Ransomware gets the headlines. But the scam quietly draining more money out of businesses every year doesn’t lock your files or demand a payout in Bitcoin. It just sends an email — and asks nicely.
It’s called business email compromise, or BEC, and according to the FBI, it now causes more reported financial losses than any other type of cybercrime, ransomware included. No malware. No ransom note. Just a convincing email that tricks someone into wiring money, changing a payment account, or handing over sensitive data.
Here’s the short answer: business email compromise a scam where criminals impersonate an executive, vendor, or trusted contact by email to trick an employee into sending money or sensitive information. It costs businesses more than ransomware because it targets people, not systems — and traditional antivirus software can’t stop a well-written email.
Below, we’ll explain how BEC scams actually work, why they’re so effective, and what your business can do to stop one before it costs you.
What Is a Business Email Compromise?
Business email compromise is a type of phishing attack where a scammer impersonates someone the victim trusts — typically a CEO, vendor, or business partner — in order to manipulate an employee into making a wire transfer, changing bank account details, or sharing confidential information.
Unlike ransomware, BEC doesn’t rely on hacking software or exploiting a technical vulnerability. It relies on social engineering: convincing a real person that a fake request is legitimate.
How Business Email Compromise Attacks Work
Most BEC scams follow a similar pattern:
- Research. The attacker studies a company’s website, LinkedIn profiles, and public records to learn names, titles, and relationships — who reports to whom, who handles payments, which vendors the company uses.
- Impersonation. The scammer creates a lookalike email address (often changing one letter) or gains access to a real account through a prior phishing attack.
- The request. An email arrives that looks like it’s from the CEO, CFO, or a known vendor. It asks for an urgent wire transfer, a change to payroll deposit information, or sensitive files like W-2s.
- Urgency and authority. The message is designed to pressure quick action: “I’m in a meeting, can’t talk, need this done in the next 20 minutes.”
- The payout. By the time anyone realises the request was fake, the money is often already gone — usually routed through several accounts before it can be traced or recovered.
Why Business Email Compromise Costs More Than Ransomware?
It Targets People, Not Firewalls
Ransomware needs to break through technical defences. Business email compromise skips that step entirely and goes straight for the weakest link in any security system: a busy employee trying to do the right thing quickly.
There’s No Ransom Negotiation — the Money Is Just Gone
With ransomware, businesses sometimes recover data through backups or negotiation. With BEC, once a wire transfer clears, that money has often moved through multiple accounts within hours, making recovery extremely difficult.
It’s Harder to Detect
Antivirus software and firewalls built to catch malicious code, not a well-written email that looks exactly like something your boss would send. BEC attacks frequently pass right through standard security filters because there’s no malware to flag.
The Losses Add Up Quietly
A single ransomware attack tends to make headlines. Thousands of smaller business email compromise losses — a $15,000 wire here, a $40,000 payroll redirect there — rarely make the news, but they add up to a bigger total industry-wide impact every year.

Common Types of Business Email Compromise Scams
- CEO fraud: An email impersonating a company executive requests an urgent wire transfer.
- Vendor invoice fraud: A scammer poses as a known supplier and asks for payment to a “new” bank account.
- Payroll diversion: An attacker impersonates an employee and asks HR to change their direct deposit details.
- Attorney impersonation: A scammer poses as legal counsel handling a confidential, time-sensitive matter to pressure a quick payment.
- Data theft requests: Instead of money, the attacker asks HR or finance for sensitive documents like tax forms or employee records.
Warning Signs of a Business Email Compromise Attempt
Train your team to slow down when an email includes any of the following:
- A request for urgency or secrecy (“don’t tell anyone else about this yet”)
- A change to payment details or bank account information.
- Slightly altered email addresses or domain names.
- Pressure to bypass normal approval processes.
- A tone or writing style that doesn’t quite match how that person usually writes.
- Requests made only by email, with no phone or in-person confirmation.
How to Protect Your Business from Email Compromise Scams
- Verify before you pay. Any request to change payment details or send a wire transfer should be confirmed by phone, using a number you already have on file — not one included in the email.
- Use multi-factor authentication on every email account to make it harder for attackers to hijack a real inbox.
- Set up email authentication protocols (SPF, DKIM, and DMARC) to make spoofed domains easier to catch and block.
- Train employees regularly on what BEC attempts look like, especially staff who handle payments, payroll, or sensitive data.
- Create a two-person approval process for wire transfers and account changes above a set dollar amount.
- Monitor for lookalike domains that could be used to impersonate your company or your vendors.
- Work with a managed IT and cybersecurity partner who can monitor for suspicious login activity and respond quickly if an account is compromised.
FAQs
1. What is a business email compromise?
Business email compromise is a scam where criminals impersonate an executive, vendor, or trusted contact by email to trick an employee into sending money or sensitive information.
2. Why does business email compromise cost more than ransomware?
Business email compromise targets people instead of technical systems, making it harder to detect with traditional security tools. Once a fraudulent wire transfer is sent, the funds are often moved quickly and are difficult to recover, unlike ransomware, where backups or negotiation can sometimes limit losses.
3. How can I tell if an email is a BEC scam?
Watch for urgent requests, last-minute changes to payment or bank details, slightly altered email addresses, pressure to skip normal approval steps, and requests that avoid phone or in-person confirmation.
4. Can antivirus software stop business email compromise?
Not on its own. Because BEC attacks typically don’t involve malware, they can pass through standard antivirus and spam filters. Preventing BEC requires a combination of email authentication tools, employee training, and verification processes.
5. What should my business do if we fall victim to a BEC scam?
Contact your bank immediately to try to recall the transfer, report the incident to the FBI’s Internet Crime Complaint Center (IC3), and notify your IT or cybersecurity provider to secure any compromised accounts and prevent further loss.
Protect Your Business Before the Email Arrives
Business email compromise doesn’t need to break through your firewall — it just needs one busy employee and one convincing message. The businesses that avoid becoming a statistic are the ones with verification processes, trained employees, and IT partners actively monitoring for suspicious activity.
Zia Networks has protected Santa Fe and Albuquerque businesses from cybersecurity threats like business email compromise since 2014. Our managed IT and security services include email authentication, employee security training, and 24/7 monitoring to help catch threats before they cost you. Schedule a free IT review to see how protected your business really is.