Business email compromise is one of the most financially damaging cyber threats facing businesses of every size. Unlike ransomware, which locks systems until a ransom is paid, or data breaches, whose financial impact unfolds over months through regulatory penalties and litigation, business email compromise (BEC) typically results in an immediate, direct financial loss: a wire transfer made to the attacker’s account, a supplier’s payment redirected to a fraudulent account, or a payroll instruction that diverts an employee’s salary.
The FBI’s Internet Crime Complaint Center consistently identifies BEC as the highest-loss category of cybercrime by financial value. In 2023, reported BEC losses exceeded five billion dollars globally. The UK’s Action Fraud receives thousands of BEC reports each year, and the actual incidence is significantly higher than the reported figure, because many organisations do not report and some do not immediately recognise that a BEC attack has occurred.
What Is Business Email Compromise?
Business email compromise is a category of attack in which an attacker manipulates email communications — either by compromising a legitimate email account, by creating a lookalike account that spoofs a trusted identity, or by intercepting and altering email chains — to cause a business to make a fraudulent payment or to disclose sensitive information.
The attack targets the trust that email communications carry. A request to change a supplier’s bank account details, to make an urgent wire transfer, or to process a payroll change, when it appears to come from a known and trusted contact, is acted upon without the verification steps that would be applied to a request from an unknown party. That trust is what the attacker exploits.
Common Attack Methods
CEO fraud: an email that appears to come from a senior executive — typically the CEO or CFO — is sent to a finance team member, requesting an urgent and confidential wire transfer. The urgency and authority of the apparent sender are used to bypass normal approval processes.
Supplier impersonation: an attacker intercepts or monitors an email chain with a known supplier and at an appropriate moment sends instructions, appearing to come from the supplier, to redirect future payments to a new bank account. The instruction often references the existing business relationship to establish credibility.
Account compromise: the attacker gains access to a legitimate email account — through phishing, credential stuffing, or exploitation of a weak password — and uses that account to conduct the fraud. Messages sent from a genuinely compromised account are significantly harder to identify as fraudulent because they pass all standard authentication checks.
Solicitor and property fraud: a variant in which the attacker intercepts communications between a buyer and their solicitor or estate agent and substitutes fraudulent account details for the legitimate completion payment. This variant has caused catastrophic losses to individual victims who have lost their entire property purchase funds.
Immediate Response Steps
When a BEC attack is identified, the first priority is to stop the outbound payment if it has not yet cleared and to contain any account compromise that may have enabled it. The response window is extremely narrow: once funds have been transferred and withdrawn from the destination account, recovery is very difficult.
Contact the sending bank immediately: if the transfer has been initiated but not yet completed, the sending bank may be able to place a hold on the transaction. Contact the fraud department, not the standard customer service line, and provide all available information about the transfer. Every hour of delay reduces the chance of recovery.
Initiate a bank recall request: if the transfer has been completed, a bank-to-bank recall request can be initiated, requesting that the destination bank freeze and return the funds. The success rate varies depending on the destination jurisdiction and how quickly the request is made.
Contact Action Fraud: report the incident to Action Fraud (0300 123 2040) and, where the loss is significant, to the NFIB’s specialist unit. A rapid response from law enforcement can, in some cases, result in funds being frozen before they are withdrawn.
Preserve all evidence: before any remediation of the email system is undertaken, preserve the full email chain, the email headers of all messages involved, any login activity logs from the email account, and any other evidence relevant to the attack. Remediation steps that overwrite logs or delete messages will destroy the evidence needed for the investigation and any subsequent legal action.
Investigation Process
The BEC investigation has two concurrent objectives: establishing how the attack occurred and tracing the funds. Both are time-sensitive, and the investigation should begin immediately.
Email header analysis: examination of the email headers from all messages in the attack chain to identify whether emails came from legitimate accounts, spoofed addresses, or compromised accounts. The headers contain routing information, authentication results, and other technical data that reveals the true origin of each message.
Account access log review: if an account was compromised, the email system’s access logs will record every login, the IP addresses used, the devices from which access was made, and the actions taken during each session. This log is the primary evidence of the attacker’s activity within the account.
Funds tracing: working with the sending bank, the correspondent banks involved in the transfer, and — where appropriate — law enforcement, to trace the destination of the funds. Cryptocurrency may have been used as a conversion step; where it has, specialist cryptocurrency tracing techniques are applied.
Technical attribution: identifying the infrastructure used in the attack — the IP addresses, domains, and hosting services — to support attribution, identify links to known threat actors, and inform any law enforcement referral.
Preventing Future Incidents
Multi-factor authentication: enabling MFA on all email accounts eliminates the risk of account compromise through credential theft alone. It is the single most effective technical control for preventing BEC attacks.
Payment verification procedures: implementing a policy that requires all requests to change payment details or initiate large transfers to be verified through a separate, pre-established communication channel — a phone call to a known number, not a response to the suspicious email.
DMARC, DKIM, and SPF: email authentication standards that reduce the risk of domain spoofing. Properly configured, they prevent attackers from sending emails that appear to come from your organisation’s domain.
Staff awareness training: regular, practical training on BEC attack patterns, including exercises that test employees’ responses to simulated BEC attempts.
Investigating a business email compromise incident? Contact iSpy Detectives for urgent digital forensic investigation and funds tracing support. We have recently undertaken compromised business email investigations for corporate clients in London, Manchester, Aberdeen, Rochester, Birmingham, and Nottingham.

