Executive and payment fraud

How do you prevent business email compromise?

The control that stops business email compromise is an out-of-band callback to a phone number you already hold on file, performed before any payment detail is changed or any unusual transfer leaves. Email cannot verify email.

BEC does not rely on malware, so tooling alone will not catch it. The attacker either takes over a real mailbox or spoofs one convincingly, then exploits a payment process that treats an email as sufficient authority.

Documented cases

  • Orion S.A. disclosed $60 million in fraudulently induced wire transfers in 2024.
  • Evaldas Rimasauskas defrauded Google and Facebook of $120 million by invoicing as a hardware supplier they genuinely used.
  • Mattel lost $3 million and recovered it, because the transfer landed on a banking holiday and the company escalated fast enough.

The control that breaks it

  • Verify by callback to a number from your vendor master file, never a number supplied in the request.
  • Require dual authorisation for new payees and for any change to existing bank details.
  • Impose a cooling-off period on first payments to a newly added account.
  • Alert on inbox rules that auto-delete or forward, the usual sign of a mailbox already lost.
  • Deploy phishing-resistant MFA on mail, so a stolen password is not enough.
  • Rehearse recovery. Mattel got its money back because speed mattered more than blame.

Related: how to verify a wire transfer · CEO fraud vs BEC · Business email compromise