← All posts
GuideAugust 19, 2026 · 6 min read

Business Email Compromise: A Defense Playbook

BEC outearns almost every other cybercrime and carries no malware. A practical playbook: payment controls, mailbox tells, simulation, and recovery.

A fraudulent bank-detail change email flagged for out-of-band verification on a navy NOUSEC-branded background

Business email compromise is the quietest heavyweight in cybercrime. It makes no headlines-friendly noise — no ransom note, no leak site, no encrypted servers — yet the FBI counted $55.49 billion in exposed losses over a decade across 305,000+ incidents, and its 2025 Internet Crime Report again ranked BEC among the costliest categories, at more than $3 billion in reported losses in a single year. Microsoft's telemetry saw roughly 10.7 million BEC threats in the first quarter of 2026 alone.

The uncomfortable part for security teams: almost none of it is stopped by the email security stack. This playbook covers how the fraud actually runs, the cases worth studying, and the controls — process, mailbox, and human — that reliably break it.

Why the email stack keeps missing it

A BEC message is engineered to be technically boring. According to the APWG Phishing Activity Trends Report for Q1 2026, 72% of BEC attacks were launched from free webmail accounts — Gmail alone accounted for 53% — with clean sending reputations and no infrastructure to blocklist. There is typically no attachment and no link: the payload is a sentence asking someone to do their job slightly differently. The same report puts the average wire amount requested at $42,663 per attack, with gift cards (48%), wire transfers (19%), and payroll diversion (11%) as the leading cash-out methods.

That profile explains why BEC is a human-layer problem. The Verizon DBIR attributes 62% of breaches to the human element, and BEC is that statistic in its purest form: the "exploit" is authority, urgency, and a plausible business context. Filters can't patch that. Process can.

How the "ordinary" email gets made

The polish is manufactured upstream. Before anything lands in an inbox, the attacker has usually spent days on open-source intelligence: LinkedIn reveals who runs accounts payable and which executive is traveling; press releases reveal deals and vendor relationships; e-invoicing portals and leaked mailboxes reveal invoice formats, payment cadence, and the tone people use with each other. Pretexting does the rest — the request arrives with the right project name, the right amount, and the right amount of impatience.

In the account-takeover variants, the attacker is not imitating the thread at all — they are inside it, reading quietly through a phished supplier or colleague mailbox, waiting for a real payment to be due before swapping the account number. That is why "does this email look suspicious?" is the wrong question to train on. The email often is genuine, right up to the bank details. The defensive question is "does this request change where money goes?" — and that question is answerable by process every single time.

The four plays attackers run

Nearly every BEC incident is a variation of four pretexts — each covered in depth in our glossary, so briefly:

  • CEO fraud: an impersonated executive orders an urgent, confidential transfer, usually timed to travel, quarter-end, or a deal.
  • Invoice fraud: a real or convincing invoice arrives with "updated" bank details after an audit or a "change of banking partner."
  • Vendor email compromise: the invoice play run from inside a supplier's genuinely compromised mailbox, in a thread you were already having.
  • Payroll diversion and attorney impersonation: HR is asked to update an employee's direct deposit, or a fake lawyer creates urgency around a deal or settlement.

Increasingly, email is only the opening channel. When the target hesitates, attackers escalate to a phone call or a deepfake video meeting to "confirm" the request — which is how the engineering firm Arup lost $25.6 million across 15 transfers.

Three cases, one missing control

Case The play Loss The control that would have stopped it
Google and Facebook (2013–2015) Fake invoices impersonating real hardware vendor Quanta Computer $121M+ Vendor verification against the master file before paying new instructions
Toyota Boshoku (2019) Urgent bank-detail change on a legitimate payment ~$37M Mandatory out-of-band callback for banking changes, no urgency exceptions
Arup (2024) Deepfake video call impersonating the CFO to authorize transfers $25.6M Dual approval routed through a second, independent channel

Two of the world's most sophisticated technology companies paid nine figures to a man with a laptop, forged invoices, and a company registered under a real vendor's name. The lesson is not that employees are careless — it's that no individual judgment call should be the last line of defense for a wire transfer.

BEC is not an email problem with a finance impact. It is a payment-process problem that happens to arrive by email — and it is defeated in the process, not in the inbox.

The defense playbook

Build these six controls in order. The first two stop most of the loss; the rest shrink the attack surface and build the reflexes.

1. Make out-of-band verification non-negotiable

Any new payee, changed bank detail, or urgent transfer request gets verified by phone against a number from your vendor master file or HR system — never a number from the email signature or the invoice. Write it as policy with zero urgency exceptions: the more pressure a request carries, the more it needs the callback. This single control would have stopped every case in the table above.

2. Require dual approval above a threshold

Two people, two channels. One approver can be deceived — or deepfaked — far more easily than two independent ones. Set the threshold to what your business can tolerate losing, not to what is convenient, and make "the CEO said to skip it" a trigger for escalation rather than compliance.

3. Authenticate your domain, watch the lookalikes

Enforce SPF, DKIM, and a DMARC reject policy so attackers can't send as your exact domain, then monitor and defensively register close variants — the one-character-off domains used in invoice fraud. Display-name impersonation warnings ("this sender is external") close the gap authentication can't.

4. Harden and watch the mailboxes that matter

Account-takeover BEC starts with a phished mailbox, so the finance and executive mailboxes deserve phishing-resistant MFA and specific detections: new inbox rules that hide or forward mail, logins from new geographies, and OAuth grants to unknown apps. These are the tells of a compromised thread — the setup phase of vendor email compromise and account takeover — and they appear days before any money moves.

5. Train the roles, then rehearse them

BEC training is not generic phishing awareness — the skill is refusing plausible authority until verification is done, and it belongs to accounts payable, payroll, treasury, procurement, and executive support. Run BEC-style simulations against those teams with CEO-fraud, invoice, and payroll pretexts, and measure who reports, who verifies, and who complies. Those signals should feed each employee's and team's human risk score, so the people who move money get the most rehearsal.

6. Pre-build the money-recovery reflex

Recovery is a race: the FBI's Recovery Asset Team and its Financial Fraud Kill Chain can freeze fraudulent transfers, but effectiveness collapses after the first 24–72 hours. Put the bank fraud desk number, the IC3 filing step, and the mailbox-containment checklist into your social-engineering incident response plan — and rehearse the wire-fraud scenario in a tabletop before it happens for real.

What to measure

You can't audit your way to zero convincing emails, but you can measure the controls: percentage of bank-detail changes verified out-of-band (target: 100%), time-to-report in BEC simulations for finance roles, DMARC enforcement coverage, and the number of payment-process exceptions granted per quarter. If the exception count is rising, your urgency culture is doing the attacker's work for them.

BEC succeeds by being ordinary. The defense wins by making verification just as ordinary — a boring, automatic step that no title, no deadline, and no perfectly forged email thread can talk your team out of.

Frequently asked questions

Why do secure email gateways miss BEC attacks?

Because there is usually nothing technical to detect. Most BEC messages carry no malware and no malicious link — the payload is a plain-text request to do something that looks like routine business. APWG data shows 72% of BEC attacks in Q1 2026 were launched from free webmail accounts with clean reputations, most commonly Gmail. Filters tuned to payloads and bad domains see an ordinary email from an ordinary provider. The controls that work are process controls (out-of-band verification, dual approval) and people controls (role-specific training and simulation), not signature detection.

What is the difference between BEC and vendor email compromise (VEC)?

Classic BEC impersonates an internal authority — a CEO or CFO ordering an urgent, confidential transfer. Vendor email compromise hijacks or impersonates an external supplier, typically by replying inside a real invoice thread with 'updated' bank details. VEC is harder to spot because the sender, the amount, and the timing are all genuine; only the account number is wrong. Both are defeated by the same control: verify every new or changed payment instruction by phone, using a number from your vendor master file, not from the email.

What should we do if we already paid a fraudulent invoice?

Move within hours, not days. Call your bank's fraud department and request a recall or a SWIFT recall, then file a complaint with the FBI's IC3 so the Recovery Asset Team can trigger its Financial Fraud Kill Chain with partner banks — it freezes hundreds of millions of dollars a year, but almost exclusively for transfers reported within the first 24–72 hours. In parallel, treat it as an identity incident: check the mailboxes involved for hidden forwarding rules and revoke sessions, since the attacker who redirected one payment usually still has access.

Which employees should get BEC-specific training?

Anyone who can move money or change payment data: accounts payable, treasury, payroll, procurement, executive assistants, and the executives themselves. Generic phishing training helps less here because BEC rarely involves a link to hover over — the skill being trained is refusing authority and urgency until an out-of-band check is done. Role-based simulations of CEO fraud, invoice fraud, and payroll-diversion pretexts, with reporting speed measured per team, are the closest thing to a rehearsal the finance function can get before the real email arrives.

See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo