overall attack volume in comparison to the prior month.
In September 2026, Gift cards remained the most prevalent BEC cash-out method, accounting for 46.9% of all attacks, followed by advanced fee frauds (24.2%) and wire transfers (15.5%).
Gift Cards
During September, Apple Store gift cards were the most frequently requested by BEC attackers, representing 53.3% of all gift card requests. Other commonly requested gift cards included Amazon (33.3%) and American Express (3.3%).
Cryptocurrency
FIRE identified 12 cryptocurrency-related scams during September, involving 9 unique Bitcoin wallet addresses. The requested amounts ranged from $800.00 to $2,360.00, with an average request of $1,542.00.
BEC Wire Transfers
Wire transfer attacks decreased by 20% during September 2026 compared to August 2026. The average amount requested per wire transfer attack was $102,201 in September, representing an increase of 96% from the previous month's average of $52,268.
Analysis of requested amounts showed that 10% of wire transfer requests were under $10,000, while 56% fell between $10,000 and $50,000. Requests between $50,000 and $100,000 accounted for 29%, and 6% exceeded $100,000.
The most common bank types used for wire transfer mule accounts were major US banks (32.0%), specialty banks (15.0%), and regional US banks (13.0%).
BEC Payroll Diversions
During September 2026, the most common bank types used for payroll diversion mule accounts were specialty banks (18.0%), online banks (9.0%), and international (non-US) banks (9.0%).
The top banks used in payroll diversion attacks during September included Green Dot/Go2Bank (22%), SoFi Bank (14%), and Pathward (9%), among 58 total banks identified.
BEC Infrastructure
In September 2026, 60% of BEC attacks were sent from free webmail providers, while 40% originated from maliciously registered domains. The use of free webmail decreased compared to 66% in August 2026.
Among registered domain providers, Google was the most prevalent, accounting for 67% of the 696 maliciously registered domains identified, followed by Microsoft and 11 Mail Media Inc..
For free webmail providers, the top three services used were NameSilo, NameCheap, and Squarespace, collectively representing 45% of all free webmail-based attacks.
BEC Attack Locations
Geographic analysis of BEC attacks during September 2026 revealed that United States was the primary source, accounting for 49% of all attacks, followed by Nigeria with 29%.
¹ Attacker locations are identified IP addresses collected by beacons that are inserted into our communications with BEC actors. IP addresses that are overtly associated with VPNs or other proxies are removed from this dataset; however, there is still a possibility that a device associated with an IP address could be used as a proxy in other ways, so the location (particularly for those outside West Africa) cannot be deemed completely definitive.
Cybercrime Intelligence Shouldn't Be Siloed
Fortra® experts are dedicated to protecting organizations and the public by delivering the latest insights, data, and defenses to strengthen security.