What is business email compromise and how do you prevent it?

Business email compromise (BEC) is a financially targeted cyber attack where criminals impersonate a trusted contact, usually an executive, supplier, or colleague, to trick employees into transferring money or handing over sensitive information. No malware is involved. No suspicious attachments. The attack works entirely through deception, exploiting the trust people place in email. For Australian businesses, BEC is consistently one of the most reported and most costly forms of cybercrime, sitting alongside ransomware as a primary threat in ASD’s ACSC Annual Cyber Threat Report for FY2024-25.
The financial and operational consequences are significant. A single successful BEC attack can result in a fraudulent wire transfer of tens of thousands of dollars, redirected payroll, a changed supplier bank account, or a data leak that triggers obligations under the Notifiable Data Breaches scheme. Funds transferred by BEC are rarely recovered. Banks treat these as authorised payments because the employee made the transfer willingly, based on what they believed was a legitimate instruction.
Business owners, finance managers, and operations staff who handle payments or sensitive data are the primary targets. This includes professional services firms, construction companies, accountants, and any business that regularly exchanges invoices with external suppliers. The ACSC has specifically warned Australia’s construction sector about BEC scams targeting payment processes. Any organisation that pays bills by email is exposed.
How business email compromise attacks actually work
BEC attacks do not rely on technical exploits. They rely on research and social engineering. Before sending a single email, an attacker will typically spend time gathering publicly available information: LinkedIn profiles, your website, press releases, and social media can all reveal who your finance team is, who your CEO is, which suppliers you use, and what your approval workflows look like.
There are three common attack variants. The first is CEO fraud: the attacker sends an email appearing to be from a senior executive, requesting an urgent wire transfer or asking an employee to purchase gift cards quietly. The email often comes from a look-alike domain, for example swapping a lowercase “l” for the number “1” or registering a domain with a single letter changed. The second is invoice fraud: the attacker poses as a supplier and sends a fake or altered invoice, changing the bank account number to one they control. The third is account compromise: the attacker gains access to a real employee email account using stolen credentials, then uses that legitimate inbox to request payments or redirect funds. This third type is the hardest to detect because the email genuinely comes from the right address.
Generative AI has changed the scale and quality of these attacks. By mid-2024, an estimated 40% of BEC phishing emails were AI-generated, producing messages that are grammatically correct, contextually relevant, and stylistically consistent with the person being impersonated. What used to require hours of manual research can now be assembled in minutes. The result is a sharp increase in volume and a harder detection problem for employees.
Why standard email filters do not stop BEC
BEC emails typically contain no malicious links, no infected attachments, and no unusual file types. This means they pass most standard spam and malware filters without triggering an alert. The email looks clean because it is clean, technically speaking. The threat is entirely in the words and the sender context, not in any payload the filter can detect.
This is the core challenge. An employee receives an email that looks like it came from the CEO asking them to process an urgent payment before end of day. The email address resembles the real one. The tone matches. There is no red flag a filter would catch. The attack bypasses technical controls and lands directly on the human decision-maker.
Even multi-factor authentication (MFA), while essential for preventing account takeover, does not stop an attacker who is simply spoofing an email address rather than logging into an account. BEC can succeed without the attacker ever needing to access your systems at all. This is why a layered defence, combining technical controls with process controls and staff training, is necessary.
Technical controls that reduce BEC risk
The first layer of technical defence is email authentication. The ACSC recommends that every business configure three DNS-based standards on their domain: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting and Conformance). SPF specifies which mail servers are authorised to send email on behalf of your domain. DKIM adds a cryptographic signature to outgoing emails. DMARC ties these together and tells receiving mail servers what to do when a message fails authentication, either reject it or quarantine it. A correctly configured DMARC policy prevents attackers from sending emails that appear to come from your domain. Without it, anyone can.
The second layer is MFA on all email accounts. MFA stops attackers from accessing a real mailbox using stolen credentials and executing a BEC from inside. This matters because account-compromise BEC, where the attacker sends from a legitimate inbox, is among the most convincing attack types. Shared mailboxes and administrator accounts are frequently left without MFA and should be included. Microsoft 365 environments should also have anti-impersonation policies enabled in Microsoft Defender for Office 365, which flags look-alike sender domains and warns recipients when an external sender is attempting to appear as an internal contact.
The third layer is DNS filtering, which can block access to newly registered look-alike domains before they reach employees. Attackers often register impersonation domains shortly before launching a campaign. DNS filtering catches these domains at the network level, before any email is even opened. You can read more about how this integrates with broader security controls in our article on DNS and Essential Eight integration.
Process controls that BEC cannot social-engineer around
Technical controls reduce the attack surface but cannot eliminate it. Process controls close the gap. These are the rules and workflows your business follows when handling financial transactions and sensitive data requests.
The most effective process control is out-of-band verification. Any request to transfer funds, change a supplier’s bank account details, or share sensitive data should be verified by calling the requester directly on a known phone number, not a number provided in the email itself. This single step stops the majority of BEC attempts. The ACSC recommends businesses introduce an approval process specifically for requests that ask to change payment details or authorise a large transfer, and verify those requests by phone before acting.
Dual authorisation for payments above a defined threshold is another strong control. No single employee should be able to approve and execute a large payment alone. This is not just a financial governance principle. It is a direct defence against CEO fraud, where urgency and authority pressure a single person to bypass normal checks.
A clear policy that no payment instruction or banking change will be actioned based solely on email is worth formalising in writing. Employees who know this rule is in place are less likely to feel social pressure to act without verifying, even when the request appears to come from a senior leader.
What TTA sees in Brisbane SME environments
Across the businesses we work with in Brisbane and South-East Queensland, BEC risk tends to concentrate in two places: finance teams handling supplier payments, and executive assistants who manage schedules and authorise expenses on behalf of leadership. These are the roles attackers research before sending anything.
The pattern we see most often is not a technically sophisticated attack. It is a well-researched one. An attacker spends a week observing a business’s public information, identifies a payment cycle (end of month, EOFY, a construction milestone), and sends one carefully timed email to the right person. The email arrives when the recipient is under pressure. Verification gets skipped. The money moves.
What we also see is that the businesses most exposed are those that have email security configured to a default Microsoft 365 baseline, with no DMARC enforcement, no anti-impersonation policies, and no documented payment verification process. These are not complex gaps to close. They are configuration and process tasks that take hours to address, not weeks. Our IT security assessments typically surface at least one of these gaps in businesses that have never had a formal review.
For businesses that want to look at their cyber insurance compliance position, BEC controls, specifically MFA, DMARC, and payment verification procedures, are now standard questions on Australian insurer questionnaires. Businesses without these in place often find their claims disputed or their premiums higher than they need to be.
Staff training for BEC: what actually works
BEC staff training is not about teaching people to recognise bad grammar or suspicious attachments. Modern BEC emails have neither. Effective training focuses on two things: understanding how urgency and authority are used to pressure people into skipping verification, and creating a culture where it is safe to pause and check before acting.
The cultural element is often overlooked. An employee who receives what appears to be an urgent CEO request may hesitate to call back because they do not want to seem unhelpful or slow. Training needs to explicitly give employees permission to verify, and leadership needs to reinforce this verbally. A CEO who publicly supports the “call before you pay” rule removes the social pressure an attacker is trying to exploit.
Practical training scenarios, using real BEC examples relevant to your industry and business size, are more effective than generic awareness content. Construction companies should see construction BEC examples. Professional services firms should see invoice fraud and data-request scenarios. Our post on security training that sticks covers what makes this type of training land versus what gets ignored.
What to do if a BEC attack succeeds
Speed matters. If you realise a fraudulent payment has been made, contact your bank immediately and ask them to initiate a payment recall. Australian banks have procedures for this, but the window for recovery closes fast once funds reach the destination account, particularly if they have been moved overseas.
Report the incident to the ACSC via the ReportCyber portal. Reporting creates an official record, which your insurer may require, and helps the ACSC identify and disrupt active BEC campaigns targeting Australian businesses.
Do not delete any emails or attempt to clean up the conversation. The email headers, message content, and timeline are evidence. Preserve everything before any account is changed or reset. If the attack appeared to come from an internal address, treat your own environment as potentially compromised and check for unauthorised inbox rules, forwarding configurations, or new mail filters that an attacker may have set up to maintain access.
Frequently asked questions about business email compromise
What is business email compromise in simple terms?
Business email compromise is a scam where a criminal pretends to be someone you trust, typically a manager, supplier, or colleague, and uses email to convince you to send money or share sensitive information. There is no malware involved. The attack works through deception alone. Because the email looks legitimate, it often bypasses standard spam and security filters and reaches the target directly.
Is business email compromise only a risk for large companies?
No. Small and mid-sized businesses are frequent targets because they tend to have fewer formal verification processes in place and their financial workflows are often managed by a small number of people. Research indicates that smaller organisations experience a disproportionately high volume of social engineering attacks. BEC is not about the size of the business; it is about the presence of a payment process that can be exploited.
Does multi-factor authentication prevent business email compromise?
MFA helps prevent one type of BEC: account compromise, where an attacker logs into a real email account using stolen credentials. However, many BEC attacks never involve logging in at all. The attacker simply spoofs a look-alike email address. For those attacks, MFA provides no protection. Preventing spoofing requires DMARC, DKIM, and SPF to be correctly configured on your domain.
What is DMARC and why does it matter for BEC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS-based email standard that tells receiving mail servers what to do when an email claiming to come from your domain fails authentication checks. Set to “reject”, it stops attackers from sending emails that appear to come from your domain. Without DMARC, anyone can send email that appears to be from your business, which is the foundation of most domain-spoofing BEC attacks.
How do attackers know enough about our business to write convincing BEC emails?
Most of the information they use is publicly available. LinkedIn profiles, company websites, press releases, and social media reveal staff names, roles, reporting lines, and supplier relationships. Attackers gather this through open-source research before launching a campaign. AI tools now speed up this process significantly. The ACSC recommends businesses limit the personal and structural information they publish publicly where possible.
What should we do immediately after a BEC attack?
Contact your bank first to request a payment recall. Then report the incident to the ACSC via ReportCyber. Preserve all emails, headers, and logs as evidence. Check your email environment for unauthorised forwarding rules or inbox filters. Notify your IT provider to assess whether an account was actually compromised. Act within hours; the window for fund recovery is short, and evidence degrades quickly if accounts are reset before it is captured.
Where do we get started with BEC prevention?
Start with three things: check whether your domain has DMARC, DKIM, and SPF configured correctly; confirm that MFA is active on all email accounts; and document a payment verification procedure that requires a phone callback before any banking change or large transfer is actioned. These three steps address the most common ways BEC attacks succeed in Australian SMEs.
How can TTA help with this?
TTA reviews email authentication configuration, Microsoft 365 security settings, and financial approval workflows as part of our standard security assessments for Brisbane and Queensland businesses. Get in touch and we can walk through where your current setup stands and what practical steps are worth prioritising.



