Business email compromise is a fraud in which an attacker gains access to, or convincingly impersonates, a business email account and uses it to redirect a payment. There is no malware to detect and no ransom note. There is an invoice with new bank details, sent by someone who sounds exactly like the person who always sends it, because in many cases, it is that person’s mailbox.

The FBI’s Internet Crime Complaint Center reported an exposed dollar loss from BEC of $55,499,915,582 across domestic and international incidents reported between October 2013 and December 2023, in a public service announcement, I-091124-PSA, published September 11, 2024. Fraud is the most costly category for businesses and is almost entirely preventable with controls already available in your Microsoft 365 or Google Workspace subscription.

What BEC actually looks like

Four patterns account for most of what we respond to.

  • Vendor invoice fraud. A real supplier’s mailbox is compromised. The attacker monitors the billing thread, waits for a genuine invoice, and then sends a duplicate using the supplier’s own address but with different bank details. This is the version that costs the most, because everything about it is legitimate except the account number.
  • Executive impersonation. A lookalike domain or a display name spoof, an urgent request to a finance staffer, a wire that has to go out before a meeting ends. Often timed to a day the executive is traveling, which the attacker knows because the mailbox told them.
  • Payroll diversion. An email from an employee asking HR to update direct deposit details before the next run. Small individually, and easy to repeat.
  • Escrow and closing fraud. Real estate, legal, and title transactions, where a single wire is large and the timing is public. The attacker inserts new wire instructions late in the process.

All four start the same way: credential theft through a phishing page that harvests the password and, increasingly, the session token, which is why “we have MFA” is a necessary answer and not a complete one.

Detection: The signals worth alerting on

BEC is quiet, so detection is about a small number of specific events rather than volume.

  • New or modified inbox rules, especially rules that move messages to a rarely used folder, mark them read, or delete them. Attackers create these within minutes of access so the real owner never sees the replies.
  • External auto-forwarding being enabled on a mailbox.
  • Impossible travel and unfamiliar sign-in properties, which catch the sessions a stolen password opens.
  • OAuth application consent grants, where a user approves an app that then reads mail without needing the password again.
  • Sign-ins from anonymizing infrastructure, or from a device that has never been seen for that user.
  • Lookalike domain registrations against your own domain and against your top vendors.
  • Messages that fail DMARC from a domain that should be passing it.

These have to be watched by someone, not merely enabled. An alert nobody reads on a Saturday morning is the same as no alert, which is why this page sits under our security operations center as a service rather than beside it.

Identity Controls: MFA and conditional access

Multi-factor authentication on every account is the floor, including service accounts and shared mailboxes, as well as the executives who asked to be exempted. Above that floor:

  • Phishing-resistant methods where they can be adopted: passkeys, FIDO2 security keys, or certificate-based authentication. These defeat the token-stealing proxy pages that ordinary MFA does not.
  • Block legacy authentication protocols, which bypass MFA entirely and are still enabled in a surprising number of tenants.
  • Conditional access by device compliance, so mail is reachable from managed devices rather than from anywhere with the right password.
  • Location and risk-based policies, requiring re-authentication on a risky sign-in and blocking the countries you never do business in.
  • Restrict who can consent to applications, so a user cannot grant a malicious app permanent mailbox access on their own.
  • Short session lifetimes for privileged accounts, which limit how long a stolen token is useful.

Mailbox Rule Monitoring

This deserves its own control because it is the highest-value single signal in the whole category. In every BEC incident we have worked on, an inbox rule was created to hide the conversation from the real mailbox owner. We monitor rule creation and modification across the tenant, alert on the patterns attackers use, and periodically audit existing rules and forwarding configuration rather than waiting for a new one to appear. Disabling external auto-forwarding at the tenant level and requiring an exception process for the handful of legitimate cases removes a whole branch of the problem.

Payment Verification: The control that stops the loss

Technical controls reduce how often an attacker gets in. Payment controls decide whether those costs cost you money. These are processes; they cost nothing, and they are the reason some compromised businesses lose a mailbox, and others lose six figures.

  • Out-of-band verification for every bank detail change. Call the vendor at the number you already have, not the number in the email. This one rule stops vendor invoice fraud outright.
  • Dual approval above a threshold you set, with the second approver required to confirm independently rather than to click.
  • A written vendor bank-change procedure that finance staff can follow without asking permission to slow down. Attackers rely on urgency, so the procedure has to make waiting the default rather than the brave choice.
  • No payment instruction changes accepted by email alone, as stated in your own terms and in your vendor onboarding.
  • External sender warnings on inbound mail, so a lookalike domain is visibly external.
  • Standing payroll change verification, the same call-back rule applies to direct deposit updates.

Incident response: the first hour

If you think a wire has gone to a fraudulent account, the order matters, and the clock is short.

  1. Call your bank immediately and ask them to recall the wire. Recovery odds fall sharply within the first day.
  2. File a complaint at ic3.gov with the transaction details. The FBI asks victims to report regardless of the amount, and the reporting is what enables a recall attempt through the financial system.
  3. Revoke sessions and reset the password on the affected account, then re-register multi-factor authentication rather than trusting the existing enrollment.
  4. Hunt for the rules. Inspect and remove inbox rules, forwarding, delegated access, and any application consents granted during the window.
  5. Establish the exposure window from sign-in and audit logs: what was reachable, for how long, and whether anything was exported.
  6. Notify affected counterparties. If the mailbox was used to email your clients, they need to know before they act on something it sent.
  7. Preserve the logs before retention expires, because your insurer and any law enforcement referral will ask for them.
  8. Notify your cyber insurer within the notice period in your policy.

Our managed security services team runs steps 3 through 7 for clients under an incident response agreement. If you are in the middle of one right now, call rather than email, because the mailbox you would email from may be the compromised one.

Cyber Insurance Requirements

Insurers have moved BEC into its own coverage conversation, usually under social engineering or funds transfer fraud, and it is frequently sub-limited well below the policy’s headline number. Two practical implications.

First, read what the sub-limit actually is for funds transfer fraud, because it is common for it to be a fraction of the aggregate limit. Second, most carriers now condition coverage on specific controls, and the application asks about them by name: multi-factor authentication for email and remote access, coverage of privileged accounts, out-of-band verification of payment changes, email filtering, and security awareness training with phishing simulation. Answering those questions inaccurately is a coverage problem later, so answer them from configuration rather than from memory. We provide clients with evidence for each control at renewal.

What we Deploy

For Los Angeles clients on a managed security agreement, BEC protection is a stack rather than a product: identity hardening and conditional access, phishing-resistant authentication where the workforce can adopt it, tenant-wide inbox rule and forwarding monitoring, DMARC enforcement so your domain cannot be spoofed, lookalike domain monitoring, email filtering and sandboxing, and phishing simulation with training. The domain authentication side is covered in more depth on our DNS-based email protection page, and the human side in dark web scanning and phishing email training.

➤ Get Your Free IT Assessment

Frequently Asked Questions About Business Email Compromise

What is business email compromise?

It is a fraud in which an attacker takes over or convincingly imitates a business email account and redirects a payment. There is usually no malware involved. The four common patterns are vendor invoice fraud, where a supplier’s mailbox is compromised, and a real invoice is resent with new bank details; executive impersonation of an urgent wire request; payroll diversion through a direct deposit change; and escrow or closing fraud on a real estate or legal transaction.

How much does business email compromise cost businesses?

The FBI Internet Crime Complaint Center reported $55,499,915,582 in exposed dollar loss from BEC across domestic and international incidents between October 2013 and December 2023, in a public service announcement I-091124-PSA published on September 11, 2024. Exposed loss counts both attempted and actual losses. For an individual small business, the figure that matters is the size of one wire, because BEC is a single-transaction fraud rather than an accumulating one.

Does multi-factor authentication stop business email compromise?

It stops the majority of attempts, but not all. Attacker-in-the-middle phishing pages proxy the login and capture the session token after the second factor is approved, which gives access without the password ever being reused. That is why phishing-resistant methods such as passkeys or FIDO2 security keys matter, along with blocking legacy authentication protocols that bypass multi-factor authentication entirely, and conditional access that requires a compliant device.

What is the single most useful thing to monitor for BEC?

Inbox rule creation and modification. In every incident we have worked on, the attacker created a rule to move or delete replies in the conversation they were hijacking, so the real mailbox owner would not see them. Monitoring rule changes tenant-wide, alerting on the specific patterns attackers use, and disabling external auto-forwarding by default catches the compromise during the reconnaissance phase, before a payment is redirected.

How do we stop a fraudulent vendor bank change from being paid?

Call the vendor at the phone number you already had on file, not the number in the email, and confirm the change verbally with a person you can identify. Put that rule in writing as a procedure so finance staff is not deciding case by case under time pressure, add dual approval above a threshold, and state in your vendor terms that you do not accept payment instruction changes by email alone. This single control defeats vendor invoice fraud even when the vendor mailbox is genuinely compromised.

What should we do in the first hour after a fraudulent wire?

Call your bank and ask for a wire recall, because recovery odds fall quickly after the first day. File at ic3.gov with the transaction details regardless of the amount. Then revoke the sessions on the affected account, reset the password, re-register multi-factor authentication, remove any inbox rules, forwarding, delegate access, or application consents created during the compromise, establish the exposure window from the audit logs, notify counterparties of the email address used, preserve the logs, and notify your cyber insurer within the notice period in your policy.

Does cyber insurance cover business email compromise losses?

Often, under a social engineering or funds transfer fraud extension, and usually with a sub-limit well below the policy aggregate. Read the sub-limit before you rely on the headline number. Carriers also condition coverage on named controls, and the application asks about them specifically: multi-factor authentication on email and remote access, coverage of privileged accounts, out-of-band verification of payment changes, email filtering, and security awareness training. Answer those from your configuration, because an inaccurate answer becomes a claim problem.

Is DMARC enough to prevent BEC?

DMARC stops other people from sending mail that appears to come from your domain, which shuts down one whole attack pattern and protects your customers and vendors from being defrauded in your name. It does nothing about the pattern that costs the most, which is mail genuinely sent from a compromised real mailbox, whether yours or a supplier’s. Deploy DMARC at enforcement, then treat identity controls, mailbox rule monitoring, and payment verification as the parts that address the rest.