Business email fraud turns familiar requests into costly payment losses

THE BRIEF
The NCSC expert blog described how attackers may first compromise a mailbox, then study writing style, timing and business relationships before sending a convincing request. One example involved a medium-sized company that transferred €45,000 after a message appeared to come from its director. The employee acted on a request that fit normal communication patterns. Smaller organizations can be especially exposed because payments may depend on informal approval and one person may control several steps. Strong email filtering helps, but it cannot replace a financial process that independently verifies unusual requests. The guidance recommends dual approval, call-back checks for bank-detail changes and monitoring for suspicious sign-ins or unauthorized connected applications. Employees should be encouraged to pause and report a questionable request without fear of blame. A culture that punishes hesitation can make urgency and authority more effective tools for the criminal.
WHY IT MATTERS
BEC can bypass expensive security tools because the final action is performed by an authorized employee. Once money reaches a fraudulent account, recovery becomes uncertain and delays are costly. The most effective controls therefore sit across finance, management and IT: separate duties, verify changes outside email and detect mailbox abuse early. For small businesses, these measures may feel slower than informal approval, but a two-minute call can prevent a loss large enough to threaten payroll or operations. Managers should make safe interruption part of the process rather than relying on staff to recognize every sophisticated message.
WHO SHOULD CARE
Small-business owners, finance staff, executive assistants, managers and managed IT providers should care. Anyone authorized to change supplier details or release payments is a potential target, while leaders determine whether verification and escalation are genuinely supported.
WHAT TO DO NOW
- Require two people to approve new beneficiaries and unusual or urgent payments.
- Call a known contact number to verify every supplier bank-detail change.
- Alert on unfamiliar mailbox sign-ins, forwarding rules and newly approved OAuth applications.
- Disable legacy authentication and require phishing-resistant multifactor authentication where available.
- Create a blame-free process for pausing and reporting suspicious payment requests.