

A familiar vendor sends an email. The invoice is expected. The conversation may even appear inside an existing thread. Then one detail changes: where the money should go.
Business email compromise, or BEC, exploits the trust already built into routine business communication. Fraudsters may impersonate an executive or vendor, spoof an email address or gain access to a legitimate mailbox before inserting fraudulent payment instructions into a real business process.
BEC does not always begin with an obviously suspicious message. A criminal may compromise a legitimate email account and monitor conversations before acting. That can reveal vendor relationships, invoices, payment timing and the language employees normally use.
The fraudulent request can then arrive with enough context to appear routine.
Common BEC scenarios include:
The FBI identifies BEC as a sophisticated fraud that targets businesses and individuals who routinely transfer funds. Read the FBI’s Business Email Compromise guidance.
The strength of BEC is often context. The sender may be known. The invoice may be real. The timing may make sense. In some cases, the email account itself may be legitimate but compromised.
That is why a conversation that seems familiar should not independently authorize a change in payment instructions.
Before you change where money goes, confirm new or revised payment instructions through a separate, trusted channel using contact information already on file, not the phone number, email address, or link supplied in the request.
Use a simple verification framework before approving an unexpected payment, changed instruction or unusual request.
Learn MoreBusinesses can reduce BEC exposure by treating changes to payment instructions as exceptions that require additional verification.
Consider the following:
TRB’s Fraud Prevention Resource Center outlines additional controls businesses can use to strengthen payment security, including dual approval, payment verification, and segregation of duties.
Act immediately if you suspect you’ve been compromised already. Contact your financial institution and ask whether the payment can be recalled or investigated. Preserve the email thread, transaction details, and related records, then report the incident through the FBI’s Internet Crime Complaint Center. Speed matters because the opportunity to recover transferred funds can narrow quickly.
BEC succeeds by making a fraudulent change look like part of a legitimate process. When the instructions change, the verification process should change with them.
Payment controls can reduce reliance on a single person, message or approval point when money moves. Talk with a TRB Treasury Management specialist about tools and processes that may fit your business.
Schedule an Appointment