We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Threats

Threats

Business Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank

Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The vendor's controller has a new bank, apparently

The bookkeeper at a 12-person architecture firm has worked with the same structural engineering vendor for six years. On a Tuesday afternoon an email arrives from the vendor's controller, same signature block, same slightly formal tone, with a PDF letter on the vendor's letterhead. The company has moved banks. Please update the remittance details for the next invoice.

She does what she has done a hundred times. She opens the accounting system, updates the account and routing numbers, and pays the outstanding invoice on Friday with the rest of the batch. Eighty-six thousand dollars. The confirmation goes out. The vendor's controller replies with thanks.

Forty days later the real controller calls. Not the one in the thread, the one she has met at the holiday party. He wants to know why two invoices are past due. She forwards him the email chain. He reads it in silence for a while and then says the words she will remember for a long time: "That is not my email address. Look at the domain again."

One letter was different. The l was a capital I. The firm's own mailbox had been read for three weeks before the first message went out, which is how the attacker knew which invoice was due, what the controller sounded like in writing, and which Friday the batch ran.

What the heck does this mean

Business email compromise, BEC for short, is fraud that uses email to talk your own people into sending money to the wrong place. No malware needs to run. No files get locked. Somebody simply asks nicely, at the right moment, from what looks like the right address, and the money goes.

Two versions do most of the damage. Invoice fraud is the one above: a vendor's bank details change, and the payment that was going to a real supplier goes to a mule account. Payroll diversion is the same trick pointed at HR. An "employee" emails payroll to update their direct deposit, and the next pay run lands in an account the employee has never seen.

Funds transfer fraud, the insurer's term, is the umbrella: any time money moves because of a lie. Mailbox rules matter here too. Once an attacker is in a mailbox, they set a rule that hides replies from the real vendor, so nobody notices the conversation has forked.

I take this one personally. My wife's business was hit by a payroll reroute, and it came close to ending the company. That experience is one of the reasons AccuSights exists.

The numbers that matter

BEC and funds transfer fraud together made up 58% of reported cyber incidents in the Coalition 2026 Cyber Claims Report, and 52% of funds transfer fraud claims began with a compromised email account. Not ransomware. Email.

Losses to business email compromise came to roughly $3 billion out of $20.9 billion in total reported cybercrime losses in the FBI IC3 2025 Annual Report. That is the reported figure. Plenty of owners never file.

Phishing drove 85% of BEC incidents, according to the Arctic Wolf 2026 Threat Report. The attacker in our story did not guess a password. Somebody typed it into a fake login page a month earlier.

What to do this week

  1. Adopt the callback rule and put it in writing: no change to bank details, payroll deposits or payment instructions takes effect until someone phones the requester on a number already on file. The email is never the source of the phone number. (CIS 14 Security Awareness and Skills Training)
  2. Turn on multi-factor authentication for every mailbox, including the owner's, and disable the legacy sign-in protocols that skip it. Ask your IT person specifically about basic authentication for IMAP and POP. (CIS 6 Access Control Management)
  3. Have IT pull a report of every mailbox forwarding rule and every rule that moves messages to deleted items or an odd folder. Then set an alert for new ones. That rule is the attacker's favorite hiding place. (CIS 9 Email and Web Browser Protections)
  4. Require two people to approve any payment above a threshold you set this week, and make sure the second approver checks the accounting system, not the email thread. (CIS 6 Access Control Management)
  5. Run one drill with the finance and HR staff using a fake vendor bank-change email. Do it kindly. The point is practice, not embarrassment. (CIS 14 Security Awareness and Skills Training)
  6. Write the "money moved" card: the bank's fraud desk number, the insurer's hotline, who calls whom in the first hour. Tape it inside the bookkeeper's drawer. (CIS 17 Incident Response Management)

Where AccuSights fits

Our assessment checks the things that let this fraud run for weeks: which mailboxes lack multi-factor authentication, which forwarding rules already exist, and whether anyone has written down a callback rule. The Cyber Hygiene Test takes three minutes and tells you where you stand. If the answer bothers you, 15 minutes with an engineer is the next step.

Questions people ask

How do I verify a request to change bank details? Call the vendor or employee on a phone number you already had before the request arrived, never one printed in the email or the attached letter. Confirm the new account out loud, then have a second person at your company approve the change in the accounting system. If the requester says there is no time for a call, that is the answer: the request waits.

Is the bank liable for a fraudulent wire? For a business account, usually not. If someone with authority on the account sent the wire, the bank treated it as an authorized payment, even though the instructions were fraudulent. Consumer protections that reverse card fraud do not extend to a business wire. Ask your bank in writing what its recall process and deadlines are before you ever need them.

Can the money be recovered after a BEC wire? Sometimes, and the odds fall by the hour. Attackers move funds out of the receiving account quickly, often the same day. The moment you suspect a wire went to the wrong place, call your bank's fraud desk and ask for a recall, then notify your insurer and file a report with the relevant authority. Waiting to be sure is how the money disappears.

The most expensive email your company will ever receive will be polite, on time and correctly spelled, except for one letter.

Questions people ask

How do I verify a request to change bank details?

Call the vendor or employee on a phone number you already had before the request arrived, never one printed in the email or the attached letter. Confirm the new account out loud, then have a second person at your company approve the change in the accounting system. If the requester says there is no time for a call, that is the answer: the request waits.

Is the bank liable for a fraudulent wire?

For a business account, usually not. If someone with authority on the account sent the wire, the bank treated it as an authorized payment, even though the instructions were fraudulent. Consumer protections that reverse card fraud do not extend to a business wire. Ask your bank in writing what its recall process and deadlines are before you ever need them.

Can the money be recovered after a BEC wire?

Sometimes, and the odds fall by the hour. Attackers move funds out of the receiving account quickly, often the same day. The moment you suspect a wire went to the wrong place, call your bank's fraud desk and ask for a recall, then notify your insurer and file a report with the relevant authority. Waiting to be sure is how the money disappears.

Controls this post maps to

CIS 9 Email and Web Browser ProtectionsCIS 6 Access Control ManagementCIS 14 Security Awareness and Skills Training

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.