Skip to content

Cybersecurity

How business email compromise actually happens, and how to stop it

10 min read

There is no malware in most business email compromise. There is a person reading your mail, waiting for a payment to come up, and sending one message at the right moment. Which is why antivirus never sees it.

Business email compromise is the most expensive category of cybercrime affecting small businesses, and it is the least technical. There is usually no malware, no exploit and nothing for antivirus to detect.

The pattern is consistent. An attacker gets a working password. They sign in, read quietly, and wait — sometimes for weeks. When a payment is being arranged they send one message with different bank details, timed to arrive when it is expected. The money moves. Recovery is rare.

The two ways in, and they need different answers

Almost every case starts one of two ways, and confusing them is why businesses buy the wrong control.

  • They get into YOUR mailbox — usually a phished password or one reused from an unrelated breach. The fix is identity: MFA, Conditional Access, and blocking the legacy protocols that bypass both.
  • They impersonate your domain from outside — no access needed at all, just a forged sender. The fix is email authentication: SPF, DKIM and DMARC set to reject. This one is DNS records and costs nothing but attention.

Most local businesses are exposed to the second one

We measured the public email records of independent Ocala and Marion County businesses across fourteen trades. The large majority could be impersonated — a stranger can send email that appears to come from them, to their own customers, and it passes every check the receiving server makes.

The full figures and the method are published in our research section, and you can check your own domain in about two seconds with the free tool on this site. It reads the same public records; nothing is sent to you.

The controls, in the order worth doing them

  • Publish SPF, DKIM and DMARC, and move DMARC to enforcement once the reports show nothing legitimate is being caught. Free, and it stops your domain being forged.
  • Enforce MFA everywhere, including administrators, and block legacy authentication so nothing sidesteps it.
  • Alert on new mailbox rules and forwarding. Attackers create these immediately; catching one is often the only warning you get.
  • Restrict third-party app consent, so a user cannot grant an app permission to read the mailbox.
  • Add external sender warnings, so a lookalike domain is visibly not internal.
  • Verify payment changes by voice, on a number you already had — never one from the email requesting the change.

That last one is not a technical control and it is the one that most reliably stops the loss. Every technical measure above can be defeated by a sufficiently good message. A phone call to a number you already had cannot.

Write the verification rule down

The reason verbal verification fails is not that people disagree with it. It is that it is treated as a preference rather than a rule, so it gets skipped under time pressure — which is exactly the condition the attacker engineers.

Make it a written procedure, with no exception for urgency, and tell your customers you follow it. That last part protects you in both directions: it makes your genuine messages more trusted, and a forged one more likely to be questioned.

Frequently asked

Would antivirus or a firewall have stopped this?

Usually not. In most BEC there is nothing malicious to detect — a legitimate sign-in with a correct password, then ordinary email. That is precisely why it works, and why the defence is identity and authentication rather than endpoint software.

Can we find out whether our domain can be forged?

Yes, in seconds, using the free email security check on this site. It reads public DNS. If it comes back clean, that particular risk is already handled.

What if we already sent the money?

Call your bank immediately and request a recall, then file at ic3.gov, then tell your insurer. The window is measured in hours. Do that before any technical investigation.

How would we know an attacker is in a mailbox right now?

Common signs are mail rules nobody created, sent items that do not belong to the user, replies to conversations the user never started, and sign-ins from unexpected locations. Alerting on rule creation is the single most useful detection to add.

Ready to secure your business?

A free assessment: we review your network, backups, Microsoft 365 settings and exposure, then hand you the findings in writing — whether or not you hire us.

Call nowFree assessment