Preskočiť na hlavný obsah

Business Email Compromise Cost Small Businesses Over $3 Billion Last Year: The Payment-Verification Controls the FBI Says Actually Stop Wire Fraud

10 minút čítaniaMike ThriftMike Thrift
Business Email Compromise Cost Small Businesses Over $3 Billion Last Year: The Payment-Verification Controls the FBI Says Actually Stop Wire Fraud

You receive an email from your most reliable vendor: they have updated their banking details, please remit the next $42,000 invoice to the new account. The logo is correct, the thread is familiar, the tone is theirs, and the request is urgent. You update the vendor master, approve the wire, and hit send. Days later the real vendor calls asking where their payment is. The account you wired to was controlled by a criminal who had been silently forwarding your vendor's email for weeks.

That scenario is Business Email Compromise (BEC), and the FBI attributes over $3 billion in exposed losses to it in the most recent year alone — part of a decade-long total now exceeding $55 billion by the Federal Reserve's accounting. BEC is not a technical hack in the classic sense; it is a payment deception that exploits the exact moment a small business is most vulnerable: when someone who can move money trusts an email.

Small and midsize businesses are disproportionately hit, not because criminals prefer them, but because the controls that stop BEC — call-back verification, dual approval, and vendor master discipline — are the ones lean teams most often skip.

How BEC Actually Works

The FBI's Internet Crime Complaint Center (IC3) tracks BEC as a category alongside Email Account Compromise (EAC). The mechanics are consistent:

  1. Compromise or impersonation. The actor gains access to a legitimate email account through phishing, credential stuffing, or mailbox forwarding rules, or they register a look-alike domain that differs by one character. Once inside, they read threads to learn payment cadence, approval language, and who authorizes wires.
  2. Manipulation of a payment. They intervene in a real transaction — a vendor invoice, a payroll file, a real estate closing — and substitute their own payment instructions. The email comes from the trusted address or a near-identical one, and it often includes a sense of urgency: "We are closing the books, please use the new account today."
  3. Wire or ACH diversion. The funds move by wire or ACH to an account the actor controls, often at a different bank than the vendor normally uses. By the time the vendor reconciles, the money has been layered through multiple accounts.

The FBI highlights five common variants small businesses encounter:

  • Vendor email compromise: A supplier's account is taken over; the "vendor" sends updated wiring instructions.
  • CEO impersonation: The owner or executive appears to direct finance to wire funds for a confidential deal. Finance complies without questioning the executive.
  • Payroll diversion: HR receives a request that looks like it came from an employee to update direct-deposit information. The next payroll goes to the actor.
  • Real estate wire fraud: A closing officer or buyer receives altered wiring instructions for a property purchase — often the largest single wire a small business ever sends.
  • Data-theft plus BEC: The actor first steals employee W-2 or vendor payment data, then uses it for follow-on fraud.

A South Carolina town's recent $545,000 loss to a municipal BEC — a single wire to an impersonated vendor — shows that even public entities with formal procurement are not immune when verification is treated as optional.

Why Small Businesses Lose the Most per Incident

BEC losses are not evenly distributed. The FBI and the Air Force Research Laboratory have both noted that small and medium organizations with limited IT resources are the most vulnerable. The reasons are operational, not technical:

  • The person who answers vendor email is often the same person who approves payments, so there is no second set of eyes.
  • Vendor masters are updated on request without a verification call, because stopping to call feels slower than fixing a late payment.
  • Payroll and vendor banking changes arrive by email and are processed the same day, because the team is lean and responsive — exactly the traits BEC exploits.
  • Multi-factor authentication is not enforced on email, so a single phished password gives the actor persistent access plus the ability to set forwarding rules that keep a copy of every future email.

The median BEC loss reported to IC3 is well above the median for other cybercrimes, because BEC targets the payment itself, not the endpoint. One successful wire can exceed a year's profit for a small business, and recovery rates drop sharply after the first 24 hours.

The Controls the FBI Says Actually Work

The FBI, the Federal Reserve's FraudClassifier model, and the Bureau's field guidance converge on the same set of controls. None require expensive technology. All require discipline at the moment of payment.

1. Verify Every Change to Payment Instructions Out of Band

This is the single most effective control, and the one most often skipped.

When any email requests a change to where money is sent — new account number, new bank, new wire instructions, new direct-deposit — do not reply to the email. Call a known number on file, not the number in the email, and speak to a known contact to confirm the change. For high-value changes, require both a phone call and a second approval in person or via a separate channel.

Document the verification: who called whom, at what number, at what time, and what was confirmed. That note is your audit trail if the counterparty later disputes receipt.

For vendor masters, add three fields and enforce them:

  • A "verified" flag that is set only after a call-back, with the call date and initials.
  • A hold period for new or changed accounts — 24 to 48 hours before the first payment to the new account is released.
  • A prohibition on updating bank details by email alone — require a signed form plus a call-back for every change, no exceptions.

2. Separate the Requestor from the Approver

No single person should be able to create a vendor, change its banking, and approve its payment. Even in a team of three, you can separate duties:

  • Person A (often the owner or operations) authorizes the vendor relationship.
  • Person B (bookkeeping) enters the vendor and payment, but cannot approve wires above a threshold.
  • Person C (owner or a second manager) approves wires or payroll changes above that threshold.

In many accounting systems, this is a workflow setting, not a headcount issue. Enable approval thresholds for ACH and wire batches, and enable alerts for any vendor master change. If your bank supports dual approval for wires — where one user creates the wire and a second user releases it — turn it on, even if it adds five minutes to the process.

3. Harden Email — the Payment Rail's Front Door

Because BEC lives in email, email hygiene is payment hygiene.

  • Require multi-factor authentication on all email accounts, especially finance, HR, and the owner.
  • Block auto-forwarding to external addresses. FBI guidance repeatedly flags forwarding rules as the persistence mechanism — the actor sets a rule to forward a copy of every email to an external address and then deletes the rule-creation notification.
  • Flag external email and look-alike domains. Configure your email system to label mail from outside the organization and to warn when the sender's display name matches an internal name but the address does not.
  • Review forwarding and delegation rules quarterly. That 30-second audit catches the rule no one remembers creating.

4. Build a Payroll Verification Ritual

Payroll diversion is a BEC variant that bypasses vendor controls entirely because it targets HR. Treat any request to change direct-deposit information as a payment change:

  • Require the employee to submit the change in the payroll system after logging in with MFA, not by email.
  • If an email request is received, verify by calling the employee at a number on file from HR, not the number in the email, and require a second factor like confirming the last four of the prior account.
  • Log every banking change with a before-and-after record and a verification note.

5. Classify and Log the Fraud Correctly

The Federal Reserve's FraudClassifier model encourages businesses to tag fraud events consistently — how the fraud occurred (impersonation, account takeover, modified payment information) and what facilitated it (compromised credentials, lack of call-back). That discipline is not just for regulators. When you log BEC attempts — even failed ones — with a consistent taxonomy, you can see patterns: which vendor is repeatedly impersonated, which employee is repeatedly targeted, and which control failed.

If a wire does go to the wrong account, the IC3 recommends immediate action:

  • Contact your financial institution to request a recall or hold on the wire.
  • Contact the FBI's IC3 at ic3.gov (select BEC) or your local field office, identifying the incident as BEC and providing wire details, including the beneficiary bank and account.
  • Preserve the original email with full headers — do not forward it inline, which strips headers. Forward as an attachment or export the .eml/.msg.

Recovery is most likely within 24 hours and drops sharply after that. The faster the recall request and the more complete the wire details, the higher the chance the funds can be frozen.

A Minimal Verification Policy You Can Adopt This Week

You do not need a 20-page policy. You need a one-page rule that everyone follows without exception:

  • No change to payment data by email alone. Every new vendor account or change to an existing account requires a call-back to a known number plus a second approval.
  • No wire or ACH above $2,500 without dual approval. Adjust the threshold to your volume, but keep it low enough to catch the median BEC wire.
  • Payroll changes only through the payroll portal with MFA, plus a call-back for any email-initiated request.
  • Monthly review of vendor master changes and email forwarding rules, with a sign-off.
  • Quarterly phishing and BEC simulation for anyone who can move money — including the owner.

Add those five lines to your accounting manual, enable the corresponding settings in your accounting system and bank portal, and you have implemented the controls the FBI attributes to the cases where money was not lost.

Keep Your Payment Records Verifiable

BEC exploits the gap between what your inbox says and what your ledger proves. A disciplined general ledger — with vendor masters that show when banking was verified, with payroll records that show when direct deposit changed and how it was verified, and with wire approvals that show who released what to whom — closes that gap. When every payment change is traceable to a call, an approver, and a timestamp, the email alone can no longer move money.

Simplify Your Financial Management

Payment verification is only as strong as the financial records behind it. Beancount.io provides plain-text, version-controlled accounting where every vendor, every bank account, every payroll change, and every approval is transparent and auditable — so your call-back discipline is documented, not just remembered. Get started for free and make your next wire fraud attempt fail at the verification step.

Zdieľať tento článok