Business email compromise: the scam built for 15-person companies
No malware, no hacking tools, just email and patience. How BEC actually unfolds at small businesses and the 4 controls that stop it.
· Jake Schaaf, Founder of Atticus Rowan
The email asking to update the payment account arrives on the Thursday before a real invoice is due. It comes from the vendor’s actual project contact, replies within the actual thread, uses the vendor’s actual signature block and references the actual PO number. The only thing wrong with it is the routing number. Accounts payable updates the record, the payment goes out Friday and the real vendor calls 3 weeks later asking where their money is.
That is business email compromise. No malware, no ransomware note, no systems down. Just email, patience and a wire that is unrecoverable by the time anyone notices.
Why this scam is built for the 10-30 user business
BEC is the most expensive cybercrime category in America and has been for years. The FBI’s Internet Crime Complaint Center logged $2.9 billion in reported BEC losses in 2023 alone, and IC3 only sees the incidents people report. For comparison, that figure dwarfs reported ransomware losses in the same period.
The headlines go to the million-dollar corporate cases, but the structure of the scam favors small targets:
- 1 person runs payables. There is no second approver, so 1 convinced human moves the money.
- Payment changes happen informally. A vendor emailing “we switched banks” is normal, and there is no written procedure that says what happens next.
- The owner’s word is final. An email that appears to come from the owner saying “wire this today, I am traveling” short-circuits whatever process exists.
- Nobody is watching the mailbox rules. Attackers hide in plain sight for weeks because no one reviews what is happening inside the email tenant.
Typical small business losses run from tens of thousands to the low hundreds of thousands of dollars per incident. For a 15-person company, 1 diverted progress payment can exceed a year of IT budget.
How the scam actually unfolds
Understanding the sequence matters, because each stage is a chance to break it.
Stage 1: get into a mailbox, or get next to one. Either the attacker phishes credentials from you or your vendor and logs into a real mailbox, or they register a lookalike domain, the vendor’s name with 2 letters swapped, and rely on nobody reading addresses closely. Mailbox compromise is worse and more common than most owners assume.
Stage 2: watch silently. This is the part that surprises people. The attacker does nothing for 2 to 6 weeks. They read threads, learn who approves payments, learn the vendors, learn the invoice cadence and the tone people use with each other. They often set a mailbox rule that forwards or hides messages so the real user notices nothing.
Stage 3: strike inside a real transaction. The payment-change request lands attached to a genuine invoice, at a believable moment, in a live thread. This is why BEC succeeds against smart, careful people. Nothing about the message looks new, because almost none of it is.
Stage 4: move the money fast. Funds land in a domestic mule account and are moved again within hours. Recovery windows are measured in the first 24 to 72 hours, and the odds fall steeply after that.
The 4 controls that actually stop it
None of these require new software. That is the uncomfortable part. BEC defenses are mostly process, which is exactly why they get skipped.
1. Out-of-band verification for every payment change, no exceptions. Any request to change banking details, by any vendor, in any format, gets a phone call to a number you already had on file, never a number from the email or the invoice. Write this down as policy, tell your vendors it applies to them and tell your own customers to expect the same from you. This single habit defeats the core of the scam.
2. Written finance rules that survive urgency. Two-person approval above a dollar threshold that makes sense for your business, and a standing rule that no payment instruction delivered only by email gets executed same-day, even one from the owner. Especially one from the owner. Urgency is the attacker’s main tool, so the process has to make urgency powerless.
3. Mailbox rule and sign-in audits. Attacker-created inbox rules, forwarding to external addresses, hiding replies in RSS folders, are the most reliable fingerprint of an active compromise. Someone should review mailbox rules and unusual sign-in activity across the tenant on a regular cadence. If nobody is looking, stage 2 lasts as long as the attacker wants.
4. MFA on every account, enforced. MFA does not stop the lookalike-domain variant, but it slams the door on the mailbox-compromise variant, which is the one that produces the most convincing frauds. If MFA is still on your someday list, our 3-week rollout playbook exists precisely because of this scam.
Alongside those 4, publish DMARC, SPF and DKIM records for your own domain. Authentication does not stop every impersonation, but it makes the crude spoofing variants fail and it protects your customers from wires sent in your name, which is a conversation no owner wants to have.
If it happens anyway
Speed decides outcomes. Call your bank’s fraud department immediately and ask them to initiate a recall and notify the receiving bank. File with IC3 at ic3.gov the same day, because the FBI’s Financial Fraud Kill Chain can sometimes freeze funds if engaged within about 72 hours. Notify your cyber insurer, preserve the emails intact and assume the mailbox is still compromised until someone verifies otherwise, which means password resets, session revocation and a rules audit before the account touches money again.
One more call belongs on that list: your insurance agent, before anything happens. BEC losses often fall under crime coverage or a social engineering rider rather than the main cyber policy, and social engineering sublimits are frequently a fraction of the headline limit, $50,000 or $100,000 on a policy that advertises $1 million. Plenty of businesses discover the gap only after the wire is gone. Ask specifically how a fraudulently induced transfer would be covered, in writing, and whether the insurer requires verification procedures as a condition of that coverage. Some now do, which makes control number 1 above a contractual obligation as well as a good idea.
Then have the honest internal conversation. In nearly every BEC case we have reviewed, the person who sent the wire followed the process the business actually had. The failure was that the process was never designed for an adversary.
Atticus Rowan builds these controls, the email security, the tenant monitoring and the finance-facing procedures, as standard parts of how we manage security for small businesses. If you cannot say with confidence what would happen today if a vendor emailed you new banking details, talk to us before someone else tests it for you.
Related insights
More on Incident response →July 30, 2026
Wire fraud hit your business: the first 48 hours
A step-by-step response plan for the first 48 hours after a fraudulent wire transfer leaves your account, from bank recall to IC3 to preserving evidence.
July 2, 2026
The cybersecurity tabletop exercise that produces decisions, not a filed PDF
How to run a cybersecurity tabletop exercise that surfaces real gaps and ends with named owners and dates, instead of a 3-hour meeting that produces a PDF for the auditor and nothing else.
April 20, 2026
Post-incident review, what to document, what to change
A practical format for the post-incident review that produces operational improvements instead of blame, scar-tissue over-correction or a forgotten document nobody reads again.