Threat Library
Business email compromise: how invoice fraud actually works
No malware, no ransomware — just a convincing email and a changed bank account. BEC is the quiet attack that drains more money than the loud ones.
Ransomware gets the headlines. Business email compromise gets the money. BEC uses no malware and trips no antivirus — just a convincing email and a bank account that quietly changes. It's the attack that drains municipal accounts and small-business payrolls without ever "breaking in."
The anatomy
- Access or impersonation. The attacker either gets into a real mailbox (a phished password, no MFA) or spoofs a trusted sender — a vendor, an executive, a title company.
- Patience. From inside a real inbox, they read. They learn who pays whom, the tone people use, the timing of invoices.
- The switch. At the right moment, a real-looking invoice arrives with new "updated" bank details — or the "CEO" urgently asks for a wire.
- The wire clears before anyone calls to confirm.
Why it beats technical defenses
There's no payload to detect. The email is often sent from a legitimate, compromised account. Everything looks normal because, mechanically, it is — the fraud is in the intent, not the code.
What actually stops it
- MFA on email — removes the easiest path to a real mailbox.
- A hard out-of-band rule: any change to payment details is verified by a phone call to a known number, never a number in the email.
- Advanced email filtering that flags look-alike domains and first-time senders.
- Awareness training so "the invoice changed" triggers a call, not a payment.
Watch our live threat feed for the campaigns hitting the region now.
Before your renewal
Run the 3-minute insurability self-check
See where you’d pass or fail your carrier’s questionnaire, with a control-by-control gap list.
Start the self-check