Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Business Email Compromise: How It Works & How to Stop It

A single well-crafted email can cost your company tens of thousands of dollars in minutes. Business Email Compromise (BEC) is not a virus or a flashy ransomware lockout. It is a quiet, patient con that turns your own trust, your habits, and your business relationships into the weapon. According to the FBI Internet Crime Complaint Center (IC3), BEC has exposed more than $55 billion in reported losses worldwide over the past decade, making it one of the most financially damaging cybercrimes affecting U.S. businesses today. Understanding how it works is the first step to making sure your organization never becomes another statistic.

What Is Business Email Compromise?

BEC is a form of targeted fraud in which a criminal impersonates a trusted person, such as an executive, a vendor, an attorney, or a coworker, to trick an employee into sending money or sensitive data. Unlike mass phishing campaigns, BEC is personal. Attackers research your company, learn who authorizes payments, study how your leadership writes, and time their requests to moments of pressure or distraction. Because the messages often contain no malicious attachments or links, they routinely slip past spam filters and antivirus tools. The exploit is not your software. It is your people and your processes.

The Main Variants

BEC schemes take several recognizable forms, and most businesses will encounter at least one of them:

  • CEO or executive impersonation. An email appearing to come from the CEO or CFO instructs an employee to make an urgent wire transfer, often while the “executive” is conveniently traveling and unreachable by phone.
  • Vendor and invoice fraud. Attackers hijack or spoof a supplier’s email account and send a legitimate-looking invoice with new banking details, redirecting a real payment into their own account.
  • Payroll diversion. Posing as an employee, the criminal emails HR or payroll asking to update direct-deposit information so that the next paycheck lands in the fraudster’s account.
  • Attorney impersonation. The scammer claims to be legal counsel handling a confidential, time-sensitive matter, pressuring a junior employee to act quickly and quietly.
  • Gift-card scams. A supposed executive asks a staffer to buy gift cards for “client rewards” or an office surprise, then requests the redemption codes.

How Attackers Get In and Why It Works

Most BEC attacks begin with reconnaissance. Criminals mine company websites, social media, and press releases to map your org chart and payment workflows. They gain a foothold through credential phishing, purchased passwords from prior data breaches, or lookalike domains that swap a single character. Once inside a real mailbox, they may silently set up forwarding rules and read email traffic for weeks, waiting for a live transaction to hijack. If a mailbox or payment has already been hit, our business email compromise investigation service traces what happened, and you can request it online.

The psychology is deliberate. BEC weaponizes authority (“the CEO is asking”), urgency (“this must go out before the bank closes”), and secrecy (“do not discuss this with anyone”). Those three pressures short-circuit the normal instinct to double-check. Our investigations and digital forensics teams see the same pattern repeatedly: a capable, well-meaning employee who simply wanted to be responsive and fast.

Red Flags to Watch For

  • Unexpected changes to banking or payment details, especially by email alone.
  • Pressure to act immediately, bypassing normal approval steps.
  • Requests for secrecy or instructions to avoid phone verification.
  • Slightly altered email domains or “reply-to” addresses that differ from the display name.
  • Messages that arrive at odd hours or reference the sender being unreachable.
  • Subtle shifts in tone, grammar, or signature formatting from a familiar contact.

How to Stop BEC Before It Starts

Prevention is far cheaper than recovery. A layered defense closes the gaps that attackers rely on:

  • Out-of-band verification. Confirm every payment request or banking change by calling a known, pre-established phone number, never a number supplied in the suspicious email.
  • Multi-factor authentication (MFA). Require MFA on all email and financial accounts so a stolen password alone cannot unlock a mailbox.
  • Email authentication. Deploy DMARC, DKIM, and SPF records to make it far harder for attackers to spoof your domain and to flag impostor messages.
  • Payment controls. Require dual approval for wire transfers above a set threshold and enforce a mandatory callback for any change to vendor payment information.
  • Ongoing training. Teach staff to slow down, question urgency, and treat verification as routine rather than rude.

Our cybersecurity services team can assess your email configuration, harden authentication, and run realistic simulations so your workforce recognizes the con before the money moves.

Hit by BEC? What to Do in the First Hours

Speed matters enormously. The window to recover funds can close within a day, so act immediately and in parallel:

  • Contact your bank right away. Ask them to recall or freeze the transfer and to initiate a SWIFT recall or hold on the receiving account. The sooner the request, the better the odds.
  • Report to the FBI IC3. File a complaint at IC3.gov and, for domestic wires, ask about the FBI’s Financial Fraud Kill Chain, which can help freeze funds still sitting in a U.S. account.
  • Preserve all evidence. Do not delete anything. Save the original emails with full headers, wire confirmations, and internal communications, and document who did what and when.
  • Engage digital forensics. Professional analysis determines whether an account was breached, whether attackers still have access, and how to contain the intrusion.

Our financial investigations specialists work alongside forensic examiners to trace the transaction, support law enforcement, and help you understand the full scope of the exposure. While no firm can promise that stolen funds will be recovered, a fast, coordinated response gives you the strongest possible chance and keeps a single incident from becoming an ongoing breach.

Protect Your Business Today

Honeybadger Solutions LLC is a veteran-owned, service-disabled veteran-owned small business (SDVOSB) headquartered in Arizona and serving clients nationwide. Our licensed team spans cybersecurity, digital forensics, financial investigations, and executive protection, giving you one trusted partner for both prevention and response.

Ready to safeguard your organization against Business Email Compromise? Schedule a free, confidential consultation today. Let us help you close the gaps before a criminal finds them.

The technical controls that close the door

Business email compromise is an identity problem, so the controls that work are identity controls. Five of them do most of the work, and they are available in every major email platform.

Multifactor authentication on every mailbox, with no exceptions carved out for executives or shared accounts. This is the single control that removes the most common entry path. Prefer app-based or hardware authentication over SMS where possible, since SIM swap attacks specifically target the text-message path.

Block legacy authentication protocols. Older mail protocols bypass modern authentication entirely, and attackers use them deliberately for that reason. Most organisations no longer need them and simply never turned them off.

Alert on mailbox rule creation. The classic move after compromising a mailbox is to create a rule that moves messages containing words like “invoice”, “wire” or “payment” into an obscure folder or deletes them, so the real owner never sees the conversation. A rule-creation alert is cheap to enable and frequently the first sign of compromise.

Alert on impossible travel and unfamiliar sign-ins. A login from Phoenix and one from another continent twenty minutes later is a detection that requires no expertise to interpret.

Publish SPF, DKIM and DMARC records, and move DMARC to an enforcing policy once reporting shows legitimate mail is passing. This does not stop a compromised real mailbox, but it does stop straightforward spoofing of your domain to your customers — which is how your clients get defrauded in your name.

The process control that stops the loss even when the email succeeds

Every technical control can fail. The process control that catches the loss anyway is verbal verification through an independently known channel, and it should be written policy rather than good practice.

The rule: any request to change banking details, any first-time wire to a new beneficiary, and any payment above a defined threshold is verified by calling a number already on file — not a number in the email, not a number in the attached letterhead, and not by replying to the message. The call confirms the request with a person the caller recognises.

Two refinements make it stick. Build dual authorisation into payments above a threshold so one compromised person cannot complete a transfer alone. And give staff explicit permission to delay a payment for verification, because the pressure tactic these frauds rely on is urgency from someone senior. A finance clerk who believes they will be criticised for slowing down a CEO’s request is the vulnerability the whole scheme is built around.

Vendor and client-side compromise

A large share of these losses do not begin in your environment at all. The attacker compromises a supplier’s mailbox, reads the genuine invoice thread, and sends an updated invoice with new banking details at exactly the right moment in a real conversation. Nothing on your side was breached, and nothing in the message looks wrong because nothing is wrong except the account number.

This is why the verification rule has to apply to people you know and trust. It is also worth telling your own customers what your payment details are and that they will never change by email — some organisations print exactly that on every invoice.

Wire fraud insurance is worth understanding here, because standard cyber policies often treat social engineering fraud as a separate endorsement with its own, much lower, sub-limit. If a wire loss is a realistic exposure for your business, read that endorsement specifically.

The first two hours after a fraudulent payment

Speed determines recovery, and the window is measured in hours.

  1. Call your bank immediately and ask for a SWIFT recall or a hold on the transfer. Follow the call with written instruction.
  2. File with the FBI’s Internet Crime Complaint Center at ic3.gov, which operates a financial fraud kill chain process that has frozen funds in transit. It works best within roughly seventy-two hours.
  3. Preserve evidence before cleaning up. Do not delete the messages, and export the full headers. Capture the mailbox audit log and sign-in log before retention windows close.
  4. Reset credentials and revoke sessions for the affected account, and check for mailbox rules, forwarding addresses and application consents the attacker may have added — a password reset alone does not remove those.
  5. Check whether anyone else was targeted from the same mailbox, including customers.
  6. Notify your insurer and involve counsel, particularly if client funds or client data were involved.

What the investigation should establish afterwards

Once the immediate response is done, three questions remain and they are worth answering properly rather than assuming.

How did they get in — credential phishing, a reused password, a token stolen from a compromised device, or a vendor’s compromised account? What else did they reach while they had access, including files, contacts and other systems using the same credentials? And how long were they present, because the answer is frequently weeks rather than hours, and that duration determines the scope of any notification obligation.

Those questions are answered from mailbox audit logs, sign-in logs and endpoint evidence, and the logs have retention limits. Preserving them early is what makes the analysis possible at all. Our digital forensics team handles this, and incident response covers the containment side.

Browse by topic

Security guard services  ·  Private investigations  ·  Cybersecurity  ·  Digital forensics  ·  Financial fraud investigation  ·  Executive protection  ·  All articles