An employee in the accounting department gets an email that looks like it's from the company's CEO, marked urgent, asking for a wire transfer to a new vendor account before the end of the day. The email address looks right at a glance. The tone matches how the CEO writes. There's no time to double-check because the CEO is described as being in back-to-back meetings. It's a scam, and it works often enough that business email compromise now accounts for some of the largest dollar losses in cybercrime — more than ransomware, more than data breaches, because it doesn't require breaking any encryption. It just requires one convincing email and one moment of urgency.
How the scam actually gets set up
Business email compromise usually starts quietly, well before the fraudulent request ever arrives. Scammers research a company's leadership, vendors, and organizational structure using public sources like LinkedIn, press releases, and the company website. In more sophisticated versions, they compromise an actual email account — often through a phishing link — and sit inside the inbox for weeks, reading real correspondence to learn how invoices are actually worded, who approves payments, and when large transactions typically happen. That patience is what makes the eventual fraudulent request feel routine rather than suspicious.
The most common versions small businesses see
The executive impersonation version asks an employee to wire money urgently on behalf of a "CEO" or "owner" who is conveniently unreachable by phone. The vendor impersonation version is subtler: a scammer either spoofs or compromises a real vendor's email and sends an invoice with updated bank details, asking that future payments go to a new account. Because the invoice amount and format look legitimate, this version is especially effective against businesses that pay the same vendors regularly. A third version targets payroll, with a fraudulent request to change an employee's direct deposit information to an account the scammer controls.
Why these emails are so hard to catch by eye
Modern business email compromise attempts rarely have the spelling errors or obviously wrong sender addresses that made older phishing attempts easy to spot. Domains are frequently registered that look almost identical to a real one, swapping a single character or using a different top-level domain. Some attacks use a genuinely compromised account, meaning the email comes from the real address. The request itself is usually written to sound completely normal — not asking for something unusual, just asking for a normal-looking payment to go to a different place.
The single control that stops most of these scams
Out-of-band verification is the practice of confirming any change to payment instructions or any unusual payment request through a separate communication channel — calling a phone number already on file, not one provided in the email, or walking over to the person's desk if that's an option. This one habit defeats the overwhelming majority of business email compromise attempts, because the scammer doesn't control the phone line. The challenge is making this a genuine policy rather than an informal habit that gets skipped under time pressure, which is exactly when these scams are designed to be attempted.
Building verification into the payment process itself
Rather than relying on an individual employee's judgment in the moment, the more durable fix is a written policy: any request to change vendor banking details or make an unscheduled wire transfer requires a phone call to a known contact before it's processed, regardless of who the request appears to come from or how urgent it seems. Dual approval for payments above a set dollar threshold adds another layer, since it requires a second person to independently agree the request is legitimate. Employees should also be explicitly told that no real executive will penalize them for taking the extra step to verify a payment request, which removes the social pressure that these scams are built to exploit.
Technical controls that reduce exposure
Email authentication protocols — SPF, DKIM, and DMARC — make it harder for scammers to send email that appears to come from your own domain, and are worth asking an IT provider to configure if they aren't already in place. Flagging external emails that claim to be from internal addresses, and enabling multi-factor authentication on email accounts to reduce the odds of an account actually being compromised, both close off common entry points. None of these technical controls replace the human verification step, but they reduce how often a business is targeted in the first place.
What to do if a fraudulent transfer already went out
Speed matters more than anything else. Contact the bank immediately and request a wire recall or hold, since banks can sometimes intercept funds that haven't yet been fully transferred out of the receiving account, especially within the first 24 hours. File a report with the FBI's Internet Crime Complaint Center, which coordinates with financial institutions on time-sensitive recovery efforts. Notify the company's bank, insurance carrier if crime or cyber coverage applies, and legal counsel, and preserve the original emails and headers rather than deleting them, since they're needed for the investigation.
Training that actually sticks
One-time training on business email compromise tends to fade from memory within months, especially for employees who don't handle payments daily. More effective is periodic, brief reinforcement — a short reminder each quarter, or a simulated phishing test that shows employees, without real consequences, what these attempts actually look like. The goal isn't to make every employee a cybersecurity expert; it's to make the specific habit of verifying unusual payment requests through a second channel feel completely normal, so that it happens automatically even when a request looks convincing and feels urgent.
Comments
Post a Comment