B2B THREATUpdated July 2026

Your employee just wired $123,000 to a scammer. Here's how it happened.

Business Email Compromise cost companies $3.05 billion in 2025, across 24,768 reports to the FBI — an average of about $123,000 per report. It is the second-costliest fraud category the FBI tracks, behind investment fraud. Tutela Digitalis shows you how to protect your business.

$3.05B
BEC losses (FBI 2025)
$123K
Average loss per BEC report
24,768
BEC reports to the FBI in 2025
62%
Of breaches involve a human
The short answer

Business fraud — including business email compromise (BEC) — targets a company's payment processes, using impersonated executives, fake invoices, or compromised email to redirect payments to criminals. The strongest defence is a verification step: confirm any change to payment details or any urgent transfer request through a second, known channel before acting.

How business fraud works

Business fraud targets processes, not just people. Most attacks begin with a convincing phishing email. The most common forms documented by Tutela Digitalis:

CEO/CFO Impersonation

Attacker spoofs an executive's email and instructs an employee to make an urgent wire transfer. Often timed for when the executive is traveling or in meetings.

Invoice Fraud

Fake invoices from "vendors" that look identical to legitimate ones, but with different banking details. Sometimes the attacker compromises a real vendor's email and changes the payment details on real invoices.

Payroll Diversion

Attacker impersonates an employee and requests HR change their direct deposit information to a new account.

Vendor Compromise

Attacker breaches a real vendor's email system and sends legitimate-looking invoices with fraudulent payment details. This is the hardest to detect because the email comes from a real, trusted address.

Sources:FBI IC3 2024 Internet Crime ReportVerizon 2025 Data Breach Investigations Report

Building a human firewall

Technology alone can't stop business fraud. You need trained people and verified processes:

  1. 1.

    Dual authorization for all wire transfers over a set threshold — no single person should be able to authorize large payments.

  2. 2.

    Verbal verification for any change to payment details — call the vendor at a known number (not one from the suspicious email) before changing anything.

  3. 3.

    Regular phishing simulation training — employees who train regularly have 1.5% click rates vs. 34% without training. This is the single highest-ROI security investment.

  4. 4.

    Clear escalation procedures — employees must feel empowered to question unusual requests, even from the CEO. Create a culture where caution is rewarded.

  5. 5.

    Segregation of duties — no single person should control the entire payment process from approval to execution.

  6. 6.

    Email authentication — implement DMARC, SPF, and DKIM to prevent domain spoofing of your own domain.

  7. 7.

    Incident response plan — know exactly what to do when (not if) a fraud attempt occurs. Practice it.

Sources:CrowdStrike 2025 Global Threat ReportVerizon 2025 Data Breach Investigations Report
FROM THE FIELD

The most effective defense I've seen isn't technical — it's cultural. Companies where employees feel safe questioning unusual requests catch fraud attempts that technology misses. The six-figure wire transfer happens when an employee is afraid to say 'this seems off' to their boss.

Why a held payment is the whole defence

Look back at how these attacks actually arrive. The email address is right or nearly right, the signature block is correct, the invoice is on the real template, the tone matches how that person writes. All of that is copied from correspondence the attacker has been reading, often for weeks. Teaching staff to spot a convincing forgery is asking them to win a contest the attacker has already prepared for.

There is one thing the attacker cannot copy: your supplier picking up the phone on the number you already had for them.

The hold

Any change to bank details, and any unusually urgent payment, gets held until someone speaks to a known contact on a number from your own records. Not a number in the email. Not a number in the invoice. The one that was in your system before this request arrived.

A genuine supplier is not offended by that call, because they carry exactly the same risk you do and most of them have been on the receiving end of it. A real finance director does not mind a large transfer being confirmed. The fraud cannot survive the hold, because the entire operation depends on the payment leaving inside a window it controls. That is why the resistance is structural rather than rudeness.

Listen for the reason the check cannot happen. Keep this between us, it is a confidential acquisition. He is in a board meeting and cannot be disturbed. The deal collapses if we miss today. The supplier has changed banks and the old number is dead. Every one of those exists to remove the second channel, and they are aimed at whoever has least standing to insist. BEC does not target the finance director. It targets the person who cannot comfortably say no to the finance director.

Which is the real reason a policy beats vigilance. If the check is a rule, the junior member of staff is not being asked to accuse a senior colleague of fraud; they are following a procedure that applies to everyone. The most useful sentence a business owner can say out loud is that nobody may override the verification, including them. After that, an instruction to skip it is not a judgement call. It is the answer.

None of this means stop training people to spot the signs. They still matter and plenty of attempts are still careless. The claim is narrower: inspecting the message is no longer sufficient on its own to release money, because the message is the part the attacker has had weeks to perfect. Use the signs to recognise it. Use the held payment to decide. The mechanics of why urgency is manufactured are in why scammers create urgency.

What to do if your business has been hit

If you discover a fraudulent transaction, act fast — the first hours decide whether the money is recoverable. For a personal-account version of this, see our scam recovery guide, and our reporting directory for exactly where to report business fraud in your country.

  1. 1.

    Contact your bank immediately — request a wire recall. Speed is everything; recalls within 24 hours have the highest success rate.

  2. 2.

    Preserve all evidence — emails, invoices, transaction records, communication logs. Do not delete anything.

  3. 3.

    Report to FBI IC3 (ic3.gov) — file a detailed complaint with all available evidence.

  4. 4.

    Notify your insurance carrier — if you have cyber liability insurance, file a claim immediately.

  5. 5.

    Conduct an internal investigation — determine how the breach occurred and what systems were compromised.

  6. 6.

    Reset compromised credentials — change passwords, revoke access tokens, and rotate API keys for any affected systems.

  7. 7.

    Notify affected parties — if vendor or customer data was compromised, you may have legal notification obligations.

  8. 8.

    Review and strengthen procedures — every incident is an opportunity to close the gap that was exploited.

P
Written by Peter
Founder, Tutela Digitalis • Updated July 2026

Written from real-world experience. All statistics sourced from verified organizations.

Frequently Asked Questions

What is Business Email Compromise (BEC)?
BEC is when an attacker impersonates an executive, vendor, or colleague via email to trick employees into making wire transfers or sharing sensitive information. BEC cost companies $3.05 billion in 2025 according to the FBI's Internet Crime Complaint Center, across 24,768 reports — an average of about $123,000 per report.
How can I protect my business from invoice fraud?
Implement dual authorization for all wire transfers, verbally verify any changes to payment details by calling the vendor at a known number (not one from the email), use DMARC/SPF/DKIM email authentication, train employees regularly with phishing simulations, and create clear escalation procedures so employees feel empowered to question unusual requests.
How effective is employee phishing training?
Very effective. Organizations with regular phishing simulation training see click rates drop from 34% to as low as 1.5%. The key is ongoing, behavior-based training — not one-time compliance sessions. Employees must practice identifying real-world examples, not just watch videos.

Sources & References

Every statistic in this guide is sourced from verified organizations. Click to verify any claim.

FBI IC3 2024 Internet Crime ReportVerizon 2025 Data Breach Investigations ReportCrowdStrike 2025 Global Threat Report

Want a business fraud audit?

Our Business Protection Audit identifies your specific vulnerabilities with a written report.

Book a Consultation →

Continue reading

PHISHING

Phishing is the #1 reported cybercrime

AI SCAMS

Deepfake CEO calls — the new threat

RECOVERY

Step-by-step scam recovery