Resource
Phishing and business email compromise
At small business scale, business email compromise causes more direct financial loss than ransomware does, and it usually involves no malware at all. In its most effective form there is nothing wrong with the email, which is precisely why no security product reliably stops it.
Six variants, and what actually stops each
The first is a technology problem with a technology answer. The others are process problems, and treating them as technology problems is why businesses keep losing money to them.
| Variant | How it works |
|---|---|
| Credential phishingMFA, password manager, email filtering | A fake login page harvesting passwords |
| Invoice fraudVoice verification on any change to payment details | A real supplier invoice with altered bank details |
| Executive impersonationA payment approval process with no urgency exception | An urgent request appearing to come from a director |
| Supplier account takeoverVerification, because the message is authentic in every technical sense | A genuinely compromised supplier mailbox |
| Payroll diversionVerification with the employee through a separate channel | A request to change an employee's bank details |
| Gift card requestUsually caught by training rather than by technology | A small value test of whether the process holds |
Six controls, mostly not technical
- Any change to bank details is verified by voice on a number already on file, never a number in the message
- The verification call goes out to the known contact rather than returning a call you received
- A second approver above a set payment threshold, with no exception for urgency
- External sender marking, so a spoofed internal address is visually obvious
- MFA everywhere, which prevents your own mailbox becoming the next authentic source
- Training aimed at this specific scenario rather than at phishing generally
The first one prevents more loss than the rest of a security stack combined, and it costs nothing beyond the discipline of applying it every time, including when the request is plausible and the person asking is genuinely known to you.
Why urgency is the tell
Almost every successful version of this attack includes time pressure. The payment must go today. The director is boarding a flight. The supplier will halt delivery.
Urgency exists in the message for one reason: it is the only reliable way to stop someone performing the verification step that would expose the fraud. It is not incidental context, it is the mechanism.
Which makes the practical rule straightforward. Urgency does not create an exception to verification, it is the signal that verification matters most. Staff need explicit permission to slow a payment down, because the alternative is a junior person deciding whether to challenge someone who appears to be a director.
Common questions
Answered before you ask.
Why can email filtering not stop this?
Because in the most damaging version there is nothing technically wrong with the message. When a supplier's mailbox is genuinely compromised, the email comes from the real address, passes every authentication check, arrives in a real thread with real history, and contains a real invoice with one field altered. No filter can reasonably reject that. This is why the defence has to be a process rule rather than a product.
What makes business email compromise worse than ransomware for some businesses?
The money leaves immediately and is rarely recovered. Ransomware is highly visible and, with tested backups, survivable. A fraudulent payment is quiet, discovered days or weeks later during reconciliation, and by then the funds have moved through several accounts. There is also often no insurance response, because many policies treat social engineering fraud separately from cyber cover, which is worth checking with your broker rather than assuming.
Which businesses are targeted most?
Any business making large, irregular payments to a rotating set of counterparties. Construction is heavily affected because payments are large and deadlines create genuine urgency. Professional services handling client funds, and any business with an established supplier chain exchanging invoices by email, are similarly exposed. The common factor is that a six figure payment to a new account does not look unusual.
What should we do if a payment has already gone out?
Contact your bank immediately and ask them to attempt a recall, because speed genuinely matters and the window is measured in hours. Then notify your insurer, report it to law enforcement, and treat the affected mailbox as compromised until proven otherwise, which means resetting credentials and reviewing mailbox rules. Attackers frequently create hidden forwarding rules that persist long after the original message.
Related
Read next.
Security awareness training
Phishing simulation and short, frequent training that changes behaviour.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Construction
Jobsite connectivity, mobile devices, project data
Ransomware protection for small business
How attacks actually start, which controls stop them, and what to do in the first hour.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.