Business email compromise (BEC) doesn’t involve malware, doesn’t trip antivirus, and doesn’t look like a movie hacking scene. It’s an email that looks exactly like it should — from your CEO, your vendor, or your bank — asking for a wire transfer or a change to payment details. The wire fraud gets the headlines, but for most small businesses, the lasting damage is what happens to their data and their name once an inbox is actually compromised.

Key Takeaways

  • The FBI’s IC3 logged 24,768 BEC complaints and just over $3 billion in reported losses in 2025 — a 10% jump in losses and a 16% jump in complaints over 2024.
  • A compromised mailbox exposes everything sitting inside it — client contracts, invoices, and personal data — which is a data breach in its own right, separate from any wire fraud.
  • Attackers routinely use a compromised account to send malicious email to the victim’s own clients and vendors, meaning the damage doesn’t stop at your business — it spreads to everyone who trusts your name in their inbox.
  • That kind of misuse can get a business’s domain flagged or blacklisted by spam filters, which quietly breaks email deliverability long after the original incident is resolved.
  • Humacentric Guardian addresses BEC through two layers together: Managed ITDR and Security Awareness Training.

How a Typical BEC Attack Actually Works

Most BEC attacks follow a familiar pattern. An attacker either compromises a real email account or registers a lookalike domain (one letter off from a real vendor or executive’s address). They study a real business relationship — who pays whom, on what schedule, through what process — often by sitting quietly inside a compromised inbox for weeks first, reading everything that passes through it. Then they send a message that looks completely routine: an invoice with “updated” bank details, a request from “the CEO” to process an urgent wire while they’re “in back-to-back meetings.”

There’s no attachment to scan, no link to a fake login page necessarily, sometimes not even a spelling error. It’s a well-timed, well-researched request that looks exactly like a hundred legitimate ones your team has processed before.

The Damage That Actually Lasts: Leaked Data and a Weaponized Reputation

The wire transfer, if there is one, is often the smallest part of what a BEC incident costs. Two kinds of damage tend to outlast the fraud attempt itself:

  • Every client record in that mailbox is now exposed. A business inbox typically holds years of client contracts, invoices, payment details, and personal information exchanged in the ordinary course of business. The moment an attacker has access to that account, all of it has effectively been breached — whether or not a single email was ever answered. Depending on what was exposed, this can trigger state data-breach notification requirements, meaning the business now has a legal obligation on top of the original incident.
  • The compromised account gets used as a weapon against your own contact list. Attackers frequently use a hijacked mailbox to send phishing or malware-laden email to every client, vendor, and partner in it — because a message that appears to come from a real, trusted business address bypasses the skepticism a stranger’s email would trigger. Recipients who click a malicious link because it came from “you” now associate the resulting problem with your business, not the actual attacker.
  • That misuse damages deliverability and trust long after the incident is contained. Email providers and spam filters that flag a domain for sending malicious mail can push future, entirely legitimate email from that domain into spam folders for months. Clients who received a phishing email “from” a vendor are also simply less likely to open the next one — a slow, hard-to-measure erosion of a business relationship that took years to build.
  • It can jeopardize cyber insurance coverage. Insurers increasingly ask directly whether a business has identity monitoring and documented payment-verification procedures in place; a BEC loss without those controls can mean a denied claim on top of everything else.

This is why treating BEC purely as a wire-fraud problem misses most of the actual damage. A business can avoid ever sending a fraudulent wire and still spend months untangling a breach notification, a blacklisted domain, and a client who no longer opens their emails.

Why the Numbers Keep Growing

The FBI’s Internet Crime Complaint Center logged 24,768 BEC complaints and just over $3 billion in reported losses in 2025 alone, continuing a decade-long climb that now totals roughly $55.5 billion in exposed losses worldwide since 2013. This isn’t a rare, targeted attack reserved for large corporations — it’s a routine tactic run at scale against businesses of every size, and small businesses are attractive targets precisely because they’re less likely to have a formal payment-verification process or identity monitoring in place.

Why Antivirus and Firewalls Don’t Catch This

BEC is fundamentally a trust and process problem wearing a technical disguise. The email itself often isn’t malicious code, and if it comes from a genuinely compromised legitimate account, it will pass every spam and authentication check that exists — which is exactly why it’s so effective at reaching your own clients undetected. Stopping it takes two things working together:

  • Identity monitoring (ITDR) to catch the account compromise itself — unusual sign-ins, suspicious mailbox rules that forward or hide messages, and privilege changes — ideally before an attacker has had weeks to read through client data or send a single email under your name.
  • Security Awareness Training (SAT) so the humans in the payment approval chain know to verify any change in payment instructions through a second channel, every time, no exceptions — regardless of how urgent or how senior the request appears to be.

One Habit That Stops Most BEC Attempts

If you take one thing from this article: never change payment or banking details based on an email alone, no matter who it appears to be from. Pick up the phone and call a known, previously verified number — not one provided in the email itself — before moving money or updating vendor details. This single habit defeats the overwhelming majority of BEC attempts, and it costs nothing to implement.

FAQ

If no money was actually stolen, was our data still breached?

Likely yes. If an attacker had access to a mailbox containing client contracts, invoices, or personal information, that data has been exposed regardless of whether a fraudulent wire ever went through — and depending on what was in it, notification laws may apply.

How would we even know if our email was used to attack our own clients?

Often the first sign is a client calling to ask why they got a strange email “from” you. Identity monitoring (ITDR) is built to catch the account compromise before it reaches that point, by flagging the unusual sign-in or mailbox rule an attacker sets up first.

Would our current email spam filter catch this?

Usually not. Spam filters are built to catch known malicious patterns, not a well-written, targeted request from what appears to be a legitimate or compromised account.

How does Humacentric Guardian help with BEC specifically?

Guardian Complete pairs Managed ITDR (to catch the account compromise before data is exposed or your name is used to attack others) with Security Awareness Training (so your team knows the verification habits that stop the fraudulent request). See plan details.

Book a free risk assessment to see whether your Microsoft 365 environment already shows signs of this happening.