Business Email Compromise:
a prevention checklist.
The most expensive email scam in the world doesn't use malware. It uses a convincing request from someone you trust — and it works on careful people at well-run organizations. Here is exactly how it happens, the variants to watch for, why your email filter waves it through, and a checklist to make your organization a hard target.
Business email compromise (BEC) is a fraud in which a criminal impersonates a trusted person — an executive, a vendor, an attorney — to trick an employee into wiring money or changing payment details. It rarely carries a link or an attachment, so antivirus and spam filters find nothing to block. The single most effective defense is out-of-band verification: confirm any new or changed payment instruction by calling a number you already had on file, never one from the email. The checklist below covers the technical, process, and human controls that stop it.
What is business email compromise?
Business email compromise is a targeted scam that asks a person with access to money or data to do something that seems routine — pay an invoice, update a vendor's bank account, buy gift cards for a "thank-you", forward a payroll file. The message appears to come from someone the recipient trusts and reports to. There is no virus to catch and usually no link to flag. The whole attack is social, which is why it slips past tools built to detect malicious code.
The FBI's Internet Crime Complaint Center (IC3) consistently ranks BEC among the costliest cybercrimes reported in the United States — far more than ransomware in total dollars. It targets organizations of every size, and small businesses and nonprofits are hit hard precisely because they rarely have a formal payment-verification process. The good news is that the controls that stop it are cheap and mostly procedural.
How does a BEC attack actually unfold?
Most attacks follow the same four steps:
- Research. The attacker learns who pays the bills, who approves them, and who your vendors are — often from your own website, LinkedIn, and out-of-office replies.
- Access or impersonation. They either take over a real mailbox with a stolen password (increasingly via an adversary-in-the-middle phishing kit that also steals the MFA session), or register a lookalike domain that reads almost identically to yours or a vendor's (for example, swapping rn for m, or .co for .com).
- The ask. At a plausible moment — often when a real invoice is due — a message arrives changing the payment details, or requesting an urgent transfer, "confidential" and time-pressured so the recipient won't stop to check.
- The cash-out. The money moves to an account the attacker controls, then is quickly wired onward or withdrawn, which is why speed of response afterward matters so much.
The main variants (and why they need different controls)
"BEC" covers several distinct plays. They look similar in the inbox but call for different defenses, so it helps to name them:
- Vendor email compromise (the "aging invoice" swap). The attacker is inside a supplier's mailbox, not yours. They watch a real invoice thread and send updated bank details just as payment is due. Defense: a vendor payment-change control — confirm every banking change with a known vendor contact before updating your records.
- Executive impersonation (CEO fraud). A spoofed or lookalike "CEO" or owner emails finance with an urgent, confidential wire or gift-card request. Defense: a rule that no leader can authorize a payment by email alone, plus a call-back to the executive on a known number.
- Payroll diversion. A message posing as an employee asks HR or payroll to change their direct-deposit account, redirecting the next paycheck. Defense: verify any direct-deposit change with the employee through a known channel, not by replying to the request.
- W-2 and data requests. Around tax season, a fake executive asks HR for employee W-2s or personal data. Defense: treat any bulk request for personal or tax data as high-risk and verify it out-of-band.
- Thread hijacking. An attacker with mailbox access replies inside a genuine existing conversation, inheriting its trust and history. Defense: the same out-of-band check — a real, ongoing thread is not proof the latest reply is genuine.
- Gift-card variant. An "executive" needs gift cards bought urgently for a client or staff reward and the codes sent over. Defense: name gift-card requests explicitly in training as a near-certain scam.
Why do email security filters miss BEC?
Because there is often nothing technically wrong with the message. Spam filters and antivirus look for malicious links, malicious attachments, and known-bad senders. A BEC email frequently has none of those. When the attacker has taken over a real account, the mail even passes SPF, DKIM, and DMARC — the three checks that prove a message came from the domain it claims — because it genuinely did come from that account.
Those checks answer is this sender who they say they are. They do not answer is this request safe. Closing that gap takes a mixture of process and judgment, not just software. That is what the checklist builds.
What it looks like in practice
A bookkeeper at a small nonprofit gets an email that appears to be from the executive director, who everyone knows is away at a conference this week: “Are you at your desk? I need you to process an urgent payment to a new vendor before end of day, and send me the confirmation once it's done. I'm going into sessions, so email is best.” The sender's name is exactly right; the address is a personal Gmail account, easy to miss on a phone. Nothing in the message is technically malicious — there's no link and no attachment, so every filter passes it. It's plausible, it's urgent, and it explains away a phone call in advance.
The only thing that reliably stops it is the bookkeeper picking up the phone, calling the director's known cell number — not replying to the email — and hearing “I never sent that.” That single call is what the whole checklist below is designed to make automatic.
The BEC prevention checklist
Process controls (the ones that actually stop the money)
- Verify every payment change out-of-band. Any new bank account, or any change to an existing one, must be confirmed by phone using a number you already had on file — never a number, link, or reply from the request itself.
- Require a call-back for urgent or unusual transfers. Make it a written rule that no wire above a set threshold moves on email alone. A five-minute call defeats most of these attacks.
- Use dual approval for payments and for changes to payment records. Two people, two sets of eyes. Attackers rely on one busy person acting alone.
- Add a cooling-off step for new payees. Hold the first payment to any newly added account for a set period, and reconcile it, so a fraudulent new payee surfaces before a second payment follows.
- Slow down "urgent" and "confidential" requests. Treat pressure and secrecy as red flags, not reasons to hurry. A real executive will understand a verification call.
- Confirm vendor bank changes with the vendor directly, using a known contact — not whoever sent the change. Invoice-redirect fraud is among the most common and most costly BEC variants.
- Ask your bank about Positive Pay and ACH fraud filters, which can flag or block outbound payments that don't match expected patterns.
Technical controls
- Turn on multi-factor authentication everywhere, especially on email, and prefer phishing-resistant MFA (a security key or passkey) for finance and admins. Stolen passwords are how attackers get inside a real mailbox; MFA is the single biggest barrier.
- Publish and enforce SPF, DKIM, and DMARC on your own domain, moving DMARC to a reject policy over time. It stops others from spoofing you, even though it won't stop a compromised-account attack.
- Disable external auto-forwarding and alert on new inbox rules. A rule that quietly forwards or hides replies is the actual fingerprint of a compromised mailbox — and a primary data-theft path.
- Flag external email with a visible banner, so a message pretending to be internal is easier to spot.
- Watch for lookalike domains that impersonate yours or your vendors', and restrict who can grant third-party apps access to mailboxes (OAuth consent phishing survives a password reset).
- Alert on high-risk requests that reach a real inbox — new payee, changed bank details, wire or gift-card language — because that is exactly where filters go quiet.
People controls
- Train the people who handle money on this specific scam, with real examples and the urgency-and-secrecy framing it relies on — not a generic annual video.
- Make it safe to pause and ask. The employee who calls to double-check a "CEO" wire request should be praised, never made to feel they slowed things down.
- Write the verification steps down so they don't depend on any one person remembering under pressure, and name who verifies, at what dollar amount, and through which channel.
What to do if you've already sent the money
Move within hours, not days — recovery depends on reaching the receiving bank while the money is still there, usually within the first day or two.
- Call your bank immediately and request a wire recall (or SWIFT recall for international transfers). Ask them to contact the receiving bank to freeze the funds.
- File a complaint with the FBI Internet Crime Complaint Center at IC3.gov. Its Recovery Asset Team can trigger a financial-fraud "kill chain" to freeze fraudulent transfers if you report fast enough.
- Preserve the original email, including its full headers, and check the mailbox for hidden forwarding or inbox rules the attacker may have set.
- Reset passwords and enable MFA on any mailbox that may have been accessed, and remove any unfamiliar rules or connected apps.
- Tell your team what happened, plainly. Silence lets the same attack work twice.
Sources & further reading: FBI Internet Crime Complaint Center 2025 Internet Crime Report and BEC advisories (ic3.gov) · CISA guidance on avoiding business email compromise and phishing. Loss figures are as reported to IC3 for the year noted. This guide is educational and does not replace advice from your bank, attorney, or a qualified security professional.
Common questions
Is business email compromise the same as phishing?
BEC is a type of phishing, but a targeted one that usually carries no link and no malware. Instead of tricking you into clicking, it impersonates a person you trust — an executive, a vendor, a lawyer — and asks you to move money or change payment details. Because there is nothing technically malicious to scan, ordinary email filters often let it through.
Why doesn't SPF, DKIM, or DMARC stop BEC?
Those three checks prove a message really came from the domain it claims. They answer “is this sender who they say they are” — not “is this request safe”. When a criminal takes over a real vendor's account and replies inside a real email thread with new bank details, every authentication check passes, because the mail genuinely is from that account.
What is the single most effective control against BEC?
Out-of-band verification. Before any new or changed payment instruction is acted on, call the requester back on a phone number you already had on file — never a number from the email itself — and confirm the request out loud. One deliberate phone call defeats the majority of BEC attempts.
What is vendor email compromise?
Vendor email compromise, or VEC, is BEC that comes through one of your suppliers rather than your own leadership. An attacker takes over a real vendor's mailbox, watches an existing invoice thread, and sends a “corrected” set of bank details right as a legitimate invoice is due. Because it arrives from the genuine vendor address inside a real conversation, it is one of the hardest variants to spot and among the most costly. The specific defense is a vendor payment-change control: confirm any change with a known vendor contact before updating your records.
How much does BEC actually cost businesses?
The FBI's Internet Crime Complaint Center reported $3.05 billion in BEC losses across 24,768 complaints in 2025, and in a 2024 public advisory tallied cumulative BEC-related exposed losses in the tens of billions of dollars since it began tracking the crime. It is consistently among the costliest cybercrimes reported in the United States — far more expensive in aggregate than ransomware.
We already sent the money. What do we do now?
Act within hours, not days. Call your bank immediately and ask for a wire recall or SWIFT recall, then file a complaint with the FBI Internet Crime Complaint Center (IC3.gov). The FBI's Recovery Asset Team can sometimes freeze funds if the report reaches the receiving bank fast enough — recovery odds drop sharply after the first day or two.
A second set of eyes on every message
Family Sentinel's Org Guard watches for the exact signals BEC relies on — lookalike domains, new-payee and wire language, and mailbox rules that hide replies — and alerts a person you choose before the money moves. Read-only, and never able to send or delete a thing.