Ransomware gets the attention because it is loud. Business email compromise is quieter, uses no malware at all, and costs businesses considerably more money every year.
There is nothing to detect in the usual sense. No file is encrypted, no payload executes, no antivirus alert fires. Someone signs in to a mailbox with valid credentials, reads quietly for a few weeks, and then sends a single convincing email at exactly the right moment. The money leaves through a payment your own finance team authorises.
The short version
- BEC uses legitimate logins, not malware — endpoint protection cannot see it.
- Attackers typically read a mailbox for two to six weeks before acting, learning tone, timing, and approval chains.
- The tell is almost always a mailbox rule quietly diverting replies so the real party never notices.
- Real estate, escrow, title, legal, and accounting firms are targeted hardest because they move large sums on scheduled dates.
- The two controls that stop it: phishing-resistant MFA, and out-of-band verbal verification of any banking change.
How the attack actually unfolds
Step one: a working login
Access usually comes from a convincing fake Microsoft 365 sign-in page. The user enters credentials and, increasingly, approves the MFA prompt too — because modern phishing kits proxy the real login in real time and capture the session token. That token lets the attacker back in later without needing the password or another MFA approval.
This is why SMS and push-approval MFA are no longer sufficient on their own, and why phishing-resistant methods matter. We go into the mechanics in our post on phishing-resistant MFA.
Step two: weeks of reading
This is the part people underestimate. A competent operator changes nothing at first. They read. They learn who approves payments, how your CFO writes, which suppliers invoice monthly, when the big transactions land, and who is about to go on leave.
By the time they act, they can write an email that sounds exactly like the person whose mailbox they are in, referencing a real project, at a moment when the request is entirely expected.
Step three: rules that hide the conversation
Before striking, the attacker creates inbox rules — typically moving anything containing "invoice", "payment", "wire", or a specific supplier name into an obscure folder, or straight to deleted items. Now they can conduct an entire email exchange from the account while the legitimate owner sees nothing.
A user creating a rule that forwards mail externally, or auto-deletes messages matching finance keywords, is one of the most reliable BEC indicators there is. It is straightforward to alert on and very rarely a false positive when the pattern matches finance terms.
Step four: the request
It arrives at a plausible moment and takes one of a few shapes.
The five common shapes of a BEC request
| Variant | How it appears | Who it targets |
|---|---|---|
| Supplier bank change | A real supplier emails updated bank details for the next invoice | Accounts payable |
| Invoice interception | A genuine invoice is intercepted and reissued with different account details | Any business paying by transfer |
| Executive request | The CEO asks for an urgent transfer while travelling and unreachable | Finance staff, junior approvers |
| Escrow or closing diversion | Closing wire instructions "corrected" shortly before a property completion | Buyers, title and escrow firms |
| Payroll redirection | An employee requests a change to their direct deposit details | HR and payroll |
Note what these have in common: none of them contain a malicious link or attachment. There is nothing for a filter to quarantine. The email is a legitimate message from a legitimate account, which is exactly why it works.
Step five: the money moves
Funds are typically moved through several accounts within hours. Recovery depends almost entirely on speed — a wire recall initiated within 24 to 72 hours has a genuine chance, and the odds fall sharply after that. The FBI's IC3 operates a Recovery Asset Team specifically for this, but it only helps if you report immediately.
Why Los Angeles businesses are disproportionately exposed
The industries that concentrate here are the ones BEC operators prefer, because they combine large scheduled payments with time pressure.
- Real estate, title, and escrow. Closing dates are public knowledge, sums are large, and wire instructions legitimately arrive by email. This is the highest-loss category in the country.
- Legal. Client trust accounts, settlement disbursements, and a professional culture of responding quickly to counsel.
- Entertainment and production. Large payments to unfamiliar vendors are routine, and production timelines create genuine urgency that an attacker can borrow.
- Accounting and financial services. Direct access to client funds, and a busy season during which unusual requests are less unusual.
The controls that actually stop it
BEC defence is unusual in that the two most effective controls are cheap, and one of them is not technical at all.
Of every measure on this list, the one that most reliably prevents loss is a policy that no banking detail changes without a verbal confirmation on a previously known number. It costs nothing and it does not depend on anyone spotting a sophisticated forgery.
If you think it has already happened
- Call your bank immediately and request a wire recall. Speed matters more than anything else here; hours count.
- Report to the FBI at ic3.gov and state that it is a BEC wire transfer. Their Recovery Asset Team can request a freeze at the receiving institution.
- Reset the password and revoke all active sessions on the affected mailbox. Revoking sessions is essential — a password change alone leaves a stolen token working.
- Audit mailbox rules and delegated access across the tenant, not just the one account. Remove anything the user did not create.
- Check what else was reachable from that account, including SharePoint, OneDrive, and any application using the same identity.
- Notify your cyber insurer. Many policies treat funds transfer fraud as a separate sub-limit with its own conditions.
- Tell your suppliers and clients if their correspondence was visible. They may be targeted next using what was learned from your mailbox.
The short answer
BEC is a patience attack that runs on a legitimate login, so tools that look for malware will never see it. The defence is to make the login hard to steal with phishing-resistant MFA, to make the mailbox rules visible with alerting, and to make the payment itself require a human voice on a known phone number. The last one is free, and it is the one that stops the loss.
Frequently asked questions
Does MFA stop business email compromise?
It stops a large share of attempts, but not all. Modern phishing kits act as a real-time proxy between the user and the genuine Microsoft login, capturing the session token after the user approves the MFA prompt. The attacker then replays that token.
Phishing-resistant methods — passkeys, FIDO2 keys, or certificate-based authentication — are bound to the legitimate domain and cannot be relayed this way. That is the upgrade worth making.
How do I know if a mailbox is currently compromised?
The most reliable indicators are inbox rules the user did not create (particularly ones that forward externally or move finance-related mail), sign-ins from unexpected countries or impossible travel patterns, and correspondents mentioning replies the user never saw.
In Microsoft 365, the unified audit log and Defender sign-in risk reports will show both. If you find one suspicious rule, audit the whole tenant rather than just that mailbox.
Can we recover money sent in a BEC wire?
Sometimes, and it depends almost entirely on speed. A recall initiated within the first 24 to 72 hours has a reasonable chance because the funds may not yet have been moved onward. After that the prospects fall away quickly.
Report to your bank and to ic3.gov the same day. The FBI's Recovery Asset Team can request freezes at receiving institutions, but only while the money is still there.
Is this covered by cyber insurance?
Often, but frequently under a separate "funds transfer fraud" or "social engineering" sub-limit that is much smaller than the main policy limit, and sometimes optional.
Check specifically whether that coverage is present, what the sub-limit is, and what conditions attach to it. Many carriers require documented verification procedures for payment changes — the phone-call policy — as a condition of paying out.
Why did our spam filter not catch it?
Because there was nothing wrong with the message. It came from a genuine, authenticated account belonging to a real person, with no malicious link or attachment, and passed SPF, DKIM, and DMARC correctly.
Email filtering catches malicious content. BEC is a legitimate message with a dishonest instruction, which is a fundamentally different problem — and why the process control around payments matters more than the filter.
Is your Microsoft 365 tenant configured to stop this?
We will review your MFA methods, Conditional Access policies, mailbox rule alerting, and legacy authentication, and give you a written list of what to change. Free, and no commitment.
