---
title: "NJ Small Businesses Lost $435M to Fraud in 2024"
published: 2026-09-19T00:09:17.432Z
updated: 2026-09-19T00:09:31.168Z
author: "Trust Onion Editorial Team"
canonical: https://trustonion.io/blog/nj-small-businesses-fraud-losses-2024
---

# NJ Small Businesses Lost $435M to Fraud in 2024

**Cite as:** NJ Small Businesses Lost $435M to Fraud in 2024, Trust Onion, 2026-09-19. https://trustonion.io/blog/nj-small-businesses-fraud-losses-2024

New Jersey businesses lost over $435 million to cybercrime and fraud in 2024, placing the state fifth in the nation for cyber-related financial losses, according to NJBIZ. The attacks are not coming from sophisticated state actors targeting Fortune 500 companies. They are hitting small businesses, hitting them hard, and the methods are getting harder to spot.

## The Threat Is Not Abstract

Small business owners tend to think of cybercrime as someone else's problem. Smaller organizations often have thinner controls, leaner finance teams, and less formal verification processes, which makes them easier targets.

The fraud types flagged in the NJBIZ report include fake vendor invoices, spoofed emails, and AI-generated voice and video impersonation. These are not isolated incidents. Fraud operators run this playbook at scale across the country.

New Jersey's $435 million in losses is a state-level figure. The national picture is worse. The FBI's Internet Crime Complaint Center reported $16.6 billion in cybercrime losses across the U.S. in 2024, a 33% increase over 2023.

## How the AI Impersonation Attack Works

Voice cloning now requires just 20 to 30 seconds of audio. Executives post on LinkedIn, speak at conferences, and appear in company videos. That audio is publicly available and usable.

A fraudster clones the CEO's voice, calls the finance department, and requests an urgent wire transfer. The caller sounds exactly right. The urgency feels real. The finance team member has no baseline way to verify the voice is genuine.

This is not a theoretical scenario. In February 2024, engineering firm Arup lost $25 million when an employee joined a video call where every other participant was a deepfake, including a convincing reproduction of a senior company officer. The employee authorized the transfer. The money was gone.

Small businesses face the same attack with fewer resources to absorb the loss.

### Why Caller ID and Email Headers Don't Help

Spoofed phone numbers look legitimate. Spoofed email headers pass basic visual inspection. A caller who sounds like the CFO, calls from what appears to be the CFO's number, and references real internal project names has done their homework.

The certified financial crimes specialist quoted in the NJBIZ piece from Kearny Bank emphasized proactive employee training and internal controls. That framing is correct. The question is what those controls actually look like in practice for a ten-person finance team.

## The Gap Between Training and Action

Most fraud prevention training focuses on awareness. Employees learn that wire transfer fraud exists, that voice cloning exists, that impersonation attempts happen. That knowledge is valuable but incomplete.

Knowing that an attack might happen does not give a finance team member anything to do when a convincing caller is on the line asking for an urgent $80,000 transfer to a new vendor account.

The common advice is to hang up and call back using a number from your internal directory or the vendor's official website. That is sound advice as far as it goes. A callback does not prove the original caller was legitimate, though, because a fraudster who initiated the first call may have additional infrastructure in place. Always source your callback number independently from a company website, official invoice, or verified internal directory, never from a number the caller provided. If something still feels wrong, escalate internally before authorizing anything.

What finance teams need is a verification mechanism that works in the moment, before a transfer leaves the account.

## What Internal Controls Actually Look Like

Large enterprises use out-of-band verification, dual authorization requirements, and dedicated fraud lines. Small businesses rarely have any of those in place.

The practical gap is significant. A small business CFO calls their accounts payable coordinator to approve a payment. The coordinator has no way to confirm the caller is actually the CFO. They use judgment. Judgment, under social pressure and time urgency, is not a reliable control.

Effective internal controls for wire transfer authorization need three properties. First, they must work in real time, because fraud calls do not give you time to open a ticket. Second, they must be out of band, because if an attacker controls the voice channel, verifying through that same channel proves nothing. Third, they must be impossible to fake without inside access. A name, a title, and knowledge of internal projects can all be researched, so the verification element needs to be something the attacker cannot obtain from public sources.

## Closing the Verification Gap

Trust Onion gives finance teams a specific answer to the question: how do we verify this caller before we authorize anything?

The answer is three rotating codewords, calculated locally on each device and refreshed every 60 seconds. When a caller claims to be the CFO authorizing a transfer, the finance team member asks one question: "What are the words?" If the caller cannot produce the current three words, the call is not verified.

The words are never transmitted over the network and require no server to generate. A cloned voice cannot know them. A spoofed number cannot produce them. An attacker who has spent months researching the company cannot guess them, because they change every 60 seconds and are only available to verified personnel inside the organization.

For higher-stakes situations, Trust Onion offers Proofies: a verified selfie with the current three words visible, signed and timestamped. An executive traveling internationally can send a Proofie before a significant approval goes through, giving the finance team a confirmation that does not rely on a phone call at all.

Trust Onion is free, requires no server infrastructure, and works offline. For a small business processing wire transfers with a lean team, it fits the operational reality.

New Jersey's $435 million in losses did not all come from sophisticated attacks on large enterprises. Much of it came from exactly the kind of call this article describes: a convincing voice, an urgent request, and no mechanism to say "prove it." Three rotating words give finance teams that mechanism.

---

*Source: NJBIZ, "NJ small businesses face rising cybercrime, fraud risks," October 6, 2025. FBI Internet Crime Complaint Center 2024 Annual Report.*

## Key takeaways

- New Jersey ranked 5th in the U.S. for cyber-related financial losses in 2024, with over $435 million lost.
- AI voice cloning requires as little as 20 to 30 seconds of audio, making executive impersonation accessible to any fraudster.
- Caller ID and email headers can be spoofed, making visual and auditory verification unreliable for wire transfer authorization.
- Callbacks to a number the suspicious caller provided do not confirm the original call was legitimate; always use independently sourced contact information.
- A rotating codeword protocol gives finance teams a real-time, out-of-band way to verify any caller before authorizing a payment.

## Frequently asked questions

### How much did New Jersey businesses lose to cybercrime in 2024?

According to NJBIZ reporting on 2024 data, New Jersey victims lost over $435 million to cyber-related fraud, placing the state fifth in the nation for such losses.

### How does AI voice cloning work in wire transfer fraud?

Fraudsters use 20 to 30 seconds of publicly available audio to clone an executive's voice, then call the finance team to authorize a transfer. The voice sounds authentic, but the caller is not who they claim to be.

### Is calling back a safe way to verify a suspicious wire transfer request?

Calling back using a number from your internal directory or official company website is better than using a number the caller provided. However, a successful callback does not prove the original caller was legitimate. Use an independently sourced number and apply additional verification before authorizing any payment.

### What internal controls can small businesses use to prevent wire transfer fraud?

Effective controls include dual authorization requirements, out-of-band verification, and real-time codeword protocols. Tools like Trust Onion provide rotating codewords that a finance team can request from any caller claiming authority to approve a payment.

### Can a cloned AI voice defeat a rotating codeword verification system?

No. A cloned voice can replicate how someone sounds, but it cannot produce time-based codewords calculated locally on a verified device. If the caller cannot say the current words, they are not verified, regardless of how convincing they sound.

## More from Trust Onion

Give your finance team a verification layer that works before the transfer goes out. Three rotating codewords, free for your organization, available now at Trust Onion.

**Safety note:** If you cannot reach the person or organization when you call back, do not assume the original caller was really them. For a family call, if the caller cannot confirm your private Trust Onion Three Words, it could still be a scam; for a bank or other organization, verify through the official app or a number from a card or statement. Always use your best common-sense judgment, and alert the authorities if you believe someone is in danger.
