Business Email Compromise: The $2.7 Billion Scam That Targets Your Inbox
The FBI calls BEC the most financially damaging cybercrime. Attackers impersonate your CEO, vendors, and clients — tricking your team into wiring money to fraudulent accounts. No malware, no hacking, just social engineering. Here is how to stop it.
BEC by the Numbers
total BEC losses reported to FBI (2024)
median loss per BEC incident for small business
of BEC attacks target companies with fewer than 100 employees
What Business Email Compromise Actually Looks Like
Unlike phishing (which casts a wide net), BEC attacks are targeted and sophisticated. The attacker researches your company — who the CEO is, who handles payments, which vendors you work with, when people are on vacation. Then they craft an email that looks exactly like it came from the CEO, a vendor, or a client. The email is urgent, it references real projects and real people, and it asks for a wire transfer or sensitive information.
The four most common BEC scenarios:
Why BEC Works — and Why Your Business Is Vulnerable
BEC works because it bypasses every technical security control you have. There is no malware for your antivirus to detect. No malicious link for your spam filter to block. No attachment to sandbox. Just words in an email that look exactly like the words your CEO would write — because the attacker copied them from your CEO's LinkedIn posts and public interviews.
Small businesses are specifically targeted because:
- Decision-makers are accessible — there is no security team screening emails to the CEO
- Payment processes are informal — "just send the wire" does not require three levels of approval
- Employees want to be helpful — especially to the boss, especially when something is "urgent"
⚡ The One Policy That Stops 90% of BEC Attacks
Any financial request received by email must be verified through a SECOND, independent channel before action is taken. Wire transfer request? Call the CEO on a known number (not the number in the email). Vendor bank change? Call your vendor contact at their known phone number. Payroll direct deposit change? Confirm in person or via video call with the employee.
This policy must come from the top and be non-negotiable. The CEO must say: "Even if it looks like it came from me, even if I actually did send it — you verify by phone before sending money." This removes the social pressure that BEC exploits.
BEC Prevention Checklist
- Implement the verification policy above. Write it down. Have everyone sign it. Enforce it. No exceptions for "really urgent" requests.
- Set up DMARC with p=reject. This prevents attackers from spoofing your domain in email headers. See our DMARC/SPF/DKIM guide for setup instructions.
- Enable MFA on all email accounts. The account compromise scenario depends on the attacker being able to log into a real email account. MFA stops this — a stolen password is useless without the second factor.
- Add an external banner to all incoming email. Both Google Workspace and Microsoft 365 can prepend a warning like "[EXTERNAL]" to every email that comes from outside your organization. This is not foolproof, but it makes spoofed internal emails slightly harder to miss.
- Train your finance and HR teams specifically. These are the two departments that handle money and sensitive data changes. They need targeted BEC training, not just general phishing awareness. Show them real examples of BEC emails.
- Flag emails where the display name matches an executive but the email address is external. Advanced email security gateways (Avanan, Proofpoint) do this automatically. For small budgets, create a mail flow rule that prepends a warning.
- Review and limit who can approve payments. Reduce the number of people with authority to send wires. Require dual authorization for amounts over a threshold. The fewer people who can say "send money," the fewer targets for BEC attackers.
What to Do If You Have Already Sent the Money
- Contact your bank immediately. Ask for the wire transfer to be recalled. This must happen within hours — ideally within minutes. After 24-48 hours, recovery rates drop sharply.
- File a report with the FBI's IC3 at ic3.gov. Include the wire transfer details, the attacker's bank account information, and all email headers from the BEC message.
- Contact your local FBI field office. The FBI has a Financial Fraud Kill Chain process specifically for BEC. In some cases, they can freeze the recipient account before the money is moved again.
- Notify your cyber insurance provider. BEC losses may be covered, but notification timing is critical — many policies require immediate notification.
The Bottom Line
BEC is not a technology problem — it is a process problem. The fix is not a better spam filter. The fix is a policy that says: no financial action happens based on an email alone. Ever. For any amount. No matter how urgent the email sounds or who it appears to come from. Implement that policy today, train your team, and you have eliminated the single most expensive threat to your business.