Cybersecurity & Compliance

Business Email Compromise (BEC): How It Works and How to Stop It

MSP Worx · 5 min read · Updated Oct 10, 2026

Business email compromise involves no malware, no encryption and no ransom note. Someone sends an email asking for money to be moved, and it gets moved. The FBI's Internet Crime Complaint Center consistently reports it among the costliest categories of cybercrime, exceeding ransomware by a wide margin in reported losses.

It works because there is nothing technically malicious to detect. The email is a genuine email, frequently from a genuine account, making a request that looks like business.

The five variants

  • Executive impersonation. A message apparently from the owner or CFO to finance, requesting an urgent transfer. Usually invokes confidentiality and time pressure.
  • Vendor invoice fraud. The most costly variant. A supplier you genuinely work with notifies you of updated banking details. Often the supplier's own mailbox has been compromised, so the email is authentic and the thread is real.
  • Payroll diversion. An employee emails HR asking to update their direct deposit details. Individually small, easy to repeat, and frequently undetected until payday.
  • Attorney impersonation. Someone claiming to represent the business in a confidential transaction, applying pressure and secrecy. Common around real estate closings and acquisitions.
  • Data theft. Targeting HR or finance for W-2 forms or employee records rather than money, usually as a precursor to tax fraud. Peaks in the first quarter.

Vendor invoice fraud deserves particular attention because it defeats the usual instincts. The email is from the real address, in the real thread, referencing a real invoice. Nothing about it is technically wrong.

VariantWho is targetedWhat the attacker wantsWarning sign
Executive impersonationFinance staffAn urgent transferConfidentiality and time pressure
Vendor invoice fraudWhoever pays suppliersPayment to new bank detailsUpdated banking details, often in a real thread
Payroll diversionHR and payrollRedirected direct depositAn emailed request to change deposit details
Attorney impersonationThe business, mid-transactionA transfer in a confidential dealPressure and secrecy around a closing or acquisition
Data theftHR and financeW-2 forms and employee recordsRequests for employee tax data, peaking in Q1

How the setup actually works

The email requesting the transfer is the last step. What precedes it is the reason it succeeds.

  1. Initial access to a mailbox, usually via a phished credential. Frequently at a vendor rather than at the target.
  2. Quiet observation, often for weeks. Reading correspondence, learning payment cycles, identifying who authorises what and how they write.
  3. A mail rule created to hide evidence — auto-forwarding to an external address, or moving certain messages to an obscure folder so the legitimate owner does not see replies.
  4. The request, timed to a moment when it is plausible: a real invoice due, a genuine transaction in progress, a decision-maker known to be travelling.
  5. Rapid movement of funds through several accounts once transferred.

The mail rule step is the most useful detection opportunity. Auto-forwarding rules to external addresses are rare in legitimate use and are a strong indicator of compromise. They also survive a password reset, which is why changing a password alone does not resolve a mailbox compromise.

The control that matters most

No change to payment details is ever accepted based on an email. Verification by voice, to a number already on file, every time, with no exception for urgency. This single procedure defeats every variant above, including the ones where the email is completely genuine.

The details matter. Call a number you already hold — never the number in the email, which will reach the attacker. Speak to a known individual rather than whoever answers. Apply it to every change without a threshold, because attackers test with small amounts.

Make it a written policy, and make clear that following it can never be a disciplinary matter. Staff bypass verification when they fear appearing obstructive to a senior person, which is precisely the dynamic executive impersonation exploits.

Technical controls that help

  • MFA on all mailboxes, which addresses the initial access step
  • Alerting on new mail forwarding rules, especially those pointing externally. One of the highest-value detections available
  • Blocking automatic external forwarding by policy where the business does not need it
  • SPF, DKIM and DMARC correctly configured, so your domain cannot be trivially spoofed
  • External sender warnings on inbound mail, which help against lookalike domains
  • Impersonation protection flagging messages that appear to come from executives but originate externally
  • Monitoring for lookalike domain registrations resembling yours or your key vendors
  • Conditional access flagging sign-ins from unusual locations

None of these stop a genuine email from a genuinely compromised vendor mailbox. That is why the verification procedure is the primary control and the technical measures are supporting.

If it happens

Speed determines recovery, and the window is measured in hours.

  1. Contact your bank immediately and request a recall. The chance of recovery falls sharply after the first 24 to 48 hours.
  2. File a complaint with the FBI's Internet Crime Complaint Center. Their Recovery Asset Team can assist in freezing funds and has a meaningful success rate when notified quickly.
  3. Report to local law enforcement, which is often required for insurance.
  4. Notify your cyber insurer — note that this may fall under a crime or social engineering endorsement rather than the main cyber policy, and those endorsements frequently carry low sublimits worth checking before you need them.
  5. Investigate the mailbox. Determine whether yours or the vendor's was compromised, check for forwarding rules, and review what else was accessible.
  6. Notify the vendor if their mailbox was the source. They may not know, and other customers are being targeted with the same access.

The insurance point is worth checking in advance. Many businesses assume BEC losses fall under their cyber policy and discover at claim time that funds transfer fraud sits under a separate endorsement with a much lower limit — or was never added at all.

StepContactWhy it matters
1. Request a recallYour bankRecovery chances fall sharply after 24 to 48 hours
2. File a complaintFBI Internet Crime Complaint CenterIts Recovery Asset Team can help freeze funds
3. Report the crimeLocal law enforcementOften required for insurance
4. Notify your insurerCyber or crime insurerMay fall under a separate endorsement with a low sublimit
5. Investigate the mailboxYour IT providerFind forwarding rules and what else was accessible
6. Warn the vendorThe supplier, if their mailbox was the sourceOther customers are being targeted with the same access

Sources

  1. FBI Internet Crime Complaint Center (IC3) — Internet Crime Report 2025
  2. FBI Internet Crime Complaint Center (IC3) — Business Email Compromise: The $55 Billion Scam (PSA I-091124-PSA)
  3. Internal Revenue Service — Dangerous W-2 Phishing Scam Evolving; Targeting Schools, Restaurants, Hospitals, Tribal Groups and Others (IR-2017-20)
  4. Microsoft Security Blog — From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
  5. Microsoft Learn (Defender for Office 365) — Control external email forwarding

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.