B2B THREATUpdated 23 September 2026

Your employee just wired $123,000 to a scammer. Here's how it happened.

Business Email Compromise cost companies $3.05 billion in 2025, across 24,768 reports to the FBI — an average of about $123,000 per report. It is the second-costliest fraud category the FBI tracks, behind investment fraud. Tutela Digitalis shows you how to protect your business.

$3.05B
BEC losses (FBI 2025)
$123K
Average loss per BEC report
24,768
BEC reports to the FBI in 2025
62%
Of breaches involve a human
The short answer

Business fraud — including business email compromise (BEC) — targets a company's payment processes, using impersonated executives, fake invoices, or compromised email to redirect payments to criminals. The strongest defence is a verification step: confirm any change to payment details or any urgent transfer request through a second, known channel before acting.

How business fraud works

Business fraud targets payment processes as well as people. It may involve a deceptive message or a compromised account. Patterns include:

CEO/CFO Impersonation

Attacker spoofs an executive's email and instructs an employee to make an urgent wire transfer. Often timed for when the executive is traveling or in meetings.

Invoice Fraud

Fake invoices from "vendors" that look identical to legitimate ones, but with different banking details. Sometimes the attacker compromises a real vendor's email and changes the payment details on real invoices.

Payroll Diversion

Attacker impersonates an employee and requests HR change their direct deposit information to a new account.

Vendor Compromise

Attacker breaches a real vendor's email system and sends legitimate-looking invoices with fraudulent payment details. This is the hardest to detect because the email comes from a real, trusted address.

Sources:FBI IC3 2025 Internet Crime Report ↗Verizon 2025 Data Breach Investigations Report ↗

Building a human firewall

Technology alone can't stop business fraud. You need trained people and verified processes:

  1. 1.

    Dual authorization for all wire transfers over a set threshold — no single person should be able to authorize large payments.

  2. 2.

    Verbal verification for any change to payment details — call the vendor at a known number (not one from the suspicious email) before changing anything.

  3. 3.

    Regular phishing simulation training — rehearse reporting and verification procedures, measure your own results and make it easy to flag mistakes promptly. Training complements payment controls; it does not guarantee prevention.

  4. 4.

    Clear escalation procedures — employees must feel empowered to question unusual requests, even from the CEO. Create a culture where caution is rewarded.

  5. 5.

    Segregation of duties — no single person should control the entire payment process from approval to execution.

  6. 6.

    Email authentication — configure SPF, DKIM and DMARC to help control unauthorized use of your domain. They do not prevent lookalike domains or messages from compromised legitimate accounts.

  7. 7.

    Incident response plan — know exactly what to do when (not if) a fraud attempt occurs. Practice it.

Sources:CrowdStrike 2025 Global Threat Report ↗Verizon 2025 Data Breach Investigations Report ↗
FROM THE FIELD

Make it safe for employees to question unusual requests and report mistakes. A written verification policy helps staff pause a payment without having to make a personal accusation against a senior colleague.

Hold unusual payments while you verify

Look back at how these attacks actually arrive. The email address is right or nearly right, the signature block is correct, the invoice is on the real template, the tone matches how that person writes. All of that is copied from correspondence the attacker has been reading, often for weeks. Teaching staff to spot a convincing forgery is asking them to win a contest the attacker has already prepared for.

Use a previously verified supplier contact and corroborate the beneficiary details. If that contact route may be compromised, escalate through another established route rather than approving the change.

The hold

Any change to bank details, and any unusually urgent payment, gets held until someone speaks to a known contact on a number from your own records. Not a number in the email. Not a number in the invoice. The one that was in your system before this request arrived.

Confirm changed bank details through a previously verified supplier contact and your approval process. A cooperative reply is not proof that a message is genuine, and a legitimate supplier may be impatient. Verify the beneficiary and authorization independently before releasing funds.

Listen for the reason the check cannot happen. Keep this between us, it is a confidential acquisition. He is in a board meeting and cannot be disturbed. The deal collapses if we miss today. The supplier has changed banks and the old number is dead. Every one of those exists to remove the second channel, and they are aimed at whoever has least standing to insist. A clear policy gives every employee a way to escalate an unusual instruction, regardless of seniority.

Which is the real reason a policy beats vigilance. If the check is a rule, the junior member of staff is not being asked to accuse a senior colleague of fraud; they are following a procedure that applies to everyone. The most useful sentence a business owner can say out loud is that nobody may override the verification, including them. After that, an instruction to skip it is not a judgement call. It is the answer.

None of this means stop training people to spot the signs. They still matter and plenty of attempts are still careless. The claim is narrower: inspecting the message is no longer sufficient on its own to release money, because the message is the part the attacker has had weeks to perfect. Use the signs to recognise it. Use the held payment to decide. The mechanics of why urgency is manufactured are in why scammers create urgency.

What to do if your business has been hit

If you discover a fraudulent transaction, act fast — prompt reporting may help stop money moving, but report even if more time has passed. For a personal-account version of this, see our scam recovery guide, and our reporting directory for exactly where to report business fraud in your country.

  1. 1.

    Contact your bank immediately — request an urgent recall or fraud notification and keep the reference number. Report even if more time has passed; a recall is not a guaranteed reversal.

  2. 2.

    Preserve all evidence — emails, invoices, transaction records, communication logs. Do not delete anything.

  3. 3.

    Report to FBI IC3 (ic3.gov) — file a detailed complaint with all available evidence.

  4. 4.

    Notify your insurance carrier — if you have cyber liability insurance, file a claim immediately.

  5. 5.

    Conduct an internal investigation — determine how the breach occurred and what systems were compromised.

  6. 6.

    Reset compromised credentials — change passwords, revoke access tokens, and rotate API keys for any affected systems.

  7. 7.

    Notify affected parties — if vendor or customer data was compromised, you may have legal notification obligations.

  8. 8.

    Review and strengthen procedures — every incident is an opportunity to close the gap that was exploited.

P
Written by Peter
Founder, Tutela Digitalis • Updated 23 September 2026

Research and educational guidance by Peter. Sources and material corrections are linked on this page.

Frequently Asked Questions

What is Business Email Compromise?
BEC uses impersonation or compromised business communications to induce transfers or disclosure of information. The FBI recorded about $3.05 billion in reported BEC losses across 24,768 complaints in 2025.
How can a business reduce invoice fraud?
Independently verify changes to beneficiary details using a previously verified supplier contact, apply appropriate separation of payment approval duties, and maintain clear escalation procedures. Email authentication supports these controls but does not prevent every impersonation or account compromise.
How effective is phishing training?
Results depend on the organization, program and measurement. Rehearse reporting and verification, measure your own outcomes and pair training with technical and payment controls. A single click-rate figure is not a universal promise of effectiveness.

Reviewed 23 September 2026. We corrected overbroad verification and recovery claims during our launch-content review. See the corrections log for the material changes.

Sources & References

Every statistic in this guide is sourced from verified organizations. Click to verify any claim.

FBI IC3 2025 Internet Crime Report ↗Verizon 2025 Data Breach Investigations Report ↗CrowdStrike 2025 Global Threat Report ↗

Want a business fraud audit?

Our Business Protection Audit identifies your specific vulnerabilities with a written report.

Book a Consultation →

Continue reading

PHISHING

Phishing is the #1 reported cybercrime

AI SCAMS

Deepfake CEO calls — the new threat

RECOVERY

Step-by-step scam recovery