What is business email compromise?
Business email compromise — BEC — is fraud that works by email alone. There is no malware, no hacked payment system and usually no technical breach at your end. Someone persuades a person in your business to send money to the wrong bank account, and the payment goes through normal channels because the person making it believed it was legitimate.
That is what makes it the most expensive category of business cybercrime almost everywhere it is measured, and why security software struggles with it: nothing about the email is technically malicious.
The five shapes it takes
- Supplier invoice fraud — the most common and most costly. A supplier you already pay appears to email new bank details, or sends an invoice that looks routine with an account that isn't theirs.
- Executive impersonation — an email that appears to come from the owner or a director, asking for an urgent transfer, often while they are conveniently travelling or in meetings.
- Payroll diversion — an employee appears to email HR asking to update their bank account before the next pay run. Smaller amounts, easily missed.
- Lawyer or conveyancer impersonation — timed around a settlement, when a large payment is expected and everyone is under time pressure. Common in property transactions.
- Account takeover — the most dangerous variant, because there is no impersonation at all. A criminal is inside a real mailbox, reading real threads, and replies from the genuine address.
Why spam filters and antivirus don't catch it
Security tools look for things that are technically wrong: malicious attachments, known-bad links, forged headers, servers with poor reputations. A BEC email usually has none of those. It is a plain text message, often from a domain registered weeks ago with perfect email authentication, or from a real supplier's real mailbox.
The only thing wrong with it is the intent behind it and the account number inside it — and neither is something a filter can measure. This is why BEC is a process problem wearing a technology costume.
If the fraud arrives from your supplier's genuine, compromised mailbox, there is nothing technically wrong with the email at all. Every filter passes it. Every header checks out.
How the attacker gets in position
Two routes, and they need different defences.
The first is impersonation: registering a domain that reads like yours or your supplier's — a swapped character, an added hyphen, a different ending — and emailing from it. Nothing of yours is breached; they simply look close enough.
The second is compromise: obtaining someone's mailbox password, usually through a phishing page, and then quietly reading. Attackers often wait weeks, learning who pays whom and how invoices are worded, before sending anything. A near-universal first step after breaking in is creating an inbox rule that hides their replies from the real owner — which is why auto-forwarding rules are one of the highest-value things to monitor.
Why it works on careful people
It is tempting to think this only catches the inattentive. The evidence says otherwise, and the reason is structural rather than personal.
The request arrives in an expected context — a real supplier, a real invoice, a real amount, often a real thread. It carries manufactured time pressure, so the natural response of slowing down feels like being obstructive. And it frequently discourages the exact behaviour that would expose it: don't call, the line is down, keep this confidential.
Someone processing forty invoices on a Friday afternoon is not being careless when they pay the forty-first. They are behaving exactly as the system was designed to make them behave.
What actually stops it
Almost every large loss in this category would have been prevented by one phone call to a number the email did not supply. That is the single highest-value control, and it costs nothing.
- Verify every bank-detail change by phone, on a number you already held — from an old invoice, their website you navigated to yourself, or your own records.
- Require a second person to approve payments to new or changed accounts. The person who received the request should never be the one who releases the money.
- Turn on multi-factor authentication everywhere, preferring passkeys or security keys over SMS.
- Monitor for inbox rules and auto-forwarding you did not create.
- Write down that bank details are never changed on the basis of an email — so staff have explicit permission to slow down.
Call the supplier on a number you already had — from an earlier invoice, their website that you navigated to yourself, or your own records. Never a number written in the email or invoice you are checking. The person who wrote that document chose that number.
Common questions
Is BEC the same as phishing?
They overlap but are not the same. Phishing usually aims to harvest credentials or deliver malware at scale. BEC is targeted and aims directly at a payment — often with no link or attachment at all. Phishing is frequently the first step that gives an attacker the mailbox access used later for BEC.
Are small businesses actually targeted?
Heavily. Controls are usually lighter, a single payment can be large relative to the business, and there is rarely a second approver. The losses are also proportionally far more damaging than they are to a large company.
Would better security software have prevented it?
Sometimes it helps at the margins — domain-based authentication makes impersonation harder, and mailbox monitoring can catch a compromise earlier. But no filter can tell whether a bank account belongs to your supplier, which is the fact the whole fraud turns on. Process controls do the work here.
Related guides
- Is this invoice a scam? Seven checks before you pay
The seven things worth checking on an invoice that doesn't feel right, and the one check that actually settles it.
- A supplier emailed new bank details. What should you do?
The single most common way businesses lose large sums — and a short, repeatable process that stops it.
- You've paid a scammer. What to do in the first hour
If money has already gone, speed decides the outcome. The order of operations that gives you the best chance.