Business email compromise (BEC) is fraud in which criminals using impersonation — a spoofed executive, a hijacked vendor email thread, a lookalike domain — trick employees into wiring money or diverting payments to accounts the fraudsters control. The FBI's Internet Crime Complaint Center has tracked tens of billions of dollars in reported BEC losses globally over the past decade, with annual reports consistently placing BEC among the costliest cyber-crime categories — more than ransomware by dollar loss. The defining feature: no malware is required. BEC defeats trust and verification processes, which is why the controls that work are procedural — call-backs, dual authorization, payment-change verification — rather than technical.
USA Post publishes information about fraud risk, not legal advice.
What are the main BEC schemes?
Four patterns cover most losses. Executive impersonation: an urgent email from "the CEO" to finance staff, often timed to a real trip or meeting, directing a confidential wire — pressure plus secrecy to defeat verification. Vendor email compromise: criminals gain access to a real supplier's mailbox, watch invoicing patterns, then send a legitimate-looking message with "updated" bank details; the company pays the real invoice to the fake account, and the fraud surfaces only when the vendor chases payment weeks later. Payroll diversion: HR receives instructions to redirect an employee's paycheck. Account takeover chaining: a compromised mailbox used to reconnoiter and launch the above — the FBI's recovery partnerships and IC3 reports show average dwell times measured in weeks, giving fraudsters authentic context that makes the eventual ask convincing. The lookalike-domain variant registers ceo-mail.co against ceo.com and exploits mobile screens that truncate sender addresses.
What happens to the money — and can it be recovered?
It moves fast: mule accounts receive the wire, funds are layered through instant payment systems, crypto exchanges and cross-border chains within hours. Recovery is time-critical: the FBI's Recovery Asset Team, engaged through IC3 reporting within 72 hours, has freeze-to-recovery rates above half when reports are immediate — and near zero when discovery lags. Banks' wire-room recall procedures work on the same clock. This is why incident response plans treat a discovered BEC as a real-time emergency: call the bank, file the recall, report to IC3 and local FBI simultaneously, and preserve the email evidence for the investigation.
Who bears the loss legally?
A contested allocation with no uniform answer. Company-versus-bank: the Uniform Commercial Code Article 4A governs wire transfers, and a bank that executed a payment order authorized in form — with agreed security procedures and commercially reasonable verification — shifts loss to the customer; the litigation turns on whether the bank's procedures were commercially reasonable and followed. Company-versus-vendor: where a vendor's email was hijacked and the victim company paid the genuine invoice to the fraudster's account, courts split on whether payment was effectively made — UCC Article 3 and 4A analogies, mistake and restitution doctrines, and contract allocation clauses all appear; some courts have held the loss to the party whose system was compromised, others the payor, and negotiated splits are the settlement norm. Insurance: crime policies cover social-engineering fraud by endorsement — first-party theft coverage often requires the entry in the policy's fraud section, with sublimits and specific conditions (verification procedures must have been followed); failure to follow the endorsed procedures voids coverage, a rising denial theory. Directors and officers exposure: derivative claims over failed payment controls have survived motions in some post-2020 cases, making BEC a governance fact, not merely an operations problem.
What controls actually work?
- Out-of-band verification for every payment-account change and every urgent wire: a call to a number on file — never one from the email — confirming details before funds move.
- Dual authorization with a second approver who verifies independently, not sequentially clicking.
- Timing rules: delays on first-time payees and same-day changes; no exceptions for executive pressure — announce the rule in advance so urgency cannot override it.
- Technical hygiene: enforce MFA and conditional access on all mail (BEC usually starts with credential phishing), register lookalike domains defensively, flag external-sender banners, and detect forwarding-rule creation.
- Train the specific targets — AP staff, HR, executive assistants — with real-thread simulations, and rehearse the 72-hour recovery playbook: bank recall, IC3 report, evidence preservation.
Why do BEC losses keep rising despite awareness?
Because the economics favor the attacker and the work-from-anywhere structure widened the attack surface. Generative AI raised the craft: fluent, context-rich lures without the grammar tells employees were trained to spot, voice cloning for the call-back-defeating "verbal confirmation," and automated reconnaissance at scale. The consistent finding of every post-incident review is the same: the victim organization had trained generally but had not made verification procedurally unavoidable — the exception process existed, and the fraud found it. The defenses that hold are boring, enforced, and audited: nobody pays a new account without the call.
For more context, read Business Interruption Insurance Explained: Triggers, Waiting Periods and the Gaps Owners Miss.
For more context, read arbitration clause enforcement.
For more context, read trademark protection small business.
