If an email can change where your business sends money, your business has a fraud problem waiting for a fraudster. That is the entire mechanism of business email compromise (BEC): an attacker poses as a supplier, an executive, or a landlord, asks accounts payable to update bank details or pay an urgent invoice, and the money leaves through your normal, approved process. The FBI's 2024 Internet Crime Report counts 21,442 BEC complaints and $2.77 billion in losses for 2024 in the US - our arithmetic on those figures puts the average reported incident around $129,000. The defense is not better antivirus. It is a payment-change protocol that assumes email is forgeable, because it is.
The scale, from the primary source
The FBI's Internet Crime Complaint Center logged 859,532 complaints in 2024 with $16.6 billion in reported losses - a 33% jump in losses over 2023, with an average reported loss of $19,372 across all crime types. Cyber-enabled fraud accounted for 83% of all reported losses. Within that, BEC stands out not for volume but for severity: it ranks mid-table by complaint count and second of all categories by money lost. Phishing generates two hundred thousand complaints of pocket-change losses; BEC generates twenty-one thousand complaints averaging six figures. It is the professional's scam, aimed at businesses precisely because businesses move large sums on routine authorization.
One caveat the report itself implies: these are reported losses only. Small businesses that quietly absorb a five-figure redirect rather than file with the FBI do not appear in these numbers.
How the scam actually arrives
The common shapes, all of which end at the same door - your payment process:
- The vendor bank-change. An email that looks like it comes from a real supplier (often from their genuinely compromised mailbox, or a lookalike domain one character off) announces new bank details "effective immediately." The next legitimate invoice gets paid to the fraudster.
- The urgent executive request. "I'm in a meeting - wire this today, I'll explain later." Authority plus urgency, engineered to bypass process.
- The invoice swap. A real, expected invoice arrives - with doctored payment details, sometimes intercepted and altered in transit through a compromised mailbox on either side.
Notice what is absent: malware, exotic exploits, anything your firewall could catch. The attack is a forged instruction inserted into a trusted channel. That is why the fix lives in process, not software.
The protocol: four rules that close the door
- No payment-detail change on email alone - ever. Every change of bank details is confirmed by calling the vendor on a number you already had on file (not one in the email, which the fraudster helpfully provides). This single rule defeats the majority of BEC shapes, costs one phone call, and should be written policy even in a two-person company.
- Dual control above a threshold. Any new payee or any payment above a limit you choose requires a second person's approval - or, for solo operators, a mandatory 24-hour delay between instruction and execution. Urgency is the scam's fuel; a forced pause is water on it.
- Verify the request channel, not the request. A well-forged email is indistinguishable from a real one by reading it. Verification must leave the channel: phone, in person, or a video call to a known face for large sums.
- Protect your own domain from being the costume. The same DMARC authentication we covered in the sender-rules article does double duty: beyond deliverability, an enforced DMARC policy makes your exact domain far harder to spoof against your own customers and suppliers. Your vendors' finance teams will thank you without knowing it.
The economics of the defense
Run the comparison our way: the controls above cost approximately one phone call per bank change, one approval click per large payment, and an afternoon of DNS work - against an average reported incident of roughly $129,000. There is no other risk in a small business's ledger with this ratio of prevention cost to expected loss. Recovery, by contrast, is a race: the FBI operates a Recovery Asset Team for rapid freezing of redirected funds, but the honest planning assumption is that money that leaves is gone - prevention is the strategy. If an incident does happen: contact your bank immediately to attempt a recall, file at ic3.gov the same day, and preserve the emails intact for investigators.
The protocol also compounds with disciplines you may already run. The payment-terms hygiene from Getting Paid on Time - deposits, milestones, current statements - keeps your payables and receivables observed weekly, and observed money is hard to steal quietly. And keeping your processing accounts clean, per the processor-risk article, matters doubly here: fraud events on your accounts are exactly what triggers platform reviews.
Limitations
The IC3 figures (report opened July 24, 2026) cover US-reported incidents in 2024 and undercount unreported losses; the per-incident average is our division of reported losses by complaints, and actual incidents range from four figures to seven. This article covers process defenses for small businesses, not enterprise email-security architecture, and nothing here is legal or insurance advice - cyber-fraud insurance terms vary widely on exactly these controls.
The bottom line
BEC works because payment instructions arrive through the same channel as lunch plans. Separate them: written policy that bank changes require a call-back to a known number, a second pair of eyes or a forced delay on large and new payments, and DMARC on your own domain. An afternoon of setup against a six-figure average loss is the easiest trade in this publication.
Discussion
Sign in with Google or just a name. No email link, no password to remember.