Business email compromise is a fraud problem that shows up in your inbox. Attackers impersonate a vendor, executive, or employee to redirect money, and the email often looks completely normal. So the best defense combines mailbox security with a payment process that does not trust email alone.
What business email compromise costs, according to the FBI
The FBI’s Internet Crime Complaint Center tracks these losses each year. In its 2024 Internet Crime Report, the IC3 recorded 21,442 business email compromise complaints with losses of about $2.77 billion.
Those figures only include reported cases. In addition, the same report put total reported cybercrime losses at $16.6 billion for the year. BEC remains one of the costliest categories on that list.
The attack needs no malware and no advanced skill. That is why it keeps working against organizations of every size.
Nonprofits and professional firms are frequent targets as well. They move money on predictable schedules, and they often rely on a small finance team. As a result, one convincing email can reach the one person who can send a wire.
How the scams actually unfold
Most BEC cases follow a few familiar scripts. Knowing them helps staff spot the pattern.
The vendor invoice change
An attacker gets into a vendor’s mailbox, or registers a lookalike domain. Then they reply to a real invoice thread with “new banking details.” Because the thread is genuine, the request feels routine.
The payroll diversion
HR receives a request from an “employee” to change their direct deposit account. The next paycheck goes to the attacker. Often nobody notices until the real employee asks where their pay went.
The executive request
Someone in finance gets an urgent note from the “CEO” asking for a wire or gift cards. The message stresses secrecy and speed. As a result, the normal checks get skipped.
Lock down the mailbox first
Many BEC attacks begin with a compromised account inside your own organization. Once in, attackers read email quietly for weeks and wait for the right invoice. So start with the basics that keep them out.
First, require MFA on every mailbox, and block legacy sign-in methods that bypass it. Next, alert on new inbox rules, especially rules that forward or hide messages. Attackers use these rules to hide replies from the real account owner.
Also, set up SPF, DKIM, and DMARC on your domain. These records make it harder for attackers to send email that appears to come from you. Finally, tag external email clearly so staff notice when a “coworker” is writing from outside.
Remember the vendor side
Your own mailbox may be perfectly secure while a vendor’s account is not. In that case, the fraud arrives inside a real thread from a real address. That is why the payment process below matters so much.
It also helps to tell key vendors how you will confirm bank changes. Then they know to expect a call, and they can warn you if someone impersonates you to them.
Fix the payment process, not just the technology
Technology helps, but no filter catches every well-written fraud. The strongest control is a payment process that assumes email can be faked. In my experience, this is the step organizations skip, because it feels like extra paperwork.
Put these controls in writing and apply them without exceptions:
- Verify any change to bank details with a phone call to a number already on file.
- Never use the phone number in the email that requested the change.
- Require two people to approve wires above a set threshold.
- Hold new or changed payment details for a short waiting period.
- Confirm payroll deposit changes in person or through the HR system.
- Give staff explicit permission to delay any “urgent” executive request.
That last item matters. People skip checks when they fear upsetting a leader. So leaders should say openly that they expect to be called back.
What to do in the first hour after a fraudulent payment
Speed matters more than anything else once money moves. First, call your bank and ask them to recall the transfer. Then file a complaint at ic3.gov right away.
The IC3’s 2024 report says its Recovery Asset Team works with banks to freeze funds through the Financial Fraud Kill Chain. It reported a 66 percent success rate for the cases it acted on that year. However, that process depends on fast reporting.
Write these steps on a single page and keep a printed copy in finance. During a business email compromise, people panic, and a checklist keeps them moving.
Next, reset the passwords of any affected mailbox and review its rules and sign-ins. Also, warn the vendor or employee who was impersonated. Finally, call your cyber insurance carrier, because many policies require prompt notice.
Train for the specific scenarios
Generic phishing training helps, but BEC needs targeted practice. Walk your finance, HR, and executive assistant staff through the three scripts above. Then run a tabletop exercise where someone receives a fake bank change request.
Keep the lesson simple. Any request that changes where money goes gets verified by phone, every time.
Red flags worth teaching
Well-crafted BEC messages rarely contain obvious typos. So teach people to notice the request itself instead:
- A change to bank details, especially near a payment date
- Pressure to act quickly or keep the request confidential
- A sender domain that is one letter off from the real one
- Reply-to addresses that differ from the sender
- A request to move the conversation to text or a personal email
How WEBIT approaches this
We set up mailbox protections, inbox rule alerts, and email authentication records as standard practice. When an alert fires, our cybersecurity team investigates the account rather than just closing the ticket.
We also help leadership write payment verification procedures, because business email compromise is as much a process gap as a technical one. That work often starts with a risk conversation through our strategic IT services.
Key takeaways
- The FBI’s IC3 recorded about $2.77 billion in BEC losses for 2024.
- Most scams target payment changes, payroll, and urgent executive requests.
- MFA, inbox rule alerts, and DMARC reduce mailbox takeover risk.
- Phone verification of payment changes is the strongest single control.
- After a fraud, call the bank and file with IC3 immediately.
Related from WEBIT: email spoofing checker and financial services IT support in Naperville.
Want someone to pressure-test your payment and email controls? Talk to an owner.





