
Last month, a controller at a 40-person manufacturing company in Worcester wired $340,000 to a vendor’s “updated” bank account. The email came from the vendor’s real address, used the vendor’s real logo, and referenced an invoice number that matched an actual open order. It just wasn’t from the vendor. By the time anyone called to confirm, the money had already moved through two more accounts and was gone.
That’s business email compromise, and it’s not a niche problem anymore. The FBI’s Internet Crime Complaint Center tracked nearly $2.8 billion in BEC losses in 2024 alone, and a 2025 survey from the Association for Financial Professionals found that 63% of organizations experienced at least one BEC attempt in the prior year. Unlike ransomware, there’s no malware to catch and no ransom note, just a well timed email that looks exactly like it should.
How the Scam Actually Works
Most BEC attacks skip the smash and grab approach entirely. An attacker compromises, or convincingly spoofs, a real email account, then spends days or weeks quietly watching how the business communicates. They learn who approves payments, how invoices are usually worded, and when leadership tends to be traveling or unavailable. Then they strike, usually with a request that feels urgent but plausible: an updated bank account, a rushed payment before a deadline, a favor for a distracted executive.
There’s no attachment to click and no obviously fake link. That’s exactly why it slips past spam filters and past employees who’ve been trained to spot the “classic” phishing email.
Why Small and Midsize Businesses Are Prime Targets
Enterprise finance departments usually have multiple approval layers built in by default. Smaller companies often don’t; one person handles accounts payable, one person has wire authority, and speed is treated as a virtue. Attackers know this. A business with $10 million in revenue and a lean finance team is, in some ways, an easier payday than a Fortune 500 company with a dozen controls standing between an email and a wire transfer.
What Actually Stops It
Spam filtering helps, but it’s not the control that matters most here. The defenses that actually work are procedural as much as technical:
- Require a phone call, to a known number, not one in the email, before changing any bank account or wire instruction
- Put dual approval on payments above a set threshold, no exceptions for “urgent” requests
- Deploy email authentication (SPF, DKIM, DMARC) so spoofed domains get flagged or blocked automatically
- Run regular phishing and BEC simulations so employees recognize pressure tactics before they’re facing a real one
The technical piece matters too. A properly configured security stack with continuous monitoring can catch the early signs of a compromised mailbox long before it’s used to request a wire transfer: unusual login locations, forwarding rules quietly added to an inbox, sign in attempts from unfamiliar devices. Those are the breadcrumbs BEC attackers leave behind, if someone’s watching for them.
The human piece matters just as much. Cloud9 Tech Solutions builds ongoing security awareness training into client engagements specifically because BEC succeeds by exploiting trust and urgency, not technical ignorance. Employees who’ve practiced spotting these attempts, calmly and without shame when they get one wrong, become the strongest layer of defense a business has.
The Bottom Line
Business email compromise doesn’t announce itself. It looks like your normal Tuesday: an invoice, a vendor update, a request from someone who sounds exactly like they should. The businesses that avoid becoming a statistic aren’t the ones with the fanciest tools. They’re the ones with a verification habit nobody’s allowed to skip, even under pressure.
If you’re not sure where your business stands, that’s worth finding out before an attacker does. Schedule a free security assessment with Cloud9 and get a clear picture of where the gaps are, and what it actually takes to close them.
