A convincing email, compromised vendor account, or AI-polished impersonation can be enough to trigger a fraudulent payment request. It should never be enough to approve one.
In 2025, Business Email Compromise losses reached approximately $3.04 billion, making BEC one of the most financially damaging cybercrime categories.
Here’s how a typical attack unfolds:
– An employee, executive, or vendor email account is compromised—or impersonated.
– The attacker monitors conversations, invoices, and payment processes.
– A request arrives to change banking details, redirect a payment, reset credentials, or approve an “urgent” wire transfer.
– The recipient acts quickly without independently verifying the request.
– AI is making these emails more believable. That means organizations can’t rely only on spotting bad grammar or suspicious wording.
A stronger defense combines awareness with practical safeguards:
– Require independent, out-of-band verification for payment changes, wire requests, payroll updates, and sensitive account changes. Call a known number—not one included in the email.
– Require dual approval for wire transfers and vendor banking changes.
– Use phishing-resistant MFA for email, financial systems, privileged accounts, and remote access. CISA identifies phishing-resistant MFA as an important defense against credential theft and MFA-bypass attacks.
– Monitor for suspicious mailbox forwarding rules, unfamiliar sign-ins, and unauthorized app access.
– Train employees to evaluate the intent of a request—not just how legitimate it looks.
– The goal is not to make people afraid of email. It’s to ensure one convincing message cannot bypass the controls protecting your organization.
– When a payment request is urgent, unusual, or outside the normal process: pause, verify, and protect the payment.
Concerned about your organization’s exposure to Business Email Compromise? Reach out to Bernie Orglmeister at support@skyviewtek.com or call 610-590-5006.