Business Email Compromise (BEC) Explained
Business email compromise (BEC) is a scam where criminals impersonate your boss, a supplier or a colleague to trick someone into moving money or sharing data. It carries no dodgy links or attachments, so spam filters wave it through. This article explains how BEC works and the layered defence — authentication, MFA, out-of-band verification and training — that actually stops it.
The scam that doesn’t look like a scam
Most people picture cybercrime as viruses, dodgy links and obvious spelling mistakes. Business email compromise is nothing like that — and that is exactly why it works.
BEC is fraud carried out through email that looks completely normal. There is no attachment to scan, no suspicious link to hover over. Instead, a criminal impersonates someone you trust — your managing director, a regular supplier, a colleague in finance — and uses that trust to talk a member of staff into moving money or handing over information.
There is no virus to catch and no malicious link to block, because the weapon is a perfectly ordinary email — the target is the person reading it, not the computer.
It is one of the most costly forms of cybercrime affecting UK businesses, and it hits small firms as readily as large ones. Understanding how it works is the first step to stopping it.
How BEC actually works
BEC comes in a few recognisable flavours. They all rely on impersonation and urgency.
CEO fraud
The criminal poses as a senior person — the owner, a director, the finance head. A member of staff receives an email that appears to come from the boss: “I’m in meetings all day, can you sort an urgent payment to this new supplier? I’ll explain later. Keep this between us for now.”
Every detail is designed to short-circuit normal caution: authority (it’s from the boss), urgency (it’s needed now), and secrecy (don’t check with anyone). The employee, wanting to be helpful and not question a senior figure, makes the payment.
Supplier impersonation and invoice fraud
The criminal poses as a genuine supplier you already work with. They send an email — sometimes from a lookalike address, sometimes from the supplier’s genuinely hacked account — saying “we’ve changed banks, please update our payment details for future invoices.”
The next real invoice gets paid, on time and in full, straight into the criminal’s account. This is the overlap with the invoice fraud we cover in stopping invoice fraud and email spoofing, and it is devastatingly effective because everything about the transaction looks routine.
Account takeover
Sometimes the criminal does not impersonate an account — they steal it. Using a phished password, they log into a real mailbox, watch the conversations, learn the tone and timing, then send fraudulent requests from the genuine account. Because the email really does come from your colleague or supplier, it is almost impossible to spot from the message alone.
Why spam filters wave it through
Spam filters are good at catching junk with tell-tale signs: malicious attachments, links to known bad websites, poor sender reputation, mass-mailing patterns. A BEC email has none of these.
It is usually a short, polite, well-written message. It often comes from a real or convincingly similar address. It contains no link and no attachment — just a reasonable-sounding request. To an automated filter, it is indistinguishable from the thousands of legitimate business emails your staff receive every week.
That is the uncomfortable heart of BEC: the technology cannot reliably tell the difference, because there is nothing technically wrong with the email. The deception is entirely in the words and the human reading them.
The layered defence that stops it
Because no single control catches BEC, you defend against it in layers. Each layer covers a different weakness, so that when one is bypassed, another still stands.
Layer 1: Email authentication (SPF, DKIM, DMARC)
The first layer stops criminals sending email as your exact domain. With SPF, DKIM and DMARC set to a reject policy, a fraudster cannot spoof yourbusiness.co.uk — attempts are refused before they reach anyone. This closes off the easiest version of the attack. Our step-by-step authentication guide shows how. It will not stop lookalike domains or a hacked genuine account, which is why it is only the first layer.
Layer 2: Multi-factor authentication (MFA)
Account takeover — where the criminal sends from a real, hijacked mailbox — is the hardest form of BEC to spot. MFA is what prevents it. Even if a password is phished or guessed, MFA blocks the login without the second factor. Cyber Essentials makes MFA mandatory for cloud services, and email is the account that matters most. If you do nothing else, protect every mailbox with MFA. Our guide to MFA explains the options in plain English.
Layer 3: Out-of-band verification
This is the single most powerful defence, and it costs nothing. The rule is simple: any request to move money, change bank details or share sensitive data is verified through a different channel from the one it arrived on.
An email asks to change a supplier’s bank details? Phone the supplier on the number you already hold — never the number in the email. The boss asks for an urgent transfer? Call them, or ask in person. A thirty-second phone call defeats a scam that could cost tens of thousands of pounds. Build this into a written payment process so it is a firm rule, not a judgement call made under pressure.
Layer 4: Staff awareness and training
BECs target people, so people are your last and most important line of defence. Staff who understand the scam recognise the warning signs: unexpected urgency, secrecy, a change to payment details, pressure to bypass the usual process, a slightly-off email address.
The most valuable thing training does is remove the fear of checking. In many BEC losses, someone had a nagging doubt but felt awkward questioning the boss or a client. A culture where verifying a payment is normal and encouraged — never seen as insubordinate or distrustful — is worth more than any piece of software. Our guide to spotting phishing emails is a good starting point for the whole team.
A simple rule to take away
If an email asks you to move money, change payment details or share sensitive information — and especially if it adds urgency or secrecy — stop and verify it through a separate channel before you act. That one habit, backed by authentication and MFA, defeats the overwhelming majority of business email compromise attempts.
BEC is not a technology problem you can buy your way out of with one product. It is a combination of sensible email settings, protected accounts, firm payment processes and a team that knows what to watch for. If you would like help putting those layers in place — from setting up authentication and MFA to helping your staff recognise the signs — get in touch and we will build a defence that fits how your business actually works. You can also see how we approach this across our cyber-security services.
Frequently asked questions
What is the difference between phishing and BEC?
Phishing usually casts a wide net with a malicious link or attachment, hoping someone clicks. BEC is targeted and often carries no link at all — it is a carefully written, plausible message impersonating someone you trust, designed to talk a specific person into transferring money or sharing information. Because there is nothing technically malicious to detect, it slips past filters.
Why don't spam filters catch BEC emails?
Spam filters look for the hallmarks of junk — bad links, malware, known scam patterns, poor reputation. A BEC email has none of these. It is often a short, polite, well-written message from a real-looking or even genuinely compromised account. To a filter it looks like ordinary business correspondence, which is exactly the point.
What is out-of-band verification?
It means confirming a request through a different channel from the one it arrived on. If you get an email asking to change bank details or make an urgent payment, you verify it by phoning the person on a number you already have on file — not the number in the email. This single habit stops the majority of BEC losses.
Can a small business really be a target?
Yes. Small businesses are attractive precisely because they often have fewer controls and less formal payment processes. Criminals do not need you to be large — they need one person able to move money and a culture where an urgent email from the boss gets actioned without a second thought.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.