featured
3 Minutes

One of the fastest-growing threats facing businesses today is Business Email Compromise (BEC), a scam that can result in significant financial losses without a single system being hacked.

BEC scams target businesses that regularly send payments to vendors, suppliers, contractors, and service providers. By impersonating trusted contacts and manipulating payment instructions, criminals can redirect funds into fraudulent accounts before anyone realizes something is wrong.

What Is a Business Email Compromise Scam?

Unlike traditional phishing attacks that rely on suspicious links or attachments, BEC scams are often highly targeted and personalized. Criminals may:

  • Impersonate a vendor, supplier, or contractor
  • Create lookalike email addresses or websites
  • Request changes to payment instructions
  • Ask that future payments be sent to a new bank account
  • Alter invoice or ACH payment information

Because the request appears to come from a trusted source, employees may not recognize the fraud until after funds have been transferred.

A Recent Real-World Example

A recent Wall Street Journal article highlighted how devastating these scams can be. The Town of Surfside Beach, South Carolina, reportedly transferred more than $545,000 to a fraudulent bank account after receiving what appeared to be legitimate instructions during an ongoing payment conversation with a contractor.

According to the reporting, the criminals gained access to a legitimate email account and monitored conversations until they identified an upcoming payment. Then using lookalike email domains they sent their own email in disguise asking to change the method of payment from check to ACH transfer.  The ACH information linked to account belonging to the fraudsters and was immediately transferred out as soon as the funds came available.

Warning Signs to Watch For

  • Requests to change ACH or wire instructions
  • Last-minute payment changes
  • New banking information for an existing vendor
  • Urgent requests involving large payments
  • Emails with slight variations in domain names
  • Messages discouraging phone verification

Any of these should trigger additional review before funds are sent.

How to Protect Your Business

Verify Payment Change Requests Offline

If a vendor requests new payment instructions, contact them using a phone number already on file. Never rely solely on the contact information provided in the email.

Require Dual Approval

Implement a two-person review process for significant payments and vendor account changes. A second set of eyes can help identify inconsistencies.

Train Employees Regularly

Employees responsible for accounts payable should understand how BEC scams work and be trained to inspect email addresses carefully.

Review Vendor Banking Changes

Establish formal procedures for validating banking changes before updating vendor records.

Leverage Bank Fraud Controls

Many financial institutions offer tools that can help businesses reduce fraud risk, including:

  • ACH Positive Pay
  • Dual-approval workflows
  • Transaction alerts
  • Wire transfer verification procedures
  • Account monitoring services

Speak with your banker about the options available for your organization.

The Bottom Line

The best defense is simple: whenever payment instructions change, verify before you send. A quick phone call can be the difference between completing a legitimate transaction and becoming the next fraud victim.