The most expensive email scam in the world doesn't use malware. It uses a convincing request from someone you trust — and it works on careful people at well-run organizations. Here is exactly how it happens, the variants to watch for, why your email filter waves it through, and a checklist to make your organization a hard target.
Business email compromise (BEC) is a fraud in which a criminal impersonates a trusted person — an executive, a vendor, an attorney — to trick an employee into wiring money or changing payment details. It rarely carries a link or an attachment, so antivirus and spam filters find nothing to block. The single most effective defense is out-of-band verification: confirm any new or changed payment instruction by calling a number you already had on file, never one from the email. The checklist below covers the technical, process, and human controls that stop it.
Business email compromise is a targeted scam that asks a person with access to money or data to do something that seems routine — pay an invoice, update a vendor's bank account, buy gift cards for a "thank-you", forward a payroll file. The message appears to come from someone the recipient trusts and reports to. There is no virus to catch and usually no link to flag. The whole attack is social, which is why it slips past tools built to detect malicious code.
The FBI's Internet Crime Complaint Center (IC3) consistently ranks BEC among the costliest cybercrimes reported in the United States — far more than ransomware in total dollars. It targets organizations of every size, and small businesses and nonprofits are hit hard precisely because they rarely have a formal payment-verification process. The good news is that the controls that stop it are cheap and mostly procedural.
Most attacks follow the same four steps:
"BEC" covers several distinct plays. They look similar in the inbox but call for different defenses, so it helps to name them:
Because there is often nothing technically wrong with the message. Spam filters and antivirus look for malicious links, malicious attachments, and known-bad senders. A BEC email frequently has none of those. When the attacker has taken over a real account, the mail even passes SPF, DKIM, and DMARC — the three checks that prove a message came from the domain it claims — because it genuinely did come from that account.
Those checks answer is this sender who they say they are. They do not answer is this request safe. Closing that gap takes a mixture of process and judgment, not just software. That is what the checklist builds.
A bookkeeper at a small nonprofit gets an email that appears to be from the executive director, who everyone knows is away at a conference this week: “Are you at your desk? I need you to process an urgent payment to a new vendor before end of day, and send me the confirmation once it's done. I'm going into sessions, so email is best.” The sender's name is exactly right; the address is a personal Gmail account, easy to miss on a phone. Nothing in the message is technically malicious — there's no link and no attachment, so every filter passes it. It's plausible, it's urgent, and it explains away a phone call in advance.
The only thing that reliably stops it is the bookkeeper picking up the phone, calling the director's known cell number — not replying to the email — and hearing “I never sent that.” That single call is what the whole checklist below is designed to make automatic.
Move within hours, not days — recovery depends on reaching the receiving bank while the money is still there, usually within the first day or two.
Sources & further reading: FBI Internet Crime Complaint Center 2024 Internet Crime Report and BEC advisories (ic3.gov) · CISA guidance on avoiding business email compromise and phishing. Loss figures are as reported to IC3 for the year noted. This guide is educational and does not replace advice from your bank, attorney, or a qualified security professional.
BEC is a type of phishing, but a targeted one that usually carries no link and no malware. Instead of tricking you into clicking, it impersonates a person you trust — an executive, a vendor, a lawyer — and asks you to move money or change payment details. Because there is nothing technically malicious to scan, ordinary email filters often let it through.
Those three checks prove a message really came from the domain it claims. They answer “is this sender who they say they are” — not “is this request safe”. When a criminal takes over a real vendor's account and replies inside a real email thread with new bank details, every authentication check passes, because the mail genuinely is from that account.
Out-of-band verification. Before any new or changed payment instruction is acted on, call the requester back on a phone number you already had on file — never a number from the email itself — and confirm the request out loud. One deliberate phone call defeats the majority of BEC attempts.
Vendor email compromise, or VEC, is BEC that comes through one of your suppliers rather than your own leadership. An attacker takes over a real vendor's mailbox, watches an existing invoice thread, and sends a “corrected” set of bank details right as a legitimate invoice is due. Because it arrives from the genuine vendor address inside a real conversation, it is one of the hardest variants to spot and among the most costly. The specific defense is a vendor payment-change control: confirm any change with a known vendor contact before updating your records.
The FBI's Internet Crime Complaint Center reported roughly $2.77 billion in BEC losses across 21,442 complaints in 2024, and in a 2024 public advisory tallied cumulative BEC-related exposed losses in the tens of billions of dollars since it began tracking the crime. It is consistently among the costliest cybercrimes reported in the United States — far more expensive in aggregate than ransomware.
Act within hours, not days. Call your bank immediately and ask for a wire recall or SWIFT recall, then file a complaint with the FBI Internet Crime Complaint Center (IC3.gov). The FBI's Recovery Asset Team can sometimes freeze funds if the report reaches the receiving bank fast enough — recovery odds drop sharply after the first day or two.
Family Sentinel's Org Guard watches for the exact signals BEC relies on — lookalike domains, new-payee and wire language, and mailbox rules that hide replies — and alerts a person you choose before the money moves. Read-only, and never able to send or delete a thing.