Business Email Compromise (BEC) is a scam that impersonates an internal or trusted party, usually an executive or vendor, to request a money transfer or data. Attackers often do not need to hack the email. They only need to trick staff with a convincing message. For a small business, one transfer to a scammer's account can burn months of capital.
Why BEC is so effective
BEC preys on alertness that drops under pressure. An email posing as the CEO asking for a "secret and urgent" transfer, or a vendor announcing "our bank details changed", looks ordinary to busy staff. Attackers study the structure and language of a business from public profiles so the request sounds familiar. The defense is not advanced technology but a simple verification process.
Practical steps to prevent BEC
Build from payment process to staff awareness. Each step closes one BEC trick.
1. Require a second channel to verify payment changes
Every transfer request or bank detail change must be verified through another channel, such as a phone call to a known number. Not a reply to the email, and not the number listed in the email itself. This single rule breaks most BEC schemes.
2. Be suspicious of urgent, secrecy-demanding emails
Requests that are urgent, secret, or "do not tell anyone" are classic BEC signs. Pressure and secrecy are designed to make staff skip verification. Make wariness of this combination part of the work culture.
3. Inspect the sender address closely
Attackers use look-alike domains that are not identical, for example companny. Com instead of company. Com, or a display name "CEO" with a foreign address. Train staff to look at the actual address, not just the display name. A small spelling difference is a sign of impersonation.
4. Set a rule: no bank changes by email alone
Write down that a vendor or employee bank detail change may not rest on email alone. Require a form or oral confirmation from someone authorized. A written rule gives finance staff a basis to refuse a suspicious request.
5. Train finance staff and enable MFA
Staff who process payments are the main target. Train them to recognize BEC patterns regularly. On the technical side, enable MFA on business email and tighten forwarding rules so a hijacked account cannot send fake requests.
Example: a "CEO" email asking for an urgent transfer
A small-business finance staff member receives an email in the CEO's name requesting an urgent transfer to a new account, with the note "do not discuss this until it is done". Because a second-channel verification rule exists, the staff member calls the CEO at a known number and learns the CEO never asked for it. The email came from a look-alike domain. One call saves a large sum.
If a fraudulent transfer already went out
Contact the bank at once and request that the recipient's account be frozen. The window is a matter of hours. Gather the email, headers, and timeline as evidence, then report to the police. If your own business email was hijacked, change the password, check forwarding rules, and sign out foreign sessions. Review the process so a similar pattern is caught earlier.
Common mistakes to avoid
- Processing urgent requests without verification. Rush is BEC's main tool.
- Changing bank details by email alone. One fake request is enough to send a payment to a scammer.
- Looking only at the display name, not the address. The name "CEO" is easy to fake. The domain is not.
Frequently asked questions
What is BEC?
A scam that impersonates an internal or trusted party, such as a leader or vendor, to request a money transfer or sensitive data.
What is the most effective prevention?
Second-channel verification for every payment change. Call a known number, not the one in the email.
A "leader" email asks for a secret transfer?
Almost certainly a scam. The combination of urgent, secret, and transfer-requesting is a classic BEC signature.
Sources and further reading
Editorial note: This article is educational and defensive. To report an actual scam, use the bank's official channels and the authority that applies in your region.

