Business Email Compromise (BEC): What Employers Need to Know
August 18, 2026
Business email compromise is a fraud in which an attacker uses a genuine or convincingly spoofed email account to direct someone inside an organization to move money or release data. It is the costliest category of fraud most employers face, and it is aimed squarely at finance, HR, and payroll.
What separates it from ordinary phishing is that there is often nothing technically malicious to detect. No attachment, no link, no malware — just a plausible message asking a person with authority to do something they are entirely capable of doing.
The four patterns
Executive impersonation. A message appearing to come from the CEO or CFO asking for an urgent wire, an off-cycle payment, or a file of employee W-2 data. It exploits authority and urgency together, and it works because challenging a senior person feels riskier to the employee than processing the request.
Employee impersonation. A message posing as a worker asking HR to update their direct deposit details — the payroll diversion scheme.
Vendor impersonation. A message from a supplier announcing new banking details, often referencing a real outstanding invoice. This variant produces the largest single losses because the amounts are larger.
Account takeover. The hardest version: the attacker controls a real mailbox — an executive's, a colleague's, or a vendor's — and sends the request from it.
Why account takeover defeats normal checks
When an attacker holds a genuine mailbox, every sender-based verification passes. The address is legitimate, the display name is right, the signature block is real.
Worse, the attacker has read the mailbox. They know the payroll calendar, the names of vendors, the tone of internal correspondence, and often the exact invoice under discussion. They frequently create inbox rules to hide replies from the real account owner, so the legitimate user never sees the conversation happening in their name.
An employee cannot reasonably detect this. Only a control that does not depend on the message can.
The control that actually works
Out-of-band verification. Any instruction to move money or release bulk data is confirmed through a channel already on file — a phone number retrieved from the HR or vendor record, not one supplied in the request.
Replying to the email is not verification. Calling a number in the signature is not verification. Confirming details the sender provided is not verification. The requirement is a separate channel using contact information the organization already held.
Applied consistently, this defeats all four patterns including account takeover, because the attacker cannot intercept a call to a number they did not choose.
Supporting measures
- MFA on email — reduces how often account takeover is available at all
- Alerting on inbox rule creation, since hiding replies is a hallmark of an active compromise
- Two-person approval for wires, banking changes, and off-cycle payments
- Waiting periods on banking changes, removing the urgency the scheme depends on
- External-sender banners so lookalike domains are visually flagged
- Email authentication configured to reject spoofed messages using your own domain
- Callback verification with the bank for wire transfers
The organizational half
The technical controls are the easy part. BEC succeeds on social pressure, and that is fixed by leadership rather than configuration.
Executives need to state plainly, and more than once, that verification is expected, that it applies to requests appearing to come from them, and that no employee will face any consequence for making the call. Where that has been said clearly, staff verify. Where it has not, the policy collapses the first time a request arrives from the CFO on a deadline.
The rule also has to be absolute. Any carve-out for seniority or urgency reintroduces exactly the judgment call the attacker is engineering.
If it has already happened
Speed is everything. Contact the bank immediately and ask about recall procedures — for wires the realistic window is hours, not days. Report to law enforcement promptly, as rapid reporting materially improves the odds of funds being frozen.
Then treat it as a compromise investigation rather than a single transaction. Determine whether a mailbox was taken over, check for inbox rules and forwarding, reset credentials, and review what else that mailbox contained. Check whether similar requests reached other employees, because these campaigns rarely target one person.
Where employee data was released, breach notification obligations may be triggered and are time-bound. That analysis should start immediately, in parallel with the financial response.
Employer's Guardian helps employers build verification and approval controls into payroll and payment operations through payroll services.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.

