Security · Fraud
What BEC is, common scenarios, warning signs, ten protections, a verification procedure and what to do if you suspect fraud.
Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.
Quick answer
Business email compromise is fraud in which a criminal uses email, by impersonation or a taken-over mailbox, to trick someone into sending money or information, often through a fake change of bank details. Protect your firm by verifying changes by phone on a number you already hold, using dual approval, enabling multi-factor authentication, setting up SPF, DKIM and DMARC, watching for mailbox forwarding rules, training staff and telling clients you never change payment details by email alone. If you suspect fraud, call your bank immediately.
Key takeaways
- Never act on a change of bank details sent by email alone; phone a number you already hold.
- Use dual approval and multi-factor authentication; watch for hidden mailbox rules.
- Tell clients and suppliers your verification rule.
- If you suspect fraud, contact your bank immediately, secure accounts and preserve evidence.
- Make it safe for staff to report near misses.
In this guide
What is business email compromise?
Business email compromise, or BEC, is a type of fraud in which a criminal uses email to trick someone into sending money or sensitive information. The attacker may impersonate a boss, a supplier, a client or a solicitor, or take over a real mailbox. A common version is the fake change of bank details: an apparently genuine email asks you to pay an invoice into a new account. Small professional firms are frequent targets because they handle large payments, client funds and sensitive documents.
Common BEC scenarios
| Scenario | How it works |
|---|---|
| Fake invoice or changed bank details | An email, seemingly from a supplier, asks you to pay into a new account |
| Impersonated executive | A message that looks like it is from a partner or director asks for an urgent payment or gift cards |
| Compromised mailbox | An attacker reads real conversations, then inserts a fraudulent payment request at the right moment |
| Fake client or conveyancing-style payment instructions | A client or a third party appears to give new payment details for funds held or due |
| Payroll diversion | An email pretending to be a staff member asks to change bank details for salary |
| Document requests | Impersonators ask for identity documents or sensitive files |
Warning signs
- A change of bank details, especially close to a payment date.
- Urgency, secrecy or pressure to bypass normal process.
- Slightly different email addresses or domains, such as one letter changed.
- A different writing style or odd phrasing.
- Requests that arrive outside normal channels.
- A reply-to address that differs from the sender.
- Unexpected attachments or links asking you to log in.
How to protect your firm
- Verify changes by phone, using a number you already hold, never one from the email itself.
- Use dual approval for payments above a threshold and for any change of bank details.
- Turn on multi-factor authentication for email and financial systems.
- Set up SPF, DKIM and DMARC to make it harder to spoof your domain.
- Watch for mailbox rules: attackers often create hidden forwarding rules. Review them and alert on new ones.
- Train staff with realistic examples and encourage them to ask without fear.
- Restrict who can change payment details and log changes.
- Use a secure portal for sensitive requests so clients know genuine requests come that way, not by email. See our security guide.
- Tell clients and suppliers your rule: you will never change payment details by email alone, and they should verify any request purporting to be from you by phone.
- Keep an incident plan and rehearse it.
What to do if you suspect fraud
- Contact your bank immediately to try to stop or recall the payment. Speed matters.
- Secure the affected accounts: change passwords, check mailbox rules, revoke sessions and enable multi-factor authentication.
- Preserve evidence: keep the emails, headers and logs.
- Report it to the relevant fraud-reporting authority in your country and to the police as appropriate.
- Tell your insurer if you have cover.
- Assess whether personal data was exposed, and follow breach notification rules where required.
- Inform affected clients or suppliers carefully.
- Review and improve your controls.
Notification duties and reporting routes vary by country and sector, so take advice. See our data breach checklist for the wider response.
A simple payment verification procedure
Payment change verification
1. Never act on a change of bank details received by email alone.
2. Call the supplier or client on a number already in your records.
3. Record who you spoke to, when and what was confirmed.
4. Have a second person approve the change.
5. For large payments, send a small test payment first where practical.
6. Log the change and who approved it.
What mistakes should you avoid?
- Calling the number in the suspicious email.
- Skipping verification because the sender seems senior or urgent.
- One person able to change and approve payment details.
- No multi-factor authentication on email.
- Never checking mailbox forwarding rules.
- Embarrassment that stops staff reporting a near miss.
Simple Automation Solutions builds approval workflows, role-based access and audit trails into client portals and internal systems, which help enforce dual approval and logging. Builds start at $3,500, and a $345 Discovery Sprint, credited toward the build, scopes them. We do not provide incident response or fraud recovery services.
Frequently asked questions
What is business email compromise?
A fraud in which a criminal uses email, often by impersonating or taking over a real account, to trick someone into sending money or sensitive information.
How can I verify a change of bank details?
Phone the supplier or client on a number you already hold, never one in the email, record the call and have a second person approve the change.
What should I do if I paid a fraudulent invoice?
Contact your bank immediately to try to recall the payment, secure the affected accounts, preserve evidence, report it and tell your insurer.
Does multi-factor authentication stop BEC?
It greatly reduces mailbox takeover, but not impersonation of a lookalike domain, so verification procedures are still needed.
How do I train staff to spot it?
Use realistic examples, teach the warning signs and make it safe to ask or report without blame.
Want approval workflows and audit trails built into your payments process?
Email us how payments and changes are handled today. We will outline a safer workflow.
Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions
About Simple Automation Solutions (SA Solutions)
Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.