It starts with an email that looks completely ordinary. The CEO needs a wire transfer done quietly before a meeting ends. A trusted supplier has updated their bank details and asks you to use the new account for this month’s invoice. A title company sends revised wiring instructions for your house closing. Each message sounds plausible, professional, and urgent — and each one can drain tens or hundreds of thousands of dollars in a single afternoon.
This is business email compromise (BEC), and it is one of the most financially destructive cybercrimes on the planet. Between October 2013 and December 2023, the FBI’s Internet Crime Complaint Center (IC3) recorded more than $55.5 billion in global losses from BEC across over 305,000 incidents. In 2024 alone, American victims and businesses reported $2.77 billion in BEC losses across 21,442 complaints — making it only the 7th most-reported crime to IC3, but the second most costly by dollar losses. A survey by the Association for Financial Professionals found that 63% of organizations experienced BEC attempts in a single year.
What makes BEC so dangerous is that it barely uses technology at all. There is usually no malware, no hacking of firewalls — just careful research, a convincing impersonation, and an employee who follows instructions. This article breaks down exactly how these scams work, the five main versions targeting businesses and individuals, the red flags that give them away, and the verification habits that stop them.
How Business Email Compromise Works: Step by Step
Step 1: Reconnaissance. The criminals study their target. Company websites, LinkedIn profiles, press releases, and social media reveal who the executives are, who handles payments, which vendors a company uses, and even when the CEO is traveling. Attackers specifically look for moments of chaos — leadership changes, mergers, or an executive posting vacation photos.
Step 2: Getting inside the inbox. There are two main approaches. In the more sophisticated version, attackers compromise a real email account — often through phishing — and silently monitor it for weeks, learning the company’s language, invoice formats, and payment rhythms. In the simpler version, they spoof an address: registering a lookalike domain (for example, replacing a lowercase “l” with the number “1”) or faking the display name so “John Smith, CEO” appears in the inbox even though the real address is different.
Step 3: The fraudulent instruction. The email arrives with an urgent, confidential request: wire funds to a new account, update vendor payment details, or divert a payroll deposit. The tone is authoritative and the deadline is tight — often “before the end of the day” or “before my meeting ends.”
Step 4: The wire. A busy employee, wanting to be helpful and responsive to the boss, sends the transfer. Wire transfers and ACH payments move fast and are extremely difficult to reverse once they leave.
Step 5: The money disappears. The funds land in accounts controlled by the criminals — frequently routed through banks in Hong Kong, the UK, or other jurisdictions — and are quickly moved again. By the time anyone notices, the trail is cold.
The Five Main Flavors of BEC
1. CEO fraud. The classic: an email impersonating the CEO or another executive urgently requests a wire transfer, often with instructions to keep it confidential. Finance staff are the usual targets because they have both the authority and the desire to please the boss.
2. Invoice and vendor fraud. Attackers impersonate a legitimate supplier — sometimes from a compromised real account — and announce “updated” bank details for future payments. The business then willingly sends real invoice payments straight to the criminals. This is one of the costliest variants because the amounts are large and the deception can run for months.
3. Payroll diversion. An email pretending to be from an employee asks HR or payroll to change the bank account for direct deposit. The next paycheck goes to the scammer. These attacks often target school districts, hospitals, and mid-size companies.
4. Real estate wire fraud. Criminals monitor real estate transactions, then pose as the title company, agent, or attorney and send “revised” wiring instructions to the homebuyer. A buyer can lose an entire down payment — often hundreds of thousands of dollars — days before closing. The FBI has specifically warned that this version is on the rise.
5. Data theft. Instead of money, the attacker requests W-2 forms, employee personal data, or tax documents — often impersonating an executive asking HR for “a quick file.” The stolen data fuels identity theft and tax fraud.
Why It Works: The Psychology
BEC succeeds because it hacks people, not computers. Three psychological levers do the heavy lifting:
Authority. A request from the CEO short-circuits skepticism. Most employees are conditioned to comply quickly with executive instructions, not to interrogate them.
Urgency. “I need this done in the next 20 minutes” leaves no time to verify. The artificial deadline is the entire mechanism — remove it and the scam usually falls apart.
Secrecy. “Keep this between us for now” isolates the target from colleagues who would instantly spot the fraud. A two-minute conversation with a coworker kills most BEC attempts, which is exactly why the scammer forbids it.
Red Flags: The BEC Checklist
- Urgent, confidential payment requests by email. Especially from an executive, especially with a tight deadline, especially marked secret.
- Slightly wrong email addresses. Lookalike domains, misspelled names, or a display name that does not match the underlying address. Always expand the sender field and read the actual address.
- Changed payment instructions. Any email announcing new bank details for a vendor, or asking to reroute a payment, should be treated as hostile until proven otherwise.
- Unusual tone or phrasing. If the “CEO” suddenly writes in stilted English, skips their usual sign-off, or makes requests they never normally make, be suspicious.
- Requests that bypass normal process. “Don’t go through the usual approval chain” or “handle this yourself” is a major warning sign.
- Pressure not to verify. Any instruction not to call, not to ask questions, or not to tell colleagues exists for one reason.
- First-time wire destinations. Payments to a new account, especially overseas, deserve extra scrutiny.
- Real estate closings with emailed wiring instructions. Treat every set of emailed wire instructions as suspect — criminals specifically target homebuyers.
How to Verify: 8 Steps for Businesses and Individuals
- Verify out of band, every time. Before acting on any payment instruction received by email, confirm it through a second channel you trust: call the person on a known number, or walk to their office. Never use phone numbers or contact details from the suspicious email itself.
- Require dual approval for wires. No single employee should be able to initiate and release a wire transfer alone. A second pair of eyes defeats most BEC attempts.
- Establish a verification rule for changed payment details. Make it written policy: any change to vendor bank information requires verbal confirmation with a known contact before the first payment to the new account.
- Turn on multi-factor authentication everywhere — especially on email. MFA blocks the account-takeover route that makes the most convincing BEC attacks possible.
- Train everyone, not just finance. HR handles payroll changes; assistants handle executive requests. Run short, realistic phishing and BEC simulations so staff recognize the patterns.
- Create a culture where verification is praised. Employees must feel safe double-checking the CEO. The companies that get robbed are often the ones where questioning the boss feels career-limiting.
- For homebuyers: confirm wiring instructions by phone using a number you looked up independently — never one from an email. Consider it mandatory, not optional.
- Limit what attackers can learn. Reduce public details about who handles payments, vendor relationships, and executive travel schedules on websites and social media.
What to Do If Money Was Already Sent
Speed is everything — wire recalls are sometimes possible within the first 24 hours:
- Contact your bank immediately and request a wire recall or reversal. Ask for the fraud department, not general customer service.
- File a complaint with the FBI’s IC3 at ic3.gov right away, with all details: amounts, accounts, emails, and headers. The FBI’s Recovery Asset Team has helped recover funds when notified quickly.
- Preserve all evidence: the original emails with full headers, any related messages, and records of the transfer.
- Notify your cyber insurance carrier if your business has a policy.
- Check for broader compromise: if an account was actually hacked (not just spoofed), reset credentials, review email rules and forwarding settings the attacker may have created, and audit recent logins.
- Alert your actual vendors or partners if their identities were impersonated, so they can warn their other customers.
How to Report Business Email Compromise
- FBI Internet Crime Complaint Center: File at ic3.gov — this is the primary reporting channel for BEC, and the FBI explicitly asks victims to report quickly to aid fund recovery.
- FTC: Report at ReportFraud.ftc.gov.
- Your financial institution’s fraud department — immediately, by phone.
- Local FBI field office for large losses.
- Outside the U.S.: Report to your national cybercrime unit or financial fraud authority.
The Bottom Line on CEO Fraud and BEC
Business email compromise is not a technology problem with a technology solution — it is a trust problem, and trust is exactly what the criminals are counterfeiting. The defense is procedural, not technical: verify payment changes through a second channel, require two people for every wire, and build a workplace where nobody is ever punished for double-checking the boss. The email will always look real. The phone call to confirm takes two minutes. Make the call.
Sources
- Infosecurity Magazine, “Business Email Compromise Costs $55bn Over a Decade” (2026) — https://infosecurity-magazine.com/news/business-email-compromise-55bn/
- Nacha, “FBI’s IC3 Finds Almost $8.5 Billion Lost to Business Email Compromise in Last Three Years” (2025) — https://www.nacha.org/news/fbis-ic3-finds-almost-85-billion-lost-business-email-compromise-last-three-years
- Abnormal AI, “2024 FBI IC3 Report: Business Email Compromise Remains a Multi-Billion Dollar Threat” (2025) — https://abnormal.ai/blog/2024-fbi-ic3-report
- HousingWire, “Cybercrime resulted in record losses in 2024” (2025) — https://www.housingwire.com/articles/cybercrime-resulted-in-record-losses-in-2024-fbi-ic3-2024-report/
- FBI Internet Crime Complaint Center (IC3), reporting portal — https://www.ic3.gov
Last reviewed: October 2026
This article is for education only and is not financial or legal advice.