There is no malware to detect, no ransom note, no dramatic breach. A genuine-looking invoice arrives from a supplier you have paid a dozen times. Everything matches — the logo, the wording, the amount — except for one line: the bank details. You pay it, and a six-figure sum lands not with your supplier but with a criminal. This is business email compromise, and it is among the most costly frauds facing organisations of any size.
Business email compromise — almost always shortened to BEC — is fraud that targets the way companies move money rather than the technology they run on. It does not need to defeat your firewall; it needs only to defeat your trust. A single altered detail on a document that looks entirely authentic is enough to divert a legitimate payment into the wrong hands. By the time anyone notices, the money has usually been moved on and withdrawn.
What makes BEC so dangerous is that the controls most businesses rely on — antivirus, spam filters, password policies — are largely beside the point. The email may be perfectly genuine; the document may be a real invoice. The fraud lives in a quiet change of context that no scanner is designed to catch. Understanding the vectors is the first line of defence.
What BEC actually is
At its core, BEC is the redirection of a payment you intended to make. The attacker does not steal from you by force; they persuade you, or your finance team, to send a payment to an account they control. The change can be as small as a single line of bank details on an otherwise faultless invoice.
Because the payment is one you meant to make — to a supplier you recognise, for goods or services genuinely owed — the transaction looks ordinary in every respect. The criminal's entire effort goes into making that one altered detail appear unremarkable, and into ensuring the request reaches someone with the authority to pay before anyone thinks to question it.
The main vectors
BEC arrives in several recognisable forms. Most cases are a variation on one of these, and many combine more than one.
1. CEO and executive impersonation
An email appears to come from a senior figure — a director, a chief executive, a finance lead — instructing a junior colleague to make an urgent, confidential payment. The authority of the supposed sender, combined with pressure not to discuss it, discourages the recipient from checking.
2. Invoice and mandate fraud
A genuine supplier's invoice is intercepted or imitated, and the bank details are quietly changed before it reaches you. The "change of bank details" notice — apparently routine — is one of the most effective tools the fraudster has.
3. Supplier-account takeover
The criminal gains access to a real email account, often at a trusted supplier, and sends genuine-looking correspondence from it. Because the messages come from the correct address, ordinary scrutiny finds nothing wrong.
4. Lookalike domains
A near-identical domain — a transposed letter, an added character, a different suffix — stands in for the real one. At a glance the address reads correctly, and a busy reader rarely inspects it letter by letter.
Why it succeeds
BEC works for the same reason confidence tricks have always worked: it exploits trust, not technology. The request comes from a familiar name, references a real transaction, and slots neatly into work that is already underway. Nothing about it feels like an attack.
The con leans on a handful of predictable levers. Authority makes a junior employee reluctant to challenge an instruction from the top. Urgency compresses the time available to verify, framing any delay as a problem. Trust in an established supplier relationship means a change of details is read as administration rather than alarm. And the simple reality of a busy finance team — processing many payments under time pressure — leaves little room for the careful, sceptical pause the fraud depends on being skipped.
The most expensive frauds rarely break in. They are waved through — by people doing their jobs, trusting documents that look exactly as they should.
Any one of these warrants a pause and an independent check before a payment is released:
- A sudden change of bank details on an invoice or in a payment instruction.
- Pressure to pay urgently or confidentially, discouraging normal checks.
- A slightly altered email domain — a transposed letter or an unfamiliar suffix.
- A request that bypasses your normal process or chain of authorisation.
The controls that stop it
BEC is defeated by process, not by software alone. The measures that matter are the ones that force a moment of verification between a payment instruction and the money leaving the account.
- Verify any change of bank details by phone. Call a known, pre-existing number for the supplier — never a number provided in the email itself, which may belong to the fraudster.
- Require dual authorisation. No single person should be able to release a significant payment alone; a second pair of eyes breaks the spell of a single urgent instruction.
- Train finance staff. The people who process payments should know exactly what BEC looks like and feel empowered to question even a request that appears to come from the top.
- Deploy email authentication. SPF, DKIM, and DMARC help block spoofed messages and make lookalike domains harder to use convincingly.
- Confirm new payees out of band. Before a first payment to any new account, verify the details through a separate, trusted channel rather than relying on the email alone.
If a payment has already gone out
Speed is everything. A diverted payment is often moved on within hours, so the first response should be measured in minutes, not days, and embarrassment should never delay action.
- Contact your bank immediately. Ask them to attempt a recall of the payment and to alert the receiving bank. The sooner the funds are flagged, the better the chance of freezing them before they are withdrawn.
- Preserve all evidence. Keep the emails, the invoice, the payment records, and the relevant domains and account details. This is the foundation of any recovery effort or claim.
- Report it. In the UK, report to Action Fraud and notify your bank's fraud team; where appropriate, alert the genuine supplier, whose systems may also have been compromised.
- Contain the breach. If an account may have been accessed, reset credentials, review mailbox rules for suspicious forwarding, and check whether other payments are at risk.
- Seek legal advice promptly. Solicitors can pursue freezing injunctions, tracing orders, and civil claims against recipients and intermediaries — remedies that depend heavily on acting quickly.
- BEC redirects a payment you intended to make, often through a single altered bank detail on a genuine-looking invoice.
- Its main vectors are executive impersonation, invoice and mandate fraud, supplier-account takeover, and lookalike domains.
- It succeeds by exploiting authority, urgency, trust, and the time pressure on busy finance teams — not by defeating technology.
- The controls that stop it are procedural: verify changes by a known phone number, require dual authorisation, and confirm new payees out of band.
- If a payment has gone out, contact your bank within minutes, preserve evidence, report it, and seek legal advice immediately.
How Crejj & Partners can help
Our Financial Recovery & Civil Claims team acts for businesses that have lost money to email compromise and invoice redirection. We move quickly to engage the banks involved, pursue freezing injunctions and tracing orders, and bring civil claims against recipients and intermediaries who can be identified. Where funds have crossed borders or passed through multiple accounts, we coordinate the appropriate channels to pursue every realistic avenue of recovery. If a payment has just gone out, or you suspect a request you are about to act on, the time to speak to us is now.
This article is provided for general information only and does not constitute legal advice or create a solicitor–client relationship. Fraud situations are fact-specific and time-sensitive; if you believe you have been targeted, seek tailored advice promptly. Crejj & Partners is a fictional firm presented for illustrative purposes on this website.