Business Email Compromise (BEC) has no malware and no obvious "hack." It attacks process and trust - which is why it is so expensive and so often succeeds.
The four common shapes
- Vendor-impersonation. A real supplier's email is spoofed or their mailbox is compromised. A "bank details have changed" invoice lands with your accounts team.
- CEO/CFO fraud. A convincing email "from the boss" demands an urgent, secret payment.
- Mandate fraud. Criminals update your own payment mandate or payroll details.
- Legal-threat fraud. A fake solicitor demands settlement of a nonexistent claim.
Why it works
- It exploits urgency and authority - the two things people least like to question.
- It looks normal - correct logos, real thread history, familiar tone.
- It bypasses technical defences because there is nothing technically malicious.
Controls that actually stop it
- Call-back verification on a known, previously-held number for any change of bank details. Never a number on the email.
- Dual authorisation for new payees and above-threshold payments.
- Written change-of-bank-details policy shared with every genuine supplier.
- Mailbox hardening - MFA and monitoring for suppliers whose email you pay.
- A no-blame reporting culture so staff flag doubts early.
If a payment has already gone
Speed is everything. Within the first hours, funds may still sit in the receiving account.
- Notify your bank's fraud line immediately and request a recall and, where possible, a network kill / freeze.
- Preserve the emails and headers - they are evidence.
- Report to Action Fraud (UK) and your insurer.
- If amounts are large, a civil freezing order can sometimes be sought against the recipient.
If your business has lost money to a BEC invoice, our team handles the tracing and the bank and legal requests. Early contact materially changes the odds.


