What Business Email Compromise really is
Business Email Compromise is fraud that uses a real or spoofed email account to trick someone in your business (or a customer or supplier) into changing payment details, paying a fake invoice, or releasing sensitive information. There is usually no malware involved. That is what makes it so hard to detect with traditional antivirus.
The FBI's 2025 Internet Crime Report records USD 3.05 billion in reported BEC losses in 2025 alone, across 24,768 complaints. The ACCC's Targeting Scams 2025 report records AUD 2.18 billion in combined reported scam losses across Australia, with small businesses reporting disproportionate BEC losses. The ACSC 2024-25 Annual Cyber Threat Report lists BEC fraud resulting in financial loss as 15 percent of self-reported business cybercrime, behind email compromise with no financial loss at 19 percent. These are reported figures; actual losses are higher.
BEC works because it targets people and processes, not technology. The attacker does not need to hack a firewall or exploit a vulnerability. They need someone in your business to trust an email, change a bank detail, or approve a payment. That is why traditional antivirus and email filters alone do not stop it.
$3.05B
Reported BEC losses in 2025 alone across 24,768 complaints. Source: FBI IC3 2025
$507M
Fraudulent wires the FBI Recovery Asset Team froze in 2025. Source: FBI IC3 2025
~$123K
Average reported loss per BEC complaint. Source: FBI IC3 2025
The FBI 2025 Internet Crime Report, released 6 April 2026, recorded USD 3,046,598,558 in reported BEC losses across 24,768 complaints, up from USD 2.77 billion in 2024, making BEC the second-costliest cybercrime tracked by the IC3 behind only investment fraud, with an average reported loss of about USD 123,000 per complaint against a median transaction near USD 50,000. FBI IC3 2025.
The FBI Recovery Asset Team froze more than USD 507 million in fraudulent domestic wires in 2025, and cumulative global exposed BEC losses reached USD 55.5 billion across 305,033 incidents between October 2013 and December 2023, so fast reporting to the bank and to IC3 materially increases the chance of recovering funds that have already left an Australian account. CNiC, BEC Statistics 2026.
Between 2022 and 2024 the IC3 tallied almost USD 8.5 billion in BEC losses, and the Association for Financial Professionals 2025 Fraud and Control Survey found 63 per cent of organisations experienced BEC last year, so BEC is not a rare event that happens to careless businesses, it is a persistent operational risk for any organisation that pays invoices. Nacha, 2025.
How a BEC actually unfolds
Almost every BEC follows the same four steps. If you can break the chain at any one of them, the attack fails.
BEC is targeted rather than opportunistic, with attackers researching a specific company on LinkedIn and the website to identify who approves payments and then crafting a message that looks like it comes from a known executive, vendor or attorney, which is why urgency, secrecy and last-minute bank detail changes are the red flags that break the chain before money moves. CNiC, BEC Statistics 2026.
1. Reconnaissance
The attacker scrapes LinkedIn, your website, ABN lookup and social media to learn who pays invoices, who approves payments, and which suppliers you use.
2. Credential capture
A targeted phishing email (often an Adversary-in-the-Middle kit) steals a user's Microsoft 365 password and session token. MFA via SMS or push is bypassed by replaying the token.
3. Mailbox manipulation
The attacker logs in, creates inbox rules to hide their messages, watches conversations for weeks, and waits for a real invoice to land.
4. Payment fraud
They reply to a legitimate thread with new bank details, often from a lookalike domain. Your team pays the wrong account. The money is gone within hours.
Red flags your team should know on sight
The controls that break the BEC chain
None of these are exotic. The reason BEC keeps working is that most businesses have not finished rolling them out.
The FBI attributed more than USD 30 million in 2025 BEC losses to scams with a confirmed AI connection, so the rise of generative AI makes lookalike domains and convincingly written payment requests harder to catch by eye, which makes out-of-band phone verification of any new bank details and dual approval on payments over a threshold the controls that actually break the chain rather than email filtering alone. CNiC, BEC Statistics 2026.
Phishing-resistant MFA
Move from SMS and push to FIDO2 keys, Windows Hello for Business or passkeys. AiTM kits cannot replay these.
Conditional Access with token protection
Block legacy auth, restrict logins to managed devices and trusted locations, and require token binding for high-risk users.
Out-of-band payment verification
New bank details get verified by phone using the supplier's known number, never the number in the email. Always.
Dual approval thresholds
Any payment over an agreed threshold requires a second approver. Document this in your finance policy.
Inbox rule monitoring
Alert on new mailbox rules that auto-forward, mark messages read, or delete invoice keywords. Available in Microsoft 365 Defender.
Email authentication
SPF, DKIM and DMARC at p=reject. Stops spoofing of your own domain to your customers and suppliers.
Identity Threat Detection (ITDR)
Detects suspicious logins, AiTM patterns and OAuth abuse the moment they happen. Manual review of audit logs is too slow.
Targeted staff training
Annual training is not enough. Run quarterly simulated phishing focused on invoice and e-signature lures, the themes Huntress saw most in 2025.
If money has already left, what to do in the first hour
The FBI Recovery Asset Team froze more than USD 507 million in fraudulent domestic wires in 2025, and the IC3 strongly recommends reporting incidents immediately even before engaging private incident response resources, because early reporting maximises the chance the team can recall funds before they leave the receiving bank, so the first call in a BEC is to your bank and the second is to cyber.gov.au. FBI IC3 2025.
Call your bank immediately
Ask for a recall on the transaction. The faster you call, the higher the chance of recovery. Many Australian banks now have dedicated fraud lines for business customers.
Reset the affected account
Force sign-out everywhere, rotate the password, revoke all refresh tokens, and check the mailbox for inbox rules and OAuth grants the attacker added.
Preserve evidence
Do not delete emails. Export the headers, capture the sign-in logs, and keep a timeline. You will need this for the bank, the insurer and any law enforcement report.
Notify your cyber insurer
Most policies require notification within a defined window. Late notice can void cover. Read your policy or call your broker first.
Report to ReportCyber
File a report at cyber.gov.au/report. This feeds the ACSC, the AFP and the joint cybercrime units. It is also often required by your insurer.
Engage IR support
A qualified incident responder will hunt for persistence (forwarding rules, OAuth apps, additional compromised accounts) and confirm the attacker is fully evicted.
Australian reporting obligations
BEC is not just a financial loss. If personal information was exposed, accessed or disclosed during the incident, you may have notification obligations under Australian law.
OAIC
Notifiable Data Breaches scheme
If the BEC involved unauthorised access to personal information likely to result in serious harm, organisations covered by the Privacy Act 1988 must notify the OAIC and affected individuals as soon as practicable. Reference: oaic.gov.au/privacy/notifiable-data-breaches.
ACSC
Report to ReportCyber
Use cyber.gov.au/report. ACSC also publishes ongoing BEC guidance for business under its Small and Medium Business resources.
Sector specific
APRA, ASIC and contractual notification
Regulated entities under APRA CPS 234 have separate cyber incident notification obligations. Many supplier contracts also require notice within 24 to 72 hours. Review your obligations early in the response.
General information only. This guide is not legal advice. For specific obligations, speak with your privacy lawyer or the OAIC.
Common questions
What is business email compromise in simple terms?
How much does business email compromise cost Australian businesses?
How do I know if my email has been compromised in a BEC attack?
What should I do in the first hour of a business email compromise?
Does cyber insurance cover business email compromise?
How do I stop business email compromise?
Worried your business is exposed to BEC?
Real Bytes runs a focused BEC readiness review covering Microsoft 365 hardening, payment controls, and staff training. No obligation.

Remote Support