All Guides
BEC Survival Guide

Business Email Compromise: how to spot it, stop it, and survive it

BEC is the most expensive cybercrime category for Australian businesses. The FBI recorded USD 3.05 billion in reported BEC losses in 2025 alone. The good news is that most successful BECs are blocked by a few simple controls. This guide walks through what BEC looks like, how to harden your environment, and exactly what to do if money has already left your account.

Last updated 4 October 202615 min read

What Business Email Compromise really is

Business Email Compromise is fraud that uses a real or spoofed email account to trick someone in your business (or a customer or supplier) into changing payment details, paying a fake invoice, or releasing sensitive information. There is usually no malware involved. That is what makes it so hard to detect with traditional antivirus.

The FBI's 2025 Internet Crime Report records USD 3.05 billion in reported BEC losses in 2025 alone, across 24,768 complaints. The ACCC's Targeting Scams 2025 report records AUD 2.18 billion in combined reported scam losses across Australia, with small businesses reporting disproportionate BEC losses. The ACSC 2024-25 Annual Cyber Threat Report lists BEC fraud resulting in financial loss as 15 percent of self-reported business cybercrime, behind email compromise with no financial loss at 19 percent. These are reported figures; actual losses are higher.

BEC works because it targets people and processes, not technology. The attacker does not need to hack a firewall or exploit a vulnerability. They need someone in your business to trust an email, change a bank detail, or approve a payment. That is why traditional antivirus and email filters alone do not stop it.

$3.05B

Reported BEC losses in 2025 alone across 24,768 complaints. Source: FBI IC3 2025

$507M

Fraudulent wires the FBI Recovery Asset Team froze in 2025. Source: FBI IC3 2025

~$123K

Average reported loss per BEC complaint. Source: FBI IC3 2025

The FBI 2025 Internet Crime Report, released 6 April 2026, recorded USD 3,046,598,558 in reported BEC losses across 24,768 complaints, up from USD 2.77 billion in 2024, making BEC the second-costliest cybercrime tracked by the IC3 behind only investment fraud, with an average reported loss of about USD 123,000 per complaint against a median transaction near USD 50,000. FBI IC3 2025.

The FBI Recovery Asset Team froze more than USD 507 million in fraudulent domestic wires in 2025, and cumulative global exposed BEC losses reached USD 55.5 billion across 305,033 incidents between October 2013 and December 2023, so fast reporting to the bank and to IC3 materially increases the chance of recovering funds that have already left an Australian account. CNiC, BEC Statistics 2026.

Between 2022 and 2024 the IC3 tallied almost USD 8.5 billion in BEC losses, and the Association for Financial Professionals 2025 Fraud and Control Survey found 63 per cent of organisations experienced BEC last year, so BEC is not a rare event that happens to careless businesses, it is a persistent operational risk for any organisation that pays invoices. Nacha, 2025.

How a BEC actually unfolds

Almost every BEC follows the same four steps. If you can break the chain at any one of them, the attack fails.

BEC is targeted rather than opportunistic, with attackers researching a specific company on LinkedIn and the website to identify who approves payments and then crafting a message that looks like it comes from a known executive, vendor or attorney, which is why urgency, secrecy and last-minute bank detail changes are the red flags that break the chain before money moves. CNiC, BEC Statistics 2026.

1. Reconnaissance

The attacker scrapes LinkedIn, your website, ABN lookup and social media to learn who pays invoices, who approves payments, and which suppliers you use.

2. Credential capture

A targeted phishing email (often an Adversary-in-the-Middle kit) steals a user's Microsoft 365 password and session token. MFA via SMS or push is bypassed by replaying the token.

3. Mailbox manipulation

The attacker logs in, creates inbox rules to hide their messages, watches conversations for weeks, and waits for a real invoice to land.

4. Payment fraud

They reply to a legitimate thread with new bank details, often from a lookalike domain. Your team pays the wrong account. The money is gone within hours.

Red flags your team should know on sight

Sudden change to bank account details on a known supplier invoice
Sender domain off by one character (rea1bytes.au, real-bytes.au)
Urgency or secrecy ("Don't mention this to anyone, it's confidential")
A reply that arrives from a Reply-To different to the From address
Attachments named "remittance" or "secure document" with login pages
New rules in your inbox you did not create (Forward, Mark as read, Delete)
Sign-ins from unusual countries or impossible travel patterns
Mobile push prompt for an MFA you did not initiate

The controls that break the BEC chain

None of these are exotic. The reason BEC keeps working is that most businesses have not finished rolling them out.

The FBI attributed more than USD 30 million in 2025 BEC losses to scams with a confirmed AI connection, so the rise of generative AI makes lookalike domains and convincingly written payment requests harder to catch by eye, which makes out-of-band phone verification of any new bank details and dual approval on payments over a threshold the controls that actually break the chain rather than email filtering alone. CNiC, BEC Statistics 2026.

Phishing-resistant MFA

Move from SMS and push to FIDO2 keys, Windows Hello for Business or passkeys. AiTM kits cannot replay these.

Conditional Access with token protection

Block legacy auth, restrict logins to managed devices and trusted locations, and require token binding for high-risk users.

Out-of-band payment verification

New bank details get verified by phone using the supplier's known number, never the number in the email. Always.

Dual approval thresholds

Any payment over an agreed threshold requires a second approver. Document this in your finance policy.

Inbox rule monitoring

Alert on new mailbox rules that auto-forward, mark messages read, or delete invoice keywords. Available in Microsoft 365 Defender.

Email authentication

SPF, DKIM and DMARC at p=reject. Stops spoofing of your own domain to your customers and suppliers.

Identity Threat Detection (ITDR)

Detects suspicious logins, AiTM patterns and OAuth abuse the moment they happen. Manual review of audit logs is too slow.

Targeted staff training

Annual training is not enough. Run quarterly simulated phishing focused on invoice and e-signature lures, the themes Huntress saw most in 2025.

If money has already left, what to do in the first hour

The FBI Recovery Asset Team froze more than USD 507 million in fraudulent domestic wires in 2025, and the IC3 strongly recommends reporting incidents immediately even before engaging private incident response resources, because early reporting maximises the chance the team can recall funds before they leave the receiving bank, so the first call in a BEC is to your bank and the second is to cyber.gov.au. FBI IC3 2025.

Call your bank immediately

Ask for a recall on the transaction. The faster you call, the higher the chance of recovery. Many Australian banks now have dedicated fraud lines for business customers.

Reset the affected account

Force sign-out everywhere, rotate the password, revoke all refresh tokens, and check the mailbox for inbox rules and OAuth grants the attacker added.

Preserve evidence

Do not delete emails. Export the headers, capture the sign-in logs, and keep a timeline. You will need this for the bank, the insurer and any law enforcement report.

Notify your cyber insurer

Most policies require notification within a defined window. Late notice can void cover. Read your policy or call your broker first.

Report to ReportCyber

File a report at cyber.gov.au/report. This feeds the ACSC, the AFP and the joint cybercrime units. It is also often required by your insurer.

Engage IR support

A qualified incident responder will hunt for persistence (forwarding rules, OAuth apps, additional compromised accounts) and confirm the attacker is fully evicted.

Australian reporting obligations

BEC is not just a financial loss. If personal information was exposed, accessed or disclosed during the incident, you may have notification obligations under Australian law.

OAIC

Notifiable Data Breaches scheme

If the BEC involved unauthorised access to personal information likely to result in serious harm, organisations covered by the Privacy Act 1988 must notify the OAIC and affected individuals as soon as practicable. Reference: oaic.gov.au/privacy/notifiable-data-breaches.

ACSC

Report to ReportCyber

Use cyber.gov.au/report. ACSC also publishes ongoing BEC guidance for business under its Small and Medium Business resources.

Sector specific

APRA, ASIC and contractual notification

Regulated entities under APRA CPS 234 have separate cyber incident notification obligations. Many supplier contracts also require notice within 24 to 72 hours. Review your obligations early in the response.

General information only. This guide is not legal advice. For specific obligations, speak with your privacy lawyer or the OAIC.

Common questions

What is business email compromise in simple terms?
Business email compromise is a scam where an attacker uses a real or spoofed email account to trick your business into changing bank details, paying a fake invoice, or releasing sensitive data, usually without any malware involved.
How much does business email compromise cost Australian businesses?
BEC is the highest-cost cybercrime category for Australian businesses. The FBI recorded USD 3.05 billion in reported BEC losses in 2025 alone across 24,768 complaints. The ACSC lists BEC fraud as 15 percent of self-reported business cybercrime. Individual Australian incidents routinely run into the tens of thousands of dollars.
How do I know if my email has been compromised in a BEC attack?
The strongest signs are inbox rules you did not create that auto-forward, mark as read or delete messages, sign-ins from unusual countries, and an unexpected MFA prompt on your phone.
What should I do in the first hour of a business email compromise?
Call your bank to request a recall on the payment, reset the affected account and revoke its sessions, preserve the evidence, then notify your cyber insurer and report the incident to ReportCyber at cyber.gov.au.
Does cyber insurance cover business email compromise?
Most Australian cyber policies cover BEC losses, but they usually require MFA on email and admin accounts and notification to the insurer within a defined window, often 72 hours.
How do I stop business email compromise?
The controls that stop most BEC are phishing-resistant MFA, out-of-band verification of any new bank details by phone, dual approval on payments over a threshold, and DMARC set to p=reject on your domain.

Worried your business is exposed to BEC?

Real Bytes runs a focused BEC readiness review covering Microsoft 365 hardening, payment controls, and staff training. No obligation.