Business email compromise is a fraud in which an attacker uses a genuine or convincingly spoofed email account to direct someone inside an organization to move money or release data. It is the costliest category of fraud most employers face, and it is aimed squarely at finance, HR, and payroll.
What separates it from ordinary phishing is that there is often nothing technically malicious to detect. No attachment, no link, no malware — just a plausible message asking a person with authority to do something they are entirely capable of doing.
Executive impersonation. A message appearing to come from the CEO or CFO asking for an urgent wire, an off-cycle payment, or a file of employee W-2 data. It exploits authority and urgency together, and it works because challenging a senior person feels riskier to the employee than processing the request.
Employee impersonation. A message posing as a worker asking HR to update their direct deposit details — the payroll diversion scheme.
Vendor impersonation. A message from a supplier announcing new banking details, often referencing a real outstanding invoice. This variant produces the largest single losses because the amounts are larger.
Account takeover. The hardest version: the attacker controls a real mailbox — an executive's, a colleague's, or a vendor's — and sends the request from it.
When an attacker holds a genuine mailbox, every sender-based verification passes. The address is legitimate, the display name is right, the signature block is real.
Worse, the attacker has read the mailbox. They know the payroll calendar, the names of vendors, the tone of internal correspondence, and often the exact invoice under discussion. They frequently create inbox rules to hide replies from the real account owner, so the legitimate user never sees the conversation happening in their name.
An employee cannot reasonably detect this. Only a control that does not depend on the message can.
Out-of-band verification. Any instruction to move money or release bulk data is confirmed through a channel already on file — a phone number retrieved from the HR or vendor record, not one supplied in the request.
Replying to the email is not verification. Calling a number in the signature is not verification. Confirming details the sender provided is not verification. The requirement is a separate channel using contact information the organization already held.
Applied consistently, this defeats all four patterns including account takeover, because the attacker cannot intercept a call to a number they did not choose.
The technical controls are the easy part. BEC succeeds on social pressure, and that is fixed by leadership rather than configuration.
Executives need to state plainly, and more than once, that verification is expected, that it applies to requests appearing to come from them, and that no employee will face any consequence for making the call. Where that has been said clearly, staff verify. Where it has not, the policy collapses the first time a request arrives from the CFO on a deadline.
The rule also has to be absolute. Any carve-out for seniority or urgency reintroduces exactly the judgment call the attacker is engineering.
Speed is everything. Contact the bank immediately and ask about recall procedures — for wires the realistic window is hours, not days. Report to law enforcement promptly, as rapid reporting materially improves the odds of funds being frozen.
Then treat it as a compromise investigation rather than a single transaction. Determine whether a mailbox was taken over, check for inbox rules and forwarding, reset credentials, and review what else that mailbox contained. Check whether similar requests reached other employees, because these campaigns rarely target one person.
Where employee data was released, breach notification obligations may be triggered and are time-bound. That analysis should start immediately, in parallel with the financial response.
Employer's Guardian helps employers build verification and approval controls into payroll and payment operations through payroll services.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.