Email Security

Business Email Compromise: Protect Your Business

HB
HMC Bot
7 min read

What Is Business Email Compromise?

Business Email Compromise (BEC) is a targeted form of email fraud where attackers impersonate a trusted person — a CEO, supplier, solicitor or colleague — to trick someone into transferring money, sharing sensitive data or changing payment details. Unlike mass phishing campaigns that cast a wide net, BEC attacks are carefully researched and personalised, making them extremely difficult to detect.

BEC is consistently one of the most financially damaging cyber threats in Australia. The ACSC reported that Australians lost over $79 million to BEC scams in the 2022–23 financial year. The average loss per incident for businesses was approximately $64,000 — and many losses are never recovered because the funds are moved offshore within hours.

How BEC Attacks Work

BEC attacks generally follow a pattern: the attacker gains intelligence about your business (often through breached credentials, social media or prior phishing), then crafts a convincing email that exploits trust and urgency. There are several common variants.

CEO Fraud (Executive Impersonation)

The attacker spoofs or compromises the email account of a senior executive and sends an urgent request to a finance team member. Typical messages include “I need you to process this payment urgently — I’m in a meeting and can’t discuss by phone.” The urgency and authority make it hard for staff to question the request.

Invoice Interception and Redirection

This is the most common BEC variant in Australia. The attacker either compromises a supplier’s email or creates a lookalike domain, then sends a legitimate-looking invoice with updated bank details. The paying business transfers funds to the attacker’s account, often without realising the fraud until the real supplier chases the overdue payment weeks later.

Account Compromise

Rather than spoofing an email address, the attacker gains actual access to a staff member’s email account (usually through phishing or credential stuffing). From inside the legitimate account, they monitor conversations, learn invoicing patterns and insert themselves at the right moment to redirect a payment.

Solicitor or Conveyancer Impersonation

Particularly common in property transactions, the attacker poses as a solicitor or conveyancer and provides fraudulent trust account details for settlement payments. Losses in these cases often run into hundreds of thousands of dollars.

Warning Signs of a BEC Attack

Train your team to watch for these red flags:

  • Unexpected requests to change bank account or payment details
  • Urgency or pressure to bypass normal approval processes
  • Requests to keep a payment confidential
  • Slight variations in email addresses or domain names (e.g., @company.com vs @cornpany.com)
  • Emails that arrive outside normal business hours from someone who usually works standard hours
  • Changes in tone, language or formatting from a known sender
  • Requests to pay via unusual methods (gift cards, cryptocurrency)

How to Protect Your Business

1. Implement Email Authentication

Configure SPF, DKIM and DMARC on your email domain. These protocols make it significantly harder for attackers to send emails that appear to come from your domain. DMARC with a reject policy is the gold standard — it tells receiving mail servers to block unauthenticated emails outright.

2. Establish Payment Verification Procedures

This is the single most effective defence against invoice fraud. Implement a mandatory policy:

  • Any request to change bank details must be verified by phone using a known number (not the number in the email)
  • Payments above a defined threshold require dual authorisation
  • New suppliers must go through a documented onboarding process that includes bank detail verification
  • Never process urgent payment changes based solely on an email request

3. Enable Multi-Factor Authentication

MFA on all email accounts is critical. If an attacker phishes a password, MFA prevents them from logging in and monitoring your conversations. Prioritise MFA on Microsoft 365, Google Workspace, and any system involved in financial transactions.

4. Train Your Staff Regularly

BEC attacks exploit human trust, not technical vulnerabilities. Regular security awareness training that includes BEC-specific scenarios is essential. Focus on:

  • How to verify unusual requests (phone callback on a known number)
  • How to spot email impersonation (checking the actual sender address, not just the display name)
  • The importance of slowing down when something feels urgent
  • Creating a blame-free culture where staff feel safe reporting suspicious emails

5. Implement Technical Controls

  • External email banners: Configure your email system to flag messages from outside your organisation with a visible banner. This helps staff immediately identify external emails that may be impersonating internal contacts.
  • Lookalike domain monitoring: Use free tools or your domain registrar’s monitoring service to detect newly registered domains that closely resemble yours.
  • Email forwarding rules: Regularly audit mailbox rules. Attackers who compromise an account often create forwarding rules to silently copy emails to an external address.
  • Conditional access policies: If you use Microsoft 365 or Google Workspace, configure policies that restrict access by location, device and risk level.

6. Strengthen Payment Controls

  • Separate the person who approves payments from the person who processes them
  • Use your accounting software’s built-in approval workflows rather than ad-hoc email requests
  • For large transactions, implement a cooling-off period before funds are released
  • Reconcile accounts payable regularly to catch anomalies early

What to Do If You Suspect a BEC Attack

  1. Act immediately. Contact your bank and request a recall of the funds. Speed is critical — you may have only hours before the money is moved offshore.
  2. Preserve evidence. Do not delete the fraudulent email. Save headers, attachments and any related correspondence.
  3. Report it. Lodge a report with the ACSC via ReportCyber (cyber.gov.au) and a police report via your state police.
  4. Notify affected parties. If customer or supplier data was involved, you may have notification obligations under the Notifiable Data Breaches scheme.
  5. Investigate the compromise. Determine how the attacker gained access — was it a phished credential, a compromised supplier, or a spoofed domain? Fix the root cause to prevent recurrence.

“The best defence against BEC is a culture where no one feels embarrassed to pick up the phone and verify a payment request — even if it comes from the CEO.”

Email security controls like SPF, DKIM, DMARC, external email banners and conditional access policies all sit within the Infrastructure pillar of the IDIA framework. IDIA organises every cybersecurity control into four pillars — Identity, Data, Infrastructure and Assurance — so you can see exactly where BEC defences fit alongside the rest of your security posture. MFA and access controls fall under Identity, while payment verification procedures and staff training sit under Assurance. This structure makes it easy to identify which pillar has gaps and prioritise fixes without losing sight of the bigger picture.

Test Your Email Security Posture

BEC defences span technology, processes and people. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical security domains in under 10 minutes — including email authentication, payment verification procedures and staff awareness. You will get a clear view of where your business is vulnerable to email-based attacks and actionable recommendations tailored to your size and industry.

Share

How secure is your business?

Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.

Try CYBER9 Free