A familiar vendor emails your accounting department with updated banking information.
The message arrives in an existing conversation. The invoice number is correct. The sender knows the project, the payment amount, and the people involved. Nothing about the request immediately looks unusual.
The problem is that the vendor’s email account has been compromised, and the new banking instructions belong to a criminal.
This is one of the reasons business email compromise can be so difficult to prevent. The request may not look like a typical phishing email. It may appear to be part of a normal business process involving someone your employees already know and trust.
Reducing the risk requires more than telling employees to look for spelling mistakes. Businesses need email and account protections, clear payment-verification procedures, appropriate approval controls, and employees who know what to do when a request feels unusual.
Key Takeaway
One convincing email should not be enough to change where your business sends money.
Business email compromise prevention works best when email security, multi-factor authentication, employee awareness, independent payment verification, and approval controls work together.
What Is Business Email Compromise?
Business email compromise, commonly called BEC, is a form of fraud in which a criminal uses email or another communication method to impersonate someone the recipient trusts.
The attacker may pretend to be:
- A company executive
- An employee
- A vendor
- A customer
- A financial institution
- A payroll or human resources representative
- An attorney, advisor, or other business partner
Some BEC attempts use a fake email address that closely resembles the real one. Others come from a legitimate account that the attacker has already taken over.
That second scenario is particularly dangerous. A compromised mailbox can give the attacker access to real conversations, signatures, invoices, calendars, vendor relationships, and payment schedules. The criminal can study how the organization communicates and wait for the right time to make a fraudulent request.
The FBI’s 2025 Internet Crime Complaint Center report recorded more than $3.04 billion in reported BEC losses, making it one of the largest categories of reported cyber-enabled fraud by financial loss.
Common Types of Business Email Compromise
BEC can affect more than the person responsible for paying invoices. Attacks regularly target executives, finance teams, payroll employees, office managers, project managers, executive assistants, and anyone who can approve a payment or change important account information.
Invoice and Payment-Change Fraud
A criminal impersonates a vendor and asks the business to send an upcoming payment to a different bank account.
The request may claim that:
- The vendor recently changed banks
- The previous account has been closed
- The invoice contains outdated payment information
- A payment must be redirected due to an accounting issue
- The vendor needs the payment sent by wire or ACH
- A new subsidiary or payment processor is handling the transaction
In some cases, the attacker creates a look-alike email address. In others, the criminal compromises the vendor’s actual mailbox and inserts fraudulent instructions into a legitimate conversation.
The invoice itself may be real. Only the payment information has been changed.
Executive Impersonation
An attacker pretends to be an owner, president, CFO, executive director, or other senior leader.
The message often asks an employee to act quickly and quietly. Common requests include:
- Sending a wire transfer
- Purchasing gift cards
- Paying an unfamiliar invoice
- Releasing sensitive financial information
- Changing a vendor’s payment details
- Sending employee tax or payroll information
- Bypassing a normal approval process
These attacks exploit authority as much as technology. An employee may notice that the request is unusual but hesitate to question a senior leader.
Compromised Vendor Accounts
A message from a compromised vendor account may pass many of the basic checks employees have been taught to use.
The sender address is correct. The email signature is real. The message may contain accurate details from previous conversations.
This is why checking the sender address is important but not sufficient. A business should independently verify any change involving payment instructions, bank accounts, direct deposits, or other sensitive information, even when the email appears legitimate.
Payroll and Direct-Deposit Fraud
The attacker impersonates an employee and asks human resources or payroll to change the bank account used for direct deposit.
The request may be short and routine:
I recently changed banks. Can you update my direct deposit before the next payroll?
Without a separate verification step, payroll could redirect an employee’s wages to the attacker.
Client Payment Redirection
BEC can also originate inside your own organization.
When a company email account is compromised, the attacker may contact customers and provide fraudulent payment instructions. Clients may believe they are paying your business when the money is actually being sent to someone else.
This can create financial loss for the client, delayed payment for your organization, and a difficult conversation about who is responsible.
Why Business Email Compromise Works
BEC attacks are effective because they are designed to resemble ordinary business activity.
Employees routinely receive invoices, payment requests, account changes, payroll questions, and urgent messages from leadership. Criminals place fraudulent requests inside those familiar workflows.
Several business conditions can make the deception more convincing:
- Finance teams work under payment deadlines.
- Executives sometimes send short or urgent requests.
- Vendors occasionally change banking information.
- Employees may be reluctant to question senior leadership.
- Small teams may have limited separation between requesting and approving payments.
- Vendor contact information may not be centrally maintained.
- Payment procedures may be informal or undocumented.
- Employees may rely on email as the only verification method.
The problem is not necessarily that an employee was careless. A well-planned BEC attempt may include accurate information and arrive at exactly the right time.
The better response is to build a process in which one convincing email is not enough to authorize a sensitive change.
How to Reduce the Risk of Business Email Compromise
No single tool or policy can prevent every BEC attempt. The strongest approach combines technical security with practical business procedures.
1. Independently Verify Payment and Account Changes
Any request to change banking, payment, payroll, direct-deposit, or account information should be confirmed through a separate communication channel.
Call a known contact using a phone number that was already on file before the request arrived. For internal requests, speak with the employee or executive directly using an established company number.
Do not verify the change by:
- Replying to the same email
- Calling a phone number included in the request
- Using contact information from an attached invoice
- Asking the email sender to confirm by email
- Relying only on the sender’s signature
- Allowing urgency to override the normal process
The FBI recommends independently verifying changes to account numbers and payment procedures, particularly when a requester is pressuring the recipient to act quickly.
Before Approving New Payment Instructions
Pause the transaction until each applicable question can be answered clearly.
- Was the change confirmed using a phone number or contact method already on file?
- Did the employee avoid using contact information supplied in the request?
- Has the identity and authority of the person requesting the change been confirmed?
- Was the change reviewed by a second person when required by company policy?
- Does the bank account name align with the vendor, employee, or intended recipient?
- Has the verification been documented, including who confirmed it and when?
Do not let urgency replace verification. Pressure to act quickly, avoid normal procedures, or keep a request confidential should trigger additional review.
2. Require Multi-Factor Authentication
Multi-factor authentication adds another verification step when someone signs in to an email account, financial platform, payroll system, or other important service.
A stolen password alone is then less likely to provide immediate access.
MFA should be consistently enforced across important systems, especially for:
- Microsoft 365 and business email
- Administrator accounts
- Banking and payment platforms
- Payroll and human resources systems
- Remote-access tools
- Accounting applications
- Cloud file storage
- Customer and vendor portals
Partial implementation can leave important gaps. Protecting executives but overlooking finance employees, administrators, shared mailboxes, or remote-access accounts may still give an attacker a useful path into the organization.
CISA describes MFA as a simple and effective step that can significantly reduce the risk of account compromise.
3. Strengthen Email Security and Account Monitoring
Email security should help identify suspicious messages before they reach employees, but filtering alone is not enough.
A stronger approach may include:
- Filtering malicious links and attachments
- Identifying messages that impersonate executives or vendors
- Flagging unusual sign-ins
- Monitoring for suspicious mailbox rules
- Reviewing automatic email forwarding
- Detecting impossible or unusual login activity
- Blocking known malicious senders
- Protecting the company’s email domain from unauthorized use
- Investigating security alerts instead of allowing them to sit unread
Email authentication controls such as SPF, DKIM, and DMARC can also help other mail systems determine whether a message claiming to come from your company was sent by an authorized source.
These controls can reduce certain forms of domain impersonation, but they do not prevent an attacker from using a look-alike domain or a legitimate account that has already been compromised.
That is why business cybersecurity should combine email protection, identity security, monitoring, access control, and employee awareness rather than relying on a single filter.
4. Use Appropriate Approval Controls
Sensitive payments and account changes should not depend entirely on one person’s inbox.
Depending on the organization, additional controls may include:
- Two-person approval for large payments
- Separate approval for new payment recipients
- Additional review of changes to vendor banking information
- Call-back verification for wire transfers
- Limits on who can change payroll or direct-deposit details
- Written documentation of who verified a change and when
- Alerts when a new payee or bank account is added
- Defined dollar thresholds for additional approval
The process should fit the organization’s size and normal transaction volume.
The goal is to make it harder for one fraudulent message to move money.
5. Train Employees Around Real Business Workflows
Generic phishing training often focuses on misspelled words, strange links, and obviously suspicious messages.
Those warning signs still matter, but BEC training should go further.
Employees should practice responding to realistic situations such as:
- A vendor changing banking information
- An executive requesting an urgent payment
- An employee asking to update direct deposit
- A client requesting sensitive financial records
- A known contact sending an unexpected file
- A supplier asking the employee to use a different phone number
- A request to bypass the normal approval process
- A message that continues a legitimate email conversation
Training should also explain exactly how to report a suspicious request and who should be contacted internally.
Finance, payroll, human resources, executives, office managers, executive assistants, and employees who manage vendor relationships deserve particular attention because their roles frequently involve sensitive transactions.
6. Make It Acceptable to Question an Unusual Request
Employees may recognize that something feels wrong and still complete the request because they do not want to delay a payment or question an executive.
Leadership should make the expectation clear:
It is acceptable to pause and independently verify any unusual payment, account change, or sensitive request.
An executive who sends legitimate urgent requests should still expect employees to follow the verification process. A vendor relationship should not be damaged because an accounting employee confirms new banking information through a known phone number.
Verification should be treated as responsible business practice, not insubordination or unnecessary delay.
7. Document the Process
Payment verification and incident reporting should not depend on employees remembering an informal conversation from several months ago.
Document:
- Which requests require independent verification
- Which contact information employees should use
- Who can approve payment changes
- When dual approval is required
- How verification should be recorded
- How suspicious emails should be reported
- Who contacts the bank after suspected fraud
- Who contacts the IT provider
- Who communicates with vendors, customers, insurers, or legal counsel
- How evidence should be preserved
This process can be incorporated into broader IT policies every business should have, including access control, incident response, acceptable use, and employee onboarding and offboarding.
What to Do After a Suspected Business Email Compromise
The appropriate response depends on whether the fraudulent request was stopped, an account was compromised, or money was already sent.
A Suspicious Email Was Received, but No Payment Was Sent
Do not reply, click links, open attachments, or call contact information contained in the message.
Instead:
- Contact the supposed sender using a known phone number or separate communication method.
- Report the email to your internal IT team or IT provider.
- Preserve the original message for investigation.
- Determine whether other employees received similar messages.
- Ask whether the sender’s real account may have been compromised.
- Review whether the attacker referenced information that may have come from another account or system.
Do not simply delete the email before it has been reported. The message headers, sender information, links, and attachments may help determine what happened.
Money Was Sent or an Account Was Compromised
Act immediately.
- Contact the financial institution. Request a recall or freeze and provide the transaction details.
- Notify your IT or cybersecurity provider. The affected accounts and systems should be investigated.
- Secure compromised accounts. Reset credentials, require MFA, revoke active sessions, and remove unauthorized access.
- Review mailbox settings. Check forwarding rules, inbox rules, delegates, connected applications, and recent sign-ins.
- Preserve evidence. Save emails, payment records, phone numbers, account information, and timelines.
- Contact affected parties. Notify vendors, employees, or clients when their information, accounts, or payments may be involved.
- Notify the cyber insurance provider. Follow the reporting and response requirements in the policy.
- Report the incident to the FBI’s Internet Crime Complaint Center.
- Review the process failure. Determine how the request bypassed technical protections or business procedures.
The FBI advises victims to contact their financial institution immediately and request that it contact the institution that received the transfer. BEC incidents can also be reported through IC3.
Fast action may improve the possibility of stopping or recovering a transfer, but recovery should never be assumed.
A Better BEC Prevention Approach
A stronger BEC strategy does not assume employees will identify every convincing message.
It creates several opportunities to stop the fraud:
- Email security attempts to identify the message.
- MFA makes account takeover more difficult.
- Monitoring identifies unusual account activity.
- The employee recognizes that the request requires verification.
- A separate communication channel confirms the request.
- Approval controls prevent one employee from acting alone.
- A documented response plan helps the business move quickly when something goes wrong.
Each layer supports the others.
Technology reduces the number of threats that reach employees. Training helps employees recognize unusual situations. Business procedures prevent a convincing email from automatically becoming an approved transaction.
How Micro Solutions Helps Businesses Reduce Email Risk
Micro Solutions helps small and mid-sized businesses manage email security as part of the broader IT environment.
Depending on the organization’s needs, this can include:
- Microsoft 365 account management
- Multi-factor authentication
- Email filtering and security
- Employee cybersecurity awareness training
- User and administrator access management
- Security monitoring
- Account onboarding and offboarding
- Incident-response support
- Security policies and procedures
- Ongoing review of cybersecurity risks
These protections are most effective when someone is also responsible for managing users, devices, accounts, backups, security alerts, and day-to-day IT support.
That is why Micro Solutions incorporates cybersecurity into TotalCare managed IT services instead of treating email protection as a disconnected product.
Reduce Email and Payment Risk
Would one convincing email be enough to change a payment?
Micro Solutions can help you review email security, multi-factor authentication, account management, employee awareness, and the procedures that support your technical protections.
Schedule a Cybersecurity ConversationNo pressure. Start with a practical conversation about what is already in place and where additional protection may be useful.
Frequently Asked Questions
Business Email Compromise
Practical answers about email impersonation, payment fraud, account protection, and incident response.
What is business email compromise?
Business email compromise is a form of fraud in which a criminal impersonates a trusted person or takes over a legitimate account to request money, payment changes, credentials, or sensitive information. The message may appear to come from an executive, employee, vendor, customer, or other known contact.
Is business email compromise the same as phishing?
BEC frequently uses phishing or social engineering, but it is usually more targeted than a broad phishing campaign. The attacker may research the organization, study real email conversations, and time the request around an actual payment, project, or vendor relationship.
Can multi-factor authentication prevent business email compromise?
MFA can significantly reduce the likelihood that a stolen password will lead to an account takeover. It cannot stop every form of BEC because criminals can still use look-alike domains, social engineering, compromised vendor accounts, or other communication methods. MFA should be combined with email security and payment-verification procedures.
How should a business verify new vendor payment instructions?
Contact a known vendor representative using a phone number or communication method already on file. Do not use phone numbers, links, or contact information supplied in the payment-change email. Document who confirmed the change, when it was verified, and who approved it.
Can an email from a legitimate vendor address still be fraudulent?
Yes. An attacker may take control of a vendor’s real mailbox and use existing conversations, signatures, invoices, and payment details to make a fraudulent request more convincing. Sensitive changes should still be independently verified.
Who is most likely to be targeted by a BEC attack?
Common targets include finance and accounts-payable employees, payroll staff, human resources, executives, executive assistants, office managers, and employees who manage vendors or customer payments. Anyone who can approve a transaction or change account information may be targeted.
What should we do after sending money to a fraudulent account?
Contact the financial institution immediately and request that it attempt to recall or freeze the transfer. Notify your IT or cybersecurity provider, secure affected accounts, preserve the evidence, contact your cyber insurance provider, notify affected parties as appropriate, and report the incident to the FBI’s Internet Crime Complaint Center.
Does email security stop every business email compromise attempt?
No. Email security can block many malicious messages and identify suspicious activity, but a convincing request may still reach an employee. Technical protections should be supported by employee training, independent verification, approval controls, and a documented response plan.

