Some of the most expensive cyberattacks don't involve any malware at all. They involve a convincing email that tricks a person into sending money to a criminal. This is business email compromise (BEC) — and because it targets people rather than systems, ordinary security tools don't always catch it. Here's how these scams work and how to protect your business.
What business email compromise is
BEC is a type of scam where an attacker impersonates someone you trust — your boss, a supplier, a client, or a colleague — to trick you into making a payment or changing payment details. Unlike ransomware, there's often no virus involved: just a carefully crafted, believable email exploiting trust and urgency.
Because the message looks legitimate and asks you to do something you'd normally do (pay an invoice, update banking details), it slips past both technical filters and human suspicion.
The common variations
- The fake invoice. You receive an invoice that looks real — sometimes from a supplier whose email has actually been compromised — with updated banking details. You pay it, and the money goes to the criminal.
- The CEO / owner scam. An email that appears to be from the boss urgently asks an employee to make a payment, buy gift cards, or send a wire — playing on authority and urgency.
- The supplier banking-change. A message claiming a vendor has "changed their banking details," redirecting your next legitimate payment to the attacker.
- Payroll diversion. A fake request to change an employee's direct-deposit details.
The warning signs
- Urgency and secrecy. "Handle this right away," "don't tell anyone yet." Pressure is designed to stop you thinking.
- A change to payment details. Any request to change banking or payment information should trigger alarm bells.
- A slightly-off email address. The display name looks right, but the actual address is subtly wrong or external.
- A request that skips normal process. A payment or change that bypasses your usual approvals.
- Unusual wording or timing for the person supposedly sending it.
The single best defence: verify out-of-band
Technology helps, but the human step is what stops BEC: for any payment or change to payment details, verify it through a separate channel — a phone call to a known number (not one from the email), or in person. Never confirm a banking change by replying to the same email. This one habit prevents the vast majority of BEC losses.
Backing it up with the fundamentals
- MFA on email, so an attacker can't take over an account to send these from the inside. See our MFA guide.
- Email filtering to catch impersonation attempts.
- Clear internal payment procedures with approval steps and verification for changes.
- Staff awareness — everyone who handles payments should know these scams. See how to spot a phishing email.
The bottom line
Business email compromise uses trust and urgency, not malware, to trick people into sending money — which is exactly why it's so effective and so costly. The defence is a mix of MFA and email filtering plus one crucial human habit: always verify payment requests and banking changes through a separate, trusted channel before acting.
We help Alberta businesses put both the technical and the human defences in place. Learn more about our cybersecurity services, or book a free evaluation.
