Business email compromise doesn't use malware, doesn't trip antivirus, and often doesn't involve a compromised account at all. It's the most expensive email threat most small businesses face — and it's a process problem more than a technical one.
What BEC actually is
BEC is fraud carried out through legitimate-looking email that convinces someone with authority to move money or release data. There's frequently no attachment, no link and no payload — which is exactly why filters struggle. The message *is* the attack.
The FBI's Internet Crime Complaint Center consistently reports BEC among the highest-loss cybercrime categories, exceeding ransomware in reported dollar losses in multiple years.
The five variants you'll actually see
1. Invoice redirection
The most damaging in practice. An attacker learns about a genuine supplier relationship — often by sitting silently in a compromised mailbox for weeks — then sends a "we've changed banks" notice with new account details, timed to a real invoice.
2. CEO fraud
A message appearing to come from your director or owner, requesting an urgent transfer, usually while they're travelling and "hard to reach." It exploits authority and time pressure together.
3. Payroll diversion
An email to HR or payroll, apparently from an employee, asking to update bank details before the next pay run. Individually small, easy to miss, and often repeated across several staff.
4. Vendor account takeover
Rather than spoofing your supplier, the attacker genuinely controls their mailbox. Requests come from the real address, in the real thread, with correct history. Address-based checks won't catch this one.
5. Data harvesting
A request from "the accountant" for employee tax file numbers or payroll records — feeding identity fraud rather than immediate theft.
Why technical controls only get you partway
SPF, DKIM and DMARC stop attackers from *spoofing your exact domain* — worth doing, and our guide covers the setup. But BEC usually sidesteps them entirely:
- A lookalike domain (
tobavarnail.com) passes its own authentication perfectly - A free-mail account with a spoofed display name shows only "Sarah Chen" on mobile
- A genuinely compromised supplier mailbox passes every check because it's real
The controls that actually work
These are process, not software — and they're the ones that stop the loss:
- Out-of-band verification for bank detail changes, always. Phone the supplier on the number you already have on file, never a number in the email requesting the change. This single rule prevents most invoice redirection.
- Dual authorisation above a threshold. Any payment over an agreed amount needs two people. Attackers need to fool both, on different channels.
- A no-blame urgency rule. Staff must feel safe slowing down a request from the boss. Urgency plus hierarchy is the entire psychological mechanism of CEO fraud.
- External sender warnings. A visible banner on mail from outside your domain makes display-name spoofing obvious.
- Register your lookalike domains — common misspellings and the
.net/.covariants of your own name. - MFA on every mailbox, no exceptions. Most vendor account takeovers start with a password that had no second factor. Tobava Mail supports authenticator-app two-step verification, with an emailed fallback code.
If you implement one thing from this article: write down that bank detail changes require a phone call to a previously known number, and make it a rule nobody can override — including the owner. It costs nothing and it stops the most expensive variant.
If it already happened
- Call your bank immediately. Same-day recall of a transfer is sometimes possible; after 24–48 hours it rarely is.
- Preserve the evidence — full message headers, not screenshots.
- Report it — in Australia, to ReportCyber and Scamwatch.
- Force password resets and check mailbox rules. Attackers routinely leave auto-forward or auto-delete rules behind so their thread stays hidden.
- Warn your suppliers and customers. If your mailbox was the compromised one, they're the next target.
Try Tobava Mail free
Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.
Create your free account