Austin Buonasera
 • 
July 16, 2025
 • 
7
 Minute read

Business Email Compromise: The Six-Figure Email That Doesn't Look Like an Attack

Business email compromise empties accounts without malware. It just takes a convincing email. Why AI made it worse, and the verification habits that actually stop it.

Quick Summary

  • Business email compromise (BEC) is fraud, not malware: a convincing email that reroutes a payment or a wire. The FBI logged $3.05 billion in reported BEC losses in 2025 alone.
  • It's common and rising — 74% of organizations faced a BEC attempt in 2025, up from 63% the year before.
  • AI removed the old giveaways. Phishing is now grammatically clean, personalized, and increasingly backed by deepfake voice and video.
  • The technology that stops it is ordinary; the habit that stops it is verification. Confirm every payment change by phone, on a number you already had.
  • Advanced email filtering, MFA, and domain authentication (DMARC/SPF/DKIM) raise the floor. Out-of-band verification is the wall.
Sunset over foggy mountains with dark silhouettes and a cloudy sky.

Most cyberattacks you picture involve malware — a virus, a locked screen, a breached firewall. Business email compromise involves none of that. It's a convincing email, sent to the right person at the right moment, asking them to move money or change where it goes. No malicious attachment. No exploit. Just a request that looks legitimate enough to act on.

That's what makes it so effective, and it isn't a fringe threat. The FBI's Internet Crime Complaint Center logged $3.05 billion in reported BEC losses in 2025 — one of the costliest categories of cybercrime it tracks, and that's only what victims reported. In the Association for Financial Professionals' 2026 survey, 74% of organizations said they faced a BEC attempt in 2025, up from 63% the year before.

How the scam works

BEC exploits trust and routine, not software flaws. The common plays:

  • Executive impersonation. An email that appears to come from the CEO or owner tells someone in finance to make an urgent wire transfer or buy gift cards. It leans on authority, urgency, and secrecy so the employee doesn't stop to verify.
  • Vendor and invoice fraud. A familiar supplier sends an invoice with new banking details — same name, same logo, different account. Sometimes the vendor's real account has been compromised, so it arrives from a genuinely trusted address.
  • Account compromise. An attacker gets into a real employee's inbox and uses it to request payments from colleagues, clients, and partners. Everything looks legitimate because it is legitimate — except the intent.
  • Attorney or closing impersonation. A fake lawyer or a compromised firm sends updated wire instructions before a closing or settlement, when large sums move on tight timelines.

The thread through all of them: someone is asked to send money or change payment details, and the request looks like it came from a person they trust.

AI removed the old warning signs

For years, the advice for spotting phishing was "look for the tells" — bad grammar, awkward phrasing, generic greetings. Generative AI erased those tells.

Attackers now produce email that's grammatically clean, written in the right tone, and personalized from public information — your website, LinkedIn, past posts, leaked data. A message can reference a real project, a real colleague, a real deal, and read exactly like the person it's pretending to be. The clumsy phishing email is going extinct.

It's moved past text, too. Deepfake audio and video can now mimic a familiar voice or face. A finance manager who'd hesitate at an emailed wire request may not hesitate when the "CEO" appears to confirm it on a call. And AI lets attackers run these plays at scale and follow up across channels — an email, then a LinkedIn message, then a call — each one reinforcing the last.

The uncomfortable takeaway: you can no longer trust that a message is real because it sounds real. Sounding real is exactly what the technology is good at now.

What actually stops it

Because BEC targets people and process rather than software, the defense is part technology and part habit — and the habit is the more important half.

Verification is the wall. The single most effective control costs nothing: confirm every payment — and every change of banking details — by phone, on a number you already had on file. Never the number in the email. Build it into your process so it's automatic, not awkward:

  • Require out-of-band, verbal confirmation for any new payee or changed banking instructions, no matter who the request appears to come from.
  • Require two approvers for wires above a set threshold.
  • Treat urgency and secrecy as red flags, not reasons to skip a step. Those are the pressure levers the scam depends on.

Technology raises the floor. The controls that make BEC harder to pull off:

  • Advanced email filtering that looks for impersonation and anomalies, not just spam and known-bad links.
  • DMARC, SPF, and DKIM so attackers can't easily spoof your own domain to your staff, clients, and vendors.
  • MFA on every account, so a stolen password doesn't hand over an inbox. Account compromise is how the most convincing BEC attacks start.
  • Least-privilege access, so a single compromised account can't reach everything.

Trained people close the gap. The staff who handle payments — finance, bookkeeping, executive assistants — are the ones attackers aim at. They should know the current playbook, including deepfakes, and know that questioning an odd request is expected, even when it appears to come from the boss.

Family offices and professional firms are especially exposed here, because they move large sums on trust and discretion — the exact conditions BEC is built to exploit. We wrote more about that in our piece on why family offices get hit.

This is the everyday work behind our managed cybersecurity service: the email defenses, the identity controls, and the verification habits that keep a convincing message from becoming a six-figure mistake.

Not sure your process would catch it? A few questions about email, payments, and access will show you where a BEC attempt could slip through. About three minutes.

Check your exposure · Book a consultation

Cards showing CPA firms scored 3/8 on client-data protection risks with notes on regulatory penalties and breaches.
3 minutes or less

Not sure what's exposed? Start here.

Answer a short set of questions about email, devices, vendors, backups, and access. No passwords, no system details — just the questions an attacker has already answered about you.
Get Your Risk Assessment