Business Email Compromise: How One Fake Invoice Drains a Small Business Industry News

Business Email Compromise: How One Fake Invoice Drains a Small Business

When people picture a cyberattack that costs a small business real money, they usually picture ransomware: locked files, a countdown timer, a ransom note. That’s the version that makes the news. But if you look at where money actually leaves small companies and never comes back, a quieter attack does more damage. It doesn’t encrypt anything. It doesn’t set off alarms. It just convinces the right person to send a payment to the wrong account.

That attack is Business Email Compromise, usually shortened to BEC, and in its most common form it comes down to a single fraudulent invoice or a single “we changed our bank details” email. The FBI’s Internet Crime Complaint Center (IC3) has, for years, reported BEC and related wire fraud as one of the largest categories of reported financial loss, well ahead of ransomware by total dollars. It works because it targets a normal business process, paying an invoice, rather than a technical flaw. There is nothing to patch. The vulnerability is the workflow itself.

This post explains how a fake-invoice attack actually unfolds, why small and mid-sized businesses are the sweet spot for it, why the money is so hard to claw back once it’s gone, and the specific, boring controls that stop it cold. No hype, no scare tactics. Just the honest shape of the problem and what to do about it.

How business email compromise works

Strip away the jargon and BEC is a confidence trick delivered by email. The attacker’s goal is to get someone with the authority to move money to send it to an account the attacker controls. Everything else is setup.

There are two main ways the attacker gets into position. The first is account compromise: they actually get into a real mailbox, usually by phishing the password or buying stolen credentials, and then read the victim’s email from the inside. This is the dangerous version, because now the fraudulent message comes from a genuine address, sits inside a real conversation thread, and can be timed to a real invoice the recipient is already expecting. Attackers who get inside a mailbox often set up quiet inbox rules that auto-file or delete replies, so the real vendor’s “wait, we never changed our bank” message never reaches the person who needs to see it.

The second is spoofing or lookalike domains: the attacker never breaks in at all. They send mail that appears to come from a trusted party, either by forging the “From” address or by registering a domain that reads almost identically to the real one. A capital-I swapped for a lowercase-L, “.co” instead of “.com”, “billing-acme.com” instead of “acme.com”. At a glance, on a phone, mid-morning, it passes.

Once they’re in position, the payload is almost always one of two moves. Either a fake or altered invoice for goods or services, often a plausible amount for a vendor you really use, or a change-of-banking-details request: “We’ve switched banks, please update the account for our next payment.” Both point your money at the attacker. The genius of it, if you can call it that, is that nothing looks broken. No malware, no locked files. Just a routine payment, approved by a real employee, sent through your real bank.

One note before we go further: this article is general education, not legal or financial advice. Your bank’s recovery options and your own liability depend on your contracts, your jurisdiction, and how fast you move, so treat this as a map, not a substitute for talking to your bank and counsel when it counts.

Why SMBs are the sweet-spot target

It’s tempting to assume attackers chase big companies with big bank balances. Some do. But small and mid-sized businesses are hit constantly, and the reasons are structural, not bad luck.

The dollar amounts are still worth it. A single fraudulent wire in the tens of thousands is a routine, quiet payday for the attacker and a serious wound for a small company. They don’t need a Fortune 500 target when a five-figure invoice clears without friction.

The process controls are thinner. In a big company, a change to vendor banking details might route through a controller, an AP system with segregation of duties, and a verification step. In a ten-person business, the person who receives the invoice, approves it, and pays it is often the same person, working fast, trusting their inbox. There’s no second set of eyes by design, because there aren’t many eyes to spare.

The email security is often lighter. Larger organizations tend to have DMARC enforcement, mailbox monitoring, and mandatory MFA. Plenty of small businesses run on a basic email plan with none of that switched on, which makes both spoofing and account takeover meaningfully easier.

The relationships are informal and knowable. Attackers can learn who your vendors are, who signs off on payments, and how you talk to each other, from your website, your invoices, LinkedIn, and social media. A small business feels personal, and that familiarity is exactly what the attacker imitates. When “your regular contact at the supplier you paid last month” emails about that same invoice, the request doesn’t feel like an attack. It feels like Tuesday.

None of this means small businesses are careless. It means the attack is engineered to exploit how small businesses normally, reasonably, operate.

Why the money is so hard to recover

Here is the part that surprises people most, and the reason prevention matters so much more than response: once the wire goes out, getting it back is often a race you lose.

A wire transfer is designed to be fast and final. Unlike a credit-card charge, there’s no easy dispute-and-reverse button. Once the funds land in the attacker’s account, they typically move again within hours, hopping through mule accounts and frequently offshore, before anyone realizes what happened. If you catch it fast enough, a bank-to-bank recall request, and in the US the FBI’s Recovery Asset Team working through IC3, can sometimes freeze funds still sitting in the receiving account. “Fast enough” usually means hours to a couple of days, not weeks.

The problem is that most victims don’t notice for a while. The fraud is discovered when the real vendor calls asking where their payment is, or when the books get reconciled at month-end. By then the money is long gone and reconstituted. And because a real employee authorized the transfer, this often isn’t a straightforward “fraudulent transaction” from the bank’s point of view. You told the bank to send it. Whether insurance covers it depends entirely on your specific policy; social-engineering and fraudulent-instruction losses are frequently excluded or sharply limited unless you bought coverage for exactly this, so don’t assume you’re protected until you’ve read the policy.

The honest summary: recovery is possible but unreliable, and it hinges on speed you probably won’t have. That’s precisely why the whole game is prevention.

A plausible fake-invoice scenario

A twelve-person architecture firm works regularly with a structural-engineering subcontractor they’ve used for years. The firm’s bookkeeper, who also handles reception and half a dozen other things, pays that subcontractor’s invoices every month without a second thought.

One morning an email arrives in an existing thread about a current project. It’s from the subcontractor’s usual contact, same name, same signature, same friendly tone. The message says their firm has switched banks and includes an updated invoice with new account and routing numbers, plus a light, believable nudge: “Sorry for the short notice, we’re trying to get everything squared away before the end of the month, so if you could route the current invoice to the new account that’d be great.” The amount matches what the firm expected to owe. The PDF looks right.

What the bookkeeper can’t see is that the subcontractor’s mailbox was compromised a week earlier through a phishing email. The attacker read enough of the real thread to blend in perfectly, quietly created an inbox rule so any reply from the architecture firm skips the real contact’s inbox, and waited for a live invoice to hijack. The “new bank” is a mule account the attacker controls.

The bookkeeper, busy and trusting a familiar sender, updates the payment details and sends the wire. There’s no alert, nothing breaks. Two weeks later the real subcontractor calls, politely confused about why last month’s invoice hasn’t been paid. That call is the moment the firm learns it was defrauded, and by then the money has moved twice and cleared out.

Notice what would have stopped it, and how ordinary it is. Not a firewall. Not antivirus. A single phone call to the number the firm already had on file, asking, “Did you change your bank details?” One out-of-band verification and the whole scheme collapses.

The common ways businesses get hit

The failure patterns are predictable, which is good news, because predictable problems are preventable ones.

  • Trusting the “From” name instead of verifying. A familiar sender name feels like proof of identity. It isn’t. Both spoofing and a genuinely compromised account produce mail that looks completely legitimate.
  • Acting on banking-change requests by email alone. A change to where money goes is the single highest-risk request in your business, and it’s routinely honored on the strength of one email, with no independent check.
  • Replying to the email to “confirm.” If the account is compromised or the domain is a lookalike, your confirmation goes straight to the attacker, who happily confirms. Verification has to happen on a separate channel.
  • Verifying using contact details from the suspicious message. The phone number or “new contact” in the fraudulent email routes to the fraudster. Only a number you already had counts.
  • No second approver for payment changes. When one person can receive, approve, and pay, there’s no point at which a fresh set of eyes catches the anomaly.
  • Urgency doing the attacker’s work. “Before end of month,” “the boss needs this today,” “we’ll lose the discount.” Manufactured time pressure is designed to skip the verification step, and it usually works.
  • Email authentication switched off. Without DMARC, SPF, and DKIM configured, outright spoofing of your domain (and weaker filtering of inbound spoofs) is far easier than it needs to be.
  • No MFA on email. A phished password with no second factor is a wide-open mailbox, and a wide-open mailbox is how the most convincing version of this attack begins.

What to actually do

You do not need an enterprise security budget to shut down the overwhelming majority of BEC attempts. You need a few controls and one cultural habit, applied consistently. Here’s the honest short list, roughly in order of impact.

Require out-of-band verification for any payment or banking change. This is the single most effective control, and it’s nearly free. Any time an invoice, an account number, or routing details change, or any new payee is added, someone calls the vendor back on a phone number you already had on file, never a number from the request itself, and confirms person-to-person. Make it a written rule, not a judgment call: banking changes are never actioned on email alone, no exceptions, no matter who seems to be asking or how urgent it feels.

Put dual approval on payment changes and new payees. No single person should be able to change where money goes and then send it. Require a second, named approver for any banking-detail change, new vendor, or wire above a set threshold. This one structural change removes the “busy person acting alone” failure that most fake-invoice attacks depend on.

Turn on MFA for all email accounts. Multi-factor authentication is the difference between “they phished a password” and “they got into the mailbox.” It is the highest-leverage technical control you can enable, it’s included in most business email plans, and it directly blocks the account-compromise version of BEC, the most convincing kind.

Configure DMARC, SPF, and DKIM on your domain. These three email-authentication standards make it much harder for anyone to spoof your business’s domain to your customers and staff, and they improve filtering of spoofed inbound mail. Set SPF and DKIM, then bring DMARC to an enforcement policy (quarantine or reject) rather than leaving it in monitor-only forever. This protects your name in your customers’ inboxes as much as your own.

Train the people who touch money to recognize the pressure play. The staff most targeted, bookkeepers, AP clerks, office managers, owners, should know the red flags by heart: a change in banking details, urgency and secrecy, a request to break normal process “just this once,” a reply-to address that’s subtly off, a nudge to skip the callback. The goal isn’t suspicion of every email; it’s a hard-wired pause on the specific requests that move money. “We verify banking changes by phone, always” should be a point of pride, not friction.

Layered together, these controls mean an attacker has to defeat your email authentication, your MFA, your dual approval, and a human being who picks up the phone. That’s a wall most of them won’t bother climbing when an easier target is one email away.

A wire-fraud prevention checklist

Here’s a plain checklist you can sanity-check your business against. A “no” in the top few lines is the loud one; those are where the money actually walks out the door.

Control                                                       In place?  Tested?
────────────────────────────────────────────────────────────  ─────────  ──────
Banking-change / new-payee requests verified by PHONE          [ ]        [ ]
  - Callback uses a number already on file (never the email)   [ ]        [ ]
Dual approval required for payment changes and wires           [ ]        [ ]
  - Second named approver above a set dollar threshold         [ ]        [ ]
MFA enabled on ALL email accounts (not just admins)            [ ]        [ ]
SPF configured for your domain                                 [ ]        [ ]
DKIM configured for your domain                                [ ]        [ ]
DMARC set to enforcement (quarantine/reject), not monitor-only [ ]        [ ]
Staff who touch money trained on BEC red flags                 [ ]        [ ]
  - Urgency, secrecy, "just this once," banking-detail changes [ ]        [ ]
Written policy: no banking changes on email alone, ever        [ ]        [ ]
Incident plan: who to call at the bank + report to IC3, fast   [ ]        [ ]

If the first two blocks aren’t checked, fix those before anything else. Out-of-band verification and dual approval are the controls that stop the loss even when the email is flawless, and the email will sometimes be flawless.

Where to start if this feels like a lot

None of these controls is technically hard. The reason BEC keeps working isn’t that the fixes are complicated; it’s that they’re easy to leave for later, until the month a fake invoice clears and the money doesn’t come back. If you take one thing from this post, let it be the cheapest control of all: any change to where money goes gets verified by a phone call to a number you already had, every single time.

This is the kind of thing we help small and mid-sized businesses put in place, without turning it into a compliance ordeal. Setting up DMARC, SPF, and DKIM correctly, switching on MFA across your mailboxes, and, just as importantly, writing the dual-approval and verified-callback rules into a policy your team actually follows. Our Cyber Essentials package includes a straightforward email and wire-fraud prevention policy built for exactly this, so the “we verify banking changes by phone” rule is written down, understood, and consistently applied rather than living in one careful person’s head.

If you’re not sure where you stand, or you just want someone to check whether your domain is spoofable and your payment process has a real second set of eyes, email support@breachsecurity.io and tell us roughly what you do and how many people are on staff. We’ll tell you honestly which of these controls you’re missing and which you already have covered, even when the answer is “less than you feared.”

Want to make sure your payment process can’t be hijacked by a fake invoice? Email us and we will scope it in 24 hours.

support@breachsecurity.io →

Get the free Acceptable Use Policy template for your business. No sign-up form, just an email.

Free AUP Template →