Business Email Compromise: Warning Signs and the First Hour After You Spot One

By MercPrivacy · Published 2026-08-16 · Updated 2026-09-07

Business email compromise is targeted fraud, not spam. Its warning signs are new payment instructions, urgency from a senior name and a thread that suddenly reads differently. First hour: stop the money and call the bank.

The warning signs of business email compromise are a request to change where money goes, pressure to act before anyone can check, and a sender who is almost, but not quite, who they claim to be. The usual forms are a vendor's new bank details, an executive asking for an urgent transfer, or a hijacked thread that suddenly reads differently. If you spot one, stop the payment, call your bank on a known number, and preserve the message headers.

This article explains how business email compromise differs from ordinary spam, the patterns criminals rely on, the authentication controls that make impersonation harder, a first-hour checklist for the moment you realize something is wrong, and the habits that prevent the next attempt. The nuance is that BEC rarely looks like spam. It arrives once, it is well written, and it is aimed at the one person who can move money.

“The messages that cost a business real money are never the ugly ones. They are the polite, correctly spelled ones that land at four on a Friday, from a name everyone trusts, asking for something only slightly outside the normal routine.”


How Business Email Compromise Differs From Spam

Spam is volume; business email compromise is research. Before the first message is sent, the criminal has studied the company: who approves payments, which vendors are paid regularly, who is traveling, what the signature block looks like and how the owner writes. That research comes from the company website, social profiles, press releases, public filings and the executives' data-broker profiles, and sometimes from weeks of quietly reading a mailbox that has already been compromised.

There is often no malware and no link. The payload is a request, and filters that inspect infrastructure see nothing wrong with it, which is why it lands in the inbox while the crude stuff goes to junk.

Two delivery methods cover most cases. The first is impersonation from outside, using a spoofed or lookalike address. The second is account takeover, where the message is sent from the genuine mailbox of a colleague or a vendor, so every authentication check passes and the only defense is the reader.

The Patterns That Should Stop a Payment

A vendor changes its bank details

An invoice arrives with new account information, or a short note says the vendor has switched banks, sometimes on convincing letterhead. Often the vendor's own mailbox is the one compromised, so the message genuinely comes from the vendor's address. Verify every change to payment instructions by phone, on a number you already have on file, never on a number in the email.

An executive asks for an urgent, confidential transfer

“I'm in a meeting and can't talk. I need this wired today. Keep it between us.” The same script produces gift-card purchases, payroll direct-deposit changes sent to HR, and requests to a bookkeeper for the company's bank balance. The urgency and the secrecy are the attack; a real executive can survive a five-minute call-back.

A thread you were already in changes character

Thread hijacking is the hardest pattern to see. A criminal with access to a mailbox replies inside a legitimate conversation, so the history is real and the context is right. The reply-to address is quietly changed to a lookalike domain so your answers go to the attacker. Check the actual address behind the display name on any message that introduces money, and compare it letter by letter.

The smaller tells

A domain one letter off, or the right name at a different extension. A display name that matches but an address that does not. A tone shift in a long-running relationship. A request to bypass the normal approval path just this once. An attachment that opens to a sign-in page. Each also appears in the fake invoice and renewal scams that hit business inboxes daily; in BEC the difference is the targeting.

The Authentication Controls That Make Impersonation Harder

Three DNS records govern whether a receiving mail server trusts a message claiming to come from your domain. SPF lists the servers allowed to send for you; DKIM signs each message so tampering is detectable; DMARC tells receivers what to do when a message fails those checks and sends you reports. With DMARC set to a reject policy, exact-domain spoofing of your address stops working, which protects your customers and vendors from mail pretending to be you. The plain-English version is in SPF, DKIM and DMARC explained.

Those records do nothing against a lookalike domain or a compromised account, which is where the mailbox controls matter. Require multi-factor authentication on every account. Alert on the creation of inbox rules, because an auto-forward or auto-delete rule is the classic footprint of a criminal reading a mailbox. Review third-party app permissions on the mail tenant, since a granted app can read mail long after a password change.

When a message looks wrong, the headers show where it really came from and which checks it passed or failed. Knowing how to find email headers takes two minutes to learn and settles most arguments about whether a message is genuine.

The First Hour After You Spot One

Speed matters most in this hour: money that has moved can sometimes be recalled if the banks are told quickly, and rarely if they are told tomorrow.

1

Stop the money. If a payment has been initiated, call your bank's fraud line immediately and ask for a recall or stop. If it has not been released, freeze the approval and tell accounts payable in person or by phone, not by replying in the thread.

2

Call the counterparty on a known number. Confirm whether the vendor or the executive actually sent the request. If they did not, their mailbox may be compromised and they need to know now.

3

Preserve everything. Do not delete or forward the message as new mail. Export the original with full headers, save the whole thread, keep the fraudulent invoice, and write down the times of every action you took.

4

Report it. File a complaint with the FBI's Internet Crime Complaint Center the same day; when a fraudulent domestic wire is reported quickly, the FBI has a process that can ask the receiving bank to freeze the funds. Notify your cyber insurer within the notice terms of the policy.

5

Contain the mailbox. Reset the affected credentials, revoke active sessions, delete any forwarding rules, review app grants and sign-in logs, and have IT check whether other mailboxes show the same footprint.

Do not reply to the suspicious message, and do not warn the apparent sender by email from the same mailbox. If an account is compromised, the criminal reads the reply and adapts. Use the phone for every conversation until the accounts are confirmed clean.

After the First Hour: Notification, Evidence and the Data Question

Once the money is addressed, work out what the criminal could see. A compromised mailbox often holds customer records, employee data, contracts and bank details, and if personal information was accessible, state breach-notification laws may apply. The steps in what to do after a data breach cover that sequence; your counsel should advise on the formal obligations.

Keep a written timeline and preserve the logs, since sign-in records and rule-creation events roll off retention windows quickly. Tell the vendors and customers who could receive fraudulent instructions “from you”, by phone, and give them a call-back protocol for any future change. Ignore any service offering to get the money back for a fee; recovery runs through the banks and the FBI.

If your executives' names, titles, direct lines and home addresses are sitting on people-search sites where an attacker can assemble the cast list in an afternoon, the free 30-minute privacy assessment will show you exactly where, and nobody will try to sell you anything on that call.

Prevention Habits That Actually Hold

Write out-of-band verification into policy: any change to payment instructions, any new payee and any transfer above a threshold you set requires a call-back to a number already on file and a second approver. Make it explicit that urgency is not an exception, and have the owner or CEO be the first to submit to the rule, because the attack works by impersonating the one person staff are afraid to question.

Shrink the public cast list. Publish role mailboxes instead of direct addresses where you can, keep the full org chart off the website, and reduce the executives' footprint on data-broker and people-search sites, which is where the criminal's research usually starts.

Train on the specific patterns rather than on generic phishing, test with simulated requests, and make it easy and safe to report. The employee who paused a payment to verify it should be thanked in front of the team, not questioned.

Where MercPrivacy Fits

MercPrivacy is not an incident-response firm, a bank or a law firm, and an active compromise belongs first with your bank, your IT team and the FBI. Where we fit is the exposure that made the attack possible and the traffic that follows it. We map where your leadership's home addresses, personal phone numbers, personal emails and family details are exposed across data brokers and people-search sites, submit and pursue removal and suppression requests on their behalf, and keep monitoring because the listings come back.

For the impersonation and spam campaigns that reach your business lines, our email spam defense work builds the evidence file and identifies the U.S. company behind a campaign, and when a matter requires legal representation, a licensed attorney is engaged. We do not give legal advice and we do not promise any outcome; we do the investigative, documentation and administrative work and keep at it.

Frequently Asked Questions

Is business email compromise the same as phishing?

They are related but different. Phishing is usually sent in volume and aims to capture credentials or install malware through a link or attachment. Business email compromise is targeted at one company and aims at a payment or a data handoff, often with no link at all. A phishing email that captures a mailbox password is frequently the first step of a BEC.

Can we get the money back after a fraudulent wire?

Sometimes, and speed is the deciding factor. Call your bank the moment you realize, ask for a recall, and file with the FBI's Internet Crime Complaint Center the same day; when a domestic wire is reported quickly, the FBI has a process that can ask the receiving bank to freeze the funds. International wires and money already withdrawn are much harder, and nothing about recovery is certain.

How do criminals know who to impersonate?

They research the company the way a salesperson would. The website supplies names and titles, social profiles supply travel and tone, press releases supply vendors and deals, public filings supply officers, and data-broker profiles supply home addresses, family members and personal phone numbers. In account-takeover cases they simply read the mailbox for weeks and learn the routines directly.

Why did the fraudulent email pass our spam filter?

Because it was technically clean. It carried no malware and often no link, and it came either from a genuine compromised account or from a lookalike domain the criminal registered and configured with proper authentication records. Filters judge infrastructure and reputation; business email compromise exploits trust and routine, which no filter can see.

Should we tell our vendors and customers about a compromise?

Yes, and quickly, especially anyone who could receive fraudulent payment instructions from your domain or from the compromised account. Tell them by phone, give them your known-good details, and ask them to verify any future change by calling a number they already hold. Whether formal written notice is legally required depends on what data was accessible and on the applicable state laws, which is a question for counsel.

Fraud starts with research, so make the research harder. MercPrivacy maps where your leadership's personal data is exposed, submits and pursues removal and suppression requests on their behalf, and monitors for the profiles that get rebuilt. The free assessment shows the exposure and what is worth pursuing. Stephanie answers instantly and free, or book your free 30-minute privacy assessment with a specialist at (830) 587-5011.

Start Your Free Privacy Assessment Ask Stephanie

This article is for educational purposes only and is not legal advice. MercPrivacy is not a law firm; when a matter requires legal representation, a licensed attorney is engaged. Statutory figures are the amounts the statutes provide, not predictions of any outcome, and laws change — verify the current text before relying on it.