It is a normal Thursday. Your office manager is closing out invoices, the phones are doing what phones do, and a longtime vendor emails to say they have switched banks and here are the new wire instructions for the invoice you already approved. The email comes from the person you always deal with, in the thread you have been using for months, in their usual writing voice. There is nothing to notice. The payment goes out that afternoon.
Eleven days later the vendor calls about the unpaid invoice. That call is the moment everything you believed about the past two weeks stops being true, and the feeling that follows is one of the most specific feelings in business. This post walks through how that sequence unfolds, hour by hour, stopping at each step to name the thing that would have broken the chain. It is the first in an ongoing series, because the pattern repeats with small variations and the defenses are learnable.
What This Is, and What It Is Not
The timeline below is a composite. It is not one customer’s story, and no detail belongs to any specific business. We built it from the patterns that show up again and again in this category of incident, called business email compromise, or BEC, meaning fraud committed by getting into or convincingly imitating a real email account rather than by breaking any technology. We are not going to describe the attacker’s side of it, because that is not useful to you and is useful to the wrong people. We will spend the words on the parts you control.
The FBI’s Internet Crime Complaint Center, in its 2025 Internet Crime Report, recorded 24,768 business email compromise complaints accounting for more than three billion dollars in reported losses, one of the largest single loss categories the bureau tracks. Almost none of those victims had a technology failure. They had a process failure with a technology entry point.
Hour Zero Through Hour Two: A Password Stops Being Secret
- Hour zero. Somebody enters credentials on a page that is not what it appears to be. Often it looks like a document sharing notice or a mailbox warning. The employee is not careless. The page is convincing and they are busy. From this moment the attacker has a working username and password. What breaks the chain: multi-factor authentication, meaning a second proof of identity beyond the password, ideally an app prompt or a physical key rather than a text message. A stolen password is close to worthless when it is not enough by itself. The FBI lists enabling multi-factor authentication among its core recommendations for avoiding exactly this crime.
- Hour one. The account is accessed from somewhere it has never been accessed from. Nothing visible happens in the office. Nobody gets a popup. What breaks the chain: sign-in alerting that a human actually reads. Most business email platforms can flag logins from unusual locations. That capability is often simply switched off, or switched on and routed to a mailbox nobody opens.
- Hour two. Quiet housekeeping begins inside the mailbox. The goal is for the real owner to stop seeing certain conversations while the attacker keeps seeing them. What breaks the chain: alerting on changes to mailbox rules and forwarding settings. This is standard in business email systems and one of the highest value alerts a small business can turn on, because legitimate users almost never make these changes and attackers almost always do.
Day Two Through Day Nine: The Patient Part
Here is the detail that surprises owners most. Nothing happens for a week or more. The attacker is not in a hurry. They read. They learn who approves payments, how your invoices are worded, which vendors are mid project. By the time they act they know your business well enough to sound like it.
- The lesson is that dwell time is your friend if you use it. Dwell time is the industry term for how long an intruder sits in your systems before doing damage. In this category it is usually days. That is a long window, and it only helps if somebody is looking. This is the strongest argument for monitored email security rather than merely configured email security.
- Least privilege limits what the week of reading is worth. If the compromised account is a shared inbox everybody can reach, or an employee given broad access years ago and never trimmed, the attacker’s homework goes further. Access reviews are boring, and they materially shrink this step.
Day Ten, Hour One Through Hour Eight: The Ask
- Morning. The banking change request arrives. It lands in an existing thread, references real project details, and carries a plausible reason plus mild time pressure, because urgency is the one ingredient every version of this fraud shares. What breaks the chain: a written rule that any change to payment details gets verified by phone, using the number already on file, never a number in the message. Not email confirmation. A phone call to a number you already had. The FBI recommends the same thing, and this single control stops most of these losses.
- Midday. Someone approves it. The person approving is doing their job correctly according to the process they were given. That is the point. What breaks the chain: a second set of eyes above a dollar threshold you set, plus explicit permission for any employee to slow a payment down without justifying it. If your culture punishes people for delaying an urgent request, you built the vulnerability yourself.
- Afternoon. The funds leave. Money moves faster than discovery. What breaks the chain: nothing, at this point. Everything that could have helped happened earlier. That is why the defenses in this post are stacked toward the front.
Discovery, and the First Hours That Actually Matter
Discovery usually arrives as an ordinary phone call about an unpaid bill. From that moment, speed is the only variable left, and the order of operations matters more than people expect.
- Call your bank first, not your IT provider. Banks have recall processes for fraudulent transfers, and those processes are dramatically more effective early. The FBI is explicit that victims should contact their financial institution immediately. Make this call before you have all the facts.
- File with the FBI at IC3.gov the same day. Reporting is not a formality. It is how federal fraud recovery processes get triggered, and it works on a clock.
- Secure the account before you investigate it. Reset the password, force every active session to sign out, and remove any rules or forwarding that were added. Signing out active sessions is the step people skip, and skipping it means the attacker is still reading while you draft your response.
- Assume the mailbox is not the only thing touched. Check what else that account could reach and whether the password was reused elsewhere. Then tell your vendors and customers, because the mailbox has likely been used to email them too.
The Bottom Line
Read back through the timeline and notice what the defenses have in common. Multi-factor authentication, an alert somebody reads, trimmed access, and a phone call before payment details change. None of it is exotic or expensive. This fraud does not beat good technology, it walks around ordinary technology through a process gap, which is genuinely good news, because process gaps are the cheapest thing a small business can fix.
Future installments will walk through other common incident shapes, including ransomware and vendor account takeover, in the same format. If reading this made you realize your business would not have caught it either, that is the useful reaction. We help small and mid-sized businesses across Denton County and the DFW area put these controls in place, and we will tell you plainly which ones you already have. Reach us at https://harrisonward.com/contact/.
Comments are closed