Business Email Compromise (BEC)

BEC attacks cost businesses billions annually through fraudulent wire transfers. Learn how to recognize and prevent invoice and payment fraud.

What You Need to Know

Business Email Compromise (BEC) targets businesses by impersonating executives, vendors, or partners to trick employees into transferring money or sensitive data. The FBI reports BEC as one of the most financially damaging cybercrimes.

Unlike ransomware or malware, BEC relies on social engineering. Criminals exploit trust, authority, and routine business processes. Attacks are often well-researched and timed for maximum effectiveness.

How BEC Attacks Work

1Account Compromise or Impersonation

Criminals either hack into legitimate business email accounts through phishing/credential theft, or create lookalike email addresses that impersonate executives or vendors.

2Reconnaissance

Attackers monitor compromised accounts to learn about business operations, relationships, communication styles, and upcoming transactions. This allows highly tailored attacks.

3Timing the Attack

Attacks are timed for maximum effectiveness—when executives are traveling, when large invoices are due, or when time zones create communication delays.

4Sending the Request

Fraudulent emails request wire transfers, payment detail changes, or sensitive information. They match normal business operations and appear to come from trusted sources.

5Receiving the Funds

Money is wired to attacker-controlled accounts, often overseas. Funds are quickly moved through multiple accounts to prevent recovery.

Warning Signs to Watch For

Urgent requests for wire transfers from executives

Emails claiming to be from the CEO requesting immediate, confidential wire transfers.

Vendor payment detail changes

Requests to update bank account information for invoice payments.

Unusual timing or communication style

Emails sent outside normal hours or with different tone/language than usual.

Requests for secrecy

Instructions to keep the request confidential or not discuss with others.

Pressure to bypass normal procedures

Claims of special circumstances requiring immediate action without normal approvals.

Slightly altered email addresses

Addresses that look legitimate but have subtle differences (ceo@cornpany.com vs ceo@company.com).

Requests for employee W-2 or personal data

Emails asking HR to send all employee tax records or sensitive information.

Psychological Tactics Used

Authority

Impersonating CEOs, CFOs, or other executives whose instructions employees are conditioned to follow without question.

Urgency

Creating time pressure that discourages verification: 'I need this done before the close of business today.'

Secrecy

Requesting confidentiality ('Don't mention this to anyone') isolates targets from the colleagues who might spot the fraud.

Trust in Relationships

Leveraging established vendor relationships and ongoing invoice streams to make fraudulent requests seem routine.

Who Is Most at Risk

  • Businesses that conduct wire transfers
  • Companies working with international vendors
  • Organizations with public information about executives
  • Finance and accounts payable employees
  • HR departments with access to employee data
  • Companies without dual approval requirements for payments
  • Businesses lacking security awareness training

Real-World Scenario

The Vendor Invoice Scam

$340,000 lost to invoice fraud

A construction company received an email appearing to be from a regular supplier, informing them that the vendor had changed banks and providing new wire transfer details. The email came from an address nearly identical to the real vendor's. The company paid $340,000 to the new account. When the real vendor inquired about the overdue payment, the company discovered the fraud. The money had already been transferred overseas.

Red Flags Present:

  • Request to change payment details via email
  • Slightly altered sender email address
  • No phone verification of banking change
  • Large payment without dual approval
  • No independent confirmation with vendor

How to Protect Your Business

Verify Payment Changes by Phone

Always confirm banking detail changes by calling a known number for the vendor—not a number provided in the email.

Implement Dual Authorization

Require two people to approve wire transfers or payments above a certain threshold.

Enable Multi-Factor Authentication

Protect all email accounts with MFA to prevent unauthorized access.

Train Employees Regularly

Conduct ongoing security awareness training focused on BEC tactics and verification procedures.

Verify New Vendor Setup

Confirm new vendor details through independent research, not information provided by the vendor.

Scrutinize Urgent Executive Requests

Establish protocols for verifying unusual requests from executives, especially for wire transfers.

What to Do If You've Been Affected

1

Contact Your Bank Immediately

Request a wire recall. Time is critical—notify your bank within 24-48 hours for the best chance of recovery.

2

File an FBI IC3 Complaint

Report to the FBI's Internet Crime Complaint Center at ic3.gov. The FBI's Recovery Asset Team works with banks to freeze funds.

3

Notify Your IT/Security Team

Determine if email accounts were compromised. Change passwords, enable MFA, and investigate the intrusion.

4

Preserve Evidence

Save all emails, headers, and communications related to the fraud for law enforcement investigation.

5

Notify Affected Parties

If employee data was compromised, notify affected employees and consider credit monitoring.

6

Review and Strengthen Procedures

Analyze how the attack succeeded and implement additional controls to prevent recurrence.

How Smart Money Verified Helps Consumers Stay Informed

Smart Money Verified provides independent educational resources to help consumers understand financial risks, scams, and warning signs. Our guides are designed to help individuals make informed decisions before committing capital or assets.

Frequently Asked Questions

Protect Your Investments

Download our free Investor Protection Guide with actionable steps to verify companies and avoid scams.

I agree to receive recurring automated text messages at the phone number provided. Consent is not a condition to purchase. Msg & data rates may apply. Reply HELP/STOP. Terms & Privacy.

Your information is secure and never sold