All Systems Operational [email protected] +1 213-245-6566 Los Angeles, CA  ·  Remote Nationwide
Back to Insights
Cybersecurity

Business Email Compromise: How Wire Fraud Actually Happens

AventixIT
AventixIT Security Team
August 1, 2026  ·  8 min read
A finance manager reviewing a suspicious payment request on a laptop

Ransomware gets the attention because it is loud. Business email compromise is quieter, uses no malware at all, and costs businesses considerably more money every year.

There is nothing to detect in the usual sense. No file is encrypted, no payload executes, no antivirus alert fires. Someone signs in to a mailbox with valid credentials, reads quietly for a few weeks, and then sends a single convincing email at exactly the right moment. The money leaves through a payment your own finance team authorises.

The short version

  • BEC uses legitimate logins, not malware — endpoint protection cannot see it.
  • Attackers typically read a mailbox for two to six weeks before acting, learning tone, timing, and approval chains.
  • The tell is almost always a mailbox rule quietly diverting replies so the real party never notices.
  • Real estate, escrow, title, legal, and accounting firms are targeted hardest because they move large sums on scheduled dates.
  • The two controls that stop it: phishing-resistant MFA, and out-of-band verbal verification of any banking change.
How a business email compromise unfolds Access Phished credentials ora stolen session token Watch Weeks of silent reading.No changes made Hide Inbox rules divertreplies to a folder Strike Invoice or wire requestat a plausible moment Vanish Funds moved withinhours of transfer
Nothing is encrypted and no malware runs. The entire attack is a legitimate login used patiently, which is why antivirus never sees it.

How the attack actually unfolds

Step one: a working login

Access usually comes from a convincing fake Microsoft 365 sign-in page. The user enters credentials and, increasingly, approves the MFA prompt too — because modern phishing kits proxy the real login in real time and capture the session token. That token lets the attacker back in later without needing the password or another MFA approval.

This is why SMS and push-approval MFA are no longer sufficient on their own, and why phishing-resistant methods matter. We go into the mechanics in our post on phishing-resistant MFA.

Step two: weeks of reading

This is the part people underestimate. A competent operator changes nothing at first. They read. They learn who approves payments, how your CFO writes, which suppliers invoice monthly, when the big transactions land, and who is about to go on leave.

By the time they act, they can write an email that sounds exactly like the person whose mailbox they are in, referencing a real project, at a moment when the request is entirely expected.

Step three: rules that hide the conversation

Before striking, the attacker creates inbox rules — typically moving anything containing "invoice", "payment", "wire", or a specific supplier name into an obscure folder, or straight to deleted items. Now they can conduct an entire email exchange from the account while the legitimate owner sees nothing.

This is the single highest-value thing to monitor

A user creating a rule that forwards mail externally, or auto-deletes messages matching finance keywords, is one of the most reliable BEC indicators there is. It is straightforward to alert on and very rarely a false positive when the pattern matches finance terms.

Step four: the request

It arrives at a plausible moment and takes one of a few shapes.

The five common shapes of a BEC request

VariantHow it appearsWho it targets
Supplier bank changeA real supplier emails updated bank details for the next invoiceAccounts payable
Invoice interceptionA genuine invoice is intercepted and reissued with different account detailsAny business paying by transfer
Executive requestThe CEO asks for an urgent transfer while travelling and unreachableFinance staff, junior approvers
Escrow or closing diversionClosing wire instructions "corrected" shortly before a property completionBuyers, title and escrow firms
Payroll redirectionAn employee requests a change to their direct deposit detailsHR and payroll

Note what these have in common: none of them contain a malicious link or attachment. There is nothing for a filter to quarantine. The email is a legitimate message from a legitimate account, which is exactly why it works.

Step five: the money moves

Funds are typically moved through several accounts within hours. Recovery depends almost entirely on speed — a wire recall initiated within 24 to 72 hours has a genuine chance, and the odds fall sharply after that. The FBI's IC3 operates a Recovery Asset Team specifically for this, but it only helps if you report immediately.

Why Los Angeles businesses are disproportionately exposed

The industries that concentrate here are the ones BEC operators prefer, because they combine large scheduled payments with time pressure.

  • Real estate, title, and escrow. Closing dates are public knowledge, sums are large, and wire instructions legitimately arrive by email. This is the highest-loss category in the country.
  • Legal. Client trust accounts, settlement disbursements, and a professional culture of responding quickly to counsel.
  • Entertainment and production. Large payments to unfamiliar vendors are routine, and production timelines create genuine urgency that an attacker can borrow.
  • Accounting and financial services. Direct access to client funds, and a busy season during which unusual requests are less unusual.

The controls that actually stop it

BEC defence is unusual in that the two most effective controls are cheap, and one of them is not technical at all.

Phishing-resistant MFA. Passkeys, FIDO2 security keys, or certificate-based authentication. These cannot be relayed by a proxy phishing kit the way codes and push approvals can.
Out-of-band verbal verification. Any change to banking details is confirmed by phone, on a number already on file — never one supplied in the email. This single policy stops most successful BEC losses.
Alert on inbox rule creation. Especially rules with external forwarding or finance keywords. Available in Microsoft 365 audit and Defender, and worth wiring to a real alert.
Block legacy authentication. Older protocols bypass MFA entirely. If anything still needs them, fix that rather than leaving the hole open.
External sender warnings. A banner on mail from outside the organisation makes lookalike domains far more visible.
Conditional Access by location and device. Restrict sign-in to expected countries and compliant devices, so a stolen token from an unexpected location fails.
Dual approval above a threshold. Two people for any transfer over an amount that would hurt. Simple, unpopular, and effective.
The phone call is the control that matters most

Of every measure on this list, the one that most reliably prevents loss is a policy that no banking detail changes without a verbal confirmation on a previously known number. It costs nothing and it does not depend on anyone spotting a sophisticated forgery.

If you think it has already happened

  1. Call your bank immediately and request a wire recall. Speed matters more than anything else here; hours count.
  2. Report to the FBI at ic3.gov and state that it is a BEC wire transfer. Their Recovery Asset Team can request a freeze at the receiving institution.
  3. Reset the password and revoke all active sessions on the affected mailbox. Revoking sessions is essential — a password change alone leaves a stolen token working.
  4. Audit mailbox rules and delegated access across the tenant, not just the one account. Remove anything the user did not create.
  5. Check what else was reachable from that account, including SharePoint, OneDrive, and any application using the same identity.
  6. Notify your cyber insurer. Many policies treat funds transfer fraud as a separate sub-limit with its own conditions.
  7. Tell your suppliers and clients if their correspondence was visible. They may be targeted next using what was learned from your mailbox.

The short answer

BEC is a patience attack that runs on a legitimate login, so tools that look for malware will never see it. The defence is to make the login hard to steal with phishing-resistant MFA, to make the mailbox rules visible with alerting, and to make the payment itself require a human voice on a known phone number. The last one is free, and it is the one that stops the loss.

Frequently asked questions

Does MFA stop business email compromise?

It stops a large share of attempts, but not all. Modern phishing kits act as a real-time proxy between the user and the genuine Microsoft login, capturing the session token after the user approves the MFA prompt. The attacker then replays that token.

Phishing-resistant methods — passkeys, FIDO2 keys, or certificate-based authentication — are bound to the legitimate domain and cannot be relayed this way. That is the upgrade worth making.

How do I know if a mailbox is currently compromised?

The most reliable indicators are inbox rules the user did not create (particularly ones that forward externally or move finance-related mail), sign-ins from unexpected countries or impossible travel patterns, and correspondents mentioning replies the user never saw.

In Microsoft 365, the unified audit log and Defender sign-in risk reports will show both. If you find one suspicious rule, audit the whole tenant rather than just that mailbox.

Can we recover money sent in a BEC wire?

Sometimes, and it depends almost entirely on speed. A recall initiated within the first 24 to 72 hours has a reasonable chance because the funds may not yet have been moved onward. After that the prospects fall away quickly.

Report to your bank and to ic3.gov the same day. The FBI's Recovery Asset Team can request freezes at receiving institutions, but only while the money is still there.

Is this covered by cyber insurance?

Often, but frequently under a separate "funds transfer fraud" or "social engineering" sub-limit that is much smaller than the main policy limit, and sometimes optional.

Check specifically whether that coverage is present, what the sub-limit is, and what conditions attach to it. Many carriers require documented verification procedures for payment changes — the phone-call policy — as a condition of paying out.

Why did our spam filter not catch it?

Because there was nothing wrong with the message. It came from a genuine, authenticated account belonging to a real person, with no malicious link or attachment, and passed SPF, DKIM, and DMARC correctly.

Email filtering catches malicious content. BEC is a legitimate message with a dishonest instruction, which is a fundamentally different problem — and why the process control around payments matters more than the filter.

Is your Microsoft 365 tenant configured to stop this?

We will review your MFA methods, Conditional Access policies, mailbox rule alerting, and legacy authentication, and give you a written list of what to change. Free, and no commitment.