Business Email Compromise: The $50 Billion Scam That Targets Small Businesses
William “BJ” Pote
CEO, eTop Technology
Ransomware gets all the news coverage. Hospitals shut down. Pipelines frozen. Big numbers and dramatic headlines. But the cybercrime that’s actually been emptying small business bank accounts in the Inland Empire isn’t ransomware. It’s Business Email Compromise.
The FBI’s IC3 unit tracks complaint data on every type of internet crime. Business Email Compromise, BEC for short, has caused over $50 billion in reported losses since the FBI started tracking it, and the 2025 IC3 Annual Report puts BEC at $3.05 billion in reported losses for that year alone — the second-largest crime category they track. And the businesses getting hit aren’t Fortune 500 companies with sophisticated finance teams. They’re 30, 50, 100-person companies in industries you’d never think of as targets. Construction firms wiring funds to a vendor. Law firms moving client trust money. Dental practices paying a supplier.
Most of them never see a dime back.
What BEC Actually Is
Business Email Compromise is a fraud scheme where an attacker either takes over a real business email account or convincingly impersonates one to trick someone into sending money or sensitive data. There’s no malware. There’s no ransomware payload. There’s just an email that looks like it came from someone you trust, asking you to do something that seems normal.
The reason it works is that BEC attacks don’t fight your security tools. They go around them. Your firewall, your antivirus, your EDR, they’re all looking for malicious code and unusual network behavior. A BEC email is just text. It looks like a thousand other emails you got that day.
The Five Plays Attackers Run
Nearly every BEC attack runs one of five plays. Knowing them is the first step to spotting them.
1. The CEO Wire Request
The owner is traveling. An email goes to the controller from what looks like the owner’s address, marked urgent, asking for a wire transfer to a new vendor. The attacker has done their homework. They know the controller’s name, they know the owner is at a conference because LinkedIn told them so, and the email signature looks right.
The controller, trying to be responsive, processes the wire. Sometimes hundreds of thousands of dollars. By the time anyone calls to verify, the money has been routed through three accounts and converted to crypto. Gone.
2. The Vendor Account Change
A vendor you’ve been paying for years emails to say their banking information changed. New routing number, new account. Could you update it on your end? Their next invoice goes out the next day, and you pay it. To the attacker.
This one is brutal because the email comes from what looks like the vendor’s real domain, sometimes from an actually compromised vendor mailbox. By the time the real vendor calls asking why they haven’t been paid, three or four invoices have already been wired to the wrong place.
3. The Payroll Diversion
An HR or payroll person gets an email from what looks like an employee asking to update their direct deposit information for the next pay run. New bank, new routing number. The change goes through. The employee’s paycheck lands in the attacker’s account. Sometimes the employee doesn’t notice for two weeks.
4. The Invoice Scam
A real invoice from a real client gets intercepted. The attacker, who has compromised someone’s mailbox somewhere along the chain, modifies the wire instructions on the PDF and forwards it on. Your client pays the modified invoice to the wrong account. They’re now down the money, and they think you got paid. Awkward conversations follow.
5. The Data Pull
This one doesn’t always involve money directly. An attacker, posing as the CEO or a senior partner, asks HR for “a copy of all W-2s for tax planning purposes” or “a list of all employees with SSNs for an audit.” HR sends it. Now the attacker has filing-grade identity data on every person at your company.
Why Small Businesses Are the Sweet Spot
Big companies have whole teams that exist to verify wire transfers. They have payment authorization workflows. They have fraud analytics on the bank side. Small businesses usually have one person who does everything, no separation of duties, and a culture of “just take care of it.”
That’s exactly the environment BEC thrives in.
Picture a 35-person construction company hit with a single fake vendor change request. The owner is on a job site. The bookkeeper gets an email that looks legitimate. The change goes through, the next progress payment — say $180,000 — gets wired to the attacker, and the real vendor calls three days later asking when they’re getting paid. Whether cyber insurance covers any of it usually comes down to whether the company can prove it had baseline controls in place. Without that, they eat the whole loss.
That’s the part that never makes the news. The post-incident reality is small businesses absorbing six-figure losses out of operating cash. Most don’t survive it twice.
The Controls That Actually Stop BEC
You can’t buy a BEC-prevention product because BEC isn’t a single technical problem. It’s part technology, part process, part training. Here’s what actually works.
Lock Down the Mailbox
Most BEC starts with a compromised mailbox somewhere, either yours or a vendor’s. The same controls that stop initial account takeover stop most BEC at the source.
- MFA on every Microsoft 365 account. Not just executives. Everyone. Phishing-resistant MFA where possible, meaning hardware keys or authenticator app push, not SMS.
- Conditional access policies that block sign-ins from countries you don’t operate in, require compliant devices, and flag impossible-travel scenarios. We covered the zero trust mechanics of this in detail.
- Disable legacy authentication. Older protocols like POP, IMAP, and basic SMTP authentication can bypass MFA. Microsoft has been pushing customers off these for years. If they’re still on, turn them off.
- Monitor mailbox forwarding rules. Attackers love to set up auto-forward rules so they can quietly read every email even after they lose access. Defender for Office 365 catches most of these. Audit them quarterly anyway.
Build a Verification Process for Money Movement
This is the part most companies skip. Technology can only do so much. Process is what stops the wire from going out.
The rule we put in place for every client: any change to payment instructions, any wire request, any banking change, gets verified by a phone call to a known number, not the number in the email. Not a return email. Not a text to a number listed in the request. A phone call to the number you already had on file.
Yes, it adds a step. Yes, the bookkeeper might roll their eyes the first few times. The first time it catches a $40,000 fake wire, nobody complains again.
If you can’t do that, at minimum:
- Two-person approval on any wire over a set threshold.
- Written authorization for any banking change, signed by an officer of the requesting company.
- A 24-hour cooling-off period on first-time payments to a new account, so an emergency request gets daylight before it goes out.
Train Specifically for BEC
Generic security awareness training is not enough. Most of it teaches people to look for misspelled URLs and bad grammar. Modern BEC has neither. The training that actually moves the needle teaches the patterns above and runs simulated BEC tests, not just generic phishing tests.
We run simulations against client finance teams that mimic real wire requests. The industry data on this is striking: KnowBe4’s 2025 Phishing by Industry Benchmarking Report found untrained users fail phishing tests at a 33.1% baseline rate, dropping to 4.1% after 12 months of consistent training. The point isn’t to embarrass anyone. The point is muscle memory. When the real one shows up, the controller has seen it before.
Configure Microsoft 365 to Catch the Spoofs
Microsoft 365 has anti-spoofing tools that most businesses never turn on or tune.
- Set up SPF, DKIM, and DMARC on your sending domain, with DMARC enforcement set to quarantine or reject. This makes it dramatically harder for attackers to send mail that appears to come from your domain.
- Enable anti-impersonation protection in Defender for Office 365 for your executives and finance team. The system learns which display names match which addresses and flags mismatches.
- Tag external senders. A simple banner that says “[EXTERNAL]” on every email from outside your domain is one of the highest-ROI controls available. Attackers spoofing internal addresses get caught instantly.
What to Do If You Get Hit
If a wire goes out and you realize within hours, every minute matters. Here is the order of operations.
- Call your bank immediately. Ask them to initiate a SWIFT recall on the wire if it has cleared, or freeze it if it hasn’t. The first 24 to 72 hours are when recovery is still possible.
- File an IC3 complaint with the FBI at ic3.gov. Reference the Financial Fraud Kill Chain. The FBI has working relationships with major correspondent banks and can sometimes claw back funds the bank can’t.
- Notify your cyber insurance carrier within whatever window your policy requires. Late notice is one of the most common reasons claims are denied. We covered this in the cyber insurance requirements post.
- Trigger your incident response plan. Even if you “just lost money,” there’s almost always a compromised mailbox or vendor relationship somewhere in the chain. Find it before the attacker hits you again.
- Reset credentials and review forwarding rules on every mailbox in the affected workflow. Vendor, internal, anyone copied on the original chain.
The Bottom Line
BEC is the cybercrime that costs small businesses the most and gets the least attention. It doesn’t use exotic malware. It uses your trust, your processes, and your hurry. The defenses are not glamorous. Lock down mailboxes. Build a verification process for money movement. Train specifically for BEC patterns. Tune the email security tools you’re already paying for.
We do this work for businesses across the Inland Empire every day. If you want a clear-eyed look at where your gaps are, reach out — qualifying businesses receive our $2,500 IT Risk Assessment complimentary. We’ll walk through your real BEC exposure, the controls you have versus the ones you need, and what it takes to close the gap before the wire goes out.
William “BJ” Pote
CEO, eTop Technology
eTop Technology has spent over 15 years in IT and over 12 years serving the Inland Empire as a trusted managed IT provider. We host the Business Tech Playbook podcast and are passionate about helping business leaders make smarter technology decisions.