Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogThreat Watch

Business Email Compromise: How Small Businesses Get Hit

Suspicious email with altered payment instructions

Short answer: business email compromise (BEC) is patient fraud, not smash-and-grab hacking. An attacker gets into (or convincingly imitates) a real mailbox, watches how your company moves money, then slips altered payment instructions into a genuine conversation. In the FBI's Internet Crime Complaint Center (IC3) annual reports, business email compromise consistently ranks among the most financially damaging cybercrimes — and the defenses are specific.

How a business email compromise actually runs

  1. Entry. A phished password or a stolen session cookie opens a mailbox — often a bookkeeper's, owner's, or vendor's.
  2. Surveillance. The attacker reads quietly for weeks: who approves payments, which vendors invoice when, how people sign their emails.
  3. The move. At the believable moment — a real invoice cycle, a real closing — payment details change. Same thread, same tone, new account number. Often a lookalike domain (one letter off) keeps the conversation going even after the real mailbox is secured.
  4. The vanish. Funds move again within hours. Recovery windows are short.

Why filters alone don't catch it

The email isn't malware — it's a normal message from (or imitating) a trusted correspondent. Nothing explodes. That's why BEC defense is layered across identity, mail security, and process.

The controls that stop business email compromise

  • MFA everywhere, with modern phishing-resistant methods for finance roles — most entries start with a stolen password.
  • Mail rules audits. Attackers add auto-forward and delete rules to hide replies; reviewing them catches quiet compromises.
  • External-sender and lookalike-domain flagging, so "sarah@yourvend0r.com" gets a visible warning.
  • The out-of-band rule. Any change to payment instructions is verified by phone at a known number. No exceptions — including for the CEO in a hurry, which is exactly what attackers imitate. AI-generated voices raise the bar here too: see voice-cloning fraud.
  • Monitoring sign-ins for impossible travel and new-device patterns, so surveillance gets caught before the move.

If it happens

Minutes matter: call your bank's fraud line to attempt a recall, preserve the emails, reset and re-secure the mailbox, and report to the FBI's IC3. Then fix the entry point — a BEC that succeeded once will be tried again.

Frequently asked questions

What is business email compromise?

Business email compromise (BEC) is patient fraud, not smash-and-grab hacking: an attacker gets into (or convincingly imitates) a real mailbox, watches how your company moves money, then slips altered payment instructions into a genuine conversation — same thread, same tone, new account number. Funds then move again within hours, so recovery windows are short.

How do attackers get into a business mailbox?

Usually with a phished password or a stolen session cookie — often a bookkeeper's, owner's, or vendor's. The attacker then reads quietly for weeks, learning who approves payments and which vendors invoice when, and adds hidden auto-forward and delete rules so replies stay out of sight.

What stops business email compromise?

MFA everywhere, regular mail-rule audits, external-sender and lookalike-domain flagging, sign-in monitoring, and an out-of-band rule: any change to payment instructions is verified by phone at a known number, no exceptions — including for the CEO in a hurry, which is exactly what attackers imitate.

Email security tuned for exactly these patterns is part of our cybersecurity service — or test your current exposure with the free 7-question assessment.

Sources and further reading

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.