Business Email Compromise: How a Stolen Login Becomes Invoice Fraud
Ransomware gets the headlines, but the attack that quietly drains the most money from small businesses is far less dramatic. There is no malware on your screen and nothing looks broken. Someone simply logs into a business email account, watches for a while, and then sends a message asking for money to be moved. It is called business email compromise, or BEC, and it is one of the costliest scams aimed at small businesses today. Here is how it works, and how to stop it.
What is business email compromise?
Business email compromise is a scam where an attacker uses access to (or a convincing impersonation of) a trusted business email account to trick someone into sending money or sensitive information. The "compromise" usually starts with a stolen login. Once inside a real inbox, the attacker does not need to break anything. They just need to be believed, and a message from a genuine company account is very believable.
How it starts: a single stolen login
Most BEC attacks begin with credential theft. An attacker gets a working email password from one of two places:
- A data breach or combolist, where your email and a reused password were exposed. (Here is how to check if your business email has been in a data breach.)
- An infostealer infection, which copies saved passwords, and often live session cookies, straight from a device.
That is why BEC and credential leaks are two ends of the same problem. The leak is the way in. The fraud is what happens next.
The anatomy of a BEC attack
Once an attacker is inside a real inbox, a typical BEC scam unfolds in stages:
- Quiet reconnaissance. They read past emails to learn how you talk, who handles payments, which vendors you use, and what a normal invoice looks like. They may set up hidden forwarding rules so they keep seeing replies.
- The setup. They wait for a real opportunity, an in-progress deal, an expected invoice, a payment about to go out, so their request fits right in.
- The ask. Posing as the owner, a manager, or a known vendor, they request a wire transfer, a change of bank details on an invoice, or a batch of gift cards, usually with a note of urgency and secrecy.
- Thread hijacking. The most convincing version replies inside a genuine email thread, so the fraudulent message sits among real ones and looks completely normal.
The common forms it takes
- Fake invoice or bank-detail change: a real or spoofed vendor emails "updated" payment details, and your next payment goes to the attacker.
- CEO or owner fraud: a message that looks like it is from the boss asks an employee to send a wire quickly and quietly.
- Payroll diversion: a request to change an employee's direct-deposit details to a new account.
- Vendor email compromise: the breached account belongs to a supplier you trust, so their fraudulent invoice sails through.
Why small businesses are prime targets
BEC works best where trust is high and checks are informal, which describes many small businesses. Payment approvals often rest on one or two people, there is rarely a formal process to verify a change of bank details, and a message from the owner tends to get actioned fast. Attackers know this, and they know a small business is less likely to have anyone monitoring for the leaked login that starts the whole thing.
Warning signs to watch for
- Urgency and secrecy: "I need this done now, and don't discuss it with anyone."
- A change in payment details, especially a new bank account for an existing vendor.
- Slightly off email addresses, a lookalike domain with one changed letter, or a reply-to that does not match.
- Small shifts in tone or wording from someone you know.
- Requests that skip your normal process, or that arrive right as a real payment is due.
How to protect your business
- Verify money moves out of band. Any wire, or any change to bank details, gets confirmed by a phone call to a known number, never a number from the email itself. This one habit stops most BEC losses.
- Turn on two-factor authentication, especially on email, so a stolen password alone cannot open the inbox.
- Monitor for leaked credentials, so you learn the moment an email login is exposed, before it can be used for fraud.
- Check for hidden forwarding or inbox rules periodically, a classic sign of a compromised account.
- Build a simple payment-approval process, so no single message can move money on its own.
What to do if you suspect BEC
Move quickly. Secure the email account first: change the password, sign out of all sessions to end any hijacked login, and confirm two-factor is on. Remove any forwarding rules you did not create. If money was sent, contact your bank immediately, a wire can sometimes be recalled within a short window, and report it to the authorities. Then check every account that shared the email's password.
How GuardPilot helps
BEC almost always starts with a leaked login, and that is exactly what GuardPilot watches for. We monitor the dark web and infostealer logs for your team's email addresses and domains, and the instant one appears, we alert you with a plain-English explanation and a guided fix, so you can lock the account down before it becomes the launch point for invoice fraud. You can start a free scan in about two minutes.
The takeaway
Business email compromise is not a technical hack so much as a confidence trick powered by a stolen login. Close the two doors it depends on, catch the leaked credential early, and verify every money move out of band, and you take away both the way in and the payoff.
See what’s already exposed.
Run a free scan of your business email and domain. It takes about two minutes.
Start your free scan →