The Most Expensive Email Your Business Will Ever Receive
No malware, no hacking scene, just a payment instruction that looks exactly right and isn’t. Business email compromise quietly causes some of the largest reported cybercrime losses every year. Here’s how it actually works, and the protocol that stops it cold.
Get the Free Business Email Compromise Guide
Six plain English pages: the anatomy, the verification protocol, the anti BEC baseline, and the first hours response if a payment already moved. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.
Why BEC Beats Companies With Good Security
Business email compromise doesn’t attack your firewall. It attacks a moment of routine trust, which is why it works everywhere.
It Rides Real Relationships
The fraudulent instruction arrives inside a genuine business relationship: a vendor you pay monthly, a customer who owes you, an executive whose requests get handled. The context is real. Only the bank account is fake.
It's Patient
Attackers compromise one inbox, set quiet forwarding rules, and read for weeks: names, amounts, schedules, tone, even inside jokes. By the time they act, they know the relationship better than a new employee would.
It Times the Ask Perfectly
The banking change lands when a real payment is due, from the expected sender, on the expected thread, often with urgency that discourages the phone call. Every element is engineered to make verification feel unnecessary.
The Anatomy of a Diverted Payment
Whether the target is an invoice, a payroll change, a closing, or a vendor payment, the play runs in the same acts.
Act One: The Way In
A phishing email or reused password compromises one mailbox, yours or a partner’s. Forwarding rules copy the correspondence out silently. Nothing looks wrong, because nothing has happened yet.
Act Two: The Study
Weeks of quiet reading: who approves payments, which vendors are due, how people sign off, when the busy days are. Sometimes a lookalike domain gets registered, one letter off, for the moment it’s needed.
Act Three: The Swap
New banking details arrive at the perfect moment, or a payroll change request, or an executive’s urgent transfer. Everything matches expectations. The payment executes, lands in a mule account, and begins hopping within hours.
The Aftermath
Recovery is possible mainly in the first hours: immediate calls to both banks and a report through law enforcement channels before the money fragments. Past that window, recovery is rare and the disputes over who bears the loss begin.
The Anti BEC Baseline
The defense is procedural first and technical second. This is the baseline worth reviewing with whoever runs your IT.
The Verification Protocol
Banking details are established once, they never change by email, and any change request triggers a phone call to a number from original documents. Written, trained, no exceptions for urgency or seniority.
MFA on Every Mailbox
One unprotected account, yours or an assistant’s, is the way in. Multifactor authentication everywhere closes act one for most attempts.
Forwarding Rule Alerts
Silent auto forwarding is the attacker’s copy machine. Monitoring that flags new rules and impossible logins catches the study phase early.
Impersonation Resistant Email
Advanced phishing protection tuned for lookalike domains and display name tricks, plus enforced SPF, DKIM, and DMARC so criminals can’t send as you.
Payment Process Hygiene
Dual approval above a threshold, vendor master file changes controlled and logged, and payroll banking changes verified with the employee by voice.
Train the Money Handlers
AP, payroll, finance, and executive assistants targeted most, trained best: short, regular, scenario based, with an easy way to report the weird one.
Common Questions
What is business email compromise?
A fraud where attackers use a compromised or convincingly impersonated email account to redirect legitimate payments: vendor invoices, payroll deposits, wire transfers, real estate closings, or executive requested transfers. There’s typically no malware involved, which is why it slips past technical defenses and why it consistently produces some of the largest reported cybercrime losses.
How do attackers make fraudulent payment emails so convincing?
They read the real correspondence first. After compromising one mailbox in the relationship, they study amounts, schedules, sign offs, and tone for weeks, then send the banking change at exactly the moment a real payment is due, from the expected thread. Sometimes they use a lookalike domain one character off from the real one.
What stops business email compromise?
A verification protocol, applied without exceptions: banking details never change by email, and any change request is confirmed by phone using a number from original documents, not from the email. Layer MFA on every mailbox, alerts on forwarding rules, impersonation resistant email filtering, and dual approval on large payments, and the attack loses its path.
What should we do if a payment already went to a fraudulent account?
Act within hours. Call your bank’s fraud line and the receiving bank immediately to request a recall and freeze, report through law enforcement cybercrime channels the same day, notify your insurer, and preserve the emails as evidence. Speed matters more than anything else, because the money begins fragmenting into other accounts almost immediately.
What is in the free business email compromise guide?
A six page plain English guide covering the anatomy of a diverted payment, why BEC defeats technically secure companies, the verification protocol ready to adopt, the anti BEC baseline checklist, and the first hours response if a payment already moved.
Start With the Guide. Decide From There.
Download the Business Email Compromise Guide and put the verification protocol in place this week. If you’d rather have your exposure verified, a free confidential assessment is available too.