Ransomware gets the headlines. Business email compromise gets the money. BEC uses no malware and trips no antivirus — just a convincing email and a bank account that quietly changes. It's the attack that drains municipal accounts and small-business payrolls without ever "breaking in."
The anatomy
- Access or impersonation. The attacker either gets into a real mailbox (a phished password, no MFA) or spoofs a trusted sender — a vendor, an executive, a title company.
- Patience. From inside a real inbox, they read. They learn who pays whom, the tone people use, the timing of invoices.
- The switch. At the right moment, a real-looking invoice arrives with new "updated" bank details — or the "CEO" urgently asks for a wire.
- The wire clears before anyone calls to confirm.
Why it beats technical defenses
There's no payload to detect. The email is often sent from a legitimate, compromised account. Everything looks normal because, mechanically, it is — the fraud is in the intent, not the code.
What actually stops it
- MFA on email — removes the easiest path to a real mailbox.
- A hard out-of-band rule: any change to payment details is verified by a phone call to a known number, never a number in the email.
- Advanced email filtering that flags look-alike domains and first-time senders.
- Awareness training so "the invoice changed" triggers a call, not a payment.
Watch our live threat feed for the campaigns hitting the region now.


