Skip to content
All resources
CybersecurityOctober 21, 2025·6 min read

Business Email Compromise: How the Money Gets Out

No malware, no alarms. Just a stolen password, weeks of quiet reading, and one wire that leaves. Here's how invoice fraud runs, and what breaks the chain.

By Cohesive Security

A vendor you’ve paid for years sends an invoice. Right logo, right amount, and it lands in the same thread you’ve been replying to all month. The only thing that changed is the bank account, plus a line saying their old bank was acquired.

Your bookkeeper pays it, because that’s the job. Two weeks later the real vendor calls asking where the money is. By then it has moved through two accounts and left the country.

Nobody in that story clicked a virus. No malware ran, no firewall was breached, no alarm went off. The gap between what people picture and what actually happens is exactly why it works, so it’s worth walking through slowly.

Key takeaways:

  • Business email compromise doesn’t involve malware. It’s a genuine login and a well-written email, so spam filters and antivirus have nothing to flag.
  • One policy stops most of it: any change to payment details gets confirmed by phone, on a number you already had on file, never one printed in the email.
  • Multi-factor authentication (MFA) on email is the highest-value control here, because the whole scam depends on someone signing in as a person you trust.
  • If a wire has already gone out, hours matter. Call the bank and request a recall the same day, then file at ic3.gov. Fraudulent transfers can sometimes be frozen, but only when they’re reported fast.

Step one: a login, not a break-in

The way in is almost always a password. Someone reused a work password on a site that later leaked it, or typed their credentials into a convincing copy of the Microsoft 365 sign-in page after an email about a shared document.

From the mail system’s point of view, what happens next is unremarkable: a valid username and password arrive, and a session opens. No exploit to detect, no file to quarantine. That’s why MFA on email matters more than almost anything else you could buy. It makes a correct password insufficient.

Step two: weeks of reading

Here’s the part that surprises people. The attacker usually does nothing at first. They read.

They learn who approves payments and who actually sends them, that invoices arrive as PDFs on the 15th, that one vendor has a large payment due at quarter end, and that nobody in your office uses the phone for this.

That’s why the eventual message doesn’t read like a scam. It was written by someone who has read a year of your correspondence and can imitate it.

Step three: the inbox rule you’ll never see

Before the ask goes out, the attacker arranges for you not to find out. They set a rule in the mailbox that quietly handles incoming mail: forwarding it out, deleting it, or moving it somewhere nobody looks.

Microsoft documents the pattern in its guidance on suspicious inbox manipulation rules: attackers move messages into a low-traffic folder such as RSS, mark them read, and often filter on keywords like “invoice” so only the risky replies vanish.

The effect is brutal. When the real vendor writes back to say “we haven’t changed banks,” that reply never reaches anyone who could stop the payment.

Step four: the message that moves the money

The ask arrives when a payment is genuinely due, which is the whole trick. It isn’t a strange request out of nowhere. It’s a routine request at a routine moment, with one detail changed.

It comes one of two ways. Either from the mailbox they already control, so the address is perfect, or from a domain that looks right at a glance: a swapped letter, an added hyphen, “.co” instead of “.com”. Our domain lookalike checker shows which near-misses of your own name are already registered, usually a sobering few minutes.

Check the other half while you’re there: whether a stranger can send mail claiming to be from your exact domain. The FTC’s business email imposters guidance puts email authentication first, and our email security checker answers that in about thirty seconds.

Why the tools you already pay for don’t catch it

Run the chain past your defenses and see what there is to object to: a correct password, a normal sign-in, an email with no attachment and no link. Filters judge attachments, links, and sender reputation, and this attack brings none of them, which is why it stays expensive.

In the FBI’s Internet Crime Complaint Center annual report covering 2024, business email compromise accounted for 21,442 complaints and $2,770,151,146 in reported losses, second only to investment fraud among all crime types that year.

It concentrates on businesses that move money on trust and on deadlines: financial firms moving client funds, law firms wiring proceeds at a closing, and anyone with a payables process and a familiar list of vendors.

Five controls, roughly in the order we’d do them

  1. MFA on every email account. No exceptions for the owner or for the person who finds it annoying. This is what breaks step one.
  2. A callback rule for payment changes. Any change to bank details, any vendor, any amount, gets verified by voice on a number from your own records. IC3’s BEC guidance says the same: use a secondary channel to verify requests to change account information. Write it down so nobody has to be brave enough to question the boss.
  3. Alerting on mailbox rules and forwarding. Microsoft 365 and Google Workspace can both alert when a new forwarding rule appears. Automated monitoring catches it at 2 a.m., someone reviews it in the morning, and that’s fast enough when the alternative is three weeks.
  4. Watch for lookalike domains. Register the obvious misspellings of your own, and know what’s already out there.
  5. Split approval from payment. Whoever authorizes a payment shouldn’t be the one who sends it. That’s an afternoon of rewriting a process, not a purchase, and it catches what everything above misses.

If the wire already went out

Call your bank first, before anything else, and ask them to recall the transfer. IC3 tells victims to request a recall along with a Hold Harmless Letter or Letter of Indemnity, and says acting quickly may reduce or eliminate the loss. Then file at ic3.gov regardless of the amount, and report it to the FTC at ReportFraud.ftc.gov.

That isn’t a formality. In 2024 the FBI’s Financial Fraud Kill Chain was initiated on 3,020 complaints covering $848.4 million in attempted theft and succeeded 66% of the time, freezing $469.1 million domestically and $92.5 million internationally. It works when the report comes in fast and does very little a month late.

Then deal with the mailbox: change the password, sign out every session, delete the rule, and look at what else sat in that account while a stranger had it open. Warn everyone on the thread, including the real vendor, whose mailbox may be the compromised one.

The part that has to keep running

Plenty of this is do-it-yourself. Turning on MFA, writing the callback policy, telling your team it applies to messages from you: none of that requires hiring anyone.

What doesn’t stay done on its own is the watching: forwarding-rule alerts somebody actually reads, sign-ins noticed when they come from the wrong place, lookalike domains registered months after you last checked. That part is what our cybersecurity service covers.

If you want a straight answer about how exposed your email is right now, we offer a free assessment, or send the question to hello@cohesivesecurity.com.

#business email compromise#wire fraud#phishing#MFA#email security

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.