A payment change request arrives from a long-standing supplier. The email carries the right logo, the right tone, and even references an active invoice. It asks Accounts Payable to update banking details before the next transfer. Nothing appears unusual until the funds are gone.
That is the operational reality behind what causes business email compromise. These attacks do not usually depend on noisy malware or dramatic system outages. They depend on trust, timing, and an attacker's ability to make one ordinary business process look legitimate. For organizations handling client funds, payroll, protected information, or critical vendor relationships, that makes business email compromise a governance risk as much as a cybersecurity risk.
What Causes Business Email Compromise Attacks?
Business email compromise, often called BEC, occurs when a criminal impersonates a trusted person or gains control of a real business email account to manipulate a transaction or obtain sensitive information. The target may be an executive, finance employee, HR manager, legal administrator, customer service representative, or a vendor with access to payment instructions.
The goal is typically financial. Attackers may redirect a wire transfer, alter direct-deposit information, steal invoices, request gift cards, or obtain tax records and banking details that support later fraud. In more targeted cases, they use a compromised mailbox to learn how decisions are made, who approves payments, and which suppliers are due to be paid.
The central cause is not a single technical failure. BEC succeeds when identity protections, email controls, financial processes, and employee verification practices leave enough room for a convincing request to move forward unchecked.
The Attack Starts With Trust, Not Code
Most BEC campaigns begin with reconnaissance. Criminals review public websites, social media profiles, press releases, job postings, and exposed contact information to map the organization. They identify leadership names, departments, suppliers, office locations, and language used in normal correspondence.
A finance employee receiving a message from a CEO may be more likely to act if the request arrives during a busy period, involves a confidential acquisition, or appears to require immediate action. A vendor impersonation can be equally effective because payment-change requests are a normal part of business.
Attackers use this context to create urgency without making the message sound obviously malicious. They may ask the recipient not to call because the sender is in a meeting, traveling, or handling a sensitive matter. That instruction is a warning sign, but under pressure it can also feel plausible.
Impersonation Can Be Simple or Sophisticated
Some attackers register a look-alike domain that differs from a legitimate address by one character. Others use display-name spoofing, where the visible sender name looks correct while the actual email address does not. These attempts can be caught by careful review and properly configured email authentication controls.
More dangerous incidents involve a legitimate account that has been compromised. When criminals access a real mailbox, they can reply within an existing thread, use prior invoices as templates, and study internal approval habits. A familiar address alone is no longer proof that a request is legitimate.
Credential Theft Opens the Door
Phishing remains a primary route to mailbox compromise. An employee receives a convincing message directing them to review a shared document, reauthenticate to an email portal, reset a password, or resolve a security issue. The linked page captures credentials and may also request a multifactor authentication code.
Password reuse increases the danger. A password exposed through an unrelated breach can become an entry point if it is also used for corporate email or a connected cloud service. Attackers also exploit weak recovery processes, legacy email protocols, poor session controls, and insufficiently protected administrator accounts.
Multifactor authentication is essential, but its quality matters. Text-message codes and push notifications are stronger than passwords alone, yet they can be vulnerable to social engineering, number porting, or repeated prompt attacks. Phishing-resistant methods and conditional access policies provide stronger protection, particularly for executives, finance teams, and administrators.
Weak Financial Verification Turns Deception Into Loss
A fraudulent email does not create a financial loss by itself. The loss occurs when an organization accepts the message as authorization.
Many businesses still rely on email as the final instruction for vendor banking changes, wire transfers, payroll updates, or requests for sensitive documents. That creates a single point of failure: one recipient, one inbox, and one decision made under time pressure. If the request appears to come from an executive or known vendor, an informal process can override caution.
The most effective control is a verification procedure that does not depend on the email itself. A payment change should be confirmed through a known phone number, secure vendor portal, or a separate trusted communication channel. The employee should not use a number contained in the suspicious email, even if it appears to belong to the supplier.
This adds a small amount of friction to routine work. That is the trade-off. For low-risk administrative requests, a streamlined process may be reasonable. For bank-detail changes, new payment recipients, payroll revisions, and high-value transfers, independent verification is a necessary control, not an inconvenience.
Gaps Between IT, Finance, and Leadership Create Exposure
BEC often succeeds in organizations where each team assumes another team owns the risk. IT may secure the email platform but have limited visibility into payment approval rules. Finance may have approval procedures but no established process for reporting suspicious requests. Leadership may expect urgent exceptions to be handled quickly without realizing that urgency is the attacker's preferred tool.
Clear accountability closes those gaps. IT and security teams need to monitor risky sign-ins, mailbox forwarding rules, unusual login locations, and unauthorized changes to email settings. Finance needs documented call-back and dual-approval procedures. Executives need to reinforce that no legitimate request is exempt from verification because of title, urgency, or confidentiality.
For regulated organizations, this coordination also supports audit readiness. A defensible process shows not only that controls exist, but that staff know when and how to use them.
Warning Signs That Need Immediate Attention
No single indicator proves fraud. A request may be legitimate and still arrive from an unfamiliar location or outside normal business hours. The risk rises when several signals appear together: a change to payment instructions, unexpected urgency, secrecy, a new recipient account, unusual wording, or resistance to a phone call.
Technical signs matter too. Unexpected inbox rules, external auto-forwarding, password reset notices that were not requested, repeated multifactor prompts, and login alerts from unfamiliar devices can indicate that an account is already under attack. Employees should know that reporting a suspicious message quickly is preferable to silently deleting it. Early reports can protect other recipients and preserve evidence.
Building a Layered Defense Against BEC
There is no single product that eliminates business email compromise. Effective protection combines secure identity controls, monitored email security, and transaction safeguards that remain effective even if a mailbox is compromised.
Start by enforcing strong, phishing-resistant multifactor authentication for high-risk users and administrative accounts. Disable outdated authentication methods, apply conditional access based on risk, and review account recovery paths. Protect domains with email authentication standards, and configure mail systems to detect impersonation, malicious links, and suspicious forwarding behavior.
Then test the business process. Ask whether a compromised executive mailbox could authorize a transfer, whether vendor payment details can change through email alone, and whether staff know the independent verification path. Tabletop exercises are useful because they reveal where policy and real-world pressure diverge.
Continuous monitoring is equally important. A 24/7 security operations function can identify unusual account behavior before it becomes a fraud event, while managed detection and response helps contain compromised identities, investigate mailbox activity, and support recovery. Aegisys approaches this as part of security-first IT management: identity, monitoring, response, and operational accountability must work together.
If You Suspect a Compromise
Treat a suspected BEC incident as urgent. Do not continue the conversation with the suspicious sender or assume a later reply is safe. Contact the vendor, executive, or employee through a trusted, previously verified channel. If funds have been sent, notify the financial institution immediately and preserve the email, headers, invoices, and payment records for investigation.
The affected email account should be secured promptly by resetting credentials, revoking active sessions, reviewing multifactor methods, and checking mailbox rules, delegated access, and forwarding settings. Security teams should also search for similar messages across the organization because BEC campaigns often target several people at once.
A well-designed verification process gives employees permission to pause. That pause protects money, confidential data, vendor relationships, and the confidence people place in your organization.
"Business email compromise works because it turns trust into a liability. The antidote isn't paranoia—it's a process that lets employees verify without feeling like they're questioning their boss. Build that process now, before the pressure starts." — Doc, Aegisys
From the Aegisys team
Stop attacks in minutes — not days.
SecureONE pairs EDR/XDR with a 24/7 SOC and automated response, built and run by Aegisys in Sudbury. SOC 2 Type II certified. Get a free security assessment and see where you're exposed.
Get your free security assessment