Business Email Compromise | Educational Resource

The Most Expensive Email Your Business Will Ever Receive

No malware, no hacking scene, just a payment instruction that looks exactly right and isn’t. Business email compromise quietly causes some of the largest reported cybercrime losses every year. Here’s how it actually works, and the protocol that stops it cold.

The anatomy of a diverted payment, in three acts
Why BEC beats companies with good security
The verification protocol, ready to adopt this week
The anti BEC baseline to review with whoever runs your IT

Get the Free Business Email Compromise Guide

Six plain English pages: the anatomy, the verification protocol, the anti BEC baseline, and the first hours response if a payment already moved. Instant delivery.
No spam. Unsubscribe anytime. Your information stays private.

Top Losses
BEC leads reported cybercrime loss totals year after year
No Malware
the weapon is a convincing email, nothing more
Hours
is the recovery window once a wire moves
One Rule
verified by phone at a known number, every time

Why BEC Beats Companies With Good Security

Business email compromise doesn’t attack your firewall. It attacks a moment of routine trust, which is why it works everywhere.

It Rides Real Relationships

The fraudulent instruction arrives inside a genuine business relationship: a vendor you pay monthly, a customer who owes you, an executive whose requests get handled. The context is real. Only the bank account is fake.

It's Patient

Attackers compromise one inbox, set quiet forwarding rules, and read for weeks: names, amounts, schedules, tone, even inside jokes. By the time they act, they know the relationship better than a new employee would.

It Times the Ask Perfectly

The banking change lands when a real payment is due, from the expected sender, on the expected thread, often with urgency that discourages the phone call. Every element is engineered to make verification feel unnecessary.

The Anatomy of a Diverted Payment

Whether the target is an invoice, a payroll change, a closing, or a vendor payment, the play runs in the same acts.

01

Act One: The Way In

A phishing email or reused password compromises one mailbox, yours or a partner’s. Forwarding rules copy the correspondence out silently. Nothing looks wrong, because nothing has happened yet.

02

Act Two: The Study

Weeks of quiet reading: who approves payments, which vendors are due, how people sign off, when the busy days are. Sometimes a lookalike domain gets registered, one letter off, for the moment it’s needed.

03

Act Three: The Swap

New banking details arrive at the perfect moment, or a payroll change request, or an executive’s urgent transfer. Everything matches expectations. The payment executes, lands in a mule account, and begins hopping within hours.

04

The Aftermath

Recovery is possible mainly in the first hours: immediate calls to both banks and a report through law enforcement channels before the money fragments. Past that window, recovery is rare and the disputes over who bears the loss begin.

The Anti BEC Baseline

The defense is procedural first and technical second. This is the baseline worth reviewing with whoever runs your IT.

The Verification Protocol

Banking details are established once, they never change by email, and any change request triggers a phone call to a number from original documents. Written, trained, no exceptions for urgency or seniority.

MFA on Every Mailbox

One unprotected account, yours or an assistant’s, is the way in. Multifactor authentication everywhere closes act one for most attempts.

Forwarding Rule Alerts

Silent auto forwarding is the attacker’s copy machine. Monitoring that flags new rules and impossible logins catches the study phase early.

Impersonation Resistant Email

Advanced phishing protection tuned for lookalike domains and display name tricks, plus enforced SPF, DKIM, and DMARC so criminals can’t send as you.

Payment Process Hygiene

Dual approval above a threshold, vendor master file changes controlled and logged, and payroll banking changes verified with the employee by voice.

Train the Money Handlers

AP, payroll, finance, and executive assistants targeted most, trained best: short, regular, scenario based, with an easy way to report the weird one.

Common Questions

A fraud where attackers use a compromised or convincingly impersonated email account to redirect legitimate payments: vendor invoices, payroll deposits, wire transfers, real estate closings, or executive requested transfers. There’s typically no malware involved, which is why it slips past technical defenses and why it consistently produces some of the largest reported cybercrime losses.

They read the real correspondence first. After compromising one mailbox in the relationship, they study amounts, schedules, sign offs, and tone for weeks, then send the banking change at exactly the moment a real payment is due, from the expected thread. Sometimes they use a lookalike domain one character off from the real one.

A verification protocol, applied without exceptions: banking details never change by email, and any change request is confirmed by phone using a number from original documents, not from the email. Layer MFA on every mailbox, alerts on forwarding rules, impersonation resistant email filtering, and dual approval on large payments, and the attack loses its path.

Act within hours. Call your bank’s fraud line and the receiving bank immediately to request a recall and freeze, report through law enforcement cybercrime channels the same day, notify your insurer, and preserve the emails as evidence. Speed matters more than anything else, because the money begins fragmenting into other accounts almost immediately.

A six page plain English guide covering the anatomy of a diverted payment, why BEC defeats technically secure companies, the verification protocol ready to adopt, the anti BEC baseline checklist, and the first hours response if a payment already moved.

Start With the Guide. Decide From There.

Download the Business Email Compromise Guide and put the verification protocol in place this week. If you’d rather have your exposure verified, a free confidential assessment is available too.

Fill the information below to download a PDF with everything you need to know about Penetration Test: