Skip to content

Business Email Compromise

Business Email Compromise

Business email compromise is impersonation of an executive, supplier, or colleague to authorise a fraudulent payment or change bank details.

Critical riskSafeGlobalCurrent
Last verified 9 February 2025
businessbecinvoicepayment

Overview

What is it

Business email compromise targets organisations rather than individuals. A criminal impersonates a senior colleague, a supplier, or a client and asks for a payment, a change of bank details, or sensitive payroll information. The message often arrives at a busy moment and is written to sound routine. Because it references real people and real projects, it can pass casual scrutiny. Strong payment controls and independent verification are the reliable defence.

Entry point

How does it usually begin

Contact comes by email, often from a look-alike domain or a compromised mailbox that is genuinely trusted. Attackers may monitor a thread for weeks before inserting themselves at the point of payment, or use a supplier's real address after taking it over.

Psychology

The psychological play

The deception exploits hierarchy and habit. A request from a chief executive feels difficult to question, and a supplier changing bank details looks like ordinary administration. Secrecy and urgency are added to discourage verification.

Warning signs

What to watch for

  • A payment request arrives with unusual urgency or secrecy.
  • Bank details for a known supplier have changed.
  • The reply-to address differs from the sender's address.
  • The message sounds like the executive's usual tone but is slightly off.
  • A colleague asks you to bypass the normal approval process.
  • The request arrives while the usual approver is away.

Victim perspective

What the victim usually sees

An email appears to come from your manager or a supplier, asking for an urgent payment to a new account. It references a real invoice or project and asks you to keep it confidential.

Anatomy

The anatomy of the deception

  1. 01

    Contact

    An email arrives that looks like it is from a senior colleague or supplier.

    Defender move

    Check the full sender and reply-to addresses.

  2. 02

    Trust

    The message references real people, projects, and invoices.

    Defender move

    Remember that a compromised mailbox can supply real context.

  3. 03

    Pressure

    You are told the payment is urgent and confidential.

    Defender move

    Treat secrecy around payments as a red flag.

  4. 04

    Request

    You are asked to pay or to change bank details.

    Defender move

    Verify any change by calling a known contact.

  5. 05

    Payment or Information

    The payment is sent to the new account.

    Defender move

    Use dual authorisation for all bank detail changes.

  6. 06

    Consequence

    Funds are gone and the supplier is never paid.

    Defender move

    Contact the bank immediately and report the incident.

Verification

What to verify

  1. 1Call the requester on a number you already have, not one in the email.
  2. 2Confirm bank detail changes directly with the supplier's known contact.
  3. 3Check the email headers and domain spelling carefully.
  4. 4Follow your organisation's approval process without exception.

Protection

How to protect yourself

  • Require two people to approve any change of bank details.
  • Provide staff with a clear, easy way to report suspected fraud.
  • Use multi-factor authentication on all business email accounts.
  • Train finance teams to recognise urgency and secrecy as warning signs.

If it happened

If you already responded

Act quickly, and don't blame yourself.

  1. 1Contact your bank immediately and request a recall of the payment.
  2. 2Preserve the email and report the incident to your IT and security teams.
  3. 3Inform the real supplier and any affected partners.
  4. 4Report to your national fraud service and consider notifying the police.

Examples

Real-world examples

Typical cases include a fake chief executive requesting an urgent transfer, a supplier email changing bank details, and a payroll request for updated salary account information.

Sources

Where this comes from

Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.

  • Verified factGOVERNMENT

    Online fraud and cybercrime threat assessments

    Europol · 12 Sept 2024

    View source
  • Verified factGOVERNMENT

    Internet Crime Complaint Center (IC3) public reports and advisories

    FBI Internet Crime Complaint Center (IC3) · 01 Mar 2024

    View source

Spotted this pattern? Help others by reporting it.