Business email compromise is fraud in which an attacker uses a genuine or convincingly spoofed email account to induce a payment to an account they control. It usually involves no malware at all — the attacker reads real correspondence and intervenes in a transaction that was already happening.
Why it defeats technical controls
There is often no malicious attachment, no exploit and no unusual software. The attacker obtains credentials — typically by phishing — logs in as the user, and reads.
Then they wait. They learn how the company writes, who authorises payments, which suppliers are mid-invoice, and when a transaction is due. The fraudulent instruction, when it comes, arrives from a real account, in the expected tone, at exactly the moment such an instruction would be expected. Security tooling built to detect anomalies sees a legitimate user doing legitimate things.
The common variants are the same technique at different points: a supplier's invoice with altered bank details, an executive instructing an urgent transfer, a payroll change request, or a diverted real estate closing payment.
The first hours decide whether money is recovered
Recovery probability falls sharply with time, and the sequence matters:
- Call the sending bank immediately and request a recall. Funds sometimes remain in the receiving account for a short window.
- Report to law enforcement. In the US, the FBI's IC3 operates a recovery process that has succeeded in freezing funds when engaged very quickly — hours, not days.
- Contact the receiving bank through counsel.
- Preserve the mailbox before remediating it. Password resets and mailbox cleanup destroy the forensic record. This is the step operations teams do first and should do after preservation.
What the forensic examination establishes
Which account was compromised, and when. Sign-in logs showing unfamiliar addresses, impossible travel, or unusual client applications.
Whether it was a real compromise or a lookalike domain. These require entirely different responses — one is an intrusion with notification implications, the other is an external deception with none.
Mailbox rules. Attackers routinely create forwarding or auto-delete rules so the victim never sees the supplier's follow-up questions. Finding one is close to conclusive evidence of compromise rather than spoofing.
What else was reachable. An attacker with mailbox access had access to everything in it, which is a potential data breach independent of the money.
Whose environment failed. In supplier-invoice fraud both parties often assume the other was compromised. Establishing which mailbox the attacker actually held frequently determines who bears the loss.
Who pays
This is litigated regularly, and the outcome usually turns on which party's negligence enabled the fraud and what the contract says about payment instruction changes. A written policy requiring out-of-band verbal verification of any change to bank details — called to a previously known number, never one supplied in the email — is both the most effective prevention available and useful evidence about which party's process failed.
From our work
Dealing with business email compromise in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
