Business fraud — including business email compromise (BEC) — targets a company's payment processes, using impersonated executives, fake invoices, or compromised email to redirect payments to criminals. The strongest defence is a verification step: confirm any change to payment details or any urgent transfer request through a second, known channel before acting.
How business fraud works
Business fraud targets payment processes as well as people. It may involve a deceptive message or a compromised account. Patterns include:
Attacker spoofs an executive's email and instructs an employee to make an urgent wire transfer. Often timed for when the executive is traveling or in meetings.
Fake invoices from "vendors" that look identical to legitimate ones, but with different banking details. Sometimes the attacker compromises a real vendor's email and changes the payment details on real invoices.
Attacker impersonates an employee and requests HR change their direct deposit information to a new account.
Attacker breaches a real vendor's email system and sends legitimate-looking invoices with fraudulent payment details. This is the hardest to detect because the email comes from a real, trusted address.
Building a human firewall
Technology alone can't stop business fraud. You need trained people and verified processes:
- 1.
Dual authorization for all wire transfers over a set threshold — no single person should be able to authorize large payments.
- 2.
Verbal verification for any change to payment details — call the vendor at a known number (not one from the suspicious email) before changing anything.
- 3.
Regular phishing simulation training — rehearse reporting and verification procedures, measure your own results and make it easy to flag mistakes promptly. Training complements payment controls; it does not guarantee prevention.
- 4.
Clear escalation procedures — employees must feel empowered to question unusual requests, even from the CEO. Create a culture where caution is rewarded.
- 5.
Segregation of duties — no single person should control the entire payment process from approval to execution.
- 6.
Email authentication — configure SPF, DKIM and DMARC to help control unauthorized use of your domain. They do not prevent lookalike domains or messages from compromised legitimate accounts.
- 7.
Incident response plan — know exactly what to do when (not if) a fraud attempt occurs. Practice it.
Make it safe for employees to question unusual requests and report mistakes. A written verification policy helps staff pause a payment without having to make a personal accusation against a senior colleague.
Hold unusual payments while you verify
Look back at how these attacks actually arrive. The email address is right or nearly right, the signature block is correct, the invoice is on the real template, the tone matches how that person writes. All of that is copied from correspondence the attacker has been reading, often for weeks. Teaching staff to spot a convincing forgery is asking them to win a contest the attacker has already prepared for.
Use a previously verified supplier contact and corroborate the beneficiary details. If that contact route may be compromised, escalate through another established route rather than approving the change.
Any change to bank details, and any unusually urgent payment, gets held until someone speaks to a known contact on a number from your own records. Not a number in the email. Not a number in the invoice. The one that was in your system before this request arrived.
Confirm changed bank details through a previously verified supplier contact and your approval process. A cooperative reply is not proof that a message is genuine, and a legitimate supplier may be impatient. Verify the beneficiary and authorization independently before releasing funds.
Listen for the reason the check cannot happen. Keep this between us, it is a confidential acquisition. He is in a board meeting and cannot be disturbed. The deal collapses if we miss today. The supplier has changed banks and the old number is dead. Every one of those exists to remove the second channel, and they are aimed at whoever has least standing to insist. A clear policy gives every employee a way to escalate an unusual instruction, regardless of seniority.
Which is the real reason a policy beats vigilance. If the check is a rule, the junior member of staff is not being asked to accuse a senior colleague of fraud; they are following a procedure that applies to everyone. The most useful sentence a business owner can say out loud is that nobody may override the verification, including them. After that, an instruction to skip it is not a judgement call. It is the answer.
None of this means stop training people to spot the signs. They still matter and plenty of attempts are still careless. The claim is narrower: inspecting the message is no longer sufficient on its own to release money, because the message is the part the attacker has had weeks to perfect. Use the signs to recognise it. Use the held payment to decide. The mechanics of why urgency is manufactured are in why scammers create urgency.
What to do if your business has been hit
If you discover a fraudulent transaction, act fast — prompt reporting may help stop money moving, but report even if more time has passed. For a personal-account version of this, see our scam recovery guide, and our reporting directory for exactly where to report business fraud in your country.
- 1.
Contact your bank immediately — request an urgent recall or fraud notification and keep the reference number. Report even if more time has passed; a recall is not a guaranteed reversal.
- 2.
Preserve all evidence — emails, invoices, transaction records, communication logs. Do not delete anything.
- 3.
Report to FBI IC3 (ic3.gov) — file a detailed complaint with all available evidence.
- 4.
Notify your insurance carrier — if you have cyber liability insurance, file a claim immediately.
- 5.
Conduct an internal investigation — determine how the breach occurred and what systems were compromised.
- 6.
Reset compromised credentials — change passwords, revoke access tokens, and rotate API keys for any affected systems.
- 7.
Notify affected parties — if vendor or customer data was compromised, you may have legal notification obligations.
- 8.
Review and strengthen procedures — every incident is an opportunity to close the gap that was exploited.
Research and educational guidance by Peter. Sources and material corrections are linked on this page.
Frequently Asked Questions
Reviewed 23 September 2026. We corrected overbroad verification and recovery claims during our launch-content review. See the corrections log for the material changes.
Sources & References
Every statistic in this guide is sourced from verified organizations. Click to verify any claim.
Want a business fraud audit?
Our Business Protection Audit identifies your specific vulnerabilities with a written report.
Book a Consultation →