In Brief:

  • Business Email Compromise (BEC) scams impersonate trusted vendors, executives, employees, or attorneys to trick businesses into sending money or sensitive information.
  • Protect your business by verifying payment changes by phone, using fraud protection tools and multi-factor authentication, and training employees to recognize suspicious requests.
  • If you suspect Business Email Compromise, contact INB immediately! The faster you act, the better the chance of recovering your funds.
  • Visit the INB fraud page for more fraud tips!

 Greg Floyd talking on the phoneAs a business owner, you’re constantly juggling priorities.

So when an email arrives from a trusted vendor asking you to update payment information, you make the change. The email address looks right, the request seems routine, and you’re busy.

Except it isn’t your vendor.

“INB recently worked with a business that nearly fell victim because just two letters in the sender’s email address had been switched,” says Greg Floyd, VP, Deposit Compliance Services for INB. “At first glance, everything looked legitimate.”

That's exactly how Business Email Compromise (BEC) works — and it could be very costly in just a matter of minutes.

What is Business Email Compromise and Why Is It a Concern?

BEC, also referred to as Email Account Compromise (EAC), is a targeted cyberattack where criminals impersonate someone you trust — like a vendor, employee, or attorney — to trick your business into sending money or sensitive information.

Unlike traditional phishing emails, BEC attacks are highly personalized and quite convincing as the emails usually look legitimate. 

In the last couple of years, small and mid-sized businesses have become the #1 target of BEC attacks, with average losses exceeding $120,000 per incident. In many cases, that money is never recovered.

“Scammers know what they’re doing: they try to get the money as fast as possible either electronically, ACH or wire. As soon as money arrives at the destination account, it’s yanked out and gone,” Greg explains.

How Business Email Compromise Can Hit Your Business

These are the Business Email Compromise schemes the INB Fraud Department sees most often today:

  • Fake Invoices: Criminals send realistic invoices with fraudulent payment instructions.
  • CEO Fraud: An attacker impersonates an executive and pressures employees to send an urgent wire transfer.
  • Payroll Fraud: Hackers trick HR into redirecting an employee’s direct deposit.
  • Vendor Account Takeover: A legit vendor’s email is hacked and used to send fraudulent requests.
  • Attorney Impersonation: Criminals pose as legal counsel to create urgency around confidential or time-sensitive payments.

These attacks often happen during busy periods — like tax season, holidays, or while you're traveling — when your team is more likely to act quickly without double-checking.

How to Protect Your Business from Business Email Compromise

The best defense against Business Email Compromise is building verification into your processes:

Don’t click email links to modify payment details

Greg emphasizes the importance: “Never ever ever accept directions through email to change a vendor’s payment detail. We try to pound that into our corporate clients to pick up the phone and call your vendor or your bank with the number you already have for them.”

Strengthen your systems

  • Understand and implement Fraud Protection services, such as Positive Pay.
  • Secure your domain. Use email authentication tools like SPF, DKIM, and DMARC to prevent spoofing.
  • Use Two-Step verification. Require multi-factor authentication for email and financial systems.

Train your team

Make sure employees know how to spot suspicious emails and verify unusual requests. 

    • Simulate phishing emails. Run regular, realistic phishing simulations to test and train employees.
    • Train during onboarding and consistently remind team members. Suspicious emails usually contain urgency, misspellings, or unusual requests.
    • Encourage skepticism. Reinforce that it’s okay to double-check, especially for financial or sensitive requests. 
    • Use the “hover test.” Teach staff to hover over links to see the real URL before clicking.
    • Verify payments. Remind your team to confirm changes to payment details or large transfers by phone or in person.

And if you suspect Business Email Compromise, act quickly.

“Once money goes through a wire, it’s considered ‘good’ — if it hits and then is withdrawn, it’s gone,” Greg warns.

Call INB immediately if you think your business email was compromised.

“The quicker we get on top of it, the better chances we can get your money back,” Greg says. “I encourage business owners to get on it as fast as you can and hope we can beat the fraudsters to your money.”

Business Email Compromise isn’t going away. But with the right safeguards and fraud protection tools, you can significantly reduce your risk and protect your business.

Contact INB to learn more about Fraud Protection Solutions designed for your business.