Business email compromise doesn’t look like hacking. There’s no dramatic breach, no malware, often no sign anything is wrong until the money is gone. It’s the quiet scam where someone convinces an employee to send a payment or change bank details — and it’s one of the most expensive cybercrimes there is. The FBI’s 2024 Internet Crime Report put BEC losses at $2.77 billion in a single year, and nearly $8.5 billion from 2022 through 2024, second only to investment fraud. What’s striking is how unsophisticated the attacks usually are. They win on psychology, not technology.
There are two main flavors, and the second is far more dangerous. Impersonation is the obvious one: an email that looks like it’s from your CEO or a vendor — a lookalike domain, a slightly-off display name, a free account set up to match. “I’m in a meeting, can you send a wire before end of day? I’ll explain later.” It works only if you don’t look closely.
Account takeover is the costly one, because there’s nothing to spot. The attacker has actually gotten into a real mailbox — usually through a phishing page that harvested a password on an account with no MFA. Now they’re reading real conversations, learning how your business talks, seeing which invoices are in flight. Then they slip into a genuine thread and redirect a real payment to their own account. The email is legitimate. It comes from the right person’s real address. That’s why it works. A common pattern: the attacker sets a hidden inbox rule that hides certain replies, waits for an invoice, then emails the customer “updated banking details” from the real account and deletes the traces. The business finds out when the vendor calls asking where their money is.
BEC targets the one thing no firewall protects: a person doing their job under normal pressure. The requests look routine and exploit authority (“the CEO asked”), urgency (“before the bank closes”), and the simple fact that most people don’t verify a payment request that appears to come from someone they trust. There’s no malicious attachment to catch and no bad link to block — the email is often completely clean, sometimes because it’s genuinely coming from a real, compromised account.
The defenses are concrete and layered. No single one is enough; together they stop the large majority of attempts.
Speed matters enormously. If a fraudulent payment goes out, contact your bank immediately and ask them to recall the wire — the FBI’s recovery team was able to freeze funds in a majority of cases where victims reported quickly. Then report it at ic3.gov. Hours count; after a day or two the money is usually gone for good.
BEC isn’t a problem you can buy your way out of with one product. It’s one essential control (MFA), one essential habit (verify payments out of band), and a handful of email settings most businesses have never switched on. Put those together and you’ve closed the door that billions of dollars walk out of every year.
Not sure whether your email is configured to catch this? Book a free 30-minute consult and we’ll review your setup for the specific gaps BEC exploits.
This article discusses financial fraud. If your business has already experienced a suspected fraudulent transfer, contact your bank immediately and report it at ic3.gov — time is the single biggest factor in recovering funds.