What is business email compromise, or payment diversion fraud?
Fraud that diverts a genuine company payment to the attacker's account, using credible email and no malware.
Business email compromise, also known as man-in-the-mail or payment diversion fraud, is a scam that diverts a legitimate company payment to an account controlled by the attacker, working inside a genuine email conversation rather than planting malware. The typical pattern: someone gains access to the mailbox of a supplier or of an accounts payable employee, reads quietly for weeks, spots an invoice in flight and then writes into the existing thread announcing a change of bank details. No attachment, no malicious link, no domain to block, which is why spam filters see it poorly and the control that matters stays a human one. In the FBI IC3 2025 annual report BEC is the second category by reported losses, with 3.04 billion dollars and an average loss per complaint above 122,000 dollars: figures that count reported cases only, and therefore understate what actually happens.
The three forms it takes
The first is supplier fraud, the most lucrative because it rides on a real invoice and an expected amount: whoever pays has no reason to doubt, only the bank account changes. The second is so-called CEO fraud, where an urgent and confidential request appears to come from the chief executive while traveling, leaning on hierarchy to skip the ordinary procedure. The third targets payroll or HR records, with a request to update the account where a salary is paid. In all three the entry point is almost always a mailbox compromised through phishing, and the most insidious part is persistence: a hidden forwarding rule copying correspondence to the attacker can stay active for months after the password is changed. Regaining control of a mailbox therefore takes a wider sequence than a password change: revoking every active session and every token issued to applications, checking the multi-factor methods registered on the account, the mailbox delegations and the permissions granted to third-party apps, and removing both forwarding rules and message organization rules. The arrival of synthetic audio and video has added the forged confirmation call, a fraudulent use of the techniques described under deepfake.
What stops the wrong payment
The decisive control is not technological and is cheap to introduce: every change of bank details must be verified by calling the supplier back on a number already held in your records, never on the one written in the email requesting the change. Alongside that you need dual authorization above a defined threshold, a hold period on changes to supplier records, and periodic review of mailbox forwarding rules. On the technical side what counts is SPF, DKIM and DMARC in reject mode to prevent spoofing of your own domain, plus an alert when a domain resembling yours gets registered.
Why it matters for decision makers
BEC is the cyber risk that hits profit most directly: it does not stop production, it moves money. Once the payment has left, the first hours decide nearly everything, because a recall request on the transfer stands a chance only before the funds are split up, and it has to go together with a criminal report. So it is worth deciding in advance who calls the bank, who opens the claim with the insurer and who coordinates the rest, inside the incident response plan. If personal data about customers or employees also left the compromised mailbox, the case is a data breach as well, with its own obligations and deadlines.
Frequently asked questions
Related terms
- Phishing · Deception that pushes a person into handing over credentials, data or money by faking a legitimate sender.
- Incident response · The set of roles, decisions and procedures by which a company detects, contains and closes a security incident.
- Data breach · An incident that exposes confidential data through an external attack or an internal error, with direct and reputational cost.
- Deepfake · AI-generated synthetic voice or face, used for corporate fraud like the fake-CEO phone call: defended with process, not detection.
- Zero Trust · A security model where no identity, human or machine, is trusted by default: every access is verified and granted with minimum privilege.
A term that hits close to home? Let's talk.
CONTACT ME