Business email compromise is the fraud where a payment goes to a criminal's bank account because an email said it should. No malware is needed. It works because the email looks like it came from someone the business trusts.

How it usually goes

An attacker gets into a mailbox, often through a fake sign-in page. They read for a while, learn who pays whom, then send or alter an invoice with new bank details. Sometimes they add a mailbox rule that hides the replies, so the real owner never sees the conversation.

The impersonation version

The attacker doesn't always need to break in. A lookalike domain, one letter off, and a message that sounds like the managing director asking for an urgent transfer can be enough.

Warning signs

Watch for a change of bank details by email, pressure to pay today, a request to keep it confidential, a reply address that differs from the sender, and messages that arrive just as a real payment is due.

The control that matters most

Verify any new or changed bank details by phoning a number you already hold, not one in the email. Make it a rule that nobody can skip, including the directors. Two-person approval for payments above a set amount adds a second check.

The technical controls

Multi-factor authentication on every mailbox stops most account takeovers. Blocking automatic forwarding to outside addresses, alerting on new mailbox rules, and setting up SPF, DKIM and DMARC for your domain make impersonation harder and takeovers easier to spot.

If it happens

Call your bank immediately, because the chance of recovering funds falls by the hour. Then reset the affected account, check mailbox rules, report it through ReportCyber, and tell your insurer.

Want security handled as part of your IT? Managed cybersecurity

All resources