
A single email costs businesses more money than almost any other cyber threat — and it usually contains no virus, no malicious link, and nothing a spam filter would flag. It’s just a convincing message asking someone to make a payment or change bank details. This is business email compromise, or BEC, one of the most financially devastating scams targeting companies today. Because it exploits human trust rather than technical flaws, BEC slips past many defenses. In this guide, we’ll explain how BEC works, why it’s so effective, and exactly how to protect your business.
What Is Business Email Compromise?
Business email compromise is a scam in which an attacker impersonates a trusted party — an executive, employee, supplier, or partner — to trick someone into transferring money or sharing sensitive information. Unlike typical phishing that casts a wide net, BEC is targeted and carefully researched, designed to look like a legitimate business request.
What makes BEC so dangerous is its simplicity. There’s often no malware to detect and no obviously malicious link. The attack is pure social engineering: a believable message, from a seemingly trusted source, asking for an action that seems routine. By the time anyone realizes something is wrong, the money is frequently gone.
How a BEC Attack Works
BEC attacks typically unfold in stages. First, the attacker researches the target, gathering information about the company, its people, and its relationships from websites, social media, and other public sources. They learn who handles payments, who the executives are, and which suppliers the business works with.
Next, they gain a foothold for impersonation. This might involve compromising a real email account through phishing, or more commonly, creating a lookalike email address that closely mimics a genuine one — often with a single altered character that’s easy to overlook. Then comes the request: a carefully worded email, matching the tone and style of the person being impersonated, asking for an urgent payment, a change to banking details, or sensitive information. Finally, if successful, the money is transferred to the attacker’s account and quickly moved on, making recovery difficult.
Common Types of BEC Scams
BEC takes several recognizable forms, each exploiting a different business relationship.
CEO Fraud
The attacker impersonates a senior executive or business owner and emails an employee — often in finance — with an urgent request to transfer funds. The apparent authority of the sender and the urgency of the request pressure the employee to act quickly without questioning.
Invoice and Supplier Fraud
Here the attacker poses as a supplier or vendor, sending a legitimate-looking invoice with updated bank details — their own. The business, believing it’s paying a genuine supplier, sends the money straight to the criminal. This is especially effective when a real invoice was expected.

Account Compromise
If an attacker gains access to a real employee’s email account, they can send fraudulent requests from a genuine address, monitor conversations, and insert themselves into real payment discussions. Because the emails come from a legitimate account, these attacks are particularly convincing and hard to spot.
Attorney or Authority Impersonation
Attackers may pose as a lawyer, accountant, or other authority figure handling a confidential or time-sensitive matter, pressuring the target to act quickly and discreetly. The claimed authority and secrecy discourage the victim from verifying the request.
Data Theft
Not all BEC targets money directly. Some attacks impersonate executives to request sensitive information — such as employee records or tax documents — which can then be used for further fraud or identity theft.
Why BEC Is So Effective
BEC succeeds because it exploits fundamental aspects of human behavior and business operations. It leverages authority, so an employee is reluctant to question a request that appears to come from a boss. It uses urgency, pressuring people to act before they take time to verify. It relies on trust in familiar names and routine processes, so a payment request doesn’t seem unusual. And it often avoids technical red flags entirely, meaning spam filters and antivirus tools have nothing to catch. In short, BEC turns the normal, trusting flow of business communication into a weapon.
Warning Signs of a BEC Attempt
Training your team to recognize the red flags is one of the most effective defenses. Be suspicious of any message that shows these signs:
- Unexpected urgency or pressure to act immediately, especially involving money.
- Requests to change bank account or payment details.
- Slight differences in the sender’s email address or domain.
- Requests to bypass normal procedures or keep the matter confidential.
- Unusual requests from executives, especially for wire transfers or gift cards.
- Changes in tone, phrasing, or writing style from the supposed sender.
- A reluctance to communicate by phone or in person to confirm.
How to Protect Your Business from BEC
Because BEC targets people and processes, your defense combines human awareness with practical safeguards.
1. Verify Financial Requests Independently
This is the single most important defense. Establish a firm rule that any request to transfer money or change payment details must be verified through a separate, trusted channel — a phone call to a known number, not a reply to the email. This one habit stops the vast majority of BEC attacks in their tracks.
2. Establish Clear Payment Procedures
Create documented processes for payments and changes to financial details, including approval steps for large transfers. When everyone follows a consistent procedure, unusual requests stand out and can’t simply bypass the system through urgency or authority.
3. Train Your Team Regularly
Educate employees — especially those in finance — about how BEC works and what the warning signs are. Regular, practical training keeps awareness high and reinforces the habit of verifying suspicious requests.
4. Secure Email Accounts with MFA
Since account compromise is a route into BEC, protect email accounts with multi-factor authentication. This makes it far harder for attackers to take over a genuine account and send fraudulent messages from it.
5. Use Email Authentication
Set up email authentication measures for your domain to make it harder for attackers to spoof your business’s email address. This protects both your team and your customers and suppliers from impersonation.
6. Scrutinize Email Addresses Carefully
Encourage employees to check sender addresses closely, especially on any message involving money. A lookalike domain with a single changed character is a classic BEC tactic that a careful glance can catch.
7. Foster a Blame-Free Culture
Employees should feel able to question an unusual request — even one that appears to come from the boss — and to report a suspected scam or mistake without fear. Attackers rely on people being too intimidated to verify; a culture that empowers verification defeats them.
What to Do If You Fall Victim
If you suspect a BEC scam has succeeded, act immediately — speed is critical to any chance of recovering funds. Contact your bank right away to report the fraudulent transfer and request a recall of the funds. Report the incident to the relevant authorities, as some transfers can be intercepted if reported quickly enough. Secure any compromised accounts by changing passwords and enabling MFA. Warn your team so others aren’t caught by the same or a related scam. Finally, review how the attack succeeded and strengthen your procedures to prevent a repeat. The faster you respond, the better your chances of limiting the damage.
Building Long-Term Resilience
Defending against BEC isn’t a one-time task but an ongoing commitment woven into how your business operates. Make verification of financial requests a permanent, non-negotiable habit. Keep payment procedures documented and followed consistently. Refresh employee training regularly, since attackers continually adjust their tactics. And review your defenses periodically to ensure they keep pace. A business that treats these practices as standard operating procedure becomes a remarkably hard target — the kind of company where a fraudulent payment request simply can’t slip through unquestioned.
A Realistic BEC Scenario
To see how easily BEC works, imagine a small design agency. The attacker studies the agency’s website and social media, learning the owner’s name and that the office manager, Sarah, handles supplier payments. They register a domain almost identical to the agency’s — swapping one letter — and email Sarah, posing as the owner: “Hi Sarah, I’m in back-to-back client meetings today. Can you urgently pay the attached invoice for our new print supplier? They’re chasing us and I promised it’d be sorted by end of day. Thanks!”
The email uses the owner’s name, matches their casual tone, creates urgency, and provides a plausible reason the owner can’t be reached. Everything is designed to make Sarah act quickly. If she processes the payment without verifying, the money goes straight to the attacker. But if the agency has a simple rule — always confirm payment requests by phone using a known number — Sarah calls the owner, discovers he sent no such email, and the scam collapses. The entire difference between loss and safety is one verification habit. That’s why the human process matters more than any single piece of software here.
Technology and People: Both Matter
Defending against BEC requires the right balance of technical measures and human vigilance, because each covers the other’s blind spots. Technology plays an important supporting role: multi-factor authentication prevents attackers from hijacking real email accounts, email authentication makes spoofing your domain harder, and some advanced email security tools can flag lookalike domains or unusual sender behavior. These measures reduce the number of convincing fraudulent emails that reach your team.
But because the most effective BEC attacks contain nothing technically malicious, people remain the decisive line of defense. An employee who pauses, notices a slightly wrong address, and picks up the phone stops an attack no filter could catch. The strongest protection therefore layers technology beneath a well-trained, alert team operating within clear payment procedures. Neither alone is enough; together, they make your business a target that’s simply too difficult and too well-defended to be worth an attacker’s effort.
Frequently Asked Questions
Why don’t spam filters catch BEC emails?
Because BEC emails often contain no malicious links or attachments — just a plausible request in plain text. There’s nothing technical for filters to flag, which is why human verification is the essential defense.
Who in my business is most at risk?
Employees who handle payments and finances are prime targets, as are executives whose accounts and authority are valuable to impersonate. However, anyone can be targeted, so awareness across the whole team matters.
Can multi-factor authentication stop BEC?
MFA helps significantly by preventing attackers from taking over genuine email accounts. However, BEC using lookalike domains doesn’t involve account takeover, so MFA must be combined with verification habits and clear payment procedures for full protection.
Is BEC really a threat to small businesses?
Yes. Small businesses are frequently targeted because they may lack formal payment controls and verification procedures. The financial impact of a single successful BEC attack can be severe for a smaller company.
Final Thoughts
Business email compromise is a reminder that the most dangerous cyber threats don’t always involve sophisticated hacking — sometimes they’re just a convincing lie in an ordinary-looking email. Because BEC targets human trust and business routine, technology alone can’t stop it. Your strongest defenses are simple but powerful: verify every financial request through a separate channel, establish clear payment procedures, train your team, secure your email accounts, and build a culture where questioning an unusual request is encouraged. Put these safeguards in place, and you’ll close the door on one of the costliest scams facing businesses today.