All Articles
Cybersecurity

Business Email Compromise: The Fraud That Looks Like a Normal Email

September 28, 20265 min read

Most people picture a cyberattack as someone breaking through a firewall or deploying malware. Business email compromise does not look like that. It looks like a normal email from your accountant, your CEO, or a vendor you have worked with for years. The goal is not to steal data. The goal is to get someone to move money. And it works more often than most small business owners realize.

What business email compromise actually is

Business email compromise, often called BEC, is a type of fraud where an attacker impersonates a trusted person to trick an employee into sending money or sharing sensitive information. No malware is involved. No systems are hacked. The entire attack runs through email.

The FBI consistently ranks BEC as one of the costliest cybercrime categories, not because it happens at massive scale but because each individual incident tends to involve a large transfer. A single successful BEC attack at a small business can mean tens of thousands of dollars wired to an account that cannot be recovered.

The three most common versions

CEO fraud is the most well-known version. An employee in accounting or operations receives an email that appears to be from the owner or a senior executive, asking for an urgent wire transfer. The email looks right. The tone sounds right. The request is just unusual enough that a careful employee might hesitate, but urgent enough that many do not.

Vendor fraud works the same way but impersonates a supplier your company regularly pays. The email explains that the vendor has changed its banking information and asks you to update your records. The next invoice gets paid to the attacker's account.

Payroll fraud targets HR or payroll staff directly. An email appearing to come from an employee requests a change to their direct deposit information before the next pay cycle. The change goes through. The real employee contacts HR wondering where their paycheck is.

Why it works so well

BEC attacks are effective for a few reasons that have nothing to do with technical sophistication.

First, attackers research their targets. Before sending anything, they study the company: who the executives are, what vendors are used, how the company communicates. A BEC email that uses the right name, the right title, and the right tone does not read like a scam.

Second, the emails almost always include urgency. The wire needs to go out today. The payroll change needs to happen before Thursday. Urgency is a deliberate tool. It short-circuits the pause that might otherwise lead someone to pick up the phone and verify.

Third, many small businesses do not have a formal process for verifying financial requests, which means there is no built-in friction standing between the email and the action.

How BEC attacks usually start

Some BEC attacks use spoofed email addresses that look like a real address but are not. The display name says the right thing, but the actual sending address is slightly different. Others start with a real account compromise: an attacker gains access to a legitimate email account and sends the fraudulent request from it directly, which makes it even harder to catch.

Domain spoofing is common too. A company that uses the domain companyname.com might find attackers sending from companyname-billing.com or company-name.com. These pass a casual glance.

What to put in place

  • A verbal verification rule for any wire transfer request, regardless of who it appears to come from. A quick phone call to a known number takes 90 seconds and stops most BEC attempts entirely.
  • A process for any banking detail change from a vendor. Changes to payment information should require a callback to a verified number, not just a reply to the email making the request.
  • Email security that flags messages where the display name does not match the actual sending domain, which catches spoofing before it reaches the inbox.
  • Multi-factor authentication on every email account, so a compromised password alone is not enough to send fraudulent emails from a legitimate account.
  • Brief staff training that covers BEC specifically, since it looks different from a phishing email and the standard advice about suspicious links does not apply.

The controls that stop BEC are not complicated. A wire transfer verification policy costs nothing and can be implemented today. Email security and MFA are standard parts of a well-configured Microsoft 365 setup. If you are not sure whether your current email environment is configured to flag spoofed senders or whether your team has a clear process for financial requests, those are worth checking before you need to.

ITM Consulting

Questions about your IT setup?

We work with small businesses and accounting firms across the Chicago area. Schedule a free 30-minute consultation and we will tell you honestly what we see.

See Our Cybersecurity ServicesSchedule Free ConsultationCall 630.392.6129

More Articles

Cybersecurity

Security Awareness Training: What It Is and Why Most Small Businesses Get It Wrong

Cybersecurity

What Is Dark Web Monitoring and Should Your Business Be Using It?

Cybersecurity

Is Your Business Wi-Fi a Security Risk? What Small Business Owners Need to Know