In October 2019, an employee in the town of Erie, Colorado approved a routine-looking request to change how a bridge contractor received payment. The request came through a form on the town's own website, not a suspicious email, and it passed a basic accuracy check. Ten days later, the town's bank flagged the transaction as fraudulent. By then, more than $1 million had already been wired out of the country. The real contractor had never asked for the change. Nobody at the town had picked up the phone to confirm it.
That single mistake, a skipped phone call, is still one of the most cited business email compromise cases involving a Colorado government entity. It is also a useful reminder that the numbers below are not abstractions. They represent thousands of Colorado organizations, many of them small businesses without dedicated IT security staff, that made a similar mistake in the past year.
Colorado's Numbers in the FBI's Latest Report
The FBI's Internet Crime Complaint Center (IC3) publishes an annual report breaking down cyber-enabled crime by state. The 2025 Internet Crime Report, released in April 2026, shows Colorado is not a minor player in the national cybercrime picture.
- 18,847 complaints were filed by Colorado residents and businesses in 2025, ranking the state 18th in the nation by complaint volume.
- Over $355 million in reported losses came out of Colorado in 2025, placing the state 17th nationally by dollar losses.
- Per capita, Colorado ranks considerably higher than its population would suggest: 7th in the nation for complaints per 100,000 residents, and 12th for losses per 100,000 residents.
- Colorado's 60-and-older population filed 4,061 complaints and reported more than $144.5 million in losses, a group that is frequently targeted through tech support scams, romance schemes, and government impersonation.
- Cryptocurrency-related complaints from Colorado totaled 4,066, with reported losses exceeding $202 million, more than half of the state's total losses for the year.
The per capita ranking is the detail most local coverage misses. National aggregators rank states by raw complaint count, which favors large states like California and Texas. When the numbers are adjusted for population, Colorado moves into the top ten, ahead of far more populous states. A Colorado resident or business is statistically more likely to file an internet crime complaint than someone in New York, Ohio, or Michigan.
How Colorado's Losses Broke Down in the Prior Year
The FBI's national 2025 report does not publish a crime-type breakdown by state, so the most recent detailed picture of what is actually costing Colorado victims comes from the 2024 data, released by the FBI's Denver Field Office in 2025. That year, Colorado lost $243.5 million to internet crime, and three categories accounted for the majority of it:
- Investment fraud took the largest share at roughly $90 million, consistent with the national trend of cryptocurrency-based investment schemes.
- Business email compromise accounted for about $48 million, the same category of fraud that hit the town of Erie. We break down how BEC actually works and what stops it in our guide to email spoofing and business email compromise.
- Personal data breach losses reached approximately $23 million.
By number of complaints rather than dollar amount, the picture shifts. Extortion, phishing and spoofing, and personal data breach were the three most frequently reported crime types in Colorado, meaning small-dollar, high-volume schemes are hitting far more Colorado businesses and individuals than the headline-grabbing investment fraud numbers suggest.
Ransomware: A National Problem With Real Local Consequences
IC3 does not break ransomware losses out by state, but the national 2025 figures give useful context for Colorado businesses. The FBI received more than 3,600 ransomware complaints in 2025 with reported losses exceeding $32 million, and the agency identified 63 new ransomware variants over the course of the year, an average of more than five new variants per month. CISA's StopRansomware resource hub tracks current variants and offers a step by step response guide worth bookmarking before an incident happens, not during one.
Colorado has its own documented history with ransomware at the government level. In February 2018, the Colorado Department of Transportation was hit by the SamSam ransomware variant. The agency chose not to pay the ransom and instead spent an estimated $1.7 million on containment and recovery, an outcome that illustrates a point many small business owners miss: refusing to pay does not mean the incident is free. Recovery, downtime, and remediation carry their own costs, often larger than the ransom demand itself.
The FBI's data also shows ransomware increasingly hitting sectors outside the usual healthcare and government headlines. Legal services, contracting, engineering, and consulting firms made up a meaningful share of non-critical-sector ransomware complaints nationally in 2025, all industries with a substantial presence in the Denver metro area.
Colorado's Data Breach Notification Law
For Colorado small businesses, the FBI's numbers connect directly to a legal obligation many owners are only vaguely aware of. Colorado's data breach notification statute (C.R.S. 6-1-716) requires businesses to notify affected Colorado residents within 30 days of determining a breach occurred, one of the shortest windows in the country. If a breach affects 500 or more Colorado residents, the business must also notify the Colorado Attorney General's office, and if more than 1,000 residents are affected, the major consumer reporting agencies must be notified as well. The Attorney General's Consumer Data Protection Laws FAQ page is the most reliable, current source for exactly what your business is on the hook for. Penalties for failing to comply can reach $20,000 per violation under the Colorado Consumer Protection Act.
This matters because personal data breach was one of the top three loss categories and one of the top three most-reported crime types in Colorado in the same year. A meaningful share of Colorado businesses that experience a breach are also on the clock for a legal notification requirement most of them have never had to think about before.
What This Means for Colorado Small Businesses
Three things stand out when the national narrative gets filtered down to Colorado specifically.
First, Colorado's per capita ranking undercuts the "we're too small a market to be a target" assumption that still drives a lot of underinvestment in security among local SMBs. Raw complaint counts make Colorado look mid-tier. Adjusted for population, it is a top-ten state.
Second, the categories doing the most damage in Colorado, investment fraud, business email compromise, and personal data breach, are not exotic, highly technical attacks. They rely on social engineering and process gaps, the same kind of gap that let a single unverified web form request drain over a million dollars from a small town government. That is a solvable problem with the right verification procedures in place, not a problem that requires enterprise-grade security spending.
Third, the compliance clock attached to a breach is short and unforgiving. A 30-day notification window does not leave much room for a business to figure out its obligations after the fact. Businesses that have not mapped out what personal information they hold and what their notification obligations would look like are effectively deciding to figure it out during a crisis.
Action Checklist for Colorado SMBs
- Verify payment change requests out of band. Any request to change banking or wire information, regardless of how it arrives, should be confirmed with a phone call to a known, previously verified number, not a number provided in the request itself.
- Enable multi-factor authentication everywhere it is available, particularly on email, VPN access, and any system that touches financial transactions.
- Maintain offline, tested backups that are encrypted and cannot be altered or deleted by an attacker who gains network access.
- Know your notification obligations before you need them. Map out what personal information your business stores, how many Colorado residents it covers, and who is responsible for the Attorney General notification if the 500-resident threshold is crossed.
- Train employees to spot social engineering, not just phishing emails. The Erie case involved no email at all, just a form submission that looked routine. The FTC's guidance on business impersonation scams is a solid, free training reference.
- Segment your network so that a single compromised account or device cannot reach every system in the business.
- Review cyber insurance coverage against the specific loss categories most common in Colorado: investment-adjacent fraud, BEC, and data breach response costs. Our breakdown of what cyber insurance policies actually require covers the requirements insurers check before paying out a claim.
Frequently Asked Questions
How much did cybercrime cost Colorado in 2025?
Colorado residents and businesses reported more than $355 million in losses to the FBI's Internet Crime Complaint Center in 2025, across 18,847 complaints.
Is Colorado a high-risk state for cybercrime?
By raw complaint volume, Colorado ranks 18th nationally. Adjusted for population, it ranks 7th in complaints per 100,000 residents, making it a higher-risk state than its size alone would suggest.
What is Colorado's data breach notification law?
Colorado law (C.R.S. 6-1-716) requires businesses to notify affected Colorado residents within 30 days of determining a security breach occurred. Breaches affecting 500 or more residents must also be reported to the Colorado Attorney General, and breaches affecting more than 1,000 residents require notification to national consumer reporting agencies.
Do small businesses have to report a data breach to the Colorado Attorney General?
Only if the breach is reasonably believed to affect 500 or more Colorado residents. Smaller breaches still require direct notification to the affected individuals, but not to the Attorney General's office.
What is the most common type of cybercrime affecting Colorado businesses?
By number of complaints, extortion, phishing and spoofing, and personal data breach were the most frequently reported crime types in Colorado in the most recent state-level breakdown. By dollar losses, investment fraud, business email compromise, and personal data breach caused the most damage.
Sources: FBI 2025 Internet Crime Report; FBI Denver Field Office's 2024 Colorado data release; Colorado Attorney General's Office, C.R.S. 6-1-716 guidance; The Colorado Sun's reporting on the CDOT SamSam ransomware incident; 9News reporting on the Town of Erie business email compromise case.
About ITGuys IT Support & Consulting
For 15 years, ITGuys has helped small and mid-sized businesses manage the technology decisions that actually move the needle, from everyday IT support to the security and compliance work that protects what you've built. If a breach notification clock is the last thing you want to be figuring out from scratch, that is exactly the kind of problem we help sort out ahead of time.
Managed IT Services | Cybersecurity | Compliance Support | Contact Us
Recent Comments