What Is Business Email Compromise? A Small Business Guide

Business email compromise (BEC) is defined as a targeted cyberattack where criminals impersonate trusted contacts via email to steal money or sensitive data. The FBI reported over $2.9 billion in verified U.S. losses from BEC in 2024 alone, making it one of the costliest cybercrimes tracked by federal law enforcement. That figure represents confirmed losses only. Actual totals run higher. Unlike mass phishing campaigns, BEC attacks exploit human trust rather than software vulnerabilities, which makes them far harder to detect and stop with standard security tools. Understanding how they work is the first step toward protecting your business.
What is business email compromise and how does it work?
BEC attacks follow a deliberate, research-driven process. Attackers begin with reconnaissance, studying a company's website, LinkedIn profiles, and public filings to map out the organizational hierarchy, vendor relationships, and payment workflows. They learn who approves invoices, who handles payroll, and who reports to whom. That knowledge lets them craft emails that feel completely routine.
Once they understand the target, attackers use one of three impersonation methods:
- Email account compromise: The attacker gains access to a real employee or executive account, often through a phishing attack or stolen credentials, and sends fraudulent requests from the legitimate address.
- Domain spoofing: The attacker forges the "From" field to display a trusted name while the actual sending address is unrelated.
- Lookalike domains: The attacker registers a domain nearly identical to the target company's, such as "acme-corp.com" instead of "acmecorp.com," and sends email from it.
The three most common BEC scenarios are CEO fraud, vendor invoice fraud, and payroll diversion. In CEO fraud, an employee in accounting receives an urgent wire transfer request appearing to come from the company's owner or president. In vendor invoice fraud, a supplier's email is compromised or spoofed, and the attacker sends a revised invoice with new banking details. In payroll diversion, an attacker impersonates an employee and asks HR to update direct deposit information before the next pay cycle.
Attackers impersonate executives and vendors to send urgent wire transfer or payment change requests, exploiting the routine nature of business communication. The emails often contain no malicious links and no attachments, which means traditional spam filters have little to flag.

Pro Tip: Always check the actual sending email address, not just the display name. Attackers rely on recipients reading only the name shown in bold, not the address behind it.
Why small businesses are prime BEC targets
Nearly 41% of BEC attacks specifically target small and mid-sized businesses. That concentration is not accidental. Smaller organizations are chosen precisely because their controls are weaker, not because attackers stumble upon them randomly.
"Most small businesses underestimate their BEC risk. Attackers deliberately pick smaller companies for their weak controls, knowing that a single employee often handles both approving and processing payments with no second set of eyes on the transaction."
Small businesses' overlapping roles and lack of multi-signer approvals make fraudulent payment requests far easier to push through. A dental practice or law firm where the office manager both receives invoices and initiates wire transfers has no internal checkpoint to catch a fraudulent request. That single-person control setup is exactly what attackers look for.
Security training is another gap. Large enterprises run regular phishing simulations and BEC awareness programs. Most small businesses do not. Employees who have never seen a BEC attempt have no frame of reference for recognizing one. The result is that a well-crafted impersonation email lands in an inbox and gets acted on without hesitation.

The common misconception that small businesses are "too small to target" is one of the most dangerous beliefs in cybersecurity. You can read more about why small businesses face outsized IT risk and why size offers no protection from determined attackers.
How does BEC differ from standard phishing?
BEC and phishing are related but meaningfully different. Standard phishing casts a wide net, sending identical malicious emails to thousands of recipients and hoping a percentage click a link or download a file. BEC is surgical. Each attack is researched and personalized for a specific target, and the goal is financial transfer or data theft rather than malware installation.
| Feature | BEC attack | Standard phishing |
|---|---|---|
| Target | Specific individual or company | Mass audience |
| Content | Personalized, text-only request | Generic with malicious link or file |
| Malware used | No | Often yes |
| Detection difficulty | High | Moderate |
| Primary goal | Wire transfer or data theft | Credential theft or malware delivery |
BEC emails typically lack malicious links or malware, which allows them to evade traditional spam filters and secure email gateways. That evasion is not a flaw in the technology. It is a deliberate feature of the attack design. When there is nothing technically suspicious to scan, the filter passes the email through. The defense must then come from the person reading it.
Multi-factor authentication (MFA) helps prevent unauthorized account access, but it cannot stop attacks that use lookalike domains or spoofed addresses. The attacker never needs to log in to your account to impersonate you. That limitation is why technical controls alone are insufficient against BEC.
What are the signs of email compromise to watch for?
Recognizing a BEC attempt before acting on it is the most reliable way to avoid loss. The warning signs fall into two categories: behavioral red flags in the email itself, and technical anomalies in your email account.
Behavioral red flags:
- Urgent requests that pressure you to act immediately and bypass normal approval steps
- Payment instructions that differ from previously established banking details
- Requests to keep a transaction confidential from other team members
- Emails from known contacts asking for something outside their normal scope
- Pressure tactics combined with appeals to authority ("The CEO needs this done before close of business")
- Subtle grammar inconsistencies or slightly off phrasing that does not match the sender's usual style
Technical account anomalies:
- Mailbox rule changes, logins from unusual locations, and unexpected payment instruction changes are documented warning signs of account compromise.
- Microsoft 365 and Google Workspace both provide alert features for anomalous sign-ins and mailbox rule modifications. Enabling those alerts costs nothing and adds a meaningful detection layer.
If you receive an email requesting a payment change or wire transfer, treat it as suspicious by default. That posture is not paranoia. It is the correct baseline given how these attacks operate.
How can you prevent BEC attacks?
Prevention does not require expensive technology. The most effective BEC defenses are procedural, and most cost nothing to implement. The following steps apply directly to small businesses and individuals managing business finances.
-
Mandate dual authorization for payments. No single employee should be able to initiate and approve a wire transfer. Require a second person to confirm any payment above a defined threshold, even if the request appears to come from an executive.
-
Require out-of-band verification for payment changes. Calling a trusted phone number to confirm any request altering payment details is the single most effective defense against BEC. Use a number already on file, never one provided in the suspicious email itself.
-
Implement SPF, DKIM, and DMARC. These email authentication protocols prevent attackers from spoofing your domain. Most business email platforms support native implementation. Your IT provider or email administrator can configure them in under an hour.
-
Train employees on BEC red flags. Awareness is not a one-time event. Run brief, regular sessions that show real examples of BEC emails. Employees who have seen the pattern recognize it faster under pressure.
-
Enable account monitoring alerts. Turn on sign-in alerts and mailbox rule notifications in Microsoft 365 or Google Workspace. Unusual activity often precedes a BEC attempt by days or weeks as attackers study email threads before striking.
-
Audit your email security posture. Review common IT mistakes small businesses make that leave email accounts exposed, including weak passwords, no MFA, and unmonitored forwarding rules.
Pro Tip: A two-minute phone call defeats nearly all BEC attacks. Attackers can fake an email address, but they cannot fake a voice on a number you already have saved.
Email is the vector for over 90% of cyberattacks on small businesses. That statistic means your email inbox is the single highest-risk entry point in your organization. Treating every payment request as requiring verification is not excessive caution. It is proportionate to the actual threat level.
Key Takeaways
Business email compromise causes billions in annual losses because it targets human trust, not software, making procedural controls more effective than technology alone.
| Point | Details |
|---|---|
| BEC targets people, not systems | Attackers exploit trust and routine, so technical filters alone cannot stop them. |
| Small businesses are primary targets | Nearly 41% of BEC attacks hit small and mid-sized businesses with weak approval controls. |
| Out-of-band verification works | A phone call to a known number stops nearly all BEC attempts before money moves. |
| SPF, DKIM, and DMARC reduce spoofing | These free email authentication protocols prevent attackers from impersonating your domain. |
| Recovery is rarely possible | Wire transfers are largely irreversible, making prevention the only reliable strategy. |
The uncomfortable truth about BEC that most guides skip
I have worked with small business owners who assumed a cyberattack would look like something from a movie: flashing alerts, obvious malware, a clear moment of crisis. BEC looks nothing like that. It looks like a normal Tuesday morning email from your boss asking you to wire $18,000 to a new vendor account before noon.
The part that concerns me most is the recovery problem. Financial loss from BEC is extremely difficult to recover because international wire transfers frequently fall outside domestic enforcement reach. By the time a business realizes the transfer was fraudulent, the funds are gone. I have seen businesses spend months working with their bank and the FBI only to recover nothing.
The good news is that the most effective defenses are free. A mandatory call-back policy for any payment change costs zero dollars and stops the attack cold. The challenge is not budget. It is discipline. Businesses that implement the habit and enforce it consistently are the ones that avoid loss. Those that treat it as optional until something goes wrong are the ones that end up in the FBI's annual report.
My honest recommendation: build the verification habit before you need it. Review your current cybersecurity threat exposure and treat email payment requests the same way you would treat a stranger handing you a check. Verify first, always.
— Nicholas
How Greatplainsnetworking helps small businesses stay protected
Small businesses in Norman, Moore, and Oklahoma City face the same BEC threats as large enterprises, but without dedicated IT staff to catch them.

Greatplainsnetworking provides managed IT support and cybersecurity services built specifically for small businesses, including proactive email monitoring, SPF/DKIM/DMARC configuration, employee security training, and verification protocol setup. The team monitors for unusual account activity around the clock and responds the same day when something looks wrong. If you want to know where your email security stands right now, Greatplainsnetworking offers a straightforward assessment with no long-term contract required. Explore dedicated cybersecurity protection tailored to businesses your size.
FAQ
What is business email compromise in simple terms?
Business email compromise is a scam where an attacker impersonates a trusted contact via email to trick an employee into sending money or sharing sensitive data. No malware is involved. The attack relies entirely on deception.
How do BEC attacks differ from phishing?
Standard phishing sends mass emails with malicious links or files. BEC is personalized, text-only, and targets specific individuals with researched, believable requests. BEC emails frequently bypass spam filters because they contain nothing technically suspicious.
Can small businesses recover money lost to BEC?
Recovery is rarely successful. Wire transfers are largely irreversible, and funds moved internationally fall outside domestic enforcement reach. Prevention through verification protocols is the only reliable protection.
What is the fastest way to stop a BEC attack?
Call the requester directly using a phone number already on file, not one provided in the email. That single step defeats nearly all BEC attempts because attackers cannot impersonate a voice on a verified number.
What email settings reduce BEC risk?
Enabling SPF, DKIM, and DMARC on your email domain prevents attackers from spoofing your address. Turning on sign-in alerts and mailbox rule notifications in Microsoft 365 or Google Workspace adds early detection for account compromise.
Recommended
Want help putting this into practice?
We'll audit your security, speed, and hardware in under an hour — no commitment, no sales pitch. Just a clear roadmap of what to fix and why.