Business email compromise (BEC) is a scam in which criminals pose as someone you trust, usually by email, to get your team to send money or sensitive information to the wrong place. It is one of the costliest cybercrimes the FBI tracks, and most business owners have barely heard of it.
Ransomware gets the headlines: encrypted files, countdown timers, demands for cryptocurrency. BEC is quieter and harder to spot. In the FBI Internet Crime Complaint Center's (IC3) annual reports, reported BEC losses run many times higher than reported ransomware losses. BEC rarely makes the news. It shows up later, in the bank reconciliation.
In a BEC attack, criminals impersonate a trusted party (an executive, a vendor, a client, a law firm, a title company or a bank) to manipulate an employee into wiring funds, changing payment details or sharing sensitive data. There is usually no malware and nothing gets encrypted. It takes a convincing email and a moment of rushed decision-making.
The FBI's IC3 reported about $2.9 billion in BEC losses in the United States in 2023, and BEC has stayed near the top of its loss rankings since. The real number is higher because many losses go unreported. A wire sent to the wrong account is often unrecoverable, and banks have limited obligations to reverse a payment the account holder authorized, even when that authorization was obtained through fraud.
An email appears to come from the CEO, CFO or another senior leader, often from an address that looks nearly identical to the real one. It asks an employee to wire funds urgently, buy gift cards or change payment account details. The urgency is deliberate: it skips the pause that would otherwise prompt a verification call.
An attacker compromises or impersonates a vendor's email account and sends an invoice with "updated" banking details. The business pays what looks like a normal invoice into an account the attacker controls. This one can go unnoticed for weeks, until the real vendor calls asking why their payment is late.
Someone impersonating an employee asks HR or payroll to change direct deposit details. The next paycheck goes to the attacker, and the employee often doesn't notice until payday.
An email posing as a law firm, title company or legal representative requests a wire tied to a transaction, closing or settlement. The legal framing adds urgency and discourages questions. Real estate closings are a common target, which is why we build verification steps into IT support for real estate offices and law firms.
Unlike the patterns above, which usually rely on spoofed addresses, this variant uses a real, compromised email account. The messages come from the genuine mailbox, pass authentication checks and are very hard to spot without behavioral monitoring. That is why multi-factor authentication (MFA) on email matters so much: it is the main control that keeps attackers out of the account in the first place. Our article on credential stuffing and password spraying explains how those accounts get taken over.
BEC exploits human habits more than technical weaknesses. A typical attack leans on:
Attackers increasingly use AI tools to write these emails, so the spelling mistakes and awkward phrasing that used to give fraud away are fading. A well-made BEC email can look identical to a real one without technical controls to check it.
Email authentication (SPF, DKIM and DMARC). These standards let receiving servers confirm that a message really came from the domain it claims. Configured correctly and enforced, they block a large share of exact-domain spoofing. Many businesses, and plenty of their vendors, still have them set up incompletely. We check and configure them as part of our Microsoft 365 support.
MFA on every email account. Account-compromise BEC needs access to a real mailbox, and MFA is the main barrier. Microsoft has reported that MFA blocks more than 99% of automated account compromise attacks. An account with MFA can still be compromised, for example through MFA fatigue or adversary-in-the-middle phishing, but it is much harder.
Email filtering with impersonation detection. Modern email security can flag lookalike domains (nerds-quad.net instead of nerdsquad.net), display-name spoofs (an email from "your managing partner" that actually comes from a free webmail account) and odd behavior, such as an executive's mailbox suddenly emailing accounting about a wire at 11 PM.
Account and endpoint monitoring. When an account is compromised, endpoint detection and response (EDR) on the device and monitoring on the account can surface warning signs, such as sign-ins from unusual locations or new mail-forwarding rules, before money moves.
Security awareness training. The human layer matters a great deal for BEC. Train staff to confirm payment changes by calling a known number (never by replying to the email), to recognize display-name spoofs, and to treat any urgent request that skips normal process with suspicion. See security awareness training for more.
A written payment verification policy. Require a call-back to a number already on file before any new or changed bank details are used, and a second approver for wires above a set amount. This is low-tech and very effective.
Move fast. If money has been wired to a fraudulent account, call your bank right away and ask it to recall the transfer, then file a complaint at ic3.gov. The FBI has a process for trying to freeze fraudulent wires, and it works best when reported within the first day or two. Recovery chances fall quickly after that.
Then notify your cyber insurance carrier, report the incident to law enforcement and preserve every related email. Don't delete anything, even the embarrassing reply. If you are a client, call us so we can secure the affected accounts, check for forwarding rules and other persistence, and help document what happened.
BEC defenses are a core part of the cybersecurity services we set up for managed IT clients: email authentication, MFA enforcement, email filtering and security awareness training. For financial services firms and other businesses that move money by wire, we also help put verification procedures in place for payment instructions that fall outside normal patterns. Dark web monitoring is available as an add-on to flag leaked staff credentials early.
In regulated industries, a BEC incident that exposes customer financial data or account credentials can trigger notification duties. Examples include Regulation S-P for SEC-registered advisers and broker-dealers, the FTC Safeguards Rule under GLBA for other financial institutions, and Florida's breach notification law (FIPA). We help you collect the technical facts and documentation your incident response plan calls for. NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.