A business email compromise attack is targeted fraud where a criminal impersonates a senior colleague or supplier and asks someone in finance to move money or change bank details. There is usually no malware, so filters miss it. The defence is a rule that every payment change is verified by phone on a known number.
What is a business email compromise attack?
Business Email Compromise (BEC) attacks are a dangerous and sophisticated form of phishing. Traditional phishing attacks might see cybercriminals sending large volumes of fake emails that appear to be genuine requests for information, usually in an effort to harvest personal account credentials for online services. BEC attacks, on the other hand, are more targeted and seek to compromise select business users in order extract sensitive corporate information for greater financial gain. Common BEC-type scams include attackers sending bogus invoices to other companies or issuing fake instructions for payment on behalf of high-profile individuals such as a company CEO or Finance Director. BEC attacks are also known as man-in-the-email attacks, and due to the highly targeted approach of scammers can often be difficult for employees to spot. Criminals will often go to great lengths to create more realistic attacks, such as closely researching individuals, supply chains and corporate news and events.BEC attacks cost organisations huge amounts of money
A number of large-scale BEC attacks have made headlines across the last year. One of the highest profile attacks came in March 2018, when Italian football giants Lazio were tricked into transferring €2million to the bank account of a scammer. This concerned an outstanding payment owed in relation to the transfer of defender Stefan de Vrij from Dutch club Feyenoord. Lazio received an email, which later turned out to be fake, supplying alternate bank account details for the final payment. Another well-publicised attack targeted Dublin Zoo, which was defrauded to the tune of €500,000 when it was tricked into paying invoices into a bank account controlled by criminals. While the cinema chain Pathe had a truly colossal €19 million stolen in one of the most successful BEC attack carried out to-date. In this example, scammers posed as the French office as the firm and requested funds for a confidential transaction.How staff can help protect businesses against BEC attacks
Understanding what a business email compromise attack looks like and its associated risks is the first step in safeguarding your business against this type of fraud. Employee education is vital. BEC attacks commonly target the members of staff in an organisation with the authority to both instruct and action financial payments. Accounts departments, in particular, need to understand the danger of these attacks and how they can be identified. There are many ways to perform staff training. A simulated phishing attack, conducted by a professional ethical hacking company, for example, can help organisations to learn how to spot the tell-tale signs of scam emails.What else can be done to prevent business email compromise attacks
While raising employee awareness is an important step, there are also things that businesses can do to help protect their employees and minimise the risk of an attack. Introducing policies and procedures in place to verbally verify payment requests is also an effective way to reduce the success of BECs. Use of DMARC, DKIM lookup and SPF protocols to block email spoofing attempts as well as implementation of multi-factor authentication on user accounts are also recommended. Finally, businesses may also wish to invest in proactive network and endpoint monitoring. SIEM and EDR technologies can help to detect malicious activity before escalates into a serious breach resulting in operational disruption, reputational damage and financial loss.Related reading
- How to Take Your Email Marketing to the Next Level
- How to Generate Leads for Your Store’s Newsletter
- Data Privacy and Email Deliverability: Compliance and Best Practices
- Introducing GetEmails: 10x Your Email List Growth in a Totally New Way
- how to organise your email inbox
Related: What Entrepreneurs Can Learn From Farmers About Managing Risk In Uncertain Markets
The trade-offs nobody puts in the board paper
Every control that reduces business email compromise risk creates friction somewhere else in the business. Nobody wants to say that out loud in a board meeting because it sounds like you’re arguing against security. But if you don’t weigh the trade-off deliberately, someone downstream weighs it for you, usually by ignoring the control the first time it slows them down.
Here are the decisions that need making, not just a policy that gets written and forgotten:
- Verification speed versus fraud risk. Requiring a callback on every bank detail change stops most BEC payment fraud dead. It also adds a day to supplier onboarding and annoys finance teams who are measured on how fast they process invoices. If the callback step gets skipped “just this once” under deadline pressure, you’ve bought the control and not the protection. Decide who has authority to override it, and make that override loud and logged, not quiet and convenient.
- Email filtering aggressiveness versus business continuity. Tighter DMARC and spoofing rules block more fake invoices. They also occasionally bounce a legitimate email from a new supplier or a rebranding partner whose domain setup is a mess. Somebody has to own the decision on how many false positives is an acceptable price for how much fraud prevented, and that’s a business call, not just an IT setting.
- Centralised approval versus a single point of failure. Routing every payment over a certain amount through one senior approver reduces the number of people who can be tricked. It also means if that one person is compromised, on leave, or simply the target of a well-timed spoof while travelling, the whole safeguard collapses. A second approver or a rotating check is more resilient but slower and costs more in senior time.
- Training spend versus technology spend. Awareness training changes behaviour for a while and then decays without repetition. Technical controls like DMARC enforcement or payment verification software are more consistent but don’t catch the attacks that arrive by phone, WhatsApp, or a compromised supplier account rather than email. Most businesses need both, in a rough 60/40 split toward the technical side, but the honest answer is neither one alone is enough and there’s no shortcut to buying just the cheaper option.
- Insurance versus prevention. Cyber insurance covers some of the financial loss after the fact. It does not cover reputational damage, lost time, or the supplier relationship that goes sideways when they realise your systems let a fraudster impersonate you. Insurance is a backstop, not a strategy, but plenty of businesses budget for it instead of for prevention because it’s a single line item that’s easier to sign off.
The honest way to decide between these is to work out where your actual exposure sits. A business moving large one-off payments to new suppliers needs strict verification more than it needs training. A business with high email volume and low payment risk needs filtering and DMARC more than callback procedures. Match the control to the exposure, not to what looks thorough on a policy document.
FAQ
Is it worth slowing down payment processing to add verification steps?
For any payment above a threshold that would hurt if lost, yes. Set the threshold based on what your finance