Business Email Compromise: How It Works | Catalyst IT

Business Email Compromise: How It Actually Works

The single most common way small and medium businesses lose real money to cybercrime — and the reason it works as well as it does.

Business Email Compromise — BEC — is responsible for more financial losses in the SMB sector than ransomware, hacking, and identity theft combined. It is also one of the least technically sophisticated attacks in the modern threat landscape. The attackers don’t break in through clever exploits. They walk in through your inbox.

Understanding how BEC works is the single highest-leverage thing an SMB owner can do to protect their business from cybercrime. The defense is partly technical and largely cultural.

This is what BEC actually looks like in the wild, why it works, and how to stop it.

BUSINESS EMAIL COMPROMISE

  • The Anatomy of a BEC Attack
  • The Three Most Common Variants
  • Why It Works So Well
  • The Wire Fraud Variant
  • Technical Defenses That Actually Help
  • The Cultural Defense (And Why It Matters More)

The Anatomy of a BEC Attack

The pattern is consistent across thousands of incidents:

  1. An attacker gains access to a mailbox — usually through phishing, a leaked password, or by impersonating a trusted contact
  2. They observe quietly for days or weeks, learning the business, the vendors, the ongoing projects, the people
  3. At a moment of maximum plausibility, they send a message that asks for money to be moved — a wire transfer, an updated banking detail for a vendor, an urgent payment
  4. The recipient acts on the message because everything about it looks right
  5. The money is gone by the time anyone realizes what happened

The attack is fundamentally about access and timing, not technical skill. The attacker is patient. The recipient is busy. The window of opportunity is real.

The Three Most Common Variants

BEC takes a few standard forms:

  • CEO Fraud: an email appearing to come from the owner or CEO, asking an employee — typically in finance — to urgently process a wire transfer
  • Vendor Impersonation: a message that looks like it’s from a known vendor, asking for an updated banking detail before the next invoice payment
  • Account Takeover: an attacker who has actually compromised a real mailbox uses it to send messages to that account’s contacts, requesting payment or information

The vendor impersonation variant is currently the most expensive on average. The amounts are larger because they’re tied to real ongoing business, and they look legitimate because they reference real invoices.

Why It Works So Well

Three reasons:

  • The messages are well-researched. The attacker has had time inside the mailbox to know what looks normal
  • The timing is plausible. The request arrives during real ongoing business
  • The financial impact is structured to bypass scrutiny. The amounts are large but not absurd. The urgency is real but not panicked. The whole interaction feels routine

This is not a Nigerian prince email. These messages would pass a casual review by an experienced employee. The defenses that work are the ones that don’t depend on casual review.

The Wire Fraud Variant

The most common BEC outcome is fraudulent wire transfer. The pattern: an attacker either spoofs or compromises an executive’s email, sends a message to finance asking for an urgent wire transfer, and the wire is sent before anyone can confirm it.

Banks don’t reverse fraudulent wires the way they reverse fraudulent credit card transactions. The money is usually unrecoverable within days. Some businesses survive a BEC wire fraud incident. Others don’t.

Technical Defenses That Actually Help

A layered technical defense reduces BEC risk substantially:

  • MFA on every account — eliminates most account takeover attacks
  • Email security with impersonation protection — flags messages that look like they’re from a known person but aren’t
  • Mailbox forwarding rule monitoring — a common attacker move is to set up auto-forwarding to harvest information
  • DMARC, SPF, and DKIM properly configured — blocks domain spoofing
  • Detection of unusual sign-in locations — flags compromised accounts faster
  • External email banner tags — visually distinguishes outside messages from internal ones
  • A properly configured Microsoft 365 tenant with Defender enabled and tuned

None of these is a complete defense. Together, they catch most attempts before they reach a human.

The Cultural Defense (And Why It Matters More)

The most reliable defense against BEC is not technology. It is a culture where any unusual financial instruction triggers an out-of-band verification — a phone call, a face-to-face confirmation — before action is taken.

Specifically:

  • Any change to vendor banking details is verified by phone using a known phone number, not the contact info in the email
  • Any wire transfer request is confirmed in person or by phone before execution
  • Any urgent financial request is treated with more skepticism, not less
  • Employees are trained to feel comfortable saying “let me call to confirm” without fear of seeming difficult

This culture is harder to build than to buy a piece of software. It is also the single most protective control available, and it sits inside a broader security posture that no individual product replaces.

If your business handles vendor payments, wire transfers, or executive financial instructions over email — and most do — assume BEC will be attempted against you. The right time to put defenses in place is before it happens.

Scroll to Top