Business email compromise, known as BEC, tricks an employee into wiring money or changing a payment based on an email that looks like it came from a boss, a vendor, or a client. The FBI’s Internet Crime Complaint Center logged $3,046,598,558 in reported BEC losses in 2025, the second-costliest cybercrime category behind investment fraud. For a Boston small business, one convincing email is often all it takes to lose a payroll run or a client deposit.
- BEC cost victims over $3 billion in 2025 alone, per the FBI’s 2025 Internet Crime Report.
- Since October 2013, the FBI has tracked more than $55.4 billion in exposed BEC losses domestically and abroad.
- Most BEC scams involve no malware at all. They exploit trust in a familiar name, not a software flaw.
- A phone callback to a number you already had on file, not one listed in the email, stops most wire fraud attempts before money moves.
- Free email authentication settings (SPF, DKIM, DMARC) make it much harder for scammers to spoof your company’s domain.
What exactly counts as business email compromise?
BEC covers any scam where a criminal impersonates someone you trust by email to redirect a payment or extract sensitive data. That includes a fake invoice from a ‘vendor’ asking you to update their bank routing number, a message that appears to come from your CEO requesting an urgent gift card purchase, or a ‘payroll update’ that quietly reroutes an employee’s direct deposit to a new account. The email address often looks almost right: a swapped letter in the domain, a reply-to address that doesn’t match the display name, or an account that was actually compromised and is being used to send real replies from inside a real conversation thread.
Why did BEC losses climb again in 2025?
Part of the answer is volume. Generative AI tools let scammers write fluent, error-free emails in minutes and clone a voice from a few seconds of audio pulled off a company website or LinkedIn video. We covered how that plays out locally in our post on AI voice cloning and deepfake fraud targeting Boston businesses, and in our breakdown of AI-written phishing emails hitting small businesses. The other part is simpler: BEC still works. Unlike ransomware, it doesn’t need to get past antivirus software or a firewall. It just needs one person, on a busy day, to skip a verification step.
What does a typical attempt look like at a Boston company?
The pattern repeats across industries. A bookkeeper gets an email that appears to come from a long-standing supplier, noting their bank has changed and asking that the next invoice go to new account details. A new hire in accounts payable gets a message that looks like it’s from the owner, marked urgent, asking for a same-day wire because the owner is ‘in meetings all day.’ An office manager receives a request that looks like it’s from HR, changing a paycheck’s direct deposit information right before payday. None of these require breaking into your network. They only require guessing who signs the checks and who might not double-check.
What can you do this week to cut the risk?
Put a rule in writing that no payment detail changes or wire transfers happen on email instructions alone. Any request to change a bank account, redirect a payment, or send funds urgently gets a phone call to a number pulled from your own records, not from the email or an attached signature block. Turn on multi-factor authentication for every email account, especially finance and executive accounts, since a compromised mailbox is how many of these scams start in the first place. Ask whoever manages your domain’s DNS to confirm SPF, DKIM, and DMARC are configured correctly, since those three settings make it far harder for someone to send mail that appears to come from your own domain. And walk new hires in finance and HR through a few real BEC examples during onboarding rather than a generic security slide, since people remember specific scenarios better than abstract warnings.
Does cyber insurance cover this?
Many cyber policies include social engineering or ‘funds transfer fraud’ coverage, but it’s frequently a separate rider with its own sublimit, lower than the policy’s main cyber coverage, and often requires proof that your company followed a documented callback or dual-approval process before paying. Read your policy’s fraudulent instruction or social engineering clause closely, or ask your broker to walk through it, before you assume a BEC loss is automatically covered.
Frequently asked questions
What’s the difference between BEC and regular phishing?
Regular phishing usually tries to steal a password or plant malware through a broad, generic email. BEC is more targeted: it impersonates a specific real person or vendor to trigger one specific action, usually a payment or a data handoff.
Can our bank reverse a fraudulent wire once it’s sent?
Sometimes, if you catch it within hours and your bank can request a recall before the receiving bank releases the funds, but there’s no guarantee. Speed matters more than almost anything else, so report a suspected fraudulent wire to your bank and to the FBI’s IC3 immediately.
How should we verify a vendor’s request to change payment details?
Call the vendor using a phone number from a past invoice or your own vendor file, never a number provided in the email making the request, and confirm the change verbally before updating anything in your accounting system.
Do we still need this if we already require MFA?
MFA protects the mailbox itself, but BEC often succeeds without ever compromising an account, since a spoofed or look-alike domain can still land a convincing email in an inbox. Payment verification steps and MFA work best together, not as substitutes for each other.
A single unverified wire instruction is what separates a routine accounts payable day from a six-figure loss, and it’s a risk that a properly configured email environment and a five-minute callback habit can largely close off. If you want a second set of eyes on your email authentication settings, admin account protections, and payment verification process, Boston Managed IT offers a free 15-minute Microsoft 365 or security review. Call (617) 322-5155 or visit bostonmit.com/contact to get started.
— Boston Managed IT