How to Prevent Business Email Compromise Attacks

A finance manager receives an email that appears to come from the managing director. It is brief, urgent and entirely plausible: a supplier’s bank details have changed, payment must be released before close of business, and discretion is required. One rushed transfer can send tens of thousands of pounds to a criminal account. To prevent business email compromise, organisations must treat email as a high-risk business system, not simply a communications tool.

Business email compromise, often shortened to BEC, is a targeted fraud technique. Attackers impersonate a senior employee, supplier, solicitor or trusted colleague to manipulate someone into transferring money, disclosing sensitive data or changing payroll details. Unlike broad phishing campaigns, BEC attacks are usually researched, carefully timed and written to fit the victim’s role.

For small businesses, the consequences can be severe. Cash flow is disrupted, customer and supplier relationships are damaged, and the incident may expose wider weaknesses in identity security. If an attacker has accessed a genuine mailbox, they may also use it to search contracts, invoices, contact lists and passwords reset emails. That creates an intrusion with consequences far beyond a single fraudulent payment.

Why business email compromise defeats ordinary caution

Many people expect a cyber attack to look suspicious: poor spelling, strange attachments or an unfamiliar sender. BEC rarely depends on those obvious warning signs. Criminals may register lookalike domains, such as replacing a letter in a supplier’s address, or compromise a real account and send messages from it.

They also exploit normal business pressure. Finance teams are expected to pay invoices promptly. Directors often send short messages between meetings. Suppliers do change bank accounts. An attacker’s goal is not to defeat every control at once. It is to create enough urgency that a sensible person skips the one verification step that would stop the fraud.

This is why awareness training matters but cannot carry the whole defence. Staff need to recognise warning signs, but the organisation also needs technical controls, approval processes and active monitoring that assume a convincing message may reach an inbox.

Prevent business email compromise with layered controls

The strongest approach combines identity protection, email security and payment verification. Each layer covers a different failure point. If a malicious email is delivered, account protections and business processes should still make it difficult for an attacker to succeed.

Protect the accounts attackers want most

Email accounts belonging to directors, finance staff, payroll administrators and anyone who can approve payments deserve particular attention. These are high-value identities. A compromised account in one of these roles gives criminals credibility and access to sensitive conversations.

Multi-factor authentication should be enforced for business email, cloud storage, finance systems and remote access. However, not all multi-factor authentication provides equal protection. Text-message codes can be intercepted through SIM-swap fraud, while push notifications can be abused through repeated approval requests. Authenticator applications, number matching and hardware security keys generally provide stronger resistance to credential theft.

Use unique, long passwords stored in a reputable password manager. Remove former employees promptly, review administrator privileges, and avoid shared mailboxes with shared passwords. Where a shared finance address is necessary, give each user an individual account with appropriate permissions and auditing.

Conditional access controls can also reduce risk. These can flag or block sign-ins from unusual locations, unfamiliar devices or impossible travel patterns. The right settings depend on how your team works. A business with staff travelling regularly needs a different policy from one operating solely from a North Devon office, but unexplained access attempts should always be investigated.

Secure the email environment, not just the inbox

Email authentication controls help receiving systems identify whether a message genuinely came from the claimed domain. SPF, DKIM and DMARC are central to this work. Configuring Google Workspace properly, will reduce direct spoofing of your organisation’s domain and provide reporting that can reveal unauthorised senders.

They do not stop every BEC attempt. A fraudster can still use a lookalike domain or a compromised supplier mailbox. Yet domain authentication is a worthwhile control because it removes one common route for impersonation and helps protect your own customers from fraudulent messages using your name.

Your email security service should scan for malicious links, dangerous attachments, spoofed senders and suspicious rules. It should also identify unusual mailbox activity, such as a new forwarding rule, deleted messages, repeated failed sign-ins or a sudden change in where a user logs in from. Attackers commonly create inbox rules to hide replies from the legitimate user while they continue the conversation with a supplier or customer.

Logging is essential. Without sign-in, mailbox and message-trace records, incident responders may struggle to establish how an attacker entered, what they accessed and which contacts were targeted. Retain logs for long enough to investigate incidents discovered weeks later.

Make payment changes difficult to fake

A verified payment process is one of the most effective BEC controls. No email alone should be enough to change supplier bank details, amend payroll information or authorise an unusual transfer.

Create a documented procedure that requires independent verification using a trusted telephone number already held in your records. Do not use the number in the email requesting the change. For higher-value payments, use dual approval and a short delay where practical. The person requesting or entering a payment should not be the only person able to approve it.

Be clear about what counts as unusual. It may be a new beneficiary, altered bank details, a request to split payments, a last-minute change to an invoice, or a director asking a junior employee to bypass normal procedure. The exact thresholds should suit your business, but ambiguity is dangerous. Staff need authority to pause a payment without fearing that they are obstructing work.

This can feel slower than a purely email-based process. That is the trade-off. A two-minute verification call is considerably less disruptive than tracing stolen funds, notifying affected parties and managing the reputational fallout of a fraud incident.

Train for decisions, not just phishing tests

Effective training uses examples that match real work. Finance staff should practise handling changed bank details. Reception and customer service teams should understand how personal data requests can be used for impersonation. Directors need to know that their status makes their accounts and writing style attractive targets.

Teach staff to pause when a message combines urgency, secrecy and a financial request. They should inspect the full sender address, not just the display name, and independently verify unexpected requests through a second channel. They should also know exactly where to report a suspicious email.

Phishing simulations can be useful if they are followed by constructive feedback. The objective is not to catch people out. It is to build reporting habits and reveal where processes are unclear. A staff member who reports a suspected message quickly may give the security team the time needed to block a wider campaign.

What to do when a BEC attempt is suspected

Speed matters, particularly when money has been transferred. Preserve the email and avoid deleting evidence. Report the incident immediately to the person responsible for security, finance and incident response. If payment has been made, contact your bank using a known number and ask for its fraud team without delay. Banks may be able to begin recall action, but the opportunity narrows quickly.

If a mailbox may be compromised, such as stolen credentials, reset them, revoke active sessions, review multi-factor authentication methods and check for malicious inbox rules, forwarding settings and delegated access. Investigate recent sign-ins, sent messages and changes to cloud files. The affected account may be only the visible part of a wider intrusion.

Notify relevant suppliers, customers or colleagues if the attacker could have used the account to target them. Clear, factual communication helps prevent secondary fraud. Where personal data may have been exposed, assess reporting obligations and preserve forensic evidence before making broad changes that could obscure the attacker’s activity.

Build a process people will actually follow

The best BEC controls are the ones staff can use under pressure. Keep payment verification procedures short, give employees a trusted escalation route and rehearse the response before an incident occurs. Review supplier details regularly, test account recovery processes and investigate unusual email activity before it becomes a confirmed breach.

Criminals rely on a moment of uncertainty and a request that feels too urgent to question. Give your people permission, process and support to stop, verify and report – and that moment becomes one of your strongest defences.