What it means
Business email compromise (BEC) succeeds when a plausible request outruns independent verification, because it uses trust in familiar business communication to redirect a decision, and a criminal might control a real mailbox or imitate an address and reply chain. The message can ask for an urgent transfer, a change to supplier bank details or sensitive employee information, and polite writing and knowledge of a genuine transaction do not authenticate the sender.
The FBI describes schemes involving executive impersonation, suppliers and payment instructions, FinCEN discusses email-compromise fraud in financial institutions, and CISA warns businesses to verify unusual requests, so their examples support a practical rule: confirm a consequential change through a channel you already trust, independent of the message asking for it. A common pattern is an invoice with altered bank details, where the amount, purchase order and due date may all be real and only the destination account changes.
If staff focus on matching the invoice total, they can miss the dangerous change, so compare payment instructions with the vendor master record and use a separate callback procedure. The callback must use a previously verified phone number or another trusted route, because calling the number in the suspicious email merely puts the potential attacker on the other end.
A reply to the same thread is also weak when the mailbox may be compromised, so record who answered, which number was used and what they confirmed. Executive impersonation adds pressure, as a message may claim that the chief executive needs a confidential transfer before a meeting, and the tone may sound familiar or the timing may fit a real deal.
Company payment controls should still apply, because a senior person's status is not a reason to bypass a second approver. Email headers and authentication checks can help technical teams triage a message, but they are not a complete proof of human authorship, since a genuine account can be compromised and forwarding systems can complicate signals.
Staff should not be expected to decide a large transfer from a green checkmark alone, so use transaction-specific verification. Controls should separate creating or editing a payee from approving a transfer, send an alert when bank details change and pause the first payment until verification is recorded, and access logs should be reviewed if a vendor master record changes unexpectedly, as dual approval helps only when the second person independently examines the destination.
Train employees with realistic examples, but avoid turning training into blame, because a rushed buyer or finance clerk may face a convincing request during a genuine purchase, and give them permission and a simple route to stop and ask, since a process that punishes delays can encourage staff to take shortcuts. Account protection matters too, as multi-factor authentication, strong unique passwords and timely removal of old access can reduce mailbox takeover risk.
Review forwarding rules and suspicious sign-ins after an incident and combine technical and payment controls, since a spoofed message may still reach the business even when its own accounts are secure. If a payment was already sent, act immediately by contacting the sending bank through a known channel, reporting suspected fraud and asking about recall or freezing options, and preserve the message and payment details for investigators.
Recovery is uncertain and can depend on timing and destination, so do not promise that the bank can reverse a transfer. Phishing-test click rate can measure one training exercise, and if 18 of 150 participants clicked, the rate is 12%, but it does not tell how many fraudulent transfers would occur or prove the company is secure, so track verified bank-detail changes, attempted exceptions and response time as well, keep vendor records accurate, test the callback process, and treat a changed destination, unusual secrecy or bypass request as a reason to stop, not as evidence of a particular person's guilt, grounding action in trusted contact and account records.
In practice
Real-world examples.
Example
A fake CEO email asks finance for an urgent transfer.
Example
A hacked supplier account sends new bank details.
Example
A look-alike domain differs by one letter.
Formula
Calculation
Phishing test failure rate = Staff who clicked / Staff tested x 100
Worked example. 18 of 150 clicked.
- Failure rate: 12%Case study
Seen in the real world.
This illustrative and entirely fictional case follows Willow Design, an invented agency that receives a supplier invoice with new bank details. Accounts payable pauses payment and calls the supplier using a number already in its records, not the number in the email. The supplier says it did not request the change. The case does not prove who controlled the message or whether the supplier's account was hacked.
Watch out
Common mistakes.
- Trusting a familiar display name or an apparently continuous email thread as proof of identity.
- Verifying a bank-detail change using the phone number supplied in the suspicious message.
- Assuming a phishing click-rate test alone measures all BEC risk.
Questions
People also ask.
What is business email compromise?
A scam using hacked or fake business email to steal money or data.
What are warning signs?
Urgency, secrecy and changed bank details.
How can it be stopped?
Verify consequential changes through a previously trusted channel, with payment controls and account security.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%