Chykalophia Docs
Security

Business email compromise explained

What business email compromise (BEC) is, how it works, and the steps every small business can take to prevent it.

Difficulty
Intermediate

Business email compromise — often shortened to BEC — is a scam aimed squarely at the moment money changes hands. The FBI describes it as a sophisticated scam that targets businesses and individuals making a transfer of funds, and says it is frequently carried out by compromising a legitimate business email account through social engineering or a computer intrusion.

Unlike many scams, BEC doesn't rely on technical hacking. It relies on impersonation and trust.

Quick summary

Business email compromise is when an attacker impersonates someone you trust — your CEO, a supplier, a lawyer — to trick you or your team into sending money or handing over credentials. The best defenses are: verify any unusual financial request by phone (using a number you already have), turn on two-factor authentication on all email accounts, and set a clear policy that payment details are never changed based on an email alone.

How BEC works

BEC attacks usually follow one of a few patterns:

The boss impersonation

An email appears to be from your CEO or owner — using either their real account (if it has been compromised) or a spoofed address that looks almost right.

The message asks for something urgent: a wire transfer, purchasing gift cards, or sharing login credentials. It says to keep the matter confidential and to act quickly.

The urgency and secrecy are deliberate — they are designed to bypass your normal caution.

The supplier payment redirect

An attacker monitors a supplier's email (often by compromising their account) and watches for an upcoming payment. At the right moment, they send an email — from the supplier's real address, or a convincing fake — saying the bank account details have changed.

The business pays the invoice to the new account — and the money is gone.

The lawyer/accountant impersonation

Before a business transaction (acquisition, real estate deal, legal settlement), attackers intercept or fake communications from a lawyer or financial professional, redirecting funds at the critical moment.

Why BEC is so effective

It does not use malware or technical exploits. The tools are simply email and social engineering.

  • The emails often come from real, compromised accounts, so spam filters have little to flag
  • Attackers research the business before striking: they know names, relationships, and pending deals
  • The requests are designed to match things that actually happen in the business
  • Urgency and authority ("the CEO needs this now") are proven ways to override careful judgment

Prevention measures

Turn on two-factor authentication for all email accounts. The most common way attackers send BEC emails from a real account is by breaking into that account. 2FA makes this much harder. See How to set up two-factor authentication.

Establish a verbal verification policy for financial requests. Any request to transfer money, change bank details, or take financial action that comes via email must be confirmed by phone call — using a number already in your records, not one from the email.

Set a policy: payment details are never changed by email alone. This single rule stops the supplier payment redirect cold.

Train your team to recognize the patterns. Share examples. Make it safe for anyone to pause and say "this feels off — let me verify."

Enable email authentication records (SPF, DKIM, DMARC) on your domain. This makes it harder for attackers to spoof emails that appear to come from your own domain. Ask your email provider or ask us to set these up. See Email DNS records.

What to do if it has already happened

If you believe you or a team member has been targeted:

If money was transferred, contact the bank that sent the money immediately, explain it was fraud, and ask them to recall or reverse the transfer. The FBI also advises asking for a Hold Harmless Letter or Letter of Indemnity. Speed matters: the FBI's guidance is to make that call as soon as the fraud is recognized.

If credentials were shared, change passwords on every affected account right now. Enable 2FA if it wasn't on.

If the attack came through a real email account, that account may be compromised. Change its password, review recent sent messages, and check for any email-forwarding rules that shouldn't be there.

Report the fraud to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov (US) or your country's equivalent authority.

Notify affected parties — your bank, any suppliers involved, your business insurance if applicable.

Act within hours, not days

Wire fraud is extremely time-sensitive. The sooner your bank is notified, the better the chance of recovering funds. Do not wait to gather information — call your bank first.

Checking for email rules planted by attackers

If an attacker had access to an email account, they sometimes set up forwarding rules to keep receiving your emails even after you change the password. Check for these:

  • In Gmail: click Settings at the top right, then See all settings. Check the Filters and Blocked Addresses tab, then the Forwarding and POP/IMAP tab (labeled just Forwarding on some accounts).
  • In Outlook: Settings → Mail → Rules
  • Also check whether anyone has been granted delegated access to the mailbox

Delete any rules you didn't create. Revoke any delegated access you don't recognize.

Common questions

How do I know if my email account was compromised?

Check your sent folder for emails you didn't send. Look for email rules you didn't create. Review recent login activity (most email services show this in security settings). If you see anything unusual, change your password immediately.

Can DMARC/SPF prevent all spoofing?

DMARC and SPF make it much harder for attackers to send emails that appear to come from your domain. However, they don't prevent attackers from registering a lookalike domain (like yourcompany-billing.com) or from using a compromised real account. They are a valuable layer but not a complete solution.

Our supplier sent the payment change from their real email. How do I know it's legitimate?

You don't — which is why the policy of calling to verify is so important. Suppliers' email accounts get compromised too. If bank details change, always call using a phone number from your existing records, not a number in the email.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Learn more

Last updated

On this page