There is no thriller about this one. No hooded figure, no countdown, no server room. Just a bookkeeper who gets an email from a vendor she has worked with for three years, in a thread she has been reading all month, saying the company switched banks and here are the updated remittance details. She updates the record. She pays the invoice. Right amount, right work, right schedule. The money goes to a criminal.

The FBI calls this business email compromise, or BEC. In a public service announcement issued in September 2024, the FBI’s Internet Crime Complaint Center reported $55,499,915,582 in exposed losses across 305,033 incidents reported between October 2013 and December 2023, with $20,089,561,364 of that coming from 158,436 victims inside the United States. It is one of the most expensive crimes in the country and almost nobody outside our industry can describe how it works. So let us walk through it.

The Play, Step by Step

  1. Get inside a mailbox, or fake one convincingly. The FBI describes criminals compromising legitimate business or personal email accounts through social engineering or computer intrusion. The cheaper version skips the break-in entirely: register a domain that looks almost right, swapping one letter or adding an s, and send from there.
  2. Go quiet and set up rules. This is the step people miss. Once inside, the attacker creates mailbox rules so certain messages never appear in the inbox. Microsoft lists exactly this among the signs of a compromised account: “Rules that automatically forward email to unknown addresses” and “Rules that move messages to the Notes, Junk Email, or RSS Subscriptions folders.”
  3. Read the mail and learn the business. Who approves payments. What the invoices look like. How your controller signs off. Whether the owner travels. This phase can run for weeks and produces nothing an alarm would catch, because reading email is what email accounts do.
  4. Wait for a real invoice thread. They do not invent a transaction. They wait for a legitimate one, with a real amount, real work, and a real history behind it. That is the entire trick.
  5. Make the swap. A reply arrives in the existing thread announcing new banking details. If they are in the vendor’s mailbox, it comes from the vendor’s actual address. If they are using a lookalike domain, the display name is right and the signature is copied.
  6. Move the money fast. The FBI describes funds being routed through intermediary bank accounts and cryptocurrency exchanges, frequently outside the country. Recovery odds fall sharply after the first day or two.

Why Your Security Tools Do Not Stop It

Here is the uncomfortable part. At no point in that sequence does anything technically malicious happen.

There is no attachment to quarantine. No link to a fake login page, at least not in the message that costs you the money. No malware to detect. The email arrives from a real account or a real domain, passes authentication checks because the sender genuinely controls it, and contains an ordinary business request in ordinary business language. Your filters look for something dangerous. This message is not dangerous. It is just false.

That is why BEC survives security stacks that block millions of phishing attempts a year. We have written before about why filtering phishing is harder than it looks, and BEC is the extreme case: the payload is a fact, and no scanner can tell you which bank account is the right one.

The Defense That Actually Works

Because the attack lives in a business process, the fix lives there too. The FBI’s own guidance is to “use secondary channels and/or two-factor authentication to verify requests for changes in account information.” Translated into an office procedure, that means one rule with no exceptions:

Any change to payment details gets verified by voice, on a phone number you already had before the request arrived.

Every word there is doing work. Here is why each piece matters:

  • By voice, not by email. If the attacker is in the mailbox, they will happily confirm their own request. Replying to ask “is this really you?” asks the criminal to vouch for the criminal.
  • A number you already had. Not the number in the email. Not the number in the new signature block. Pull it from your vendor record, a past contract, or the number you have called for years.
  • Every time, including from the boss. The rule only works if the newest person in accounting can apply it to the owner without fear. Say that out loud, in a meeting, so nobody has to guess.
  • Applied to your outbound changes too. When your own banking details change, call your customers. You are the vendor in somebody else’s version of this story.
  • Written down and dated. Note who called, what number, and who confirmed. That record matters to your bank and insurer if something goes wrong.

The FBI adds two habits worth teaching alongside it: check that the URL in an email actually belongs to the business it claims to come from, and verify the sending email address rather than the display name, which is especially easy to miss on a phone.

Making Step One Harder

Callback verification catches the fraud. Mailbox hardening keeps you from being the account that gets read for six weeks. A few things belong on every small business email tenant:

  • Multi-factor authentication on every mailbox, no exemptions. Microsoft is direct that MFA “effectively safeguards against account compromise and is essential for accounts with admin privileges.” Phishing-resistant methods are stronger still, which we covered in our comparison of hardware keys, passkeys, and app-based MFA.
  • Alerting on new mailbox rules and forwarding. Someone should be notified when a rule that forwards mail externally or files messages into RSS Subscriptions appears. Rules can be hidden from the normal interface, so check at the administrative level.
  • Block or restrict automatic external forwarding unless a specific business need justifies it.
  • Watch third-party app consents. An attacker who cannot beat MFA may instead get a user to approve an app that reads mail. Microsoft’s response guidance includes removing and revoking applications that should not be allowed.
  • Have a response plan that includes revoking sessions. A password reset alone can leave an attacker signed in. Microsoft notes that revoking active sessions “immediately invalidates any active access using the stolen credentials.” One more detail from that guidance worth internalizing: do not email the new password to the user, because the attacker may still be reading that mailbox.

If It Already Happened

Speed matters more than blame. Call your bank immediately and ask them to attempt a recall of the wire. File a complaint with the FBI’s Internet Crime Complaint Center at ic3.gov, the route into the process banks and law enforcement use to try to freeze funds. Preserve the mailbox and its logs before anyone cleans up, because the audit trail is how you learn whether one account or five were involved.

The Bottom Line

Business email compromise is a paperwork crime dressed up as a cyberattack. It beats technical controls because there is nothing technical to catch, and it beats busy people because it arrives inside a conversation they already trust. The defense is unglamorous and cheap: multi-factor authentication so the mailbox is hard to enter, monitoring so a hidden rule does not sit unnoticed for a month, and a phone call before any bank detail changes. Nobody will make a movie about that either. It works anyway.

If you are not sure whether your email tenant would tell you about a suspicious forwarding rule, or you want a payment verification procedure your team will actually follow, we can help you put both in place. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).