Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

How to mitigate the risk of Business Email Compromise attacks

A business email compromise attack is targeted fraud where a criminal impersonates a senior colleague or supplier and asks someone in finance to move money or change bank details. There is usually no malware, so filters miss it. The defence is a rule that every payment change is verified by phone on a known number.

How aware are you of BEC attacks? Businesses of all sizes are at growing risk of this growing type of cyber-crime. In fact, between 2013 and 2018 the FBI estimates that cybercriminals have stolen more than $12 billion through this form of fraud. Here we take a look at exactly what a BEC attack is, and what your organisation can do to mitigate the risk of business email compromise attacks.

What is a business email compromise attack?

Business Email Compromise (BEC) attacks are a dangerous and sophisticated form of phishing. Traditional phishing attacks might see cybercriminals sending large volumes of fake emails that appear to be genuine requests for information, usually in an effort to harvest personal account credentials for online services. BEC attacks, on the other hand, are more targeted and seek to compromise select business users in order extract sensitive corporate information for greater financial gain. Common BEC-type scams include attackers sending bogus invoices to other companies or issuing fake instructions for payment on behalf of high-profile individuals such as a company CEO or Finance Director. BEC attacks are also known as man-in-the-email attacks, and due to the highly targeted approach of scammers can often be difficult for employees to spot.  Criminals will often go to great lengths to create more realistic attacks, such as closely researching individuals, supply chains and corporate news and events.

BEC attacks cost organisations huge amounts of money

A number of large-scale BEC attacks have made headlines across the last year. One of the highest profile attacks came in March 2018, when Italian football giants Lazio were tricked into transferring €2million to the bank account of a scammer. This concerned an outstanding payment owed in relation to the transfer of defender Stefan de Vrij from Dutch club Feyenoord. Lazio received an email, which later turned out to be fake, supplying alternate bank account details for the final payment. Another well-publicised attack targeted Dublin Zoo, which was defrauded to the tune of €500,000 when it was tricked into paying invoices into a bank account controlled by criminals. While the cinema chain Pathe had a truly colossal €19 million stolen in one of the most successful BEC attack carried out to-date. In this example, scammers posed as the French office as the firm and requested funds for a confidential transaction.

How staff can help protect businesses against BEC attacks

Understanding what a business email compromise attack looks like and its associated risks is the first step in safeguarding your business against this type of fraud. Employee education is vital. BEC attacks commonly target the members of staff in an organisation with the authority to both instruct and action financial payments. Accounts departments, in particular, need to understand the danger of these attacks and how they can be identified. There are many ways to perform staff training. A simulated phishing attack, conducted by a professional ethical hacking company, for example, can help organisations to learn how to spot the tell-tale signs of scam emails.

What else can be done to prevent business email compromise attacks

While raising employee awareness is an important step, there are also things that businesses can do to help protect their employees and minimise the risk of an attack. Introducing policies and procedures in place to verbally verify payment requests is also an effective way to reduce the success of BECs. Use of DMARC, DKIM lookup and SPF protocols to block email spoofing attempts as well as implementation of multi-factor authentication on user accounts are also recommended. Finally, businesses may also wish to invest in proactive network and endpoint monitoring. SIEM and EDR technologies can help to detect malicious activity before escalates into a serious breach resulting in operational disruption, reputational damage and financial loss.

Related reading

Related: What Entrepreneurs Can Learn From Farmers About Managing Risk In Uncertain Markets 

The trade-offs nobody puts in the board paper

Every control that reduces business email compromise risk creates friction somewhere else in the business. Nobody wants to say that out loud in a board meeting because it sounds like you’re arguing against security. But if you don’t weigh the trade-off deliberately, someone downstream weighs it for you, usually by ignoring the control the first time it slows them down.

Here are the decisions that need making, not just a policy that gets written and forgotten:

  • Verification speed versus fraud risk. Requiring a callback on every bank detail change stops most BEC payment fraud dead. It also adds a day to supplier onboarding and annoys finance teams who are measured on how fast they process invoices. If the callback step gets skipped “just this once” under deadline pressure, you’ve bought the control and not the protection. Decide who has authority to override it, and make that override loud and logged, not quiet and convenient.
  • Email filtering aggressiveness versus business continuity. Tighter DMARC and spoofing rules block more fake invoices. They also occasionally bounce a legitimate email from a new supplier or a rebranding partner whose domain setup is a mess. Somebody has to own the decision on how many false positives is an acceptable price for how much fraud prevented, and that’s a business call, not just an IT setting.
  • Centralised approval versus a single point of failure. Routing every payment over a certain amount through one senior approver reduces the number of people who can be tricked. It also means if that one person is compromised, on leave, or simply the target of a well-timed spoof while travelling, the whole safeguard collapses. A second approver or a rotating check is more resilient but slower and costs more in senior time.
  • Training spend versus technology spend. Awareness training changes behaviour for a while and then decays without repetition. Technical controls like DMARC enforcement or payment verification software are more consistent but don’t catch the attacks that arrive by phone, WhatsApp, or a compromised supplier account rather than email. Most businesses need both, in a rough 60/40 split toward the technical side, but the honest answer is neither one alone is enough and there’s no shortcut to buying just the cheaper option.
  • Insurance versus prevention. Cyber insurance covers some of the financial loss after the fact. It does not cover reputational damage, lost time, or the supplier relationship that goes sideways when they realise your systems let a fraudster impersonate you. Insurance is a backstop, not a strategy, but plenty of businesses budget for it instead of for prevention because it’s a single line item that’s easier to sign off.

The honest way to decide between these is to work out where your actual exposure sits. A business moving large one-off payments to new suppliers needs strict verification more than it needs training. A business with high email volume and low payment risk needs filtering and DMARC more than callback procedures. Match the control to the exposure, not to what looks thorough on a policy document.

FAQ

Is it worth slowing down payment processing to add verification steps?

For any payment above a threshold that would hurt if lost, yes. Set the threshold based on what your finance

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.