Confirmed confidenceCurrent
Business Email Compromise Still Targets Payment Cycles
Reports continue to show payment redirection timed to real invoice cycles.
Published 10 February 2025
- Threat category
- Business Email Compromise
- Location
- Global
- Affected population
- Businesses and finance teams
What we are seeing
Business email compromise cases commonly involve a message that appears to come from a supplier or executive, timed to an upcoming payment. The request is often to change bank details.
Why it matters
Because the message references real projects, it can pass casual checks. Secrecy and urgency are used to discourage verification.
Defensive takeaway
- Require two people to approve any bank detail change.
- Verify changes by calling a number already on file.
- Use multi-factor authentication on business email.
- Give staff a clear way to report suspected fraud.
Unverified social-media claims are never presented as fact. Confidence labels reflect how well a claim is corroborated, not how alarming it sounds.
Source
Verified factGOVERNMENT
Internet Crime Complaint Center (IC3) public reports and advisories
FBI Internet Crime Complaint Center (IC3) · 01 Mar 2024
View source