Common targets include invoice payments, payroll, gift cards, tax information, and property transactions.
BEC often succeeds without a malicious attachment. Attackers may spoof a similar-looking address, compromise a genuine mailbox, study existing conversations, create forwarding rules, and insert believable instructions into the normal workflow. The strongest defenses therefore combine account security with independent verification and financial controls.
Key points
Common warning signsUrgency, secrecy, changed bank details, unusual payment methods, subtle address differences, or a request that bypasses normal approval.
Preventive controlsPhishing-resistant MFA, protected email domains, conditional access, mailbox monitoring, separation of duties, and payment-change procedures.
Critical checkVerify sensitive or changed instructions through a known, independent channel — not contact details supplied in the message.
If money was sentContact the financial institution immediately, preserve evidence, and report the fraud to the relevant authorities.
Important limitationEmail filtering alone cannot stop a convincing request sent from a genuinely compromised account.