Skip to content

6 min read

American Corners

Business email compromise

The quiet, expensive scam

Business email compromise (BEC) is where the big money is lost. It is not a flashy attack with malware. It is a carefully written email about a payment, sent to the person who can make that payment, at a moment when it looks completely normal.

The goal is simple: get real money sent to the attacker's account instead of the right one. Because the request fits the everyday flow of business, it often sails past people who would spot a clumsy phishing email in a second.

How it works

A typical BEC unfolds patiently. The attacker gains access to, or convincingly imitates, an email account, often a supplier's or a senior manager's. Sometimes they sit quietly inside a real mailbox for weeks, reading how the business talks to its partners: the tone, the names, the timing of invoices.

Then, at the right moment, they send a message that fits right in:

  • an invoice from a familiar supplier, with new bank details "because we have changed banks"
  • an urgent note from the boss asking finance to make a wire transfer before end of day
  • a request to update the account where an employee's salary is paid

Nothing about the email looks broken. The language is right, the amount is plausible, and the story explains itself. That is exactly what makes it dangerous.

A worked example

A finance officer receives an email that appears to be from a regular supplier. The invoice is for a normal amount, the format matches previous ones, and the only difference is a line noting that the supplier's bank account has changed, so please pay the new one.

  • The setup: the attacker has watched this supplier relationship and copied its style.
  • The hook: a change of bank details, wrapped in an ordinary invoice.
  • The loss: if the officer pays, the money goes to the attacker, and it is usually gone for good.

The weak point is not the officer's intelligence. It is that there was no step forcing anyone to confirm the change before the money moved.

The one habit that stops it

BEC targets a gap in your process, so the fix is a step in your process. Treat any change to payment details, a new bank account, a different beneficiary, an unusual urgent transfer, as something to confirm before you act, every time, no exceptions.

Verify the change through a separate, trusted channel: phone the supplier or the manager on a number you already have on file, not one printed in the suspicious email. A one minute call is nothing against the amount at risk.

Tip

Make "we always call to confirm a change of bank details" a written rule, not a personal favour. A rule protects the junior employee who would otherwise feel awkward questioning a message that looks like it came from the boss.

Check yourself

Social engineering & account safety

Where this lesson comes from

Built from

  • Workshop 6: Social Engineering and the Human Factor (V3.0): business email compromise, invoice fraud

alphaPlan courses are built from taught programmes rather than invented for the web. Where a claim rests on an outside standard or a reported case, it is named above so you can check it rather than take our word for it.

shënim: ky material u krijua në kuadër të projektit 'U.S. Cybersecurity Leadership in AI for Albania', financuar nga departamenti i shtetit i shteteve të bashkuara. mendimet, gjetjet dhe përfundimet e paraqitura këtu janë të autorit(ëve) dhe nuk pasqyrojnë domosdoshmërisht ato të departamentit të shtetit të shteteve të bashkuara.

Disclaimer: This material was created on behalf of the 'U.S. Cybersecurity Leadership in AI for Albania' project, funded by the United States Department of State. The opinions, findings, and conclusions stated herein are those of the author(s) and do not necessarily reflect those of the United States Department of State.

Disclaimer

Found something unclear, outdated or improvable? Suggest an improvement