Opens in a new tab
Hands typing on a laptop with an email notification displayed on the screen, next to a plant, notebook, pen, glasses, and coffee cup.

Business Email Compromise: The $3 Billion Fraud That Needs No Malware

By Jason Russell · September 11, 2026

The worst calls I get are not about ransomware. Ransomware announces itself. Screens lock, a ransom note appears, and everyone in the building knows something is badly wrong within about ninety seconds.

The worst calls are the quiet ones. A controller phones on a Tuesday afternoon and says a vendor just called about an unpaid invoice, and she is confused, because she paid it three weeks ago. Somebody pulls the wire confirmation. The receiving account number does not match the one in the vendor file. Nobody clicked a bad attachment. No antivirus alert ever fired. Nobody was locked out of anything. The money is simply gone, and it has been gone for twenty-one days.

That is business email compromise. In 2025 it cost American businesses and individuals $3,046,598,558 in reported losses, according to the FBI Internet Crime Complaint Center. It is the second most financially damaging category of cybercrime in the United States, behind only investment fraud. And it almost never involves malware.

Most writing on BEC jumps straight from “attackers send fake emails” to “train your staff,” skipping the middle. The middle is where the money is, and where your controls belong. So this walks through the whole sequence, phase by phase, the way I have watched it play out on real tenants.

What the FBI data actually says

Every figure below comes from the FBI 2025 IC3 Annual Report. I cite it directly because most BEC statistics circulating in MSP marketing trace back to vendor surveys with undisclosed methodology, and I will not put those in front of a client.

Year BEC complaints Reported losses Avg. per complaint
2023 21,489 $2,946,830,270 $137,131
2024 21,442 $2,770,151,146 $129,192
2025 24,768 $3,046,598,558 $123,005

Source: FBI IC3 Annual Reports, 2023 through 2025. Average per complaint is calculated, not published.

That average deserves a caveat, and here is where I part ways with a lot of security marketing. The roughly $123,000 figure is an average of losses reported to the FBI, and it is pulled upward by large real estate closings and corporate wires. It is not a forecast for a thirty-person dental practice. Treat it as evidence that BEC is a high-dollar crime, not as a number you can plug into your own risk model.

The comparison that matters more is against the threats people actually budget for. In the same 2025 report:

  • Ransomware: 3,611 complaints, $32,320,105 in reported losses. The FBI notes plainly that this figure excludes lost business, downtime, wages and remediation, so it understates the real cost. Still, on direct dollars out the door, BEC outran it by roughly 94 to 1.
  • Malware: 893 complaints, $19,370,572.
  • Phishing and spoofing: 191,561 complaints, the most reported crime type of any kind, but only $215,843,126 in losses. That works out to about $1,127 per complaint. Phishing is the volume business. BEC is the payday.

Zoom out and the shape is unmistakable. Cyber-enabled fraud made up 45 percent of 2025 complaints but 85 percent of all reported losses. Money is not mostly leaving through encrypted servers. It is leaving through approved payments.

One more figure worth knowing, because it kills a common assumption: only 1,526 of those 24,768 BEC complaints had any cryptocurrency involvement, accounting for $83,771,329 of the $3.05 billion. BEC money moves by wire and ACH, through ordinary banks, in ordinary business hours. That is good news, because it means the funds can sometimes be stopped.

Florida ranked third nationally in 2025 with 71,843 complaints and $1,596,138,595 in total reported losses, behind California and Texas. We are not on the quiet end of this map.

Anatomy of a business email compromise

What follows is the composite pattern. The details vary. The sequence rarely does.

Phase 1: Getting in, without installing anything

The entry point is almost always credentials, not code. Someone receives a link to a document share, a voicemail notification, or a DocuSign lookalike. They land on a sign-in page that is a pixel-accurate copy of the Microsoft 365 login. They type their password. In the modern version, the fake page is a live proxy sitting between the user and the real Microsoft login, so the multi-factor prompt is genuine, the user approves it on their own phone, and the attacker captures the resulting session token. The account is now open to them without a password and without tripping an MFA challenge again.

Nothing was installed. No file was written to disk. Your endpoint protection has nothing to look at, because from its point of view nothing happened. An employee visited a website and logged in, which is the single most normal thing an employee does all day. This is why the targeted version of phishing is a different problem from the bulk version, something we covered in Spear Phishing vs Regular Phishing.

And it does not have to be your mailbox. If your vendor is the one compromised, every control you own is irrelevant to the breach itself, and the fraudulent invoice arrives from a genuine, authenticated vendor address.

Phase 2: Persistence you will never notice

This is the step that separates BEC from ordinary phishing, and the step almost nobody audits. Within minutes, the attacker establishes persistence and concealment. Microsoft publishes the indicators in its own guidance for compromised Microsoft 365 accounts, and the list reads like a field manual:

  • Inbox rules that automatically forward mail to an unknown external address.
  • Inbox rules that move incoming messages into the Notes, Junk Email, or RSS Subscriptions folders. That last one is the tell. Nobody has looked in the RSS Subscriptions folder since 2011, which is exactly why it gets used to hide a vendor replying “that is not our bank account.”
  • Recently added external forwarding at the mailbox level.
  • Changes to the user contact record in the Global Address List, such as a swapped phone number.
  • Hidden inbox rules, which do not appear in Outlook at all and only surface in PowerShell with Get-InboxRule and the IncludeHidden switch.

The sophisticated operators also grant themselves an OAuth application consent. That matters enormously, because an app consent survives a password reset. I have watched a business reset a password, declare the incident closed, and get hit again eleven days later through the token they never revoked.

Phase 3: Reading your mail

Then they wait and read. Dwell time in BEC is frequently measured in weeks, not hours. They are not hunting secrets. They are studying your business:

  • Which vendors you pay, how often, and roughly how much.
  • Who requests payments, who approves them, and what that exchange normally sounds like.
  • Whether your controller signs off with “Thanks!” or “Best,” and whether your owner writes in full sentences or fragments.
  • Your banking relationships, your wire process, and whether anyone ever calls to confirm anything.

A rule filtering on words like invoice, wire, ACH, remittance and banking quietly collects the relevant thread into a folder for them. They are building a model of how money moves through your company, and they are building it from your own words.

Phase 4: Choosing the moment

Timing is deliberate. Requests land at month end, on the Friday before a long weekend, or mid-closing, and usually while the owner is traveling, which the attacker knows from the out-of-office reply and the conference post on LinkedIn. The point is to hit a window where verification is inconvenient and the person who would ask a question is unreachable.

Phase 5: The ask

There are two common shapes, and they are not equally dangerous.

Executive impersonation. An urgent, confidential request from the owner or CFO to move funds or buy gift cards. This is the version everyone has been trained on. It is also the version most likely to come from a lookalike domain, which means it is the version your technical controls have a real chance of catching. We took that flavor apart stage by stage in Whaling Attacks: When the Scammer Is Impersonating Your Owner.

Vendor payment redirection. This is the expensive one. An existing invoice thread continues, from the real address, with the real signature block, quoting the real invoice number, and the message says the bank has changed and here is the updated remittance detail. Sometimes it is a PDF on genuine letterhead. There is no link to hover over and no attachment to sandbox. Everything about it is authentic except the account number.

On the artificial intelligence question, I want to be precise rather than dramatic. The 2025 IC3 report tracked AI as a descriptor for the first time: 22,364 complaints and $893,346,472 in losses across all crime types. Within BEC specifically, the FBI attributed 135 complaints and $30,256,592 to incidents with a confirmed AI component. That is about one percent of BEC losses. The FBI also says that figure is almost certainly low, because victims do not recognize AI involvement when it happens.

So the honest read is this: AI is not yet the main driver of BEC losses, and anyone selling you a deepfake-shaped panic is ahead of the data. But voice cloning is real, it is cheap, and it directly attacks the callback verification step I am about to recommend. Plan for it.

Phase 6: The cash out

Once the wire lands, it moves fast, hopping through mule accounts and often offshore within a day or two. The recovery window is short and it closes quickly, which is the entire reason the next section exists.

Why your email filter did not stop it

I sell email security. I think it is worth buying. I am also going to tell you plainly that it is not the control that stops this, and here is why.

A filter looks for things that are detectably bad: a malicious attachment, a known-bad URL, a sender failing authentication, content matching a known campaign. A payment redirection email sent from a genuinely compromised vendor mailbox has none of those properties. No payload, no link, and SPF, DKIM and DMARC all pass cleanly, because the message really did originate from that domain. Email authentication proves a message came from the domain it claims. It says nothing about whether the human operating that mailbox is the right human. I configure SPF, DKIM and DMARC for every client, and it is worth doing, but it solves a different problem than this one.

That is not a product failure. It is a category boundary. You are being attacked at the layer where a legitimate-looking business request meets a human decision about money, and no filter sits at that layer. We went further into what filtering does and does not cover in Email Filtering for Small Businesses.

Verizon reached a similar conclusion from different data in its 2026 Data Breach Investigations Report: the human element was present in 62 percent of breaches, social engineering was the third most common breach pattern at 16 percent, and pretexting, meaning fabricated scenarios built to manipulate a target, appeared as an initial access vector in 6 percent.

The controls that actually work

Notice that the first four are not technology purchases. That ordering is intentional, and it is the reverse of how most of my industry sells.

Process controls, in priority order

  1. Callback verification on a number you already had. Any change to payment instructions gets confirmed by voice, to a phone number pulled from your own vendor file or a prior contract, never a number printed in the email requesting the change. The FBI guidance is explicit on this point. Write it into the accounts payable procedure so it is a required step, not a habit that erodes when things get busy.
  2. Treat a banking change like new vendor onboarding. Same paperwork, same approvals, same verification. An existing relationship is not a reason to skip steps. It is the reason attackers chose that relationship.
  3. Dual approval above a dollar threshold. Pick a number that fits your business and require a second person to approve anything above it. Critically, that second person should not be someone already inside the email thread, because the attacker is reading that thread.
  4. Kill the urgency exception out loud. Tell your staff, in a meeting, that nobody will ever be criticized for delaying a payment to verify it, and that you will never ask them to bypass the process because something is urgent and confidential. That sentence is free and it removes the emotional lever the entire scheme depends on. It also does more than most awareness training will.

Technical controls, in order of value for a small business

  1. Phishing-resistant multi-factor authentication for anyone who can move money, approve vendors, or administer the tenant. Passkeys and FIDO2 security keys are bound to the real domain, which is what defeats the proxy login page in Phase 1. App-based approval prompts do not.
  2. Alert on inbox rule creation, mail forwarding, and new mailbox delegate permissions. Disable automatic external forwarding by default and require an exception to turn it on. This is the single highest-value detection for Phase 2 and it costs nothing but configuration time.
  3. Restrict user consent for third-party applications so employees cannot grant mailbox access to an unvetted app, and so the attacker cannot leave a token behind that outlives your password reset.
  4. Turn on audit logging and extend retention. Most small tenants I inherit keep 90 days or less. BEC dwell time can exceed that, so the evidence of how the attacker got in has already aged out before anyone looks.
  5. Bring DMARC to enforcement and register your lookalike domains. This genuinely helps against the executive impersonation flavor. Be clear-eyed that it does nothing against a compromised real mailbox.

The first few hours, in order

If a fraudulent payment goes out, speed is the only variable you still control. The odds are better than most people assume, but they decay by the hour.

  1. Call the originating bank immediately. Request a recall or reversal, and ask specifically for a Hold Harmless Letter or Letter of Indemnity. The FBI states that moving quickly here may reduce or eliminate the loss. Do this before you call anyone else, including me.
  2. File at ic3.gov with complete transaction detail, including the full banking information. This is not paperwork for its own sake. A complete complaint is what activates the FBI Recovery Asset Team and its Financial Fraud Kill Chain process.
  3. Preserve before you clean. Export the mailbox audit log and sign-in logs before remediating. Cleanup destroys the evidence your insurer and your attorney are going to ask for.
  4. Do the full remediation, not just a password reset. Microsoft prescribes the sequence: reset the password or disable the account, revoke active sessions, remove forwarding addresses, disable inbox rules including hidden ones, verify Global Address List contact details, review app consents, and read the audit logs from the onset of suspicious activity forward.
  5. Warn the other side. If your mailbox was the compromised one, your clients and vendors are being solicited right now using your own thread history. They need to know today.
  6. If protected health information sat in that mailbox, a compromised account is a potential HIPAA breach with its own regulatory clock. Get counsel involved on day one, not week three. The same logic applies to trust account activity at a law firm.

For scale on what the recovery process can do: in 2025 the FBI Recovery Asset Team initiated 3,900 Financial Fraud Kill Chain incidents covering $1,163,919,846 in attempted theft, and froze $679,013,183 of it. That is a 58 percent success rate. Those are real odds, and they belong to businesses that called their bank and filed with IC3 quickly.

What this does not fix

Every honest security recommendation comes with a boundary. Here are mine.

  • Callback verification fails if the attacker changed the phone number in your vendor master file first. Vendor data changes need the same dual control as vendor payments.
  • Voice cloning means a familiar voice on the phone is no longer proof of identity. The control still works, but only because you dialed a number you already trusted, not because you recognized the voice.
  • Nothing here recovers money that has already hopped through several accounts and been withdrawn overseas. Prevention and speed are the whole game.
  • Dual approval adds friction. Payments will take longer and someone will complain about it in month two. That is the trade you are making, and you should make it deliberately rather than discover it.
  • None of this addresses the credential theft that starts the compromised-mailbox version. That is a separate discipline, covered in Identity Is the New Perimeter.
  • Cyber insurance usually covers social engineering and funds transfer fraud under a sublimit that is far below your policy limit, and coverage is frequently conditioned on having callback verification in place at the time of loss. I am not a licensed insurance advisor. Read the endorsement now, not after.
  • None of this addresses a genuinely malicious insider. Different problem, different controls.

Where I have skin in the game

You should know my interests before weighing my advice. Harmony MSP sells managed IT and security services, including Microsoft 365 hardening, identity protection, monitoring and the alerting configuration described above. If you hire us for that work, I make money. That is a direct commercial interest in you believing BEC is serious.

So here is the counterweight. The four process controls in this post are free. You can implement callback verification, banking change procedures, dual approval and the urgency exception policy this week, with no vendor and no contract, and doing so will remove more BEC risk than anything I would sell you. I am telling you that because writing it down is the only way to prove I meant it.

If you want a second set of eyes

If you want a second set of eyes on your payment approval process, or you want to know whether anyone has quietly built forwarding rules inside your Microsoft 365 tenant, that is a conversation I am glad to have. No pitch deck, no obligation, and if you are already in decent shape, I will tell you that.

Harmony MSP is based in Lake Mary and works with small businesses, law firms and medical practices across Central Florida. You can reach me at (407) 720-6540.

Sources

A note on statistics: all complaint counts and dollar figures above come directly from the FBI IC3 2025 Internet Crime Report. Secondary-source figures that could not be traced to a primary document have been excluded.

Our latest posts