Understanding the threat
What is business email compromise?
Business email compromise is a form of fraud where attackers use email accounts, impersonation or deceptive messages to manipulate employees, customers or suppliers.
The attacker may compromise a real mailbox or create a convincing imitation of a trusted address. The message may then request a payment, banking-detail change, confidential document or account access.
Attackers often study normal communication, job titles, suppliers and payment processes before sending the fraudulent instruction.
Common attack methods
How business email attacks usually happen.
Stolen Credentials
A user enters their password into a fake login page, allowing the attacker to access the real mailbox.
Email Impersonation
A similar domain or display name is used to make a fraudulent message appear to come from a trusted person.
Mailbox Rule Abuse
Attackers create hidden forwarding or deletion rules to monitor conversations and conceal warnings.
Supplier Fraud
Existing invoice conversations are copied or altered to introduce fraudulent banking details.
Recommended controls
Security controls that reduce email compromise risk.
Enable multi-factor authentication
Require an additional verification method for email and cloud accounts. This reduces the value of a stolen password.
Block legacy authentication
Older authentication protocols may not support modern security controls and should be disabled where they are not required.
Configure SPF, DKIM and DMARC
Email-domain authentication helps receiving servers identify which systems are authorised to send mail for the domain.
Monitor suspicious sign-ins
Review alerts for unusual locations, unfamiliar devices, impossible travel and repeated failed login attempts.
Limit administrative access
Administrative privileges should be assigned only where required and protected with stronger controls.
Train employees regularly
Staff should know how to recognise urgent payment requests, unexpected login pages and suspicious attachments.
Financial controls
Verify banking and payment instructions separately.
Email security alone cannot eliminate every risk. Financial and operational procedures must also prevent one fraudulent message from authorising a payment.
Recommended payment-verification checklist
- Confirm banking-detail changes using a known telephone number.
- Do not use contact details supplied only in the change-request email.
- Require dual approval for high-value or unusual payments.
- Review the sender domain carefully for small spelling differences.
- Treat urgency and secrecy as warning signs.
- Record who verified the instruction and how.
A banking-detail change should never be approved solely because the email appears to come from a known supplier or manager.
User awareness
Warning signs employees should recognise.
Unexpected Urgency
Pressure to act immediately without normal verification.
Banking Changes
A request to pay into a new or unfamiliar account.
Unusual Secrecy
Instructions not to discuss the request with colleagues.
Unexpected Login Links
A request to sign in through an unfamiliar page.
Incident response
What to do when compromise is suspected.
Reset the password
Change the affected account password from a trusted device.
Revoke active sessions
Force sign-out from existing sessions and connected applications.
Review mailbox rules
Remove unknown forwarding, deletion or redirection rules.
Review sign-in activity
Identify suspicious locations, devices and authentication events.
Notify affected parties
Warn relevant employees, customers and suppliers about fraudulent messages.
Contact financial institutions
If payment fraud occurred, immediately contact the relevant bank and follow formal reporting procedures.
Delays may allow attackers to continue using the mailbox, hide evidence or target more contacts.
Final recommendation
Combine technical security with business process.
The strongest defence combines identity security, email authentication, monitoring, employee awareness and independent financial verification.
Organisations should review these controls regularly and update their response procedures as systems, users and suppliers change.