What's Happening Right Now
Business Email Compromise (BEC) has firmly cemented its position as the highest-grossing cybercrime globally. According to the FBI’s Internet Crime Complaint Center (IC3) 2025 report, BEC schemes resulted in over $3.1 billion in actual losses in the United States alone, with worldwide figures significantly higher. What makes this threat landscape uniquely dangerous in 2025 and 2026 is the widespread integration of generative AI. Attackers no longer rely on broken grammar or obvious typos to bypass defenses. Modern BEC campaigns use AI to perfectly mimic executive writing styles, adjust urgency levels, and generate context-aware correspondence that slips past traditional spam filters and human skepticism. For small and midsize enterprises with 10 to 500 employees, this shift is critical. Without dedicated security operations teams, your organization relies entirely on procedural rigor and layered technical controls to stop these financially devastating attacks.
How This Attack Works
BEC is rarely a technical breach in the traditional sense; it is a social engineering campaign that aligns with the MITRE ATT&CK framework under Initial Access and Resource Development. Here is the typical lifecycle:
First, attackers gather intelligence through public records, LinkedIn profiling, or targeted phishing campaigns to obtain valid credentials. They frequently target mid-level managers or administrative staff rather than the C-suite directly, as these accounts are easier to compromise but still carry enough authority to influence financial workflows.
Once inside, the threat actor monitors internal communications for weeks or months, learning approval hierarchies, vendor relationships, and payment cycles. This patient reconnaissance phase allows them to map exactly who needs to be impersonated and when to strike.
Next comes the fraudulent request. The attacker sends an email that appears to originate from a trusted executive, attorney, or established vendor. Thanks to AI drafting, the message reads naturally, references recent projects, and often includes a subtle sense of urgency—such as a time-sensitive acquisition or an urgent invoice correction.
The final step is the diversion. The recipient is instructed to update wire details, shift payroll deposits, or forward sensitive contracts. Because the request aligns with normal business operations and comes from a compromised or perfectly spoofed domain, finance teams often process the transfer before realizing the mistake. By the time verification occurs, the funds have already been moved through multiple accounts or converted into cryptocurrency.
Real-World Examples
The financial impact of BEC is not theoretical. In 2024, a midsize manufacturing firm lost $1.4 million after an attacker compromised the CEO’s email account and instructed the accounts payable team to redirect a vendor payment to a new banking entity. The email perfectly matched the executive’s tone, referenced an ongoing supply chain negotiation, and included a legitimate-looking PDF attachment with updated routing numbers.
Similarly, a regional law firm was targeted through a vendor impersonation scheme. Attackers posed as a bankruptcy trustee’s legal counsel, requesting an immediate wire transfer to settle a case. The firm’s staff verified the email domain visually but failed to initiate out-of-band verification. The $890,000 transfer was completed before the actual law firm could respond. These cases highlight a consistent pattern: technical email authentication was either misconfigured or bypassed, and human verification relied solely on visual inspection of the sender address.
Who Is Most at Risk
While large enterprises face sophisticated BEC campaigns, SMEs with 10 to 500 employees represent the primary target. These organizations typically lack dedicated IT security staff, operate with streamlined approval chains, and maintain closer financial workflows where a single employee can authorize significant transactions. Industries handling frequent wire transfers, such as construction, wholesale distribution, real estate, legal services, and manufacturing, face elevated exposure. Companies undergoing mergers, payroll restructuring, or vendor onboarding are also prime targets, as attackers exploit periods of organizational change to introduce fraudulent payment requests that blend into routine operations.
Warning Signs to Watch For
AI-driven BEC attacks are designed to look normal, but operational inconsistencies remain the most reliable indicators. Finance teams and managers should immediately flag requests that:
- Deviate from established payment workflows or bypass dual-approval requirements
- Introduce urgency with phrases like “handle this today” or “do not discuss with others”
- Request changes to banking details, invoice numbers, or vendor routing information via email alone
- Come from addresses with subtle domain variations (e.g., @company-support.com instead of @company.com)
- Include attachments or links that prompt credential entry or document editing in unfamiliar cloud environments
When in doubt, the request is suspect. Modern attackers rely on procedural fatigue; treating every financial deviation as a potential compromise until verified is the only sustainable posture.
How to Protect Your Business
Defeating BEC requires aligning technical controls with strict financial protocols, following guidance from NIST SP 800-63B and CIS Controls v8. Start by enforcing phishing-resistant multi-factor authentication across all email accounts. This means deploying FIDO2 security keys, Windows Hello, or passkeys—not SMS or voice calls, which are vulnerable to SIM swapping and relay attacks. Configure conditional access policies that block sign-ins from unfamiliar locations or devices without secondary verification.
Email infrastructure must be hardened with strict SPF, DKIM, and DMARC records set to reject or quarantine unauthorized messages. Implement domain-based message authentication (DANE) where supported, and deploy AI-aware email security gateways that analyze sender behavior and content anomalies rather than relying solely on signature-based filtering.
Most critically, establish out-of-band verification protocols for every financial transaction. This requires a secondary confirmation channel that operates completely outside email—such as a verified phone call to a known number, an in-person sign-off, or a secure internal messaging platform with end-to-end encryption. Finance teams should maintain a master vendor payment register updated only through controlled change requests, and any banking detail modification must require dual authorization from designated approvers who have never communicated with the requester via email.
Quick Action Checklist
- Enroll all finance, executive, and administrative accounts in phishing-resistant MFA (FIDO2 keys or passkeys)
- Publish and enforce DMARC with p=reject policy across all corporate domains
- Document and distribute out-of-band verification procedures requiring phone or in-person confirmation for any payment changes
- Implement dual-approval workflows for wire transfers exceeding $5,000
- Conduct a quarterly review of vendor banking details against original signed contracts
- Enable audit logging on email accounts and financial platforms to track credential usage and transfer approvals
Start Here This Week
Schedule a 30-minute meeting with your finance and operations leads to review current payment approval workflows. Identify every instance where banking details or wire instructions can be changed via email, and implement a mandatory out-of-band verification step before the end of the month. Enable phishing-resistant MFA for all users who process payments, and publish your DMARC rejection policy. These foundational controls align with CISA’s mitigation guidance and will immediately reduce your exposure to BEC fraud. Visit the FBI IC3 website to report any suspicious activity and subscribe to CISA’s alerts for ongoing threat intelligence.