IT Insights
Business Email Compromise: How Small Businesses Get Tricked

Business email compromise rarely begins with an obvious virus warning. It looks like an ordinary request from a boss, vendor, customer, title company, or payroll provider. The message asks someone to change bank details, buy gift cards, release tax documents, or keep a transaction quiet.
The attacker does not need perfect access to succeed. A look-alike domain, a compromised vendor mailbox, or a believable signature can be enough when the request arrives at the right moment.
The strongest control is a second way to verify
Any request that changes where money goes should be confirmed through a known phone number or an established approval process. Do not use the number in the questionable email. The same rule applies to payroll changes, wire instructions, direct-deposit updates, and requests for sensitive employee or customer records.
This is a business process, not merely an IT setting. Technical controls reduce the number of malicious messages that arrive, but they cannot decide whether an unusual payment request makes sense.
Signs worth slowing down for
- A familiar name with a slightly different email domain
- A sudden request to use a new bank account
- Pressure to act quickly or avoid the normal approval chain
- A conversation that changes tone, spelling, or signature details
- Unexpected forwarding rules or messages missing from the sent folder
- A login alert from a location the user does not recognize
Technical protections still matter
Use multifactor authentication, block legacy sign-in methods, maintain SPF, DKIM, and DMARC, and monitor for unusual mailbox rules. Limit who can change payment information and who can see the data an attacker would use to make a request believable.
If money was sent
Call the bank or payment provider immediately and ask about a recall or fraud hold. Then preserve the emails and account logs, secure the affected mailbox, notify the appropriate insurer or counsel, and report the incident. Speed matters; waiting for a complete technical investigation can reduce the chance of recovering funds.
Make verification normal
Employees are more likely to stop a fraudulent request when verification is expected and supported by management. A two-minute phone call should never be treated as an inconvenience when the alternative is sending money to the wrong account.