Date Published: 

September 2, 2026

Business Email Compromise: Warning Signs and Prevention Steps

Business Email Compromise is not just an IT issue. It is a business risk that targets the way people approve payments, share sensitive information and trust familiar names in their inbox.

A BEC attack usually starts with a believable email. It may appear to come from an owner, executive, vendor, attorney, client or coworker. The message asks someone to send money, update banking details, buy gift cards, share employee data or log in to a fake Microsoft 365 page. The email may not contain malware. It may not look dramatic. That is exactly why it works.

For small and midsize businesses, the best defense is a mix of awareness, clear approval procedures and practical security controls. Your team does not need to become cybersecurity experts, but they do need to know when to pause.

What Business Email Compromise Means

Business Email Compromise, often called BEC, is a targeted email scam that uses impersonation to trick a business into taking an action that benefits the attacker. The goal is usually financial, but not always. Attackers may also want payroll data, tax documents, client files, passwords or access to cloud accounts.

At the center of most BEC attempts are three things: a trusted identity, a believable request and a gap in the approval process. The attacker might pretend to be your CEO asking for an urgent wire transfer. They might pose as a vendor with new ACH instructions. They might compromise a real employee mailbox and continue an existing email thread, which makes the message much harder to question.

BEC often overlaps with phishing and spoofing, but it is more focused on business decisions than random spam. If your team needs a plain language refresher on those email tactics, VM Tech’s guide to phishing and spoofed emails is a useful companion to this article.

Why BEC Works Against Real Businesses

BEC succeeds because it blends into normal business activity. In a busy office, requests move quickly. A manufacturer may need to pay a supplier to avoid a shipping delay. A law firm may be coordinating sensitive client matters. An accounting firm may be under pressure during tax season. A nonprofit may rely on fast approvals when a board member or executive sends an urgent request.

Attackers study those pressures. They use language that sounds routine and take advantage of moments when employees are busy, distracted or trying to be helpful.

They also know that many growing businesses still rely on informal approval habits. A trusted employee may be allowed to process payments based on email alone. A vendor banking change may not require a call back. A senior leader may text or email instructions outside the normal workflow. Those habits may feel efficient, but they create openings for fraud.

The goal is not to make your team suspicious of every message. The goal is to create a few simple rules that make risky requests easy to verify before damage is done.

Warning Signs Your Team Should Take Seriously

The request involves money movement

The clearest warning sign is any email asking for a wire transfer, ACH change, new payment destination, gift card purchase or payroll direct deposit update. These requests deserve extra scrutiny even when they appear to come from someone familiar.

A common example is a vendor email that says their bank account has changed and future invoices should be paid to the new account. Another is an executive message asking an office manager to send funds today because a deal is closing. The request may sound normal, but money movement should never depend on email alone.

The message creates pressure or secrecy

BEC emails often include urgency. The sender may claim they are in a meeting, traveling, unavailable by phone or handling something confidential. The purpose is to keep the employee from asking questions.

Phrases like handle this now, do not call me or keep this between us should trigger a pause. Healthy business processes do not require employees to bypass normal controls because someone sent an urgent email.

The sender looks familiar but not quite right

Display names are easy to fake. An email may show the name of your owner, controller or vendor contact, but the actual email address may be different. Sometimes the domain is off by one letter. Sometimes the message comes from a free email account with a familiar name attached.

Employees should be trained to look beyond the display name, especially on phones where email apps often hide the full address. If a request affects money, data or access, the sender identity should be verified through a separate trusted method.

The request enters an existing conversation

Some of the most dangerous BEC attacks happen inside real email threads. If an attacker has access to a vendor or employee mailbox, they may wait until an invoice or payment conversation is already active. Then they insert new banking instructions or a payment change at the right moment.

This feels convincing because the history is real. That is why process matters. Even if the thread is legitimate, a payment destination change still needs independent verification.

The email points to a Microsoft 365 login page

Many BEC incidents begin with stolen passwords. An employee receives a message that appears to be a shared document, voicemail, scanner notification or password alert. The link leads to a fake login page that collects the employee’s Microsoft 365 credentials.

Once attackers gain access to a mailbox, they may watch conversations, set hidden rules, forward messages or send fraud requests from the real account. If an employee enters a password into a suspicious page, treat it as urgent even if nothing obvious happens right away.

The request avoids your normal process

A message that asks someone to use a personal email address, communicate only by text, skip a second approval or ignore the usual accounting workflow is a major warning sign. Attackers often try to move the conversation away from systems where the business has records and controls.

Your safest response is simple: return to the approved process. If the request is legitimate, it can withstand verification.

A business owner, office manager, and IT consultant review an email security checklist on a laptop in a conference room.

Prevention Steps That Actually Reduce Risk

Require independent verification for payment changes

Every business should have a firm rule for vendor banking changes, payroll direct deposit updates and urgent payment requests. Verify the request using a phone number already on file, not the number included in the email.

This single habit prevents many BEC losses. If a vendor emails new ACH details, call the trusted contact your team already knows. If an executive requests a wire transfer, confirm through a known phone number or approved internal channel. Do not rely on a reply to the same email thread.

Set approval rules before the emergency happens

Approvals should be clear before someone is under pressure. Decide which transactions need approval by two people, which dollar amounts require executive review and which types of changes can never be approved by email alone.

For example, a business might require approval by two people for any new payee, any banking change and any same day wire request. The exact thresholds depend on your operation, but the principle is the same. Employees should not have to guess when they are allowed to slow down.

These rules should be part of your written procedures. If your company is growing and needs stronger structure, VM Tech’s guide to IT policies every growing business should have explains how basic policies can reduce confusion and risk.

Use MFA on email and financial systems

Multifactor authentication, or MFA, adds a second verification step when someone signs in. It is not perfect, but it makes stolen passwords far less useful to attackers.

MFA should be enabled for Microsoft 365, remote access, accounting software, banking portals and any system that contains sensitive company data. It should also be managed carefully. Employees need to understand that unexpected approval prompts should be denied and reported.

For a practical explanation written for business leaders, see VM Tech’s article on why small businesses need MFA.

Review mailbox rules and forwarding settings

After attackers access a mailbox, they often create rules that hide security alerts, move replies to obscure folders or forward email outside the company. These changes can remain unnoticed if nobody is looking for them.

Ask your IT provider to periodically review suspicious inbox rules, external forwarding, unusual sign in activity and inactive accounts that still have access. This is especially important after an employee leaves, a password is entered into a suspicious site or a mailbox behaves strangely.

Improve Microsoft 365 security settings

Microsoft 365 can be configured in ways that reduce the likelihood of email fraud. Examples include stronger sign in controls, email authentication records, alerting for suspicious activity and restrictions on automatic external forwarding.

Business owners do not need to know every technical setting, but they should ask whether these protections are reviewed regularly. The right configuration depends on how your team works, where employees sign in from and which data needs the most protection.

Train employees with business examples

Generic cybersecurity training often fails because it feels disconnected from daily work. BEC training should use examples your employees can recognize.

For an accounting team, focus on invoice changes, tax forms and payroll updates. For a manufacturer, focus on supplier payments and shipping pressure. For a law office, focus on client funds, document sharing and executive impersonation. For a nonprofit, focus on donor data, board requests and urgent expense approvals.

The most useful training gives employees permission to pause. A simple phrase can help: I need to verify this through our approved process. That sentence protects the employee and the business.

What To Do If You Suspect Business Email Compromise

If something feels wrong, move quickly but carefully. Do not continue the email conversation with the suspicious sender. Do not use phone numbers, links or contact details included in the message.

If money was sent, contact your bank immediately and ask about recall options. Time matters. Then notify your IT support team so they can review affected accounts, reset passwords where needed, revoke active sessions and check for mailbox rules or forwarding.

Preserve the evidence. Save the original emails, payment details, timestamps and any related messages. Do not delete the mailbox or wipe devices before your IT team has reviewed what happened.

Depending on the situation, you may also need to notify your cyber insurance carrier, legal counsel, affected clients or law enforcement. Your response should follow your incident response policy and any contractual or regulatory requirements that apply to your business.

After the immediate issue is contained, review what allowed the request to get through. Was MFA missing? Was a vendor change accepted by email? Did an employee feel pressured to bypass approval? The lesson should become a better process, not blame directed at one person.

A Practical BEC Readiness Check

A business that is prepared for BEC can answer a few questions with confidence. Who is allowed to approve payments? How are vendor bank changes verified? Is MFA enabled on email and financial systems? Who reviews suspicious mailbox activity? Do employees know how to report a questionable email without fear of being criticized?

If the answers are unclear, that does not mean the business has failed. It means there is an opportunity to strengthen controls before an attacker tests them.

For many Southern California businesses, the right next step is a focused review of email security, Microsoft 365 settings and financial approval procedures. BEC prevention works best when technology and business process support each other.

Frequently Asked Questions

Is Business Email Compromise the same as phishing? No. Phishing is often used to steal passwords or push users to fake login pages. Business Email Compromise is a targeted fraud that uses trust, impersonation and business processes to get money or sensitive information. The two often overlap.

Can a small business really be targeted by BEC? Yes. Attackers target small and midsize businesses because they often have real payment activity, valuable data and informal approval processes. A smaller company may also have fewer people available to review suspicious requests.

Does MFA stop Business Email Compromise completely? No single control stops every attack. MFA reduces the risk of account takeover, but businesses still need payment verification, employee awareness and regular review of mailbox activity.

What is the first step if an employee sent money to a fraudster? Contact the bank immediately using a trusted phone number and ask about recall options. Then contact IT support so they can secure accounts, preserve evidence and review whether any mailboxes were compromised.

How often should employees receive BEC training? At least annually, with shorter reminders when risks are high, such as tax season, leadership travel, major vendor changes or busy financial periods. Short practical refreshers are often more effective than long sessions that employees quickly forget.

Strengthen Your Email Security With a Practical Partner

Business Email Compromise is easier to prevent when your people, processes and technology are aligned. Clear payment rules, MFA, Microsoft 365 security reviews and responsive support all work together to reduce risk.

VM Tech helps small and midsize businesses across Southern California improve cybersecurity, manage Microsoft 365 and build dependable IT practices that support daily operations. If you want a practical review of your current exposure to BEC, connect with VM Tech and start with a clear conversation about your business risks.