Authors: Jeff Weeks, Senior Vice President and Chief Information Security Officer
David Dawson, Vice President, BSA/AML Officer
Your controller receives an email from a longtime vendor. The contact’s name is familiar. The message appears in the same email thread your team has used for months. The invoice looks right, and the amount matches expectations. There is just one small note: “We’ve recently changed banks. Please use the updated wiring instructions below.”
The invoice is real. The amount is right. The only thing that is wrong is where the money goes.
That, in a nutshell, is business email compromise (BEC), a targeted form of email fraud and one of the most financially damaging crimes facing businesses and individuals today. According to the FBI’s Internet Crime Complaint Center (IC3), businesses and individuals reported more than $3 billion in BEC losses in 2025 alone, across nearly 25,000 complaints. That’s an average loss of roughly $123,000 per incident.1 Year after year, BEC ranks among the top cybercrimes by dollar loss. In 2025, it was second only to investment fraud.2 Furthermore, 86% of BEC losses moved through wire transfers or ACH payments — the everyday payment rails many businesses rely on.3
The good news: BEC is largely preventable. And when it does happen, fast action can make the difference between recovering funds and losing them for good. Here is what every individual and every business should know.
What Is Business Email Compromise (BEC)?
A BEC scam is not a typo-riddled scam from a stranger. It's a targeted fraud in which a criminal either takes over a legitimate email account or convincingly impersonates one, then uses that trusted position to redirect a payment that was going to happen anyway.
Common variations include:
- Vendor or supplier impersonation. The fraudster hijacks or spoofs a vendor’s email and sends “updated” payment instructions, often inside a genuine, ongoing email thread.
- Executive impersonation or CEO fraud. An urgent message that appears to come from an owner or executive that directs an employee to send a confidential, time-sensitive wire.
- Payroll diversion. HR receives a request from an “employee” to change their direct deposit account.
- Real estate and closing fraud. Buyers receive last-minute wiring changes that appear to come from their title company, attorney or agent.4
What makes BEC so dangerous is that there is often no malware, suspicious link or obvious red flag. The email may come from the actual account of someone you trust because that account has been quietly compromised, sometimes for weeks, while the criminal reads email, learns payment patterns and waits for the right invoice. Add in AI-generated messages that are polished and personalized, and even voice cloning used to “confirm” requests by phone, and today’s BEC attempts can be nearly indistinguishable from legitimate business.5
How to Protect Yourself and Your Business
1. Verify every payment change out-of-band
This is the single most important habit. Any request to change payment instructions, banking details or direct deposit information should be verified by calling the requester at a phone number you already have on file. Never rely on a number provided in the email itself. Make this a written policy with no exceptions, especially for urgent requests from the boss.6
2. Treat urgency and secrecy as red flags
“This must go out today.” “Keep this confidential.” “I’m in a meeting and can’t talk.” Fraudsters manufacture pressure precisely so you will skip verification. A legitimate business partner should not object to a confirmation call.
3. Look closely at the sender, then look again
Criminals register lookalike domains, such as yourvendor-inc.com instead of yourvendorinc.com, and alter reply-to addresses. But remember: a perfectly correct address does not guarantee safety if the account itself is compromised. That is why verification via another contact method is the real control.
4. Use strong authentication on your email
To prevent BEC from happening to you, enable multi-factor authentication (MFA) on every email account, business and personal. Most email account takeovers begin with a stolen or reused password. Microsoft’s research has found that MFA blocks over 99% of automated account-compromise attacks.7
5. Watch for signs your own email is compromised
Unexpected password reset notices, missing messages or mail rules you did not create can mean someone is inside your account. Review your mailbox rules and connected devices periodically. Be on the lookout especially for rules that auto-forward or auto-delete messages.
6. Layer controls on the payment itself
For businesses: require dual approval for wires and ACH origination, set transaction limits and use the account services your bank offers, such as positive pay, ACH debit filters and blocks, and account alerts. Controls on the money are your safety net when controls on the email fail.
7. Train the people who move money
Your accounts payable, payroll and treasury staff are the targets. Brief them on these schemes, empower them to slow down and make it clear that no one will ever be penalized for taking time to verify.
How Businesses Can Strengthen Email Security
Most business email compromise attacks do not start with the fraudulent wire request. They start earlier, when an email account is quietly compromised. Detecting that compromise before the fraudulent payment request arrives is the true value of modern email security.
As your bank, we do not endorse or recommend any particular email security vendor, and this article shouldn't be read as promoting one. But we do strongly encourage all our business customers, as a matter of both financial security and business integrity, to put dedicated email security in place through any widely available, reputable provider. There are many capable options on the market, including tools built into the major business email platforms you may already pay for. Whatever you choose, look for capabilities such as:
- Advanced phishing and impersonation detection that flags lookalike domains, spoofed senders and unusual payment-related language.
- Alerts for suspicious sign-ins, unfamiliar locations or devices, and newly created forwarding or deletion rules — classic fingerprints of a compromised account.
- Email authentication standards, including SPF, DKIM, and DMARC, configured for your own domain, which make it harder for criminals to impersonate you to customers and vendors.
- Multi-factor authentication enforcement across all mailboxes.
Given the sophistication of today’s threat landscape, enhanced email security should be viewed as essential for any business that sends or receives payment instructions by email. The cost of a capable email security service is small compared to the average BEC loss.
What to Do If You Experience Business Email Compromise
If you discover or suspect that you have sent money based on fraudulent instructions, act immediately:
- Call us first, right away. Contact your banker or our fraud team the moment you suspect a fraudulent transfer. We can attempt to recall the wire or return the ACH and coordinate with the receiving bank to freeze the funds. Recovery is possible, but it is extremely time sensitive. The odds of recovery drop sharply once the money leaves the first receiving account, often within hours.8
- File a complaint at ic3.gov immediately. The FBI’s Recovery Asset Team works with financial institutions to freeze fraudulent transfers. In 2025, it placed holds on more than $679 million, successfully freezing funds in 58% of incidents when it was engaged.9 For international wires of $50,000 or more, the FBI’s Financial Fraud Kill Chain process can generally be activated only when the fraud is reported within 72 hours of the transfer.10 Do not wait for certainty; file a complete complaint, including the wire details, as soon as fraud is suspected.
- Preserve the evidence. Keep the original emails, including full headers, invoices and wire confirmations. Do not delete anything, and do not tip off the fraudster by replying.
- Assume the email account is still compromised. Change the affected account’s password from a different, clean device and revoke active sessions, remove unfamiliar mailbox rules and enable MFA before using the account again.
- Widen the review. Check whether other payments, vendors or employees were targeted, notify affected business partners through a channel other than email, and contact your insurance carrier and legal counsel as appropriate.
The Bottom Line
Business email compromise succeeds not by breaking technology, but by borrowing trust. The defenses are refreshingly practical: verify by voice, slow down under pressure and put two sets of eyes on every payment. Pair those habits with modern essentials like multi-factor authentication and dedicated email security protection, and you will reduce the risk of one of the most expensive cybercrimes in America.
Have questions about wire fraud protections, account alerts or payment controls? Contact your banker or our customer service team. They will be glad to walk through the options with you.
Frequently Asked Questions About BEC
Treat any unexpected request to change payment instructions, banking information or direct deposit details as suspicious, especially when the request creates a sense of urgency or secrecy. Verify the request using a phone number or other contact method you already have on file, rather than relying on information provided in the email.
Contact your bank or financial institution immediately and ask whether the transfer can be recalled or the funds recovered. You should also report the fraud to the FBI's Internet Crime Complaint Center (IC3), preserve the original emails and other evidence, and secure any compromised email accounts.
About the Authors
Jeff has been with FNBO for more than 26 years and is currently the Senior Vice President and Chief Information Security Officer. The executive leadership and oversight provided by Jeff in the development, management, and execution of information security for FNBO enables the company’s ability to posture and protect private, personal information, and assets of the company’s clients, employees, and business partners.
David has been with FNBO for more than a decade and currently serves as Vice President, BSA/AML Officer. The enterprise leadership and oversight provided by David in the development, management, and execution of FNBO's Financial Crimes Compliance program enables the company's ability to detect, prevent, deter, and report money laundering, sanctions violations, and other illicit financial activity that could harm its customers, employees, and business partners.
Sources
1FBI Internet Crime Complaint Center, 2025 Internet Crime Report, p. 7.
2FBI Internet Crime Complaint Center, 2025 Internet Crime Report, p. 7.
3FBI Internet Crime Complaint Center, 2025 Internet Crime Report, p. 10.
4 FBI Internet Crime Complaint Center, “Business Email Compromise: The $50 Billion Scam,” PSA230609, June 9, 2023. See also: FBI Internet Crime Complaint Center, “Business Email Compromise: The $55 Billion Scam,” PSA240911, Sept. 11, 2024.
5 FBI Internet Crime Complaint Center, “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud,” PSA241203, Dec. 3, 2024.
6 FBI Internet Crime Complaint Center, “Business Email Compromise: The $55 Billion Scam,” PSA240911, Sept. 11, 2024.
7 Microsoft Security Blog, “One simple action you can take to prevent 99.9 percent of attacks on your accounts,” Aug. 20, 2019. See also: Microsoft Research, “How effective is multifactor authentication at deterring cyberattacks?” 2023.
8 FBI Internet Crime Complaint Center, “Business Email Compromise: The $55 Billion Scam,” PSA240911, Sept. 11, 2024.
9 FBI Internet Crime Complaint Center, 2025 Internet Crime Report, p. 17.
10 American Land Title Association, “Hit by Wire Transfer Fraud? Use the Kill Chain Process,” Jan. 31, 2019. See also: ABA Insurance Services, “Financial Fraud Kill Chain may be used to recover fraudulent international wire transfers.”