Business email compromise involves no malware, no encryption and no ransom note. Someone sends an email asking for money to be moved, and it gets moved. The FBI's Internet Crime Complaint Center consistently reports it among the costliest categories of cybercrime, exceeding ransomware by a wide margin in reported losses.
It works because there is nothing technically malicious to detect. The email is a genuine email, frequently from a genuine account, making a request that looks like business.
The five variants
- Executive impersonation. A message apparently from the owner or CFO to finance, requesting an urgent transfer. Usually invokes confidentiality and time pressure.
- Vendor invoice fraud. The most costly variant. A supplier you genuinely work with notifies you of updated banking details. Often the supplier's own mailbox has been compromised, so the email is authentic and the thread is real.
- Payroll diversion. An employee emails HR asking to update their direct deposit details. Individually small, easy to repeat, and frequently undetected until payday.
- Attorney impersonation. Someone claiming to represent the business in a confidential transaction, applying pressure and secrecy. Common around real estate closings and acquisitions.
- Data theft. Targeting HR or finance for W-2 forms or employee records rather than money, usually as a precursor to tax fraud. Peaks in the first quarter.
Vendor invoice fraud deserves particular attention because it defeats the usual instincts. The email is from the real address, in the real thread, referencing a real invoice. Nothing about it is technically wrong.
| Variant | Who is targeted | What the attacker wants | Warning sign |
|---|---|---|---|
| Executive impersonation | Finance staff | An urgent transfer | Confidentiality and time pressure |
| Vendor invoice fraud | Whoever pays suppliers | Payment to new bank details | Updated banking details, often in a real thread |
| Payroll diversion | HR and payroll | Redirected direct deposit | An emailed request to change deposit details |
| Attorney impersonation | The business, mid-transaction | A transfer in a confidential deal | Pressure and secrecy around a closing or acquisition |
| Data theft | HR and finance | W-2 forms and employee records | Requests for employee tax data, peaking in Q1 |
How the setup actually works
The email requesting the transfer is the last step. What precedes it is the reason it succeeds.
- Initial access to a mailbox, usually via a phished credential. Frequently at a vendor rather than at the target.
- Quiet observation, often for weeks. Reading correspondence, learning payment cycles, identifying who authorises what and how they write.
- A mail rule created to hide evidence — auto-forwarding to an external address, or moving certain messages to an obscure folder so the legitimate owner does not see replies.
- The request, timed to a moment when it is plausible: a real invoice due, a genuine transaction in progress, a decision-maker known to be travelling.
- Rapid movement of funds through several accounts once transferred.
The mail rule step is the most useful detection opportunity. Auto-forwarding rules to external addresses are rare in legitimate use and are a strong indicator of compromise. They also survive a password reset, which is why changing a password alone does not resolve a mailbox compromise.
The control that matters most
No change to payment details is ever accepted based on an email. Verification by voice, to a number already on file, every time, with no exception for urgency. This single procedure defeats every variant above, including the ones where the email is completely genuine.
The details matter. Call a number you already hold — never the number in the email, which will reach the attacker. Speak to a known individual rather than whoever answers. Apply it to every change without a threshold, because attackers test with small amounts.
Make it a written policy, and make clear that following it can never be a disciplinary matter. Staff bypass verification when they fear appearing obstructive to a senior person, which is precisely the dynamic executive impersonation exploits.
Technical controls that help
- MFA on all mailboxes, which addresses the initial access step
- Alerting on new mail forwarding rules, especially those pointing externally. One of the highest-value detections available
- Blocking automatic external forwarding by policy where the business does not need it
- SPF, DKIM and DMARC correctly configured, so your domain cannot be trivially spoofed
- External sender warnings on inbound mail, which help against lookalike domains
- Impersonation protection flagging messages that appear to come from executives but originate externally
- Monitoring for lookalike domain registrations resembling yours or your key vendors
- Conditional access flagging sign-ins from unusual locations
None of these stop a genuine email from a genuinely compromised vendor mailbox. That is why the verification procedure is the primary control and the technical measures are supporting.
If it happens
Speed determines recovery, and the window is measured in hours.
- Contact your bank immediately and request a recall. The chance of recovery falls sharply after the first 24 to 48 hours.
- File a complaint with the FBI's Internet Crime Complaint Center. Their Recovery Asset Team can assist in freezing funds and has a meaningful success rate when notified quickly.
- Report to local law enforcement, which is often required for insurance.
- Notify your cyber insurer — note that this may fall under a crime or social engineering endorsement rather than the main cyber policy, and those endorsements frequently carry low sublimits worth checking before you need them.
- Investigate the mailbox. Determine whether yours or the vendor's was compromised, check for forwarding rules, and review what else was accessible.
- Notify the vendor if their mailbox was the source. They may not know, and other customers are being targeted with the same access.
The insurance point is worth checking in advance. Many businesses assume BEC losses fall under their cyber policy and discover at claim time that funds transfer fraud sits under a separate endorsement with a much lower limit — or was never added at all.
| Step | Contact | Why it matters |
|---|---|---|
| 1. Request a recall | Your bank | Recovery chances fall sharply after 24 to 48 hours |
| 2. File a complaint | FBI Internet Crime Complaint Center | Its Recovery Asset Team can help freeze funds |
| 3. Report the crime | Local law enforcement | Often required for insurance |
| 4. Notify your insurer | Cyber or crime insurer | May fall under a separate endorsement with a low sublimit |
| 5. Investigate the mailbox | Your IT provider | Find forwarding rules and what else was accessible |
| 6. Warn the vendor | The supplier, if their mailbox was the source | Other customers are being targeted with the same access |
Sources
- FBI Internet Crime Complaint Center (IC3) — Internet Crime Report 2025
- FBI Internet Crime Complaint Center (IC3) — Business Email Compromise: The $55 Billion Scam (PSA I-091124-PSA)
- Internal Revenue Service — Dangerous W-2 Phishing Scam Evolving; Targeting Schools, Restaurants, Hospitals, Tribal Groups and Others (IR-2017-20)
- Microsoft Security Blog — From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
- Microsoft Learn (Defender for Office 365) — Control external email forwarding


