Business Email Compromise: The Costliest Attack Nobody Talks About
Business email compromise uses no malware, just a convincing message about a changed bank account. Here is the finance-team playbook that stops it.
When people picture a cyberattack, they picture malware: a locked screen, a ransom note, a scramble to restore backups. Business email compromise looks nothing like that. There is no virus to catch and no alarm to trip. There is only a believable email about a changed bank account, and a well-meaning employee who does exactly what the message asks.
That quiet simplicity is why it works. Business email compromise consistently ranks among the costliest categories of cybercrime in the FBI Internet Crime Complaint Center reporting, and it targets the ordinary payment routines that keep a business running.
Why this attack beats your antivirus
Security tools are built to spot malicious code and suspicious files. Business email compromise carries neither. The attacker either steals a real mailbox login or spoofs a familiar sender, then sends a plain message that asks finance to update a vendor's payment details or wire funds for an urgent deal.
Because the request travels over normal email and often references real projects, real people, and real invoices, it slides past filters and straight to a human being. The vulnerability is the process, not the computer.
The anatomy of a convincing request
These messages are effective because they respect how your team already works. They arrive at plausible moments, use the right names, and apply just enough pressure to discourage a second look.
- A supplier you actually use writes to say their banking details have changed, right before a scheduled payment.
- An executive appears to ask for a wire transfer while traveling, and stresses that it is time-sensitive and confidential.
- A new invoice matches an ongoing project but points to an account no one has verified.
- The reply-to address is slightly off, or a mailbox rule quietly hides the attacker's messages from the real owner.
Out-of-band verification is the core control
The single most effective defense costs nothing and requires no software. Any change to payment details, and any unexpected transfer request, must be confirmed through a separate channel before money moves. If the request came by email, verify it by phone using a number you already have on file, never a number supplied in the message itself.
This one habit breaks the entire attack, because the criminal controls the email thread but not your independent contact records. Make it a firm rule, not a judgment call, so no one has to decide in the moment whether a message feels trustworthy.
Build the change into finance workflows
Verification only holds up when it is part of the routine rather than a personal favor. Give your finance team a short, unambiguous playbook and the authority to slow a payment down.
- Require dual approval for new payees and for any change to existing bank details.
- Confirm every payment-detail change by calling a known contact, then log who verified it and when.
- Audit mailbox rules regularly to catch hidden or auto-forwarding rules an attacker may have planted.
- Set a threshold above which wire transfers need a second, documented sign-off.
Make reporting safe and blame-free
The most damaging outcome is not the initial email. It is an employee who suspects a mistake and stays silent out of embarrassment. Every hour of delay makes funds harder to recover. Tell your team plainly that reporting a possible incident quickly is always the right move, even if it turns out to be nothing, and that no one will be punished for pausing a payment to check.
A culture that rewards the pause is worth more than any filter, because it turns every person who touches money into part of the defense.
Where to start this quarter
You do not need new technology to close most of this exposure. Write a one-page payment-change policy, require out-of-band verification and dual approval, review mailbox rules for anything unexpected, and walk your finance team through a realistic example so the process feels familiar before it is ever tested.
Business email compromise thrives on speed, trust, and silence. Take away the speed with verification, protect the trust with dual approval, and replace the silence with fast, blameless reporting. If you want help designing the workflow, a managed services partner can help you sequence this work.