This site only uses technical cookies required for it to work: no tracking, no profiling. Cookie Policy

Skip to content
All terms

What is business email compromise, or payment diversion fraud?

Fraud that diverts a genuine company payment to the attacker's account, using credible email and no malware.

Business email compromise, also known as man-in-the-mail or payment diversion fraud, is a scam that diverts a legitimate company payment to an account controlled by the attacker, working inside a genuine email conversation rather than planting malware. The typical pattern: someone gains access to the mailbox of a supplier or of an accounts payable employee, reads quietly for weeks, spots an invoice in flight and then writes into the existing thread announcing a change of bank details. No attachment, no malicious link, no domain to block, which is why spam filters see it poorly and the control that matters stays a human one. In the FBI IC3 2025 annual report BEC is the second category by reported losses, with 3.04 billion dollars and an average loss per complaint above 122,000 dollars: figures that count reported cases only, and therefore understate what actually happens.

The three forms it takes

The first is supplier fraud, the most lucrative because it rides on a real invoice and an expected amount: whoever pays has no reason to doubt, only the bank account changes. The second is so-called CEO fraud, where an urgent and confidential request appears to come from the chief executive while traveling, leaning on hierarchy to skip the ordinary procedure. The third targets payroll or HR records, with a request to update the account where a salary is paid. In all three the entry point is almost always a mailbox compromised through phishing, and the most insidious part is persistence: a hidden forwarding rule copying correspondence to the attacker can stay active for months after the password is changed. Regaining control of a mailbox therefore takes a wider sequence than a password change: revoking every active session and every token issued to applications, checking the multi-factor methods registered on the account, the mailbox delegations and the permissions granted to third-party apps, and removing both forwarding rules and message organization rules. The arrival of synthetic audio and video has added the forged confirmation call, a fraudulent use of the techniques described under deepfake.

What stops the wrong payment

The decisive control is not technological and is cheap to introduce: every change of bank details must be verified by calling the supplier back on a number already held in your records, never on the one written in the email requesting the change. Alongside that you need dual authorization above a defined threshold, a hold period on changes to supplier records, and periodic review of mailbox forwarding rules. On the technical side what counts is SPF, DKIM and DMARC in reject mode to prevent spoofing of your own domain, plus an alert when a domain resembling yours gets registered.

Why it matters for decision makers

BEC is the cyber risk that hits profit most directly: it does not stop production, it moves money. Once the payment has left, the first hours decide nearly everything, because a recall request on the transfer stands a chance only before the funds are split up, and it has to go together with a criminal report. So it is worth deciding in advance who calls the bank, who opens the claim with the insurer and who coordinates the rest, inside the incident response plan. If personal data about customers or employees also left the compromised mailbox, the case is a data breach as well, with its own obligations and deadlines.

Frequently asked questions

As a rule no, because a transfer the company authorized is, from the bank's side, correctly instructed: the deception happened upstream, in the decision to pay, not in the execution. Since 9 October 2025, though, Regulation (EU) 2024/886 requires every euro-area bank to offer a free verification of payee check before any euro credit transfer, flagging a mismatch between the IBAN and the account name, and provides for reimbursement by the payment service provider where that service is not properly delivered and the payment is executed incorrectly: if the warning never came, or came wrong, there is a basis for a claim. The faster route is still the other one: have the bank send a recall request to the beneficiary bank immediately, which is a request and not a right. Once the funds have been withdrawn or split there is nothing left to recall, which is why the first hours matter more than the procedure.

Not by default: many cyber policies cover the technical incident, meaning intrusion, downtime and recovery, and exclude social engineering losses where an employee authorizes the payment. Those need a specific extension, usually called social engineering fraud, carrying its own and typically much lower limit. Read that clause with your broker before an incident and check which internal controls the policy assumes are in place: if it requires a callback on every change of bank details and no callback happened, the claim can be disputed.
  • Phishing · Deception that pushes a person into handing over credentials, data or money by faking a legitimate sender.
  • Incident response · The set of roles, decisions and procedures by which a company detects, contains and closes a security incident.
  • Data breach · An incident that exposes confidential data through an external attack or an internal error, with direct and reputational cost.
  • Deepfake · AI-generated synthetic voice or face, used for corporate fraud like the fake-CEO phone call: defended with process, not detection.
  • Zero Trust · A security model where no identity, human or machine, is trusted by default: every access is verified and granted with minimum privilege.

A term that hits close to home? Let's talk.

CONTACT ME