The LedgerBusiness Dog · $BUSINESS · it's just business
🕵️ Sus Business

Business Email Compromise: The $2.8 Billion Fake-Invoice Scam

BEC is the costliest cybercrime most business owners have never heard of — no malware, just a convincing email that reroutes a real payment. How it works and how to make your business unhackable-by-email.

CowDog4 min readShare on X →

There's a fraud that stole more from businesses last year than ransomware, needs zero technical skill to fall for, and targets the most trusted part of your company: the person who pays the bills. It's called Business Email Compromise, and if you run a business — or approve a single payment — this is the one to understand.

How BEC actually works

There's no hacking in the movie sense. A criminal studies your business — often from your own website, LinkedIn, and out-of-office replies — then sends an email that looks exactly right, at exactly the right moment.

  1. 1

    Reconnaissance

    They learn who pays invoices, who your vendors are, who the CEO is, and when big payments happen. Much of this is public. Some comes from a genuinely hacked inbox they've been quietly reading for weeks.

  2. 2

    The impersonation

    They pose as someone trusted — via a spoofed address (ceo@yourcompny.com — spot the typo?), a look-alike domain, or an actually-compromised real account. The message fits the relationship perfectly.

  3. 3

    The plausible ask

    "We've changed banks — please update our payment details for this month's invoice." Or, as the CEO: "I'm in a meeting, need you to wire the deposit for the deal today, keep it quiet till it's announced." Urgent, authoritative, and utterly routine-sounding.

  4. 4

    The payment you'll never claw back

    Accounts payable does its job — pays the "vendor," updates the "new" bank details — and the money lands in a criminal-controlled account, often moved onward within minutes by money mules. Wires are fast and hard to reverse. By the time the real vendor asks where their payment is, it's gone.

The flavors you'll actually see

The four classic BEC plays

1) CEO fraud — "the boss" urgently needs a wire, quietly. 2) Vendor/invoice fraud — a supplier "changed bank details" (this is the most expensive variant). 3) Payroll diversion — an "employee" asks HR to update their direct-deposit account. 4) Attorney impersonation — pressure around a "confidential, time-sensitive" deal. All four share urgency + authority + a change to where money goes.

Why it beats smart people

BEC doesn't attack your firewall; it attacks your trust and your hurry. The email comes from a "known" person, references real details, and arrives when you're busy. Nothing looks broken because nothing is broken — the technology worked perfectly; a human was simply convinced. That's why a $2.8-billion-a-year crime runs on emails a filter can't catch.

How to make your business nearly BEC-proof

  1. 1

    The out-of-band verification rule (this is 90% of the defense)

    Any request to send money or change payment details gets verified through a separate, already-known channel — call the vendor on the number you had on file before the email, never a number the email provides. One phone call defeats almost every BEC.

  2. 2

    Make 'the CEO is rushing you' a red flag, not a reason

    Train everyone that urgency + secrecy + payment = stop and verify. Give staff explicit permission to slow down a "boss" request. Real executives will thank them.

  3. 3

    Lock the process, not just the people

    Dual approval for wires over a threshold, a mandatory call-back for any bank-detail change, and a hard rule that vendor banking changes are never actioned from email alone.

  4. 4

    Harden the inboxes

    Multi-factor authentication on all email accounts (stops the "actually hacked account" version), and scrutinize look-alike domains and reply-to mismatches.

If you've been hit

Move fast — speed is everything. Contact your bank immediately to request a wire recall, and file with the FBI's IC3 (ic3.gov) right away; their Recovery Asset Team has clawed back funds when victims report within hours. Then tell your team what happened — silence just lets it happen to the next person.

Frequently asked questions

We're small — are we really a target?

Yes. BEC scales down beautifully: a five-person company wiring a $12,000 "vendor payment" is a perfect, low-effort target. Criminals often prefer small businesses precisely because the payment controls are looser.

Won't our spam filter or antivirus catch it?

Usually not. There's no attachment or malicious link to flag — just a well-written email asking for a normal-sounding business action. Technical tools help at the margins; the process rule is the real protection.

What if the email really is from our CEO's hacked account?

Then it will pass every technical check — because it is their account. This is exactly why out-of-band verification (a phone call) is non-negotiable: it doesn't trust the channel the request arrived on.

BEC is a reminder that the most dangerous vulnerability in any company isn't a server — it's a busy, trusting human being asked to do their normal job a little too quickly. Slow the money down, verify on a second channel, and you close the door. It's just business — verified twice.

Sources

  1. FBI IC3 — 2024 Internet Crime Report
  2. FBI — Business Email Compromise (public guidance)

Keep reading

This article is educational and satirical content from Business Dog. It is not financial, legal, or tax advice. It's just business.