EMAIL SECURITY RESOURCE
Business Email Compromise: How Fake Executive and Invoice Scams Work
A fraudulent email does not have to look suspicious. Business email compromise attacks
often imitate executives, vendors, attorneys, accounting departments, or existing email
conversations to convince someone to send money or disclose sensitive information.
Understanding how these attacks work, and establishing a few simple verification
procedures, can dramatically reduce the risk.
Quick Take
- Business email compromise, or BEC, relies primarily on trust and impersonation.
- Attackers may impersonate executives, vendors, clients, or financial institutions.
- Some attacks originate from genuinely compromised email accounts.
- MFA helps protect accounts, but it cannot prevent an employee from voluntarily approving a fraudulent payment.
- Payment and banking changes should always be verified using a method other than the email requesting the change.
What Is Business Email Compromise?
Business email compromise is a form of social engineering in which an attacker uses email
or another trusted communication channel to impersonate someone the recipient expects to
hear from.
The attacker’s goal is usually financial fraud, credential theft, sensitive information,
or access to additional business systems.
Unlike traditional phishing emails that may contain obvious spelling mistakes or suspicious
attachments, modern BEC messages can look extremely convincing. Attackers may know the names
of executives, vendors, employees, projects, or customers before making contact.
How Business Email Compromise Usually Works
1. Executive Impersonation
An employee receives what appears to be a message from the CEO, CFO, owner, or another
executive requesting an urgent payment, wire transfer, gift-card purchase, document, or
other unusual action.
The request often creates artificial urgency:
- “I’m heading into a meeting and need this handled immediately.”
- “Please keep this confidential until the transaction is complete.”
- “I’m traveling and cannot call right now.”
2. Fake Vendor or Invoice Requests
Attackers may impersonate a trusted vendor and submit a realistic-looking invoice or request
that future payments be sent to a different bank account.
In some cases, the attacker has researched the relationship between the two businesses.
In others, a vendor’s real email account has been compromised, allowing the attacker to
insert fraudulent payment instructions into an existing conversation.
3. Bank Account Change Fraud
One of the most dangerous BEC scenarios is a request to change banking or ACH information.
The email may appear to come from a long-standing vendor, employee, executive, or customer.
Once the payment is sent to the attacker’s account, recovering the money can be difficult
or impossible.
4. Hijacked Email Conversations
Some BEC attacks begin after a legitimate Microsoft 365 or other email account has already
been compromised.
The attacker can read previous conversations, understand business relationships, learn how
employees communicate, and wait for the right moment to insert fraudulent instructions.
Because the message comes from a real account and may appear inside an existing email thread,
employees may have very little reason to suspect fraud.
5. Lookalike Domains and Sender Names
An attacker does not always need to compromise a real account. They may register a domain
that looks nearly identical to a legitimate company domain or simply configure the sender
name to resemble someone familiar.
For example, a recipient may notice the display name “John Smith” but overlook a slightly
altered email address.
The Most Important Rule
Never approve a new payment destination or bank-account change using email alone.
Verify the request using a known phone number, established vendor contact, or another
communication method that did not originate from the email requesting the change.
Why MFA Alone Does Not Stop Business Email Compromise
Multifactor authentication is an important security control, but BEC is often a human
verification problem rather than purely an account-security problem.
MFA can make it harder for an attacker to compromise an email account. It cannot prevent
an employee from voluntarily sending money after receiving a convincing fraudulent request.
Modern attacks may also use phishing techniques designed to steal authenticated sessions
or trick users into approving authentication requests.
That is why businesses need both technical controls and strong financial-verification
procedures.
Warning Signs Employees Should Recognize
- An unexpected request to send money urgently
- A new bank account or ACH destination
- An executive asking to bypass normal approval procedures
- A request for secrecy or confidentiality
- A vendor suddenly changing payment instructions
- An unusual reply-to address
- A slightly misspelled company domain
- A change in writing style or tone
- An unexpected request for payroll, tax, or employee information
- Pressure to act before someone can independently verify the request
Five Controls Every Business Should Have
- Verify banking changes outside email.
Call the vendor using a previously verified phone number. - Require dual approval for significant payments.
One person should not be able to initiate and approve a high-value financial transaction alone. - Train employees to recognize impersonation.
Security awareness training should include realistic scenarios involving executives,
vendors, payroll, and invoices. - Protect Microsoft 365 accounts.
Use MFA, Conditional Access where appropriate, strong email-security controls, endpoint
protection, and monitoring for suspicious sign-ins. - Create an easy verification culture.
Employees should never feel uncomfortable calling an executive, vendor, or PCC to confirm
an unusual request.
CURRENT THREAT EXAMPLE
Executive and Invoice Impersonation Remains an Active Threat
Recent Microsoft security research continues to show attackers using executive
impersonation, realistic invoices, lookalike domains, fabricated email conversations,
and social engineering to target organizations with fraudulent payment requests.
The technology behind these attacks changes, but the underlying defense remains the same:
independently verify unusual financial requests before money is sent.
What To Do If You Suspect Business Email Compromise
If you receive a suspicious message, do not reply, click links, open attachments, or follow
payment instructions until the request has been independently verified.
Contact PCC immediately if:
- You believe an email account may have been compromised
- An employee entered Microsoft credentials into a suspicious website
- A suspicious MFA request was approved
- Fraudulent payment instructions were received
- A wire or ACH payment may already have been sent
If money has already been transferred, contact your bank or financial institution immediately
in addition to contacting PCC. Time can be critical when attempting to stop or recover a
fraudulent payment.
How PCC Helps Reduce Business Email Compromise Risk
Business email compromise cannot be addressed with a single security product.
Effective protection requires multiple layers.
Depending on the client’s environment, Professional Computer Concepts may use controls such as:
- Microsoft 365 security configuration and monitoring
- Multifactor authentication
- Conditional Access
- Email-security and impersonation protections
- Endpoint detection and response
- DNS and web filtering
- Security awareness training and phishing simulations
- Dark web monitoring
- Security reviews and ongoing technology management
Technology reduces risk, but employees and business processes remain an important part of the defense.
Unsure Whether a Payment Request Is Legitimate?
Stop before sending money. PCC clients can contact our support team and ask us to help verify suspicious email activity or unusual Microsoft 365 behavior.
It is better to verify a legitimate request than discover a fraudulent one after the payment has been sent.
