Skip to content

Resource

Phishing and business email compromise

At small business scale, business email compromise causes more direct financial loss than ransomware does, and it usually involves no malware at all. In its most effective form there is nothing wrong with the email, which is precisely why no security product reliably stops it.

Six variants, and what actually stops each

The first is a technology problem with a technology answer. The others are process problems, and treating them as technology problems is why businesses keep losing money to them.

Business email compromise variants and their countermeasures
VariantHow it works
Credential phishingMFA, password manager, email filteringA fake login page harvesting passwords
Invoice fraudVoice verification on any change to payment detailsA real supplier invoice with altered bank details
Executive impersonationA payment approval process with no urgency exceptionAn urgent request appearing to come from a director
Supplier account takeoverVerification, because the message is authentic in every technical senseA genuinely compromised supplier mailbox
Payroll diversionVerification with the employee through a separate channelA request to change an employee's bank details
Gift card requestUsually caught by training rather than by technologyA small value test of whether the process holds

Six controls, mostly not technical

  • Any change to bank details is verified by voice on a number already on file, never a number in the message
  • The verification call goes out to the known contact rather than returning a call you received
  • A second approver above a set payment threshold, with no exception for urgency
  • External sender marking, so a spoofed internal address is visually obvious
  • MFA everywhere, which prevents your own mailbox becoming the next authentic source
  • Training aimed at this specific scenario rather than at phishing generally

The first one prevents more loss than the rest of a security stack combined, and it costs nothing beyond the discipline of applying it every time, including when the request is plausible and the person asking is genuinely known to you.

Why urgency is the tell

Almost every successful version of this attack includes time pressure. The payment must go today. The director is boarding a flight. The supplier will halt delivery.

Urgency exists in the message for one reason: it is the only reliable way to stop someone performing the verification step that would expose the fraud. It is not incidental context, it is the mechanism.

Which makes the practical rule straightforward. Urgency does not create an exception to verification, it is the signal that verification matters most. Staff need explicit permission to slow a payment down, because the alternative is a junior person deciding whether to challenge someone who appears to be a director.

Common questions

Answered before you ask.

Why can email filtering not stop this?

Because in the most damaging version there is nothing technically wrong with the message. When a supplier's mailbox is genuinely compromised, the email comes from the real address, passes every authentication check, arrives in a real thread with real history, and contains a real invoice with one field altered. No filter can reasonably reject that. This is why the defence has to be a process rule rather than a product.

What makes business email compromise worse than ransomware for some businesses?

The money leaves immediately and is rarely recovered. Ransomware is highly visible and, with tested backups, survivable. A fraudulent payment is quiet, discovered days or weeks later during reconciliation, and by then the funds have moved through several accounts. There is also often no insurance response, because many policies treat social engineering fraud separately from cyber cover, which is worth checking with your broker rather than assuming.

Which businesses are targeted most?

Any business making large, irregular payments to a rotating set of counterparties. Construction is heavily affected because payments are large and deadlines create genuine urgency. Professional services handling client funds, and any business with an established supplier chain exchanging invoices by email, are similarly exposed. The common factor is that a six figure payment to a new account does not look unusual.

What should we do if a payment has already gone out?

Contact your bank immediately and ask them to attempt a recall, because speed genuinely matters and the window is measured in hours. Then notify your insurer, report it to law enforcement, and treat the affected mailbox as compromised until proven otherwise, which means resetting credentials and reviewing mailbox rules. Attackers frequently create hidden forwarding rules that persist long after the original message.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment