The FBI's Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025, with total adjusted losses of $3.05 billion — the highest figure the FBI has ever recorded for this category of crime. That number still understates the actual damage because the majority of BEC incidents go unreported. Unlike ransomware, which announces itself with a locked screen and a ransom demand, BEC attacks are silent. By the time you realize what happened, the wire transfer is gone and the money is nearly impossible to recover.
What is business email compromise
Business email compromise is a category of fraud where attackers either hijack a legitimate email account or create a convincing imitation of one to deceive employees into wiring money, changing payment details, or disclosing sensitive financial information. The deception relies on trust: an employee receives what looks like a request from their CEO, a known vendor, or the company's accountant — and follows it because it appears completely legitimate.
BEC has five primary variants, each targeting a different point in the financial workflow:
- CEO or executive fraud. The attacker impersonates the business owner or another senior leader and sends an urgent request to someone in accounting or finance, asking them to wire funds to a new account before the end of the day. The message typically includes a reason that discourages verification ("I'm in a meeting, please just handle this").
- Fake invoice or vendor impersonation. The attacker poses as a known vendor and sends an email with updated banking details for an upcoming payment. The message arrives on a lookalike domain or from a compromised vendor email account. The payment goes to the attacker's account instead of the real vendor.
- Account takeover. The attacker gains access to a legitimate email account — through a phished password or a credential stuffing attack — and uses it from the inside. They monitor email traffic, identify upcoming payments, and then send fraudulent payment instructions from the real account. This variant is particularly dangerous because the email passes all technical authenticity checks.
- Payroll diversion. The attacker contacts HR or the payroll administrator, impersonating an employee, and requests a change to their direct deposit account number before the next pay cycle. The employee's wages go to the attacker. Because payroll changes are routine, many small businesses process them without additional verification.
- Attorney or legal impersonation. The attacker poses as the company's lawyer or an external legal representative and creates urgency around a confidential transaction — a settlement, acquisition, or compliance requirement that must be handled immediately and quietly. The secrecy framing is designed to prevent the target from consulting colleagues.
The FBI categorizes all of these as BEC because they share the same core pattern: establish or compromise a trusted email relationship, introduce a financial request with artificial urgency, and create conditions that discourage verification before the money moves.
Why small businesses and childcare centers are prime targets
Small businesses are disproportionately targeted by BEC for reasons that have nothing to do with the size of their bank accounts. They are targeted because of how they operate.
In a business with 5 to 20 employees, the owner is often directly involved in day-to-day financial decisions. That closeness means employees are accustomed to receiving urgent personal requests from leadership without a formal approval process. When the owner emails someone asking for a quick wire transfer before a meeting, employees act. That is how things normally get done. BEC attackers exploit exactly that dynamic.
There is also a vendor payment vulnerability specific to small businesses. Payments to contractors, suppliers, and service providers are often handled by one person using a direct wire or ACH transfer. There is no finance department verifying account numbers, no accounts payable team with a relationship history on file. When an attacker inserts a fake payment instruction into that workflow, the person processing it has no second set of eyes to catch the error.
Childcare centers face a particular version of this exposure. Directors typically handle tuition, vendor invoices, payroll, and government subsidy payments directly. Staff have no formal financial controls because there is no finance team. An email that appears to come from the director, the landlord, or a long-standing curriculum vendor will receive exactly the level of trust a BEC attacker is counting on. FBI data shows that companies with 10 to 50 employees represent the single largest group of BEC victims by incident count.
How AI has changed BEC in 2026
Business email compromise has always worked because the deceptive messages appear plausible. In 2026, AI has made them appear nearly identical to the real thing. Three specific capabilities have changed the threat landscape over the past 18 months.
Writing style mimicry
Large language models can analyze a sample of intercepted emails and produce new messages that precisely match the sender's tone, vocabulary, sentence length, and even punctuation habits. Where a BEC email in 2022 might have contained awkward phrasing or unusual word choices that a careful reader would notice, a 2026 BEC email reads exactly like the person it claims to be from. Researchers at Barracuda Networks found that AI-generated BEC emails bypass human detection at significantly higher rates than traditionally crafted messages, specifically because there are no longer the grammatical or stylistic tells that security training once taught employees to spot.
Voice cloning for call-back verification bypass
When a well-trained employee pushes back on a financial request by calling to verify, attackers now have a way to pass that check. Voice cloning tools can produce a convincing audio replica of a specific person from as little as 15 seconds of publicly available audio. Attackers harvest voice samples from YouTube videos, podcast appearances, conference recordings, and social media. When the employee calls to verify the wire transfer, an AI-generated version of the CEO answers. Verizon's 2025 Data Breach Investigations Report documented the first confirmed incidents where voice-cloned calls were used specifically to bypass call-back verification — a control that had previously been considered definitive protection against BEC.
Targeted research at scale
Traditional BEC attacks required manual research: reading a target company's website, finding executive names on LinkedIn, and studying a few email samples. AI-assisted BEC tools can now automate all of that research simultaneously across hundreds of targets, surfacing the names of executives, key vendors, payment schedules visible in public filings, and the writing patterns of specific people. What used to take an attacker hours to research for a single target now takes seconds. That is why BEC attempt volume keeps growing even as awareness of the threat increases.
Warning signs of a BEC attempt
Recognizing a BEC attempt in the moment requires knowing what patterns to look for. These are the most reliable signals:
Urgency combined with secrecy. The request includes language like "don't mention this to anyone until it's processed" or "I need this done before the board meeting." Real executives rarely ask employees to keep financial transactions secret from other colleagues. This combination is designed to prevent the one step that would stop the attack: talking to someone else before acting.
A request to update known payment details. A vendor you have paid regularly for months or years sends an email with new bank account information for the next invoice. This is the most common BEC entry point for small businesses and childcare centers. Attackers either compromise the vendor's email account or register a lookalike domain and wait for the right moment in the billing cycle.
A slightly wrong email address. The message appears to come from your CEO at firstname.lastname@yourcompany.com, but the actual sender domain is slightly different: yourcompany.net instead of .com, or a character substitution (the letters "rn" together look like "m"). These differences are only visible when you look at the full email address, not the display name shown in most email clients.
A financial request through an unusual channel. An email from the owner when they always communicate via Teams, or a payment instruction from a personal Gmail address when all business happens through the company domain. Attackers use alternative channels when they cannot convincingly mimic the primary one.
Payment to an account or country you have never used. The wire destination is a bank your business has no prior relationship with, or the payment is being routed internationally when all your vendor relationships are domestic. Attackers often move funds through several accounts in different countries within hours of receiving a transfer.
Six steps to protect your business from BEC
The good news about business email compromise is that most of the protection comes from procedure, not expensive technology. These six steps give you the layered defense that stops the majority of BEC attempts.
Step 1: Implement the call-back verification rule
Any request to change banking details, authorize a wire transfer, or redirect payroll must be confirmed by calling the requester at a known, pre-stored phone number — not a number provided in the request itself. This rule should be written, signed off by leadership, and posted near the workstation of anyone who handles financial transactions. It should apply without exception, even when the request appears to come from the owner.
One important update given the 2026 voice cloning threat: your call-back procedure should include a pre-arranged challenge word or phrase that only real executives know. If a "CEO" answers your verification call but cannot provide the challenge word, the request is not verified.
Step 2: Require two-person approval for wire transfers
Set a dollar threshold above which any wire or ACH payment requires a second person to approve using a separate login. The threshold should reflect the size of your business — $5,000 is a reasonable starting point for most small businesses and childcare centers. This eliminates the single-point-of-failure that BEC attacks depend on. If two people must independently authorize a payment, an attacker has to deceive both of them simultaneously.
Step 3: Configure DMARC, DKIM, and SPF on your email domain
These three email authentication standards prevent attackers from sending email that appears to come from your domain. Without them, anyone can compose a message that displays your company name as the sender. DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the outer layer: it tells receiving mail servers what to do when a message fails authentication. DKIM (DomainKeys Identified Mail) adds a cryptographic signature to outgoing messages so recipients can verify they are genuine. SPF (Sender Policy Framework) specifies which mail servers are authorized to send on behalf of your domain.
Google and Yahoo began enforcing sender authentication requirements for business email in early 2024, and Microsoft followed with full enforcement by November 2025 — non-compliant mail is now rejected at the server level, not just flagged. Despite this, 68% of small businesses still have no DMARC record published on their domain, according to a 2026 industry survey. Your IT provider can audit and fix all three records in under an hour. This is one of the highest-impact, lowest-cost security configurations available to a small business.
Step 4: Enable multi-factor authentication on every email account
Stolen credentials are the primary way attackers take over real email accounts for the account takeover BEC variant. MFA means that even with the correct password, signing into your email requires a second factor — a code from an authenticator app or a hardware security key. For small businesses using Microsoft 365, enabling MFA via Microsoft Entra ID takes about 15 minutes and stops the account takeover attack path almost entirely. The FBI's 2025 Internet Crime Report notes that the vast majority of account takeover incidents involved accounts without MFA enabled.
Step 5: Register lookalike domains before attackers do
Attackers commonly register domains that look like yours to use in impersonation campaigns: if you own yourcompany.com, they register yourcompany.net, your-company.com, or yoUrcompany.com. Registering those variants yourself and pointing them nowhere — or redirecting them to your real site — costs roughly $15 to $25 per domain per year and permanently removes those attack vectors. A quick search for your company name across common domain extensions will show you which variants are still available. Your IT provider can help you identify and register the most at-risk variations.
Step 6: Run BEC-specific employee training annually
Security awareness training is only as effective as the scenarios it covers. Generic phishing awareness videos that focus on malicious links and attachments do not adequately prepare employees to recognize a BEC attempt, which typically contains no links or attachments at all. Annual training should include real BEC examples, practice with the warning signs covered above, and a role-play exercise where employees practice applying the call-back verification rule under realistic urgency pressure. Employees who have rehearsed the procedure respond correctly when it matters.
What to do if your business has been targeted
If a wire transfer has already been initiated based on a fraudulent instruction, the window for recovery is narrow but real.
Contact your bank within the first two hours. Ask them immediately to initiate a SWIFT recall or ACH reversal. Most major banks have fraud desks that operate 24 hours, and some maintain direct relationships with the FBI's Financial Fraud Kill Chain (FFKC) unit. The FFKC has frozen and returned a significant portion of recovered BEC funds when notified before the money moves out of the receiving account. Speed matters more than anything else at this stage.
File a complaint at ic3.gov immediately. The FBI's Internet Crime Complaint Center creates a case record and connects your incident to FFKC recovery efforts. The complaint can be filed in about 10 minutes and is the required first step for federal assistance.
File a local police report. While federal agencies handle the fraud investigation, a local police report documents the incident officially. You will need this report number for your cyber insurance claim.
Notify your cyber insurance carrier. BEC losses are typically covered under social engineering coverage, which is a standard rider on most cyber liability policies. Contact your carrier the same day the incident is discovered, not after you have confirmed all the details. Carriers have their own response teams and can begin the claims process while recovery efforts are ongoing.
Audit and secure every affected account. If the attack involved a compromised email account, reset all credentials, revoke any active sessions, and audit the inbox for forwarding rules the attacker may have set up. Attackers routinely configure auto-forwarding to maintain visibility after a compromised account is discovered. Review what correspondence was accessible during the period of compromise and notify any third parties whose information may have been exposed.
Frequently asked questions
Is business email compromise the same as phishing?
They overlap but are not the same. Phishing is a broad category that includes mass emails sent to thousands of recipients hoping someone clicks a malicious link. BEC is a targeted attack focused on a specific company and a specific financial transaction. BEC attackers research the target in advance, learn the names of executives and vendors, and craft messages that match the communication style of the person they are impersonating. BEC results in direct financial losses through wire transfers, ACH fraud, or payroll redirection — not just credential theft.
Can my business recover money after a BEC wire transfer?
Recovery is possible but depends entirely on speed. The FBI's Financial Fraud Kill Chain (FFKC) has helped recover hundreds of millions of dollars in BEC losses, but it requires notification within 24 to 48 hours of the transfer. Contact your bank immediately and ask them to initiate a SWIFT recall or ACH reversal. Then file a complaint at ic3.gov so the FBI can coordinate with the receiving bank. Recovery rates drop sharply after 48 hours as funds move through additional accounts or are converted. Never assume the money is gone before making these calls.
What is the most common BEC attack against childcare centers?
Vendor payment fraud is the most common BEC variant targeting childcare centers. An attacker either compromises or spoofs the email address of a trusted vendor — a food supplier, cleaning service, or curriculum provider — and sends the director an email with updated bank account details for the next invoice. Because the relationship is trusted and the request sounds routine, the payment goes to the attacker's account before anyone notices the change. A simple policy — call the vendor at their known phone number any time banking details change — stops this attack every time.
Does my business need cyber insurance to be protected against BEC?
Cyber insurance does not prevent BEC attacks — technical controls and trained employees do. But insurance matters for managing the financial damage if an attack succeeds. Most cyber liability policies include a social engineering rider that covers BEC losses up to a defined limit. Before assuming you are covered, read your policy. Some carriers require specific controls — MFA, documented call-back verification procedures — as a condition of coverage for social engineering losses. Implementing those controls protects you twice: it prevents the attack, and it ensures you are eligible to collect if one succeeds.
What is the call-back verification rule and how do I implement it?
The call-back verification rule requires that any request to change banking details, initiate a wire transfer, or redirect payroll must be confirmed by calling the requester at a known, pre-stored phone number — not a number provided in the request. Write a one-paragraph policy covering three scenarios: wire transfer requests above a defined threshold, any change to vendor banking information, and any payroll account change. Have every employee who handles financial transactions sign it and keep a printed copy at their workstation. Train them to follow the rule even when the request appears to come from someone they know personally.
The bottom line
Business email compromise is the costliest cybercrime affecting small businesses right now, and it is getting more sophisticated with every passing quarter. The combination of AI-generated messages that read like your executives, voice cloning that can bypass phone verification, and automated targeting tools that identify vulnerable businesses at scale means the threat is not going to recede on its own.
The practical reality is that most of the protection against BEC does not require expensive security products. It requires three things: clear written procedures that employees follow consistently, email authentication records that prevent domain spoofing, and multi-factor authentication that stops account takeovers. None of those cost much to implement, and all of them pay for themselves the first time they stop a $50,000 wire from going to the wrong account.
The businesses that lose money to BEC are not unsophisticated. They are businesses that trusted the urgency in an email and acted before verifying. The solution is building a culture where verification is the default, not the exception — and backing it up with the technical controls that close the gaps attackers exploit when human judgment fails under pressure.
Ready to close your BEC exposure?
EDCON helps small businesses and childcare centers in Southern California configure email authentication (DMARC, DKIM, SPF), enable MFA across Microsoft 365, and train employees on the specific patterns that stop BEC attacks before a wire goes out. Contact us for a free security consultation and we will audit your current email controls and identify your highest-risk gaps.
Book a Free Security Consultation