Business Email Compromise: The Costliest Scam Aimed at Small Businesses

George
By George
4 September 2026
Calling to verify a request

On a Friday afternoon, a controller wires a five-figure payment to a supplier the company has used for years, against an invoice that matches an open order, from an email thread that reads exactly like every previous one. On Monday the real supplier calls about the unpaid invoice. Nothing was hacked in the cinematic sense, no malware, no ransom note, just a message convincing enough to move money. That is business email compromise, and it earns its reputation as the costliest scam aimed at businesses precisely because it attacks the one system no firewall protects: a busy person's trust in their inbox.

This guide explains what business email compromise is, the five schemes it almost always takes, how an attack actually unfolds behind the scenes, and why your spam filter is structurally blind to it plus the layered controls, procedural, technical, and human, that reliably stop the wire.

What Is Business Email Compromise?

Business email compromise (BEC) is a fraud in which an attacker uses email that appears to come from a trusted party, an executive, a vendor, a colleague, a law firm, to trick an employee into sending money or sensitive data. The BEC meaning is right there in the name: the compromise is of the email channel's trust, whether by taking over a real mailbox or by imitating one closely enough. It is a subspecies of social engineering, distinguished by its target, payments and payroll rather than passwords, and by its polish: the best BEC messages contain no links, no attachments, and no errors, only a plausible request at a believable moment.

The Five Schemes BEC Almost Always Takes

The costumes change; the plays do not. Nearly every BEC attack is one of five.

Executive impersonation

A message appearing to come from the owner or a senior leader asks an employee to make an urgent payment or purchase, with a reason the request cannot go through normal channels, a confidential deal, a traveling executive, a deadline. The authority does the work: people are wired to help the boss quickly and question the boss slowly.

Vendor and invoice fraud

The most expensive variant. The attacker either compromises a real vendor's mailbox or imitates it, then sends an invoice that matches genuine business, or, deadlier, a polite note that the vendor's banking details have changed. The next legitimate payment flows to the attacker's account, and because the invoice was real, nobody notices until the true vendor asks where the money went.

Invoice with changed bank details

Payroll diversion

HR receives a request, apparently from an employee, to update direct-deposit details. The paycheck lands in the attacker's account, and the real employee discovers it on payday. Small dollar amounts per hit, high volume across campaigns, and almost zero technical skill required.

The urgent professional

A message from an attorney, escrow officer, or accountant, sometimes impersonating a firm the company genuinely uses, demands a confidential, time-critical transfer connected to a deal, a closing, or a filing deadline. The professional framing suppresses the phone-call instinct that would kill the fraud in a minute.

Data theft as the payout

Not every BEC asks for money. Requests for employee tax forms, payroll data, or customer lists monetize later, in identity fraud or in the next, better-informed attack. Payroll and HR inboxes see this play every filing season.

How a BEC Attack Actually Unfolds

The Friday wire is the last move of a longer game, and seeing the earlier moves is what makes the defenses obvious.

Reconnaissance

The attacker studies the company using entirely public material: the website's team page for names and roles, social profiles for travel and events, vendor relationships visible in testimonials and job posts. Out-of-office replies helpfully contribute the org chart and the calendar. The goal is a cast list, who pays, who approves, who is away, and a believable moment. Even job postings contribute: an ad seeking someone experienced in your accounting platform tells the attacker precisely which system's invoice format to copy.

Access or imitation

Two roads lead to the convincing message. The first is takeover: a phished or reused password, often one already circulating on the dark web, opens a real mailbox, and multi-factor authentication left off is the door left unlocked. The second road needs no breach at all: a lookalike domain, one letter off from the real one, registered that morning, indistinguishable at a glance in a crowded inbox.

Patience inside the mailbox

With genuine access, the attacker does not strike immediately. They read. They set a quiet forwarding rule so copies of interesting threads flow out, learn the rhythm of invoices and the phrasing between colleagues, and wait for a real payment conversation to hijack, replying inside an authentic thread with authentic history. This dwell period is why mailbox-rule changes and unusual sign-ins are among the highest-value alerts a business can watch, and why detection that includes mailbox behavior, the kind delivered by managed detection and response, catches BEC that filters never see.

Blog image

The thread hijack, up close

The most dangerous version deserves a close look. A real conversation about a real invoice is in progress between your controller and a vendor whose mailbox the attacker quietly controls. Mid-thread, the attacker replies from inside it, same subject line, full quoted history, familiar sign-off attaching an invoice identical to the last one except for the remittance account, or adding a gentle note that the bank details have changed "for the new fiscal year." Sometimes the reply-to address shifts one letter; sometimes it does not shift at all. Every visual trust signal a person checks is present and genuine, which is why no amount of squinting at the email defeats this variant, and a thirty-second phone call to the number on file does, every single time.

Comparing genuine and hijacked emails

The ask

The request lands at the engineered moment: end of quarter, Friday afternoon, the approver's vacation, the real deal's deadline. It is specific, calm, and consistent with everything around it, because everything around it was studied first. The vocabulary repeats across campaigns — quick favor, confidential, before end of day, are you at your desk, handling this personally — and finance teams who have seen the list greet it like an old, unwelcome friend.

Why Your Spam Filter Misses It

Filters hunt for payloads, malicious links, infected attachments, mass-mail fingerprints, and the polished BEC message carries none. It is a short, clean, personally addressed email, frequently sent from a genuinely legitimate mailbox, either the attacker's fresh lookalike domain with a spotless reputation or a real compromised account. There is nothing to detonate and nothing to blocklist. Modern defenses do narrow the gap: impersonation detection in the Microsoft 365 phishing protection stack flags lookalike senders and first-time correspondents, and properly enforced email authentication — SPF, DKIM, and DMARC — stops attackers from sending mail as your exact domain, which protects your customers and vendors from messages wearing your name. Those layers are worth deploying and worth tuning, and a good email security stack now blocks a meaningful share of attempts. But the residue that gets through is exactly the well-crafted residue, which is why the decisive controls in BEC are not filters at all.

Why Your Spam Filter Misses It

The Controls That Actually Stop the Wire

BEC is defeated by making the last step, the payment, procedurally impossible to rush. Three layers, in order of importance.

Process: verification that does not bend

Two rules, written and announced, stop the overwhelming majority of BEC cold. First, callback verification: any request to change banking details, vendor or employee, and any unusual or urgent payment request is confirmed by phone to a number already on file, never to a number in the email. Second, dual approval above a threshold: payments over an amount you choose require two humans, which converts "fool one busy person" into "fool two, one of whom is now suspicious." Design the second approval to travel a different channel from the request itself, a signature in the banking portal or an in-person nod, so compromising the email thread cannot satisfy both steps. Add a standing cultural rule that urgency plus secrecy equals verification, and announce from the top that no executive will ever be offended by a confirmation call. The rules cost nothing and survive every clever email ever written. Run the same play defensively toward your own customers: tell them, in writing, at the start of the relationship, that your banking details never change by email and that any such notice should trigger a call to you, because the lookalike domain they will someday receive will be wearing your company's name.

Two-person payment verification in action

Technical: close the takeover road

Multi-factor authentication on every mailbox removes the easiest path to genuine access. Alerts on new mailbox forwarding rules and impossible-travel sign-ins surface the dwell period. Enforced DMARC keeps your own domain out of the attacker's toolbox. None of this stops the lookalike-domain variant by itself, which is the honest reason the process layer comes first.

People: rehearsed suspicion

Finance, HR, and executive assistants are the actual attack surface, and they deserve targeted preparation, not a generic annual video: the five schemes above, real examples, and explicit permission to slow down money. Ongoing awareness training builds the reflex, and phishing simulations that include BEC-style lures, no links, just a convincing ask, measure whether the reflex exists where it matters.

If the Money Already Moved

Speed is nearly everything. Call your bank the moment fraud is suspected and request a recall and a freeze on the receiving account; the realistic window for clawing back a wire is measured in hours, not days. File a complaint promptly with the FBI's Internet Crime Complaint Center, whose recovery team has pulled back transfers when notified fast. Call your cyber insurer's hotline the same day, both because coverage may apply and because policies expect early notice. Then preserve the evidence: do not delete the emails, export the affected mailbox, audit it for forwarding rules and unfamiliar sign-ins, and reset credentials everywhere the compromised account's password was reused. The post-incident hour that matters most is the one spent asking how the message got believed, and fixing that, the missing callback rule, the absent threshold, is what turns a painful week into the last such week. Businesses across Los Angeles call us most often in exactly this week, and the pattern repeats: the controls installed afterward were all available before.

Frequently Asked Questions

Business email compromise is a fraud in which attackers use email appearing to come from a trusted party, an executive, vendor, employee, or professional firm, to trick staff into transferring money or sensitive data. It relies on impersonation or genuine mailbox takeover rather than malware, which is why it routinely slips past technical filters.
Ordinary phishing is high-volume and payload-driven, links and attachments hunting credentials or infections. BEC is low-volume and research-driven: targeted messages, often with no link at all, aimed at a specific person with payment authority at a chosen moment. Phishing wants your password; BEC wants your wire, and sometimes uses the stolen password as its first step.
Because there is nothing conventionally malicious to detect: no attachment, no bad link, clean sending infrastructure, and sometimes a genuinely legitimate compromised mailbox. Filters and impersonation detection remove a share of attempts, but the well-crafted remainder is stopped by process, callback verification and dual approval, not by scanning.
It closes the mailbox-takeover road, which is a major share of attacks and the most damaging variant, so it is mandatory. It does nothing against lookalike-domain impersonation, where no login ever occurs. MFA plus payment-verification procedures together cover both roads; either alone leaves one open.
Call your bank immediately and request a wire recall and freeze, minutes matter. Then file with the FBI's Internet Crime Complaint Center, notify your cyber insurer's hotline, preserve the emails and mailbox evidence, and audit the account for forwarding rules and foreign sign-ins before resetting credentials.
Disproportionately so. Smaller companies move real money with fewer approval layers, publish their org charts on one webpage, and rarely have verification rules in writing, exactly the conditions the scheme is built for. The attacks are not bespoke; the same campaign hits thousands of businesses and succeeds wherever the callback rule is missing.

Business email compromise wins by being ordinary, an unremarkable email asking a busy person for a routine-looking payment, and it loses to businesses that made verification ordinary first. If you want the whole layer installed, rules, mailbox alerts, authentication, and the training that makes it stick, book a BEC readiness review with GlobeVM and we will close both roads before the Friday email arrives.

Comments

0 Comments