Business Email Compromise (BEC) is one of the most financially damaging forms of online fraud affecting businesses, organizations, homebuyers, vendors, and individuals who transfer money.
A BEC scam may begin with an email that appears to come from a company executive, vendor, attorney, title company, employee, or trusted business partner.
The message then attempts to change payment instructions, redirect a wire transfer, alter payroll information, obtain sensitive records, or convince someone to send money.
The email may come from a lookalike address — or from a real email account that criminals have already compromised.
Quick Verdict
Business Email Compromise caused more than $3 billion in reported losses during 2025 alone, according to the FBI Internet Crime Complaint Center. Never approve a new bank account, wire instruction, direct-deposit change, gift-card purchase, or unusual payment request based solely on email.
Business Email Compromise scams impersonate executives, vendors, attorneys, or trusted partners to redirect payments or steal sensitive information. Verify every unexpected payment or banking change through a separate trusted channel.
What Is Business Email Compromise?
BEC stands for Business Email Compromise.
The FBI describes BEC as a sophisticated scam targeting businesses and individuals involved in transferring funds.
Criminals may use:
- Compromised legitimate email accounts
- Lookalike email domains
- Spoofed sender information
- Social engineering
- Spear phishing
- Stolen passwords
- Malware or other computer intrusions
The ultimate objective is often to make a fraudulent payment request appear to be part of an ordinary business conversation.
How Much Money Is Lost to BEC Scams?
The scale of Business Email Compromise is substantial.
According to the FBI Internet Crime Complaint Center's 2025 Annual Report:
- 24,768 BEC complaints were reported in 2025.
- $3,046,598,558 in reported losses were attributed to BEC.
- BEC ranked second among cyber-enabled fraud categories by reported dollar loss, behind investment fraud.
Those figures represent incidents reported to IC3 and therefore should not be interpreted as the total amount of BEC fraud occurring worldwide.
How a BEC Scam Works
A typical attack may develop gradually.
- The criminal researches a company, employee, executive, vendor, customer, attorney, or transaction.
- The attacker compromises an email account or creates an address designed to resemble a legitimate one.
- The criminal watches or imitates normal business communication.
- An email requests a payment, wire transfer, account change, direct-deposit update, or sensitive document.
- The request is timed to appear routine or urgent.
- The employee sends money or information to the criminal.
- The fraud may not be discovered until the real vendor, employee, or customer reports that payment never arrived.
A BEC Email May Come From a Real Account
This is one of the most important things to understand about Business Email Compromise.
A fraudulent message does not always come from an obviously fake email address.
Criminals may first obtain access to a legitimate employee or vendor mailbox.
Once inside, they may be able to:
- Read existing conversations
- Identify upcoming invoices or transactions
- Learn how employees communicate
- Wait for a large payment
- Create email-forwarding rules
- Reply from the genuine email account
- Delete or hide messages
- Substitute fraudulent payment instructions
That means checking the sender address alone is not enough.
Common Types of Business Email Compromise
Vendor Bank-Account Change
A company receives what appears to be a legitimate email from a regular supplier.
The message says:
- The vendor changed banks.
- The previous account is closed.
- A new account should be used for future payments.
- An outstanding invoice should be redirected immediately.
The bank information actually belongs to the criminal.
CEO or Executive Impersonation
An employee in accounting or finance receives an urgent message supposedly from the CEO, owner, CFO, or another executive.
The request may involve:
- An urgent wire transfer
- A confidential acquisition
- A vendor payment
- Gift cards
- A supposedly sensitive legal matter
The message may specifically instruct the employee not to discuss the payment with anyone else.
Invoice Manipulation
A criminal gains access to an existing conversation between a business and a customer.
Shortly before payment is due, the criminal sends revised wiring instructions.
Because the message appears inside a genuine conversation and may include the real invoice amount, company names, and transaction details, it can be extremely convincing.
Payroll and Direct-Deposit Fraud
A scammer impersonates an employee and asks payroll or human resources to change the bank account used for direct deposit.
The employee's next paycheck is then redirected to an account controlled by the criminal.
Changes to payroll banking information should therefore be verified independently rather than relying solely on email.
W-2 and Employee Data Theft
An attacker impersonating an executive may ask human resources to send employee tax forms, payroll records, or other sensitive information.
The information can then be used for identity theft, tax fraud, or additional targeted scams.
Real Estate Wire Fraud
BEC also affects individuals.
A homebuyer may receive what appears to be an email from a real estate agent, attorney, lender, or title company shortly before closing.
The email provides new wiring instructions for the down payment or closing funds.
The money instead goes to a criminal-controlled account.
The FBI includes this scenario among its examples of Business Email Compromise.
Business Email Compromise vs. Phishing
BEC and phishing overlap, but they are not always identical.
A traditional phishing campaign may send the same fake login or malicious link to thousands of people.
BEC is often more targeted.
The criminal may know:
- Who authorizes payments
- Who processes invoices
- Which vendors the company uses
- When a transaction is scheduled
- The names of executives
- How employees normally communicate
Phishing may also be the first step in a BEC attack if it allows criminals to obtain access to a real email account.
Common BEC Warning Signs
A Vendor Suddenly Changes Banking Information
Any request to change where money is sent should receive independent verification.
Call a known contact using a telephone number already on file rather than a number supplied in the email requesting the change.
The Request Is Urgent
Criminals often try to prevent careful review by creating a deadline.
Examples include:
- "This must be paid today."
- "I am in a meeting — please handle this immediately."
- "The transaction is confidential."
- "Do not call me."
The Sender Wants Secrecy
An instruction to bypass normal procedures or keep a transaction secret is a major warning sign.
The Email Address Is Slightly Different
Lookalike domains may change only one character.
For example:
- company.com → cornpany.com
- company.com → company-payments.com
- vendor.com → vend0r.com
Display names are easy to imitate.
The Writing Looks Perfect
Do not assume an email is genuine merely because it contains no spelling or grammar mistakes.
BEC messages may be professionally written and, when a legitimate mailbox is compromised, may closely match the tone of previous conversations.
The Payment Process Changes
Be cautious when an email suddenly introduces:
- A new bank
- A new account number
- A new routing number
- A different country
- A different payment method
- An unexpected intermediary
The Most Important BEC Prevention Rule
Do not reply to the email asking whether the new bank account is correct. If the email account itself is compromised, you may simply be asking the criminal to confirm the criminal's own instructions.
Instead, call a previously verified telephone number or speak with the vendor, employee, customer, or executive directly.
The FBI specifically recommends using a secondary channel to verify changes in account information. :contentReference[oaicite:1]{index=1}
Require Two-Person Approval for Important Payments
Businesses can reduce risk by requiring another employee to independently review high-value or unusual payments.
Consider requiring additional verification for:
- New vendors
- Bank-account changes
- Large wire transfers
- International payments
- Urgent executive requests
- Payroll changes
- Payments outside normal procedures
The purpose is not simply to have a second person click "approve."
The second reviewer should independently confirm that the transaction and payment destination are legitimate.
Use Multi-Factor Authentication
Businesses should enable multi-factor authentication on:
- Accounting systems
- Payroll
- Banking platforms
- Cloud storage
- Administrative accounts
MFA can make account takeover harder even if a password is stolen.
It does not eliminate BEC risk, because criminals can also use spoofed domains, compromised third parties, and social engineering.
Use SPF, DKIM and DMARC
Companies using their own email domain should also consider email-authentication protections.
The Federal Trade Commission recommends three technologies:
- SPF — identifies servers authorized to send mail for a domain.
- DKIM — adds a digital signature that helps recipients verify messages sent from the domain.
- DMARC — helps receiving systems evaluate whether the visible sender aligns with authenticated information and allows the domain owner to specify how suspicious messages should be handled.
These controls can make direct domain spoofing more difficult. They do not stop criminals who have actually taken over a legitimate mailbox, so payment verification procedures are still necessary.
Train Accounting, Payroll and Executive Staff
BEC defenses should not be limited to the IT department.
The people most likely to receive fraudulent requests often work in:
- Accounts payable
- Accounting
- Payroll
- Human resources
- Executive support
- Treasury
- Purchasing
- Real estate and closing operations
Employees should know that questioning an unusual payment request is expected — even when the email appears to come from the CEO.
What to Do If Your Company Sent Money to a BEC Scammer
Act immediately.
The FBI advises victims to contact the originating financial institution as soon as the fraud is discovered. :contentReference[oaicite:2]{index=2}
- Contact your bank immediately.
- Tell the bank that the transfer resulted from Business Email Compromise or wire fraud.
- Request a recall or reversal.
- Ask the bank about contacting the receiving financial institution.
- Ask whether a Hold Harmless Letter or Letter of Indemnity is appropriate.
- File a detailed complaint at IC3.gov.
- Include the sending and receiving bank information in the IC3 report.
- Preserve the original emails and message headers.
- Preserve invoices, wiring instructions, telephone numbers, bank information, and transaction records.
- Notify your IT or security team.
- Secure any compromised email account.
Do not wait until an internal investigation is complete before contacting the financial institution.
Why Speed Matters After a Fraudulent Wire
The FBI's Internet Crime Complaint Center operates a Recovery Asset Team that works with financial institutions and FBI field offices to attempt to freeze fraud proceeds.
The 2025 IC3 report describes a case involving a BEC attack on a real estate transaction in which more than $1.3 million was wired using fraudulent instructions and the Recovery Asset Team moved quickly to freeze funds. :contentReference[oaicite:3]{index=3}
Recovery is never guaranteed.
But fast reporting can be the difference between funds remaining in a recipient account and being moved through additional accounts or overseas.
What If an Email Account Was Compromised?
If attackers gained access to a real mailbox:
- Change the password from a trusted device.
- Enable or reset multi-factor authentication.
- End unfamiliar sessions.
- Review recovery email addresses and phone numbers.
- Inspect email-forwarding rules.
- Inspect inbox rules that delete, archive, or hide messages.
- Review delegated mailbox access.
- Check recent login activity.
- Notify relevant customers or vendors if attackers may have impersonated your company.
- Investigate whether other business accounts were accessed.
Do not assume changing the password alone removes every persistence method the attacker may have created.
What If Your Vendor's Email Was Compromised?
Your own company's email can be completely secure and you can still become a BEC victim.
A criminal may compromise:
- A supplier
- A customer
- An attorney
- An accountant
- A title company
- A real estate agent
- A payroll provider
This is another reason payment verification must happen outside the email conversation itself.
Small Businesses Are Also Targets
BEC is not only a large-company problem.
Small businesses may be attractive targets because a single employee may have authority to receive invoices, approve transactions, and send payments.
The FTC specifically advises small businesses to protect their domains from impersonation, train staff, use email authentication, and verify suspicious requests independently.
A fraudulent payment that a large corporation might absorb could create a serious cash-flow problem for a small company. :contentReference[oaicite:4]{index=4}
Business Email Compromise Checklist
Before sending money based on an email request, ask:
- Is this payment expected?
- Has the bank account changed?
- Have I verified the change using an old, trusted phone number?
- Is the sender pressuring me to act quickly?
- Does the transaction bypass our normal process?
- Am I being told to keep it confidential?
- Has another employee independently reviewed it?
- Does the email domain exactly match the legitimate domain?
- Does the amount or destination differ from previous payments?
If something has changed, stop and verify before sending the funds.
Official BEC and Cybersecurity Resources
- FBI IC3 Business Email Compromise Guidance
- FBI Business Email Compromise Warning
- FBI Internet Crime Complaint Center
- FTC Cybersecurity for Small Business
Related Think It's a Scam Warnings
- Jones Day Scam or Legit? Law Firm Impersonation Warning
- Meta Verified Message Scam: Fake Business Account Warning
- Geek Squad Renewal Scam: Fake Invoice & Subscription Email
Frequently Asked Questions
What does BEC mean?
BEC stands for Business Email Compromise. It generally refers to targeted fraud in which criminals impersonate or compromise trusted business contacts to redirect money or obtain valuable information.
How common is Business Email Compromise?
The FBI IC3 received 24,768 BEC complaints during 2025 involving more than $3.046 billion in reported losses.
Does a BEC email always come from a fake address?
No. Some attacks use lookalike or spoofed addresses, while others involve criminals gaining access to a legitimate employee, vendor, attorney, or business email account.
What is vendor-payment fraud?
A criminal impersonates or compromises a supplier and provides fraudulent bank information so that a legitimate invoice payment is redirected to the scammer.
What is CEO fraud?
CEO fraud is a BEC variation in which a criminal impersonates an executive and instructs an employee to send money, buy gift cards, provide sensitive information, or bypass normal procedures.
Can BEC affect homebuyers?
Yes. Criminals may impersonate attorneys, real estate professionals, lenders, or title companies and send fraudulent wiring instructions shortly before a closing.
Should I reply to an email to verify new banking information?
No. If the mailbox is compromised, the criminal can simply reply and confirm the fraudulent instructions. Contact the person or business using previously verified information through a separate channel.
What should I do if I already sent the wire?
Contact the originating financial institution immediately, request a recall or reversal, and file a detailed BEC complaint at IC3.gov. The FBI stresses that rapid action may help reduce or prevent financial loss.
Do SPF, DKIM and DMARC stop all BEC attacks?
No. They can reduce certain forms of domain spoofing but cannot prevent every BEC attack, particularly when criminals compromise a legitimate mailbox.
Have You Encountered a BEC Scam?
If your business encountered a Business Email Compromise attempt, share the non-sensitive details below.
- Was an executive, employee, vendor, attorney, or customer impersonated?
- Was the email account actually compromised or was a lookalike domain used?
- Did the request involve changed banking instructions?
- Was a wire transfer or payroll payment redirected?
- How was the fraud discovered?
- Did the bank successfully stop or recover any funds?
- What control would have prevented the payment?
Please do not post employee names, private email addresses, account numbers, routing numbers, wire details, passwords, security codes, confidential company information, or other sensitive information in the comments.
Page researched and reviewed: September 18, 2026.
Disclaimer
ThinkItsAScam.com is an independent consumer-information website. This article provides general information about Business Email Compromise, phishing, impersonation, and wire fraud and is not legal, financial, banking, or cybersecurity advice.
Individual fraud incidents vary. Businesses that experience an active compromise or substantial financial loss should promptly contact their financial institution and consider obtaining assistance from qualified legal, cybersecurity, accounting, insurance, and law-enforcement professionals as appropriate.
No comments:
Post a Comment