No malware. No suspicious attachments. Just a convincing email from someone pretending to be your boss or your vendor — and a wire transfer that's already gone.
When most business owners think about cybercrime, they think about ransomware locking up their files, or hackers breaking into their network. Those are real threats — and we've written about them. But there's another kind of attack that quietly causes more financial damage than almost anything else, and most small business owners have never heard of it.
It's called Business Email Compromise, or BEC. The FBI's Internet Crime Complaint Center reports that BEC has cost U.S. businesses over $2.7 billion in a single year — more than ransomware, more than phishing, more than any other category of cybercrime. And unlike most attacks, it doesn't require any malware, any hacking, or any technical sophistication at all.
All it requires is a convincing email and an employee who's in a hurry.
Here's how it works, why it's so devastatingly effective, and — most importantly — the specific things you can do right now to protect your business from it.
BEC is not phishing in the traditional sense. A phishing email is a broad attack — someone sends out a million emails hoping a few people click a bad link. BEC is the opposite: it's targeted, personalized, and researched. The attacker studies your business before they strike.
The playbook usually goes something like this. An attacker spends time on LinkedIn, your company website, social media, and public records. They learn who your CEO is, who handles accounts payable, who your major vendors are, and how your business communicates. Then they craft an email that looks completely legitimate — right name, right title, right tone — and they wait for the right moment to send it.
The goal is almost always the same: money. Specifically, getting someone at your company to wire funds somewhere, change payment details on a vendor account, or send gift card codes (yes, really — gift cards are common in smaller BEC attacks because they're fast and irreversible).
What makes this different from a typical scam is the effort. These aren't random criminals spraying emails at the internet. They're patient, organized, and they know your business well enough to be convincing. Some BEC groups spend weeks studying a target before sending a single email.
This is the classic version. Your bookkeeper or office manager gets an email that appears to be from you — or from whoever is in charge — asking them to wire money urgently. The email might say something like: "I'm in a meeting and can't talk. I need you to send $14,500 to this account right away to close a deal. Don't mention this to anyone yet — I'll explain when I'm out. Handle ASAP."
The sense of urgency, the request for secrecy, and the authority of the sender all work together to shut down the employee's skepticism. They want to help. They want to do their job well. So they wire the money.
The email might come from a domain that looks almost right — "yourcompany-ceo@gmail.com" or "openexperts.tech" with an extra character. Or, in more sophisticated attacks, the attacker actually compromises a real email account and sends from the real address.
In this version, the attacker pretends to be one of your regular vendors or suppliers. They send an email that looks like a routine invoice or payment update: "We've updated our banking details. Please use the new account information for all future payments."
If your team processes this as a normal vendor communication, they start sending payments to the attacker's account instead of your real vendor. This can go undetected for months — until you get a call from your actual vendor asking why they haven't been paid.
This is the most sophisticated version. The attacker doesn't impersonate anyone — they actually compromise a real email account, either yours or a vendor's, and lurk inside the inbox for weeks. They read emails, learn communication patterns, identify ongoing deals, and wait for the right moment to intercept a legitimate transaction and redirect funds.
When a real invoice is sent, they jump in and "correct" the payment details. Because the email comes from a real account and references a real deal you're both familiar with, nobody suspects a thing.
Here's the hard truth: BEC victims aren't foolish. They're normal, competent people who were put in a situation designed to exploit very human instincts — the desire to be helpful, to respond quickly to authority, and to avoid making their boss wait.
Attackers use several psychological levers deliberately:
Authority. The request comes from the CEO, the owner, or a senior manager. Most employees aren't in the habit of questioning direct requests from leadership — especially urgent ones.
Urgency. The email always creates time pressure. "Handle ASAP." "This needs to clear today." "I'm heading into a meeting." Urgency is a way of bypassing careful thinking. When you're rushing, you don't stop to verify.
Secrecy. "Don't mention this to anyone yet" is a red flag in hindsight, but in the moment it sounds like normal business confidentiality around a deal or acquisition. It also prevents the employee from doing exactly what would catch the fraud: checking with someone else.
Familiarity. Because the attacker has done their research, the email sounds right. The name is right, the title is right, the tone matches how that person usually writes. There's nothing obviously wrong with it.
We've seen this hit businesses where the owners thought it couldn't happen to them. A law firm. A construction company. A medical practice. A real estate office. The common thread isn't the industry — it's that they had a process for wiring money and didn't have a verification step built into that process.
Training your team to recognize BEC attempts doesn't require a security degree. It just requires knowing what to look for. Here are the warning signs that should trigger a stop-and-verify response every time:
The most important thing you can do is make it culturally safe for employees to pause and verify — even if it means making their boss wait an extra ten minutes. If your team is afraid to slow down a "CEO request," the attackers are counting on that.
The good news about BEC is that it's very preventable. You don't need expensive technology. You need the right processes — and a team that knows to follow them.
This is the single most effective control you can put in place. Any request to wire money or change payment details must be verified by calling the requester at a known number — not a number provided in the email. Pick up the phone and call your CEO directly. Call your vendor at the number you already have in your system. If the request is legitimate, they'll confirm it. If it's fraud, you just stopped it cold.
This one step stops the vast majority of BEC attempts. Attackers depend on the request being processed without verification. Force them to have a phone conversation with the real person, and the attack collapses.
Many BEC attacks start with a compromised email account. If an attacker gets your credentials — through a phishing email, a data breach, or a password leak — they can log in and impersonate you from inside your real inbox. Multi-factor authentication stops this cold. Even with the right password, they can't get in without access to your phone.
We've covered MFA in detail in a separate post — if you haven't turned it on for Microsoft 365 yet, that's the most important thing you can do today. And check out our guide on Microsoft 365 security settings for the full picture of what to lock down.
SPF, DKIM, and DMARC are email authentication protocols that make it much harder for attackers to spoof your domain. Without these in place, someone can send an email that appears to come from your domain — even if it didn't. Setting these up is a technical task, but it's quick work for any IT provider and makes a real difference in how many spoofed emails make it through to your staff and your clients.
Your email administrator should be able to confirm whether these are configured. If they don't know what SPF, DKIM, and DMARC are, that's worth knowing too.
Document exactly what your process is for wire transfers, vendor payment changes, and anything involving moving money. Who can authorize it? What verification is required? What's the dollar threshold that requires a second approver? Put this in writing, train your team on it, and stick to it — even when the CEO sends an "urgent" email asking to skip the process.
The policy has to include the rule that the policy itself cannot be bypassed by email alone. That's the whole point.
You don't need an elaborate training program. You need to sit down with the people who handle your finances and walk through what BEC looks like. Show them a real example. Walk through the red flags. Make it clear that pausing to verify is not just allowed — it's required. And that no legitimate authority figure will ever be upset that someone took five minutes to call and confirm a wire transfer request.
If you're interested in understanding how your team responds to social engineering in practice, security training and simulations can be eye-opening. We wrote about what we learned from running phishing simulations with real small businesses — the results are instructive. And for more on how social engineering works in general, check out our post on what a modern security threat actually looks like.
If you suspect you've been the victim of a BEC attack, time is everything. Wire transfers can sometimes be reversed if you act fast enough — but the window is usually measured in hours, not days.
Step one: call your bank immediately. Tell them you believe you're a victim of wire fraud and you need to attempt a recall. Ask them to contact the receiving bank and initiate a reversal. This doesn't always work, but it sometimes does — especially if the funds haven't moved to a third account yet.
Step two: file a report with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. The FBI has a special team that works BEC cases and has, in some cases, been able to help recover funds through coordination with financial institutions.
Step three: preserve everything. Don't delete emails. Don't try to clean things up. Save the original fraudulent emails, any correspondence, and a timeline of what happened. You'll need this for the bank, law enforcement, and your cyber insurance claim if you have one.
Step four: figure out how it happened. Was an email account actually compromised? If so, change all passwords and force sign-outs on all sessions immediately. Enable MFA if it wasn't on. Then audit what the attacker may have seen while they were in the account.
We've written a step-by-step playbook for what to do after a security incident that covers the broader response process if you need a complete guide. And if you don't yet have cyber insurance, a BEC incident is a good reminder of why it exists.
Most of the threats we write about are things that could happen to your business. BEC is one of the things that almost certainly will be attempted, if it hasn't already. The FBI's data consistently puts it at the top of cybercrime categories by financial loss — and unlike ransomware, there's no getting the money back once the criminals have it.
The encouraging part is that it's also one of the more preventable threats. You don't need a big security budget. You need a phone-verification policy for financial requests, MFA on your email accounts, and a team that knows what the attack looks like before it arrives in their inbox.
That's it. Those three things will stop the overwhelming majority of BEC attempts against your business. The attackers will move on to an easier target.
If you're not sure whether your current setup has these controls in place — or if you want help training your team on what to watch for — that's exactly the kind of thing we do. No sales pitch, just a straight conversation about where you stand.