Skip to content
Digital Security Consulting

How to Spot Business Email Compromise Before You Wire the Money

The most expensive email scams contain no malware and no suspicious link. They arrive inside a real conversation, from a real address. Here's how to recognise them — and the procedural control that works when recognition fails.

Published 3 min read

The FBI’s Internet Crime Complaint Center consistently reports business email compromise as one of the costliest forms of cybercrime — more costly than ransomware in many years. It’s also one of the least technical. There’s usually no malware, no attachment, and no suspicious link for software to catch.

How it actually works

  1. An attacker gets into one mailbox. Usually through a reused password on an account without multi-factor authentication.
  2. They read. Quietly, sometimes for weeks. They learn who pays whom, how invoices are worded, when payments are due, and how people sign off.
  3. They set up concealment. A mailbox rule that hides replies from the real supplier, so the conversation can’t be corrected.
  4. They strike at the right moment. A reply inside a real thread: “Please note our banking details have changed — updated form attached.”

Frequently, the compromised mailbox isn’t yours at all. It’s your supplier’s. You receive a genuine email from a genuine account, and there’s nothing in the headers to find.

Warning signs

None of these is conclusive on its own, which is exactly why the procedural control matters more than any checklist:

  • A change of banking details, especially close to a payment date
  • Urgency or secrecy — “needs to go out today,” “please keep this between us”
  • A request from an executive to bypass the normal approval process
  • Subtle domain differences — rn for m, an extra letter, a different top-level domain
  • Replies that arrive faster or slower than that person normally responds
  • A PDF form for “updated details” that was never part of your process before

The control that actually works

Train people to spot the signs, but don’t rely on it. Attackers are good, and a busy accounts-payable clerk at month-end is not going to catch a flawless reply in a real thread.

Instead, make it procedural:

Banking details never change on the strength of an email. Any change is confirmed by phone, on a number you already held before the request arrived.

That single rule defeats the majority of invoice fraud, and it costs nothing.

The technical layer

The procedure stops the payment. These make you a harder target in the first place:

  • Multi-factor authentication on every mailbox — not only the executives’
  • SPF, DKIM and DMARC, so impersonating your domain becomes harder and attempts become visible
  • Alerts on new forwarding and inbox rules, the attacker’s favourite hiding place

We walk through a real version of this in we almost wired money to a fraudster. The broader work sits in our cybersecurity practice.

Frequently asked questions

What is business email compromise?

An attacker gains access to a real mailbox — yours or a supplier's — reads the correspondence, and then sends a convincing request at the right moment, usually to change banking details or authorise an urgent payment. Because the email comes from a legitimate account, technical filters rarely flag it.

What is the single best defence?

A rule that banking details are never changed on the strength of an email. Any change is confirmed by phone, using a number you already had on file before the request arrived — never one supplied in the message. This one procedural control defeats most invoice fraud and costs nothing.

We sent a payment and think it was fraud. What now?

Call your bank immediately and ask them to attempt a recall, then report it to police. Speed matters: the chance of recovery drops sharply after the first day or two as funds move on. Then have the mailboxes involved examined to find out how the attacker got in.

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.