Business Email Compromise
Business Email Compromise
Business email compromise is impersonation of an executive, supplier, or colleague to authorise a fraudulent payment or change bank details.
Overview
What is it
Business email compromise targets organisations rather than individuals. A criminal impersonates a senior colleague, a supplier, or a client and asks for a payment, a change of bank details, or sensitive payroll information. The message often arrives at a busy moment and is written to sound routine. Because it references real people and real projects, it can pass casual scrutiny. Strong payment controls and independent verification are the reliable defence.
Entry point
How does it usually begin
Contact comes by email, often from a look-alike domain or a compromised mailbox that is genuinely trusted. Attackers may monitor a thread for weeks before inserting themselves at the point of payment, or use a supplier's real address after taking it over.
Psychology
The psychological play
The deception exploits hierarchy and habit. A request from a chief executive feels difficult to question, and a supplier changing bank details looks like ordinary administration. Secrecy and urgency are added to discourage verification.
Warning signs
What to watch for
- A payment request arrives with unusual urgency or secrecy.
- Bank details for a known supplier have changed.
- The reply-to address differs from the sender's address.
- The message sounds like the executive's usual tone but is slightly off.
- A colleague asks you to bypass the normal approval process.
- The request arrives while the usual approver is away.
Victim perspective
What the victim usually sees
An email appears to come from your manager or a supplier, asking for an urgent payment to a new account. It references a real invoice or project and asks you to keep it confidential.
Anatomy
The anatomy of the deception
- 01
Contact
An email arrives that looks like it is from a senior colleague or supplier.
Defender move
Check the full sender and reply-to addresses.
- 02
Trust
The message references real people, projects, and invoices.
Defender move
Remember that a compromised mailbox can supply real context.
- 03
Pressure
You are told the payment is urgent and confidential.
Defender move
Treat secrecy around payments as a red flag.
- 04
Request
You are asked to pay or to change bank details.
Defender move
Verify any change by calling a known contact.
- 05
Payment or Information
The payment is sent to the new account.
Defender move
Use dual authorisation for all bank detail changes.
- 06
Consequence
Funds are gone and the supplier is never paid.
Defender move
Contact the bank immediately and report the incident.
Verification
What to verify
- 1Call the requester on a number you already have, not one in the email.
- 2Confirm bank detail changes directly with the supplier's known contact.
- 3Check the email headers and domain spelling carefully.
- 4Follow your organisation's approval process without exception.
Protection
How to protect yourself
- Require two people to approve any change of bank details.
- Provide staff with a clear, easy way to report suspected fraud.
- Use multi-factor authentication on all business email accounts.
- Train finance teams to recognise urgency and secrecy as warning signs.
If it happened
If you already responded
Act quickly, and don't blame yourself.
- 1Contact your bank immediately and request a recall of the payment.
- 2Preserve the email and report the incident to your IT and security teams.
- 3Inform the real supplier and any affected partners.
- 4Report to your national fraud service and consider notifying the police.
Examples
Real-world examples
Typical cases include a fake chief executive requesting an urgent transfer, a supplier email changing bank details, and a payroll request for updated salary account information.
Sources
Where this comes from
Claims are labelled by verification status. Treat reported, alleged and unresolved claims as exactly that.
- Verified factGOVERNMENT
Online fraud and cybercrime threat assessments
Europol · 12 Sept 2024
View source - Verified factGOVERNMENT
Internet Crime Complaint Center (IC3) public reports and advisories
FBI Internet Crime Complaint Center (IC3) · 01 Mar 2024
View source
Spotted this pattern? Help others by reporting it.