Business Email Compromise: The £30,000 Fraud Most SMEs Don't See Coming
The finance manager receives an email from the CEO. The subject is "Urgent — supplier payment." The body of the email explains that a payment to a key supplier needs to be made today, outside the normal process, due to an urgent situation. Please transfer £28,000 to the account details below. Don't mention this to anyone as it's commercially sensitive.
The finance manager transfers the money. The CEO never sent the email.
This is Business Email Compromise (BEC), and it's responsible for more financial loss to UK businesses than any other type of cybercrime. The average BEC fraud in the UK causes tens of thousands of pounds of losses, and in many cases those losses are not recovered.
How Business Email Compromise Works
BEC attacks work by exploiting trust. The attacker either compromises a real email account (gaining access through phishing or credential theft) or creates a convincing impersonation of a real account. They then use that trust to instruct staff to take actions that benefit the attacker financially.
The most common BEC scenarios are:
CEO fraud — an attacker impersonates a senior executive and instructs a finance team member to make an urgent payment. The social engineering is straightforward: authority, urgency, confidentiality. These three elements bypass normal process verification.
Supplier impersonation — an attacker compromises or impersonates a supplier's email account and sends updated payment details. The next time your business pays that supplier, the money goes to the attacker. These attacks can go undetected for multiple payment cycles.
Invoice manipulation — an attacker intercepts email communications during a genuine transaction and modifies payment details on invoices or remittance instructions.
Internal account changes — an attacker who has access to HR or payroll systems changes bank account details for salary payments, redirecting payroll to attacker-controlled accounts.
Why It's So Effective
BEC attacks succeed because they exploit human psychology rather than technical vulnerabilities. The techniques are specifically designed to bypass rational decision-making.
Authority: instructions from the CEO are typically followed without question. The hierarchy of the organisation becomes the attack vector.
Urgency: time pressure prevents careful verification. "This needs to happen today" and "I need you to do this right now" are standard elements of BEC scripts because they work.
Confidentiality: "Don't mention this to anyone" prevents the natural check of asking a colleague whether this request seems right.
Context manipulation: sophisticated attackers research their targets. They know who the CEO is, who handles finance, what suppliers the business uses, and what transactions are in progress. The email references real names, real amounts, and real business context. It feels genuine.
The Technical Component
Not all BEC attacks require a compromised account. Many succeed with domain spoofing — using an email address that looks similar to the real one but has a subtle difference. ceo@companyname.co.uk becoming ceo@company-name.co.uk. In a hurried reading, the difference is invisible.
Email authentication controls — DMARC, DKIM, and SPF — prevent exact domain spoofing (sending an email that appears to come from your actual domain). They don't prevent lookalike domain attacks, which require different controls.
Genuine account compromise is more dangerous. If an attacker has access to your CEO's real email account — gained through phishing or credential theft — they can communicate through the actual account, respond to replies, and carry on the deception indefinitely. Detection is very difficult because the email is genuinely coming from the right account.
Prevention Controls
Process controls are your primary defence. No email instruction — regardless of who it appears to come from, regardless of urgency, regardless of confidentiality requests — should result in a payment without a separate verification step. Call the requester on a known phone number (not a number provided in the email). Walk to their office if they're on site. The verification has to happen through a different channel from the one carrying the instruction.
This should be a formal, written policy that all finance staff are trained on and that managers understand applies to them — including the CEO. "But the CEO told me not to verify" is the scenario this policy is designed to address.
MFA on all email accounts prevents account takeover attacks. If an attacker can't access your CEO's email account, they can't conduct BEC from it.
Email security configuration — DMARC with a reject policy — prevents emails that fail authentication checks from reaching your users. This blocks exact domain spoofing attacks.
Invoice verification procedures should require confirmation of any changed payment details through a separate channel before the change is applied. Updated bank details in an email should never be acted on without a phone call to a known contact at the supplier.
Staff awareness training is essential. Finance staff need to understand what BEC looks like, why the psychological pressure techniques are effective, and why verification procedures exist. A staff member who understands the attack is far less likely to fall for it.
Lookalike domain monitoring can alert you when domains similar to yours are registered — often a signal that a BEC campaign targeting your clients or suppliers is being set up.
When It Happens
If you suspect you've made a fraudulent payment, act immediately. Contact your bank and request a payment recall or freeze — the faster you act, the higher the chance of recovery. Report to Action Fraud (UK). Preserve evidence, including the email correspondence.
The recovery rate for BEC fraud is low, particularly after 24 hours. Speed is everything.
The Bottom Line
BEC fraud isn't a technical attack. It's a social engineering attack that exploits real business processes and real human psychology. The defences are primarily procedural — verification processes that can't be bypassed by urgency or authority.
If you want to assess your exposure and put practical controls in place, we can help. A review of your email security configuration, payment authorisation processes, and staff awareness tells you exactly where the gaps are.