Urgent: Windows 10 is now no longer supported, making systems vulnerable : 👉 Get Expert advice now
Source by Qual is live (Beta)

Business Email Compromise: How to Spot and Prevent BEC Attacks

I’m sure most people reading this blog have received an email from a Nigerian Prince or Banker asking for help moving several million dollars, but today’s cybercriminals are far more advanced. Business email compromise (BEC) is a cyberattack in which criminals use email to impersonate a trusted person or take control of a legitimate account. The objective may be to redirect a payment, steal sensitive information, obtain login credentials or persuade somebody within a business to take an action they would not normally take.

business email compromise-banner

Table of Contents

What makes BEC particularly challenging is that the suspicious email may not always come from an obviously fake address. If an attacker gains access to a genuine mailbox, messages appear to come from somebody the recipient already knows and trusts. Also, if they have access to the mailbox, they can review previous email exchanges and mimic the language used.

Understanding that distinction can help businesses look beyond obvious spam and phishing emails and consider how people, processes and technology work together to reduce the risk.

What Is Business Email Compromise (BEC)?

Business email compromise is a targeted type of phishing that uses business relationships and trusted identities to make fraudulent requests appear legitimate.

For example, an attacker might impersonate a Managing Director and ask Finance to make an urgent payment. In another scenario, an attacker could compromise a supplier’s genuine email account and use it to send altered payment instructions to its customers.

BEC attacks can be effective because they often exploit normal business behaviour.

Employees routinely receive requests from directors, colleagues, suppliers and customers. Invoices are paid, bank details change, documents are shared and people are sometimes asked to act quickly.

An attacker may attempt to make a fraudulent request look like another ordinary business interaction.

How Does Business Email Compromise Work?

There is no single method used in every BEC attack.

Two important approaches are email impersonation and email account compromise.

With impersonation, an attacker attempts to make an email look as though it has come from somebody tries to make an email look like it came from someone the recipient trusts. This might involve a similar-looking domain, a misleading display name or another form of email spoofing.

Account compromise can be more difficult for a recipient to identify.

If an attacker obtains access to a genuine business mailbox, they may be able to send messages from the real account. Depending on the circumstances and access obtained, they may also review previous correspondence and use that information to make subsequent messages more convincing.

This is why recognising BEC cannot depend solely on checking whether a sender’s name looks familiar.

Common Types of Business Email Compromise

Although the techniques vary, several scenarios are particularly relevant to businesses.

Executive or CEO Impersonation

An attacker may impersonate a senior member of the organisation and contact an employee who has authority to make payments, purchase with authority to make payments, purchase goods, or disclose information.

The request might appear urgent or confidential:

  • Make an urgent payment.
  • Purchase something on behalf of a director.
  • Send financial information.
  • Change an existing process.
  • Provide login or employee information.

Urgency can discourage the recipient from verifying the request through another channel.

Businesses can reduce this risk by having clear verification procedures for unusual or sensitive requests, particularly those involving money, credentials or confidential information.

Supplier and Invoice Fraud

An organisation may receive what appears to be a genuine message from a supplier stating that its bank details have changed.

Sometimes the sender may be impersonating the supplier. In other cases, a genuine supplier account may have been compromised.

This makes verification especially important.

A request to change payment details should not be trusted automatically simply because it appears in a familiar email conversation.

Businesses should consider confirming significant financial changes through a known, separate communication method using contact information they already trust.

Compromised Employee Email Accounts

A compromised employee mailbox can create risks beyond the individual account.

Depending on the access available, an attacker may be able to view correspondence, identify business relationships or send messages that appear to come from the employee.

This could potentially expose colleagues, customers or suppliers to further fraudulent approaches.

Strong account security therefore forms an important part of wider business cyber security rather than being treated purely as an email problem.

Phishing and QR-Code Attacks

Phishing remains a common way attackers try to obtain account credentials.

A message might direct an employee to a convincing-looking login page or encourage them to open a malicious attachment.

QR-code phishing — sometimes referred to as quishing — provides another variation. Instead of asking somebody to click a conventional link, an email may encourage the recipient to scan a QR code with a mobile device.

The technique may change, but the underlying principle is similar: persuade somebody to trust a request and take an action that benefits the attacker.

Why Can Business Email Compromise Be Difficult to Spot?

Traditional phishing emails can sometimes contain obvious warning signs such as poor spelling, unexpected attachments or unusual sender addresses.

BEC can be more subtle.

An attacker may research an organisation before making contact. Publicly available information can help identify employees, senior management, suppliers or business activities.

A compromised mailbox can potentially provide even richer context.

This means a malicious request could:

  • Use the name of somebody the recipient knows.
  • Refer to an existing business relationship.
  • Appear within a familiar conversation.
  • Use a genuine compromised email account.
  • Imitate normal invoice or payment processes.
  • Create a plausible sense of urgency.

The question therefore shouldn’t simply be:

“Do we recognise the sender?”

Businesses should also consider:

“Does this request make sense, and have we independently verified anything unusual or sensitive?”

What Can an Attacker Do With a Compromised Email Account?

The consequences depend on the account, its permissions, and the nature of the compromise.

Potential activity can include:

  • Reading sensitive email correspondence.
  • Impersonating the account owner.
  • Targeting colleagues or external contacts.
  • Attempting to redirect payments.
  • Requesting confidential information.
  • Using existing conversations to make fraudulent requests more convincing.
  • Creating forwarding or inbox rules that help monitor or conceal activity.
  • Using information obtained from email to support further attacks.

This is one reason security visibility matters.

Preventing every malicious action is an important objective, but businesses should also consider whether they would identify unusual activity if preventative controls were bypassed.

Understanding how to improve cyber security visibility can help organisations think about what they can actually see across their environment and where potential blind spots may exist.

Warning Signs of Business Email Compromise

No single warning sign proves that an email account has been compromised.

However, employees should be encouraged to question unexpected or unusual behaviour, particularly when several warning signs appear together.

These may include:

  • Unexpected requests to change bank details.
  • Urgent or unusual payment instructions.
  • Requests to bypass normal approval procedures.
  • Subtle changes in a sender’s language or behaviour.
  • Unexpected login or authentication notifications.
  • Unfamiliar inbox or forwarding rules.
  • Messages asking for passwords or authentication information.
  • Requests for sensitive information that would not normally be sent by email.
  • Pressure to keep a transaction confidential.
  • Unexpected QR codes, links or attachments.

A request can also be suspicious even when the email address itself appears legitimate.

When something doesn’t feel right, employees should have a clear way to report it.

How Can Businesses Reduce the Risk of BEC?

Business email compromise is not solely a technology problem.

A stronger approach combines technical protection with account security, employee awareness and appropriate business processes.

Strengthen Email and Account Security

Multi-factor authentication adds an extra layer of protection to business accounts, while appropriate email-security controls can help identify and block some malicious messages.

Access should also reflect what each employee genuinely requires.

Former employees should not retain active accounts, unused accounts should be reviewed, and privileged access should be restricted appropriately.

Our cybersecurity checklist for small businesses covers wider practical controls businesses can review across users, systems, cloud services and security processes.

Make Sensitive Requests Verifiable

Employees should know what to do when they receive an unusual financial or sensitive request.

For example, organisations can establish procedures for independently verifying:

  • Changes to supplier bank details.
  • Unusual payment requests.
  • Requests for confidential information.
  • Changes to established financial processes.

Verification should use a trusted method rather than simply replying to the potentially compromised email.

Build Employee Awareness

Employees do not need to become cybersecurity specialists.

They do need to understand the types of requests that should make them stop and check.

Training can help staff recognise suspicious behaviour, while clear internal reporting procedures make it easier to raise a concern without delaying unnecessarily.

Review Access Regularly

Accounts and permissions should change as employees join the organisation, move between roles or leave.

Regular access reviews can help identify inactive accounts, unnecessary privileges and administrative access that is no longer required.

Consider Detection as Well as Prevention

Even well-designed preventative controls may not stop every incident.

Businesses should therefore consider how they detect, investigate, and escalate suspicious activity.

The aim is not simply to ask:

“Can we stop this?”

It is also:

“If something unusual happens, would we know?”

What Should You Do If You Suspect Business Email Compromise?

If an employee suspects an email account has been compromised, they should report the concern quickly through the organisation’s established IT or security process.

The appropriate response depends on what happened, but may involve securing affected accounts, reviewing suspicious activity, and determining whether other people or organisations have been contacted.

If a fraudulent payment may have been made, contact the relevant bank or financial provider promptly using trusted official contact details.

Businesses should also preserve relevant information and follow their established incident-response procedures.

Where appropriate, incidents may need to be reported to relevant authorities or other affected parties.

The important point is to avoid continuing to trust the potentially compromised communication channel while the situation is being investigated.

Review Your Business Email Security

Business email compromise demonstrates why cyber security cannot rely on a single control.

Email protection, account security, multi-factor authentication, employee awareness, appropriate access, payment-verification processes, monitoring, and incident response can all help reduce risk.

The right combination depends on the organisation, its systems, and how its employees work.

Qual Limited can help businesses review their existing cyber security arrangements, identify potential gaps and determine where additional controls or protection may be appropriate.

Could your business spot a compromised email before somebody acts on it?

Talk to Qual about reviewing your email and cyber security arrangements.

James McKee
WRITTEN BY

James McKee

Senior Cyber Security Specialist
meet the team

Tailored Expert Advice
is a few clicks away

Blog Popup

We’ll be in touch within the next 24 hours (Mon-Fri)

New Starter
IT Cost Calculator

New Starter IT Cost Calculator

£
%
£


Your estimated annual onboarding IT cost

Estimated cost: £

This estimate is based on your onboarding volume, average setup time, and whether laptops and day-one readiness are consistent.

Next: enter your email to receive a tailored recommendation.

System Upgrade
Check Instructions

Quick System Check Instructions:

  1. Press the Windows Key or click Start.
  2. Open Settings.
  3. Navigate to Update & Security.
  4. Select Windows Update.
  5. Click Check for updates.

Your system will automatically determine if Windows 11 is available for your device. If compatible, the upgrade option will appear. If not, you'll receive information about what needs to be updated to proceed.

Your system will automatically determine if Windows 11 is available for your device.

Business IT Services & Hardware | Qual Limited UK

We're ready
to help👋

Request a quick call back for a no-obligation chat. With over 30 years of practical experience, our UK-based experts are ready to help. Guaranteed no pushy sales, just a friendly call to understand your challenges and explore some potential solutions. 

Start the conversation

Qual Main Popup full page

Please note preferred dates are targets, not guarantees 

By submitting, you consent to contact regarding our products and services in accordance with our Privacy Policy

Business IT Services & Hardware | Qual Limited UK

Chat to
An Expert

Are you looking to connect with a dedicated account manager who can tailor IT solutions to meet your business needs?

Start the conversation

Qual Main Popup full page

Please note preferred dates are targets, not guarantees 

By submitting, you consent to contact regarding our products and services in accordance with our Privacy Policy

Business IT Services & Hardware | Qual Limited UK

Chat to
An Expert

Are you looking to connect with a dedicated account manager who can tailor IT solutions to meet your business needs?

Start the conversation

Qual Main Popup full page

Please note preferred dates are targets, not guarantees 

By submitting, you consent to contact regarding our products and services in accordance with our Privacy Policy