Blog / Threats
Threats
Business Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank
Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.
The vendor's controller has a new bank, apparently
The bookkeeper at a 12-person architecture firm has worked with the same structural engineering vendor for six years. On a Tuesday afternoon an email arrives from the vendor's controller, same signature block, same slightly formal tone, with a PDF letter on the vendor's letterhead. The company has moved banks. Please update the remittance details for the next invoice.
She does what she has done a hundred times. She opens the accounting system, updates the account and routing numbers, and pays the outstanding invoice on Friday with the rest of the batch. Eighty-six thousand dollars. The confirmation goes out. The vendor's controller replies with thanks.
Forty days later the real controller calls. Not the one in the thread, the one she has met at the holiday party. He wants to know why two invoices are past due. She forwards him the email chain. He reads it in silence for a while and then says the words she will remember for a long time: "That is not my email address. Look at the domain again."
One letter was different. The l was a capital I. The firm's own mailbox had been read for three weeks before the first message went out, which is how the attacker knew which invoice was due, what the controller sounded like in writing, and which Friday the batch ran.
What the heck does this mean
Business email compromise, BEC for short, is fraud that uses email to talk your own people into sending money to the wrong place. No malware needs to run. No files get locked. Somebody simply asks nicely, at the right moment, from what looks like the right address, and the money goes.
Two versions do most of the damage. Invoice fraud is the one above: a vendor's bank details change, and the payment that was going to a real supplier goes to a mule account. Payroll diversion is the same trick pointed at HR. An "employee" emails payroll to update their direct deposit, and the next pay run lands in an account the employee has never seen.
Funds transfer fraud, the insurer's term, is the umbrella: any time money moves because of a lie. Mailbox rules matter here too. Once an attacker is in a mailbox, they set a rule that hides replies from the real vendor, so nobody notices the conversation has forked.
I take this one personally. My wife's business was hit by a payroll reroute, and it came close to ending the company. That experience is one of the reasons AccuSights exists.
The numbers that matter
BEC and funds transfer fraud together made up 58% of reported cyber incidents in the Coalition 2026 Cyber Claims Report, and 52% of funds transfer fraud claims began with a compromised email account. Not ransomware. Email.
Losses to business email compromise came to roughly $3 billion out of $20.9 billion in total reported cybercrime losses in the FBI IC3 2025 Annual Report. That is the reported figure. Plenty of owners never file.
Phishing drove 85% of BEC incidents, according to the Arctic Wolf 2026 Threat Report. The attacker in our story did not guess a password. Somebody typed it into a fake login page a month earlier.
What to do this week
- Adopt the callback rule and put it in writing: no change to bank details, payroll deposits or payment instructions takes effect until someone phones the requester on a number already on file. The email is never the source of the phone number. (CIS 14 Security Awareness and Skills Training)
- Turn on multi-factor authentication for every mailbox, including the owner's, and disable the legacy sign-in protocols that skip it. Ask your IT person specifically about basic authentication for IMAP and POP. (CIS 6 Access Control Management)
- Have IT pull a report of every mailbox forwarding rule and every rule that moves messages to deleted items or an odd folder. Then set an alert for new ones. That rule is the attacker's favorite hiding place. (CIS 9 Email and Web Browser Protections)
- Require two people to approve any payment above a threshold you set this week, and make sure the second approver checks the accounting system, not the email thread. (CIS 6 Access Control Management)
- Run one drill with the finance and HR staff using a fake vendor bank-change email. Do it kindly. The point is practice, not embarrassment. (CIS 14 Security Awareness and Skills Training)
- Write the "money moved" card: the bank's fraud desk number, the insurer's hotline, who calls whom in the first hour. Tape it inside the bookkeeper's drawer. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment checks the things that let this fraud run for weeks: which mailboxes lack multi-factor authentication, which forwarding rules already exist, and whether anyone has written down a callback rule. The Cyber Hygiene Test takes three minutes and tells you where you stand. If the answer bothers you, 15 minutes with an engineer is the next step.
Questions people ask
How do I verify a request to change bank details? Call the vendor or employee on a phone number you already had before the request arrived, never one printed in the email or the attached letter. Confirm the new account out loud, then have a second person at your company approve the change in the accounting system. If the requester says there is no time for a call, that is the answer: the request waits.
Is the bank liable for a fraudulent wire? For a business account, usually not. If someone with authority on the account sent the wire, the bank treated it as an authorized payment, even though the instructions were fraudulent. Consumer protections that reverse card fraud do not extend to a business wire. Ask your bank in writing what its recall process and deadlines are before you ever need them.
Can the money be recovered after a BEC wire? Sometimes, and the odds fall by the hour. Attackers move funds out of the receiving account quickly, often the same day. The moment you suspect a wire went to the wrong place, call your bank's fraud desk and ask for a recall, then notify your insurer and file a report with the relevant authority. Waiting to be sure is how the money disappears.
The most expensive email your company will ever receive will be polite, on time and correctly spelled, except for one letter.
Questions people ask
How do I verify a request to change bank details?
Call the vendor or employee on a phone number you already had before the request arrived, never one printed in the email or the attached letter. Confirm the new account out loud, then have a second person at your company approve the change in the accounting system. If the requester says there is no time for a call, that is the answer: the request waits.
Is the bank liable for a fraudulent wire?
For a business account, usually not. If someone with authority on the account sent the wire, the bank treated it as an authorized payment, even though the instructions were fraudulent. Consumer protections that reverse card fraud do not extend to a business wire. Ask your bank in writing what its recall process and deadlines are before you ever need them.
Can the money be recovered after a BEC wire?
Sometimes, and the odds fall by the hour. Attackers move funds out of the receiving account quickly, often the same day. The moment you suspect a wire went to the wrong place, call your bank's fraud desk and ask for a recall, then notify your insurer and file a report with the relevant authority. Waiting to be sure is how the money disappears.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Remote Desktop Security: RDP, VPN and RMM Are the New Front Door, and It Is Usually Unlocked
Remote desktop security in 2026 is about three doors: RDP, the VPN box and the RMM tool. How attackers find them in days, and how to lock each one this week.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
ThreatsData Extortion Without Encryption: They Did Not Lock Anything. They Just Took It.
A data extortion attack skips encryption and goes straight to the threat: pay or your customer files go public. How it works, and what to do in the first hour.
