Business email compromise: the scam that quietly costs companies billions

Tobava Security Team · · 7 min read
← All articles

Business email compromise doesn't use malware, doesn't trip antivirus, and often doesn't involve a compromised account at all. It's the most expensive email threat most small businesses face — and it's a process problem more than a technical one.

What BEC actually is

BEC is fraud carried out through legitimate-looking email that convinces someone with authority to move money or release data. There's frequently no attachment, no link and no payload — which is exactly why filters struggle. The message *is* the attack.

The FBI's Internet Crime Complaint Center consistently reports BEC among the highest-loss cybercrime categories, exceeding ransomware in reported dollar losses in multiple years.

The five variants you'll actually see

1. Invoice redirection

The most damaging in practice. An attacker learns about a genuine supplier relationship — often by sitting silently in a compromised mailbox for weeks — then sends a "we've changed banks" notice with new account details, timed to a real invoice.

2. CEO fraud

A message appearing to come from your director or owner, requesting an urgent transfer, usually while they're travelling and "hard to reach." It exploits authority and time pressure together.

3. Payroll diversion

An email to HR or payroll, apparently from an employee, asking to update bank details before the next pay run. Individually small, easy to miss, and often repeated across several staff.

4. Vendor account takeover

Rather than spoofing your supplier, the attacker genuinely controls their mailbox. Requests come from the real address, in the real thread, with correct history. Address-based checks won't catch this one.

5. Data harvesting

A request from "the accountant" for employee tax file numbers or payroll records — feeding identity fraud rather than immediate theft.

Why technical controls only get you partway

SPF, DKIM and DMARC stop attackers from *spoofing your exact domain* — worth doing, and our guide covers the setup. But BEC usually sidesteps them entirely:

The controls that actually work

These are process, not software — and they're the ones that stop the loss:

If you implement one thing from this article: write down that bank detail changes require a phone call to a previously known number, and make it a rule nobody can override — including the owner. It costs nothing and it stops the most expensive variant.

If it already happened

  1. Call your bank immediately. Same-day recall of a transfer is sometimes possible; after 24–48 hours it rarely is.
  2. Preserve the evidence — full message headers, not screenshots.
  3. Report it — in Australia, to ReportCyber and Scamwatch.
  4. Force password resets and check mailbox rules. Attackers routinely leave auto-forward or auto-delete rules behind so their thread stays hidden.
  5. Warn your suppliers and customers. If your mailbox was the compromised one, they're the next target.

Try Tobava Mail free

Encrypted email, a private inbox, and a full workspace — built by a cybersecurity company. No ads, no tracking, no message scanning.

Create your free account