Skip to content
Confirmed confidenceCurrent

Business Email Compromise Still Targets Payment Cycles

Reports continue to show payment redirection timed to real invoice cycles.

Published 10 February 2025

Threat category
Business Email Compromise
Location
Global
Affected population
Businesses and finance teams

What we are seeing

Business email compromise cases commonly involve a message that appears to come from a supplier or executive, timed to an upcoming payment. The request is often to change bank details.

Why it matters

Because the message references real projects, it can pass casual checks. Secrecy and urgency are used to discourage verification.

Defensive takeaway

  • Require two people to approve any bank detail change.
  • Verify changes by calling a number already on file.
  • Use multi-factor authentication on business email.
  • Give staff a clear way to report suspected fraud.
Unverified social-media claims are never presented as fact. Confidence labels reflect how well a claim is corroborated, not how alarming it sounds.

Source

Verified factGOVERNMENT

Internet Crime Complaint Center (IC3) public reports and advisories

FBI Internet Crime Complaint Center (IC3) · 01 Mar 2024

View source