Security
Business Email Compromise: How a Single Email Can Redirect Your Money
Of all the phishing-style attacks businesses face, Business Email Compromise (BEC) is one of the most financially damaging — and one of the hardest to catch, because it often doesn't look like an attack at all. No malware, no suspicious link, no obvious red flag. Just an email that looks like it's from someone you already trust, asking for something that sounds routine.
7 min read

What BEC Actually Looks Like
In a typical BEC attack, someone impersonates an executive, a vendor, or a business partner — sometimes from a look-alike domain, sometimes from an account they've actually compromised — and sends a request that seems completely normal on its face: approve an invoice, process a payment, or update payment details on file.
That last one is where one of the most common and costly versions of this scam plays out.
The ACH Account-Change Scam
A frequent variation: attackers pose as a known vendor or supplier and send a message — often timed around a real, expected invoice — saying their banking details have changed and asking that future ACH payments be sent to a new account number. The email looks legitimate. It may reference a real invoice, a real amount, even a real project. The only thing that's changed is the account number, and it doesn't get noticed until the actual vendor calls asking why they haven't been paid.
By then, the money has usually already moved, and ACH transfers are notoriously difficult to reverse once they've cleared. This scam works precisely because it doesn't ask for anything unusual — updating a vendor's banking details is a completely normal administrative task. The email just needs to be believable enough to skip a verification step that would normally catch it.
Why These Attacks Succeed
They exploit trust, not technology. The email itself often passes basic spam filters because it isn't carrying malware — it's just text and a request.
They're well-timed. Attackers often wait for a real invoice cycle or a moment when an executive is traveling and less reachable for quick verification.
They rely on routine. Approving invoices and updating vendor records are everyday tasks, which makes them easy to process quickly without a second look.
They target the right person. BEC attacks are frequently aimed at whoever handles accounts payable or wire approvals specifically, based on information gathered from the company website or LinkedIn.
The One Habit That Stops Almost All of These
Any request to change payment or banking details — no exceptions — should be verified through a separate, known channel before anything is processed. That means calling the vendor at a phone number already on file (not one provided in the email), and confirming the change directly with a real person. This single step defeats the vast majority of ACH account-change scams, because the attacker doesn't control that phone line.
A few other habits that help:
Treat any change to payment details as an event, not a formality. It should always trigger verification, regardless of how routine or well-timed the request seems.
Watch for subtle sender mismatches. A vendor's actual email domain versus a nearly identical look-alike domain is often the only visible clue.
Slow down around urgency. BEC emails frequently include soft pressure — "please process today," "we're behind on this invoice" — designed to discourage a verification call.
Separate approval and execution where possible. Having one person request a payment and a different person approve it adds a natural checkpoint.
What This Means for You
Technical email security helps filter out a lot of phishing attempts, but BEC is specifically designed to slip past those filters because it doesn't look malicious to a scanner — it looks like ordinary business correspondence. The real defense is procedural: a verification habit that gets followed every time, without exception, especially around banking and payment changes.
If your team handles vendor payments or wire transfers regularly, it's worth confirming everyone involved knows this verification step and follows it consistently. Ask your managed service provider if you'd like help building a simple payment-verification policy, or a short training refresher for whoever handles accounts payable.