HD Tech - SecurITy Delivered
Back to Blog
Managed IT

Business Email Compromise: What It Is and How to Stop It

By Tom Hermstad · HD Tech

Business Email Compromise: What It Is and How to Stop It

What is business email compromise, and how does it work?

Business email compromise (BEC) is a targeted scam where criminals impersonate a trusted person — your CEO, a known vendor, or outside counsel — to trick an employee into wiring money or handing over sensitive data. It's not a technical hack. It's a con. According to the FBI's Internet Crime Complaint Center (IC3), BEC generated over $3 billion in losses across 24,768 complaints in the latest reporting period — the second-highest cybercrime category by dollar loss in the U.S.


BEC Is Not a Hack. It's a Con.

Here's what makes business email compromise different from most cyber threats: there's no malware. No virus. No suspicious link that your antivirus flags.

It's a carefully crafted lie, delivered by email, designed to exploit the way your business already operates.

The attacker doesn't need to break into your network. They just need one employee to believe the email is real — and act on it before anyone asks questions.

That's the con. And it works.

The U.S. Secret Service describes BEC as one of the most common cybercrimes affecting businesses and individuals in the United States and is explicit: it's not a matter of if you're targeted. It's when.

That phrase should sound familiar. It's the same thing I tell every business owner I sit down with. It's not if, it's when.

Here's the part that too few owners recognize: the businesses that weather BEC attempts without losses aren't just lucky. They have the right systems, the right training, and the right partner watching their back — doing real work in the background every single day. When that Thursday afternoon email arrives with "updated wiring instructions," the question isn't just whether your employee recognizes the red flag. It's whether your managed IT partner has already built the technical net that catches it before it lands. Managed IT done right isn't a cost center — it's the competitive edge that keeps you off the casualty list.


How a BEC Attack Actually Works

Every BEC attack follows roughly the same playbook. Here's what it looks like from the attacker's side.

Step 1 — Reconnaissance

Before they send a single email, attackers do their homework. They study your company website, LinkedIn profiles, press releases, and court filings. They learn who your CFO is. Who your vendors are. What deals are in motion. In some cases, they've already read months of your emails — because they quietly compromised a mailbox weeks earlier.

Step 2 — Spear phishing or account takeover

They either register a look-alike domain (think curtisandburnight-law.com instead of curtisandburnight.com) or they send a targeted phishing email to steal real credentials and log directly into an actual inbox.

Step 3 — Impersonation

Now they either spoof the sender's identity or — in the more dangerous version — they are the sender. They've read the real email thread. They know the context. They jump in and redirect the conversation.

Step 4 — The urgent request

An AP clerk gets an email from "the CFO": "Change the bank account on this vendor payment — needs to go out today." A paralegal gets a message from "the title company": "Updated wiring instructions for the closing tomorrow." Urgency is the weapon. It short-circuits your normal approval process.

Step 5 — Money moves and disappears

Once the wire hits the attacker-controlled account, funds are rapidly forwarded through multiple banks — often out of the country — within minutes or hours. Recovery becomes extremely difficult.


The 5 Most Common BEC Attack Types

1. CEO Fraud

An employee receives an email that looks like it's from the owner or CEO — often sent while the executive is traveling. The message asks for an urgent wire transfer to close a deal or handle a confidential matter. The email address is slightly off, but close enough that no one checks.

For Orange County manufacturing companies, this one hits accounts payable hard. The amounts are typically large enough to matter and small enough not to trigger automatic review.

2. Vendor Impersonation

An attacker monitors your vendor relationships, then steps in at just the right moment — typically when a legitimate invoice is in the pipeline — with "updated payment instructions." Your AP team pays the attacker instead of your real vendor.

This is the BEC variant that hits law firms and title companies the hardest. Real estate closings involve large wire transfers, tight timelines, and multiple parties communicating by email. That's a perfect environment for this attack.

3. Payroll Redirect

HR receives an email, seemingly from an employee, asking to update their direct deposit information before the next payroll run. A few days later, that employee's paycheck lands in an attacker's account.

This one is particularly common at smaller firms — exactly the size range where HR is handling everything manually and there's rarely a formal change-verification process.

4. Attorney Impersonation

This variant targets businesses mid-deal. An attacker poses as outside counsel — your M&A attorney, your escrow attorney, a compliance advisor — and requests that funds be wired immediately for a time-sensitive legal matter. The implied authority of "the lawyers need this now" creates pressure that bypasses common sense.

For CPA firms and their clients, this attack often surfaces during tax season or at the close of an acquisition. Our cybersecurity guidance for accounting firms covers this scenario in detail.

5. Data Theft Request

Not every BEC attack asks for money. Some ask for W-2s, employee records, or customer data. An attacker posing as your CEO emails HR or finance requesting "a list of all employee SSNs for a benefits audit." That data then fuels identity theft or future attacks.


I've been doing this for many years. I've seen every version of these attacks hit businesses that thought they were prepared. It's not if, it's when. The question isn't whether someone will try this on your business. The question is whether you'll be ready when they do.

Here's the timing piece that most business owners miss: BEC attempts spike during high-dollar, high-pressure moments — year-end payment cycles when your AP team is pushing invoices, or mid-deal closings when everyone's focused on getting across the finish line. Attackers know your calendar better than you think. They wait for exactly those windows because urgency is already built into the moment. Waiting costs more than acting — and waiting until your busiest financial period to think about this means you're walking into the most dangerous window without a net.


BEC vs. Phishing — What's the Difference?

People often treat BEC and phishing as the same thing. They're related, but not the same.

Phishing is broad. It's a mass email campaign designed to steal login credentials or install malware. Think of it as fishing with a net — cast wide, catch whatever bites.

BEC is a spear. One target. One customized email. Researched, timed, and delivered with precision. The goal isn't credentials — it's a wire transfer or sensitive data.

The other critical difference: phishing usually contains a malicious link or attachment. BEC typically contains neither. It's plain text, written in a tone that matches how your leadership actually communicates. That's why spam filters miss it. There's nothing technically wrong with the email — only the intent behind it.

If you want a fuller picture of how these attacks compare, our Cybersecurity Statistics 2026 Small Business breakdown covers the current threat landscape.


What Does a BEC Email Actually Look Like?

Here are the red flags — the ones that are easy to miss when you're busy and the request sounds plausible.

  • The email domain is slightly off. @vendor-co.com instead of @vendorco.com. One character. One hyphen. Easy to miss.
  • The request is urgent and confidential. "Don't loop in the team on this one — handle it directly." Urgency + secrecy is a manipulation tactic.
  • Normal approval steps are bypassed. "Skip the usual process this time — I'll explain later." Any request to skip verification is a red flag.
  • Payment instructions changed at the last minute. A vendor suddenly has "new banking details." Always call to confirm using a number you already have on file — not one in the email.
  • The tone is slightly off. Not wrong enough to be obvious, but your gut says something's different. Trust that instinct.
  • The request comes when leadership is traveling. Attackers time this deliberately. A CEO who's "on a plane" or "in a board meeting" can't be reached to confirm.

A Hypothetical Scenario: The Large Wire That Disappeared

The following is a hypothetical example illustrating a BEC pattern that FBI reporting and industry incident data confirm is one of the most common in professional services.

A law firm is handling a commercial real estate closing. The title company has been communicating with the firm's paralegal by email for two weeks. The closing is set for Friday.

On Thursday afternoon, the paralegal receives an email that appears to be from the title company with "updated wiring instructions." The email matches the thread perfectly — same names, same deal details, same professional tone. The only difference is the bank account number.

The paralegal processes the wire. A substantial sum leaves the client's account.

Within minutes, the money is already moving through multiple different accounts. By the time the real title company calls Friday morning asking why the funds never arrived, the money is gone.

Here's what I want you to sit with: in this scenario, the firm didn't have a managed IT partner enforcing DMARC on their domain. They didn't have AI-powered email filtering catching that look-alike sending address. They didn't have a trained team running Security Awareness Training that month. Those aren't complicated things to have in place — but they require a real, proactive partner who's thinking about them before Thursday afternoon arrives. That's the gap between a "nephew solution" and a managed IT relationship that actually earns its keep.

FBI reporting and industry incident data confirm this is one of the most common BEC patterns in professional services. Law firms and title companies are prime targets precisely because wire transfers are routine and the stakes are high.


How to Prevent Business Email Compromise

There's no single control that stops BEC. What stops it is layers — technical controls working together with trained people following consistent processes.

Informal IT relationships — a nephew who handles things on weekends, a part-time consultant who checks in monthly — simply don't deliver those layers. They're not running enforced MFA policies across every account. They're not configuring DMARC. They're not running Security Awareness Training programs that keep your team sharp month after month. Helpful doesn't stop a substantial wire transfer. Layered controls do. That's the difference between a "nephew solution" and a real managed IT partner — and in the BEC world, that gap is measured in dollars.

Multi-Factor Authentication (MFA)

Multi-factor authentication — meaning you need a second form of verification beyond your password, like a phone approval or code — is the single most important technical control against BEC. If an attacker steals a password but can't get past MFA, they can't take over the mailbox. Full stop.

A real managed IT partner doesn't just offer MFA as a checkbox — they enforce it. Every account. Every user. No exceptions and no workarounds.

How do SPF, DKIM, and DMARC actually stop BEC?

Sit across a conference table from me and I'll walk you through exactly how this works — because I've seen this exact gap cost a firm a wire transfer. Without these three records properly configured on your domain, someone can send an email that looks exactly like it came from you. That's how BEC gets in the door.

Here's the short version of each:

  • SPF (Sender Policy Framework) — the guest list. It tells the world which mail servers are allowed to send on your behalf. Anything not on the list shouldn't be trusted.
  • DKIM (DomainKeys Identified Mail) — the digital signature. It proves the email wasn't tampered with in transit.
  • DMARC (Domain-based Message Authentication, Reporting & Conformance) — the enforcement layer. It tells receiving mail servers to quarantine or reject anything that fails the checks above.

Configuration isn't a one-time task. These records require ongoing review as your email infrastructure changes. In my experience, the most common failure point isn't the initial setup — it's six months later when someone updates a mail server and forgets to update the SPF record. That's the kind of gap a proactive managed IT partner catches before it becomes a problem. Not after the wire goes out.

Security Awareness Training

Your employees are your last line of defense — and your first line of prevention if they're trained. Security Awareness Training (SAT) teaches your team to recognize BEC red flags, practice healthy skepticism on payment requests, and follow verification procedures. HD Tech includes security awareness training in every package tier, starting with the entry-level SecurITy Lifeline. It's not an add-on. It's standard.

Callback Verification Policy

The single most effective procedural control against BEC is a standing rule: any request to wire money or change payment details requires a phone call to a known number to confirm. Not a reply email. Not a text from an unknown number. A call to a contact saved in your system.

This one policy, enforced consistently, is highly effective at stopping BEC attacks before they succeed.

AI-Powered Email Filtering

Modern email security tools use AI to detect subtle signs of impersonation — look-alike domains, anomalous sending patterns, unusual requests embedded in otherwise normal email. These tools go well beyond traditional spam filters and are increasingly effective at catching BEC before it reaches an inbox. For a deeper look at how AI factors into your security posture, our small business cyber threats overview is a good starting point.

Businesses that invest in layered, proactive security — managed by a real team, not a part-time contact — are turning IT into a competitive edge. When your competitors are still relying on a "nephew solution" and you have enforced MFA, DMARC, and trained employees, you're not just safer. You're more trustworthy to clients, more resilient to disruption, and better positioned to win contracts that require security attestation.


What to Do If You've Already Been Hit

Stop what you're doing. Right now.

Every minute that passes after a BEC wire goes out is a minute the money moves further out of reach. This isn't the moment for a meeting or an email chain. It's the moment for a phone call.

  1. Call your bank right now. Ask them to recall the wire or freeze the transaction. The faster you call, the better your odds. I've walked clients through this call. Make it now — every minute counts.
  2. Contact the FBI IC3. File a report at ic3.gov. They have a recovery asset team specifically for BEC wire fraud.
  3. Preserve everything. Don't delete emails. Screenshot the suspicious messages. Your IT team and law enforcement will need them.
  4. Change every compromised password immediately and force a sign-out of all active sessions.
  5. Enable MFA on every account if it isn't already.
  6. Notify affected parties. If client funds or data were involved, you have legal and ethical obligations to disclose.
  7. Call HD Tech. If you're a client, your Relentless Response Engine™ is already engaged. If you're not yet, this is the moment to make that call.

You made a mistake. Now move fast, stay methodical, and don't stop until it's done. Keep paddling.

You recover from a BEC hit by getting the right people on the phone immediately and working through each step above in order. Don't be a casualty.


Frequently Asked Questions

Business email compromise is a targeted scam where criminals impersonate someone your business trusts — a CEO, attorney, or vendor — and trick an employee into sending money or sensitive data. There's typically no malware or suspicious link involved. It's a social engineering con delivered by email, and it's one of the costliest categories of cybercrime in the U.S. — second only to investment fraud by reported dollar losses in the latest FBI IC3 data.

Phishing is a broad, mass-scale attack designed to steal credentials or install malware across many targets at once. Business email compromise is a targeted, customized attack aimed at a specific employee or company, with the goal of fraudulently obtaining a wire transfer or sensitive records. BEC emails typically contain no malicious links or attachments, which is why traditional spam filters often miss them.

Key red flags include: a domain name that's slightly different from the real sender's, urgent requests that ask you to skip normal approval steps, last-minute changes to payment instructions, requests marked confidential that bypass normal channels, and timing that coincides with leadership travel or a known financial deadline. If something feels off about a payment request — verify it with a phone call before acting.

According to the FBI's IC3 2025 report, BEC generated $3,046,598,558 in losses across 24,768 complaints — making it the second-highest cybercrime category by reported dollar loss in the United States, behind investment fraud. The average loss per complaint works out to around $123,000. Once a wire transfer has cleared, recovering those funds is extremely difficult.

Yes — and they're often specifically targeted because their verification controls tend to be lighter than those of large enterprises. The U.S. Secret Service notes that businesses of all sizes, including small and mid-size companies, are frequently targeted. Law firms, CPA firms, real estate companies, and manufacturers in Orange County all handle the types of financial transactions BEC attackers look for.

MFA significantly reduces the risk of account takeover — which is one of the two main methods attackers use to execute BEC. If a criminal steals a password but can't bypass MFA, they can't access the mailbox or monitor email threads to time their attack. MFA doesn't stop every BEC scenario (spoofed domains don't require account access), but it's one of the most effective single controls available.


Book your free Cyber Preparation Assessment now — before your busiest payment cycles open that window. HD Tech's assessment identifies exactly where your business is exposed and what it takes to close those gaps. Book at hdtech.com and let's make sure you're protected before it's your turn.

Greg Burnight, Principal at Curtis & Burnight Law in Seal Beach, has worked with HD Tech for many years. In his words: "Careful attention to detail, solution-oriented services and implementation and fair pricing... we are extremely satisfied with their professionalism and capabilities." That's the level of attention that protects firms like his from scenarios like this one.

business email compromise
Tom Hermstad, President of HD Tech

Tom Hermstad

President & CMO, HD Tech

Tom Hermstad has led HD Tech since 1995, building one of Southern California's most trusted managed IT and cybersecurity firms. He specializes in helping Orange County businesses eliminate IT headaches and stay ahead of evolving cyber threats — in plain English.

Need Help With Your IT?

Get a free, no-pressure IT health check. We'll show you exactly where you're exposed — in plain English.