
Short answer: business email compromise (BEC) is patient fraud, not smash-and-grab hacking. An attacker gets into (or convincingly imitates) a real mailbox, watches how your company moves money, then slips altered payment instructions into a genuine conversation. In the FBI's Internet Crime Complaint Center (IC3) annual reports, business email compromise consistently ranks among the most financially damaging cybercrimes — and the defenses are specific.
How a business email compromise actually runs
- Entry. A phished password or a stolen session cookie opens a mailbox — often a bookkeeper's, owner's, or vendor's.
- Surveillance. The attacker reads quietly for weeks: who approves payments, which vendors invoice when, how people sign their emails.
- The move. At the believable moment — a real invoice cycle, a real closing — payment details change. Same thread, same tone, new account number. Often a lookalike domain (one letter off) keeps the conversation going even after the real mailbox is secured.
- The vanish. Funds move again within hours. Recovery windows are short.
Why filters alone don't catch it
The email isn't malware — it's a normal message from (or imitating) a trusted correspondent. Nothing explodes. That's why BEC defense is layered across identity, mail security, and process.
The controls that stop business email compromise
- MFA everywhere, with modern phishing-resistant methods for finance roles — most entries start with a stolen password.
- Mail rules audits. Attackers add auto-forward and delete rules to hide replies; reviewing them catches quiet compromises.
- External-sender and lookalike-domain flagging, so "sarah@yourvend0r.com" gets a visible warning.
- The out-of-band rule. Any change to payment instructions is verified by phone at a known number. No exceptions — including for the CEO in a hurry, which is exactly what attackers imitate. AI-generated voices raise the bar here too: see voice-cloning fraud.
- Monitoring sign-ins for impossible travel and new-device patterns, so surveillance gets caught before the move.
If it happens
Minutes matter: call your bank's fraud line to attempt a recall, preserve the emails, reset and re-secure the mailbox, and report to the FBI's IC3. Then fix the entry point — a BEC that succeeded once will be tried again.
Frequently asked questions
What is business email compromise?
Business email compromise (BEC) is patient fraud, not smash-and-grab hacking: an attacker gets into (or convincingly imitates) a real mailbox, watches how your company moves money, then slips altered payment instructions into a genuine conversation — same thread, same tone, new account number. Funds then move again within hours, so recovery windows are short.
How do attackers get into a business mailbox?
Usually with a phished password or a stolen session cookie — often a bookkeeper's, owner's, or vendor's. The attacker then reads quietly for weeks, learning who approves payments and which vendors invoice when, and adds hidden auto-forward and delete rules so replies stay out of sight.
What stops business email compromise?
MFA everywhere, regular mail-rule audits, external-sender and lookalike-domain flagging, sign-in monitoring, and an out-of-band rule: any change to payment instructions is verified by phone at a known number, no exceptions — including for the CEO in a hurry, which is exactly what attackers imitate.
Email security tuned for exactly these patterns is part of our cybersecurity service — or test your current exposure with the free 7-question assessment.
Sources and further reading
- FBI Internet Crime Complaint Center (IC3) — where these crimes are reported and tracked nationally.
Turn insight into action.
Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.



