Business email compromise is a fraud in which an attacker gains access to, or convincingly impersonates, a business email account and uses it to redirect a payment. There is no malware to detect and no ransom note. There is an invoice with new bank details, sent by someone who sounds exactly like the person who always sends it, because in many cases, it is that person’s mailbox.
The FBI’s Internet Crime Complaint Center reported an exposed dollar loss from BEC of $55,499,915,582 across domestic and international incidents reported between October 2013 and December 2023, in a public service announcement, I-091124-PSA, published September 11, 2024. Fraud is the most costly category for businesses and is almost entirely preventable with controls already available in your Microsoft 365 or Google Workspace subscription.
What BEC actually looks like
Four patterns account for most of what we respond to.
- Vendor invoice fraud. A real supplier’s mailbox is compromised. The attacker monitors the billing thread, waits for a genuine invoice, and then sends a duplicate using the supplier’s own address but with different bank details. This is the version that costs the most, because everything about it is legitimate except the account number.
- Executive impersonation. A lookalike domain or a display name spoof, an urgent request to a finance staffer, a wire that has to go out before a meeting ends. Often timed to a day the executive is traveling, which the attacker knows because the mailbox told them.
- Payroll diversion. An email from an employee asking HR to update direct deposit details before the next run. Small individually, and easy to repeat.
- Escrow and closing fraud. Real estate, legal, and title transactions, where a single wire is large and the timing is public. The attacker inserts new wire instructions late in the process.
All four start the same way: credential theft through a phishing page that harvests the password and, increasingly, the session token, which is why “we have MFA” is a necessary answer and not a complete one.
Detection: The signals worth alerting on
BEC is quiet, so detection is about a small number of specific events rather than volume.
- New or modified inbox rules, especially rules that move messages to a rarely used folder, mark them read, or delete them. Attackers create these within minutes of access so the real owner never sees the replies.
- External auto-forwarding being enabled on a mailbox.
- Impossible travel and unfamiliar sign-in properties, which catch the sessions a stolen password opens.
- OAuth application consent grants, where a user approves an app that then reads mail without needing the password again.
- Sign-ins from anonymizing infrastructure, or from a device that has never been seen for that user.
- Lookalike domain registrations against your own domain and against your top vendors.
- Messages that fail DMARC from a domain that should be passing it.
These have to be watched by someone, not merely enabled. An alert nobody reads on a Saturday morning is the same as no alert, which is why this page sits under our security operations center as a service rather than beside it.
Identity Controls: MFA and conditional access
Multi-factor authentication on every account is the floor, including service accounts and shared mailboxes, as well as the executives who asked to be exempted. Above that floor:
- Phishing-resistant methods where they can be adopted: passkeys, FIDO2 security keys, or certificate-based authentication. These defeat the token-stealing proxy pages that ordinary MFA does not.
- Block legacy authentication protocols, which bypass MFA entirely and are still enabled in a surprising number of tenants.
- Conditional access by device compliance, so mail is reachable from managed devices rather than from anywhere with the right password.
- Location and risk-based policies, requiring re-authentication on a risky sign-in and blocking the countries you never do business in.
- Restrict who can consent to applications, so a user cannot grant a malicious app permanent mailbox access on their own.
- Short session lifetimes for privileged accounts, which limit how long a stolen token is useful.
Mailbox Rule Monitoring
This deserves its own control because it is the highest-value single signal in the whole category. In every BEC incident we have worked on, an inbox rule was created to hide the conversation from the real mailbox owner. We monitor rule creation and modification across the tenant, alert on the patterns attackers use, and periodically audit existing rules and forwarding configuration rather than waiting for a new one to appear. Disabling external auto-forwarding at the tenant level and requiring an exception process for the handful of legitimate cases removes a whole branch of the problem.
Payment Verification: The control that stops the loss
Technical controls reduce how often an attacker gets in. Payment controls decide whether those costs cost you money. These are processes; they cost nothing, and they are the reason some compromised businesses lose a mailbox, and others lose six figures.
- Out-of-band verification for every bank detail change. Call the vendor at the number you already have, not the number in the email. This one rule stops vendor invoice fraud outright.
- Dual approval above a threshold you set, with the second approver required to confirm independently rather than to click.
- A written vendor bank-change procedure that finance staff can follow without asking permission to slow down. Attackers rely on urgency, so the procedure has to make waiting the default rather than the brave choice.
- No payment instruction changes accepted by email alone, as stated in your own terms and in your vendor onboarding.
- External sender warnings on inbound mail, so a lookalike domain is visibly external.
- Standing payroll change verification, the same call-back rule applies to direct deposit updates.
Incident response: the first hour
If you think a wire has gone to a fraudulent account, the order matters, and the clock is short.
- Call your bank immediately and ask them to recall the wire. Recovery odds fall sharply within the first day.
- File a complaint at ic3.gov with the transaction details. The FBI asks victims to report regardless of the amount, and the reporting is what enables a recall attempt through the financial system.
- Revoke sessions and reset the password on the affected account, then re-register multi-factor authentication rather than trusting the existing enrollment.
- Hunt for the rules. Inspect and remove inbox rules, forwarding, delegated access, and any application consents granted during the window.
- Establish the exposure window from sign-in and audit logs: what was reachable, for how long, and whether anything was exported.
- Notify affected counterparties. If the mailbox was used to email your clients, they need to know before they act on something it sent.
- Preserve the logs before retention expires, because your insurer and any law enforcement referral will ask for them.
- Notify your cyber insurer within the notice period in your policy.
Our managed security services team runs steps 3 through 7 for clients under an incident response agreement. If you are in the middle of one right now, call rather than email, because the mailbox you would email from may be the compromised one.
Cyber Insurance Requirements
Insurers have moved BEC into its own coverage conversation, usually under social engineering or funds transfer fraud, and it is frequently sub-limited well below the policy’s headline number. Two practical implications.
First, read what the sub-limit actually is for funds transfer fraud, because it is common for it to be a fraction of the aggregate limit. Second, most carriers now condition coverage on specific controls, and the application asks about them by name: multi-factor authentication for email and remote access, coverage of privileged accounts, out-of-band verification of payment changes, email filtering, and security awareness training with phishing simulation. Answering those questions inaccurately is a coverage problem later, so answer them from configuration rather than from memory. We provide clients with evidence for each control at renewal.
What we Deploy
For Los Angeles clients on a managed security agreement, BEC protection is a stack rather than a product: identity hardening and conditional access, phishing-resistant authentication where the workforce can adopt it, tenant-wide inbox rule and forwarding monitoring, DMARC enforcement so your domain cannot be spoofed, lookalike domain monitoring, email filtering and sandboxing, and phishing simulation with training. The domain authentication side is covered in more depth on our DNS-based email protection page, and the human side in dark web scanning and phishing email training.
➤ Get Your Free IT Assessment
