What is business email compromise?
Business email compromise (BEC) is fraud using a fake or compromised email account to request a payment, a change of bank details or confidential information. The sender may impersonate a manager, colleague or supplier.
A message can include real business details and continue an existing conversation. The question is therefore not only “Do I recognise the sender?” but also “Has this particular instruction been verified?”.
Notice what the request changes
Pause when a message asks for a new payment account, an exception to approval, unusual information or secrecy from colleagues normally involved. Urgency adds to the need for verification.
Inspect the full sender address, but do not stop there. A similar domain may be fake, while a correct domain may belong to a compromised account. Neither fluent writing nor a familiar signature confirms an instruction.
Verify before acting
- Pause the suspicious payment, account change or disclosure.
- Contact the relevant person on a previously known number or another independent internal channel. Do not obtain new contact details from the message you are checking.
- Confirm the specific instruction: who is being paid, why and to which account, or what information is needed and why.
- Complete approval under your organisation’s procedure. Do not make an exception simply because the request appears to come from a manager.
Always verify changed instructions and urgent requests through an independent channel.
If money or information has already been sent
For a suspicious payment, contact your bank immediately and provide the transaction details. The bank can assess what action remains possible; recovery is not guaranteed.
Notify the responsible team under your internal procedure. Preserve the original message, attachments and time of the event. If confidential information was disclosed or account takeover is suspected, involve IT or the security team to assess the incident and protect access. Do not delete the thread yourself or circulate sensitive attachments widely.
Reporting to FIN-CSIRT supports cyber incident handling and does not replace urgent contact with the bank or an internal report.
Reduce the chance of a repeat
Protect business accounts with multi-factor authentication and train staff to report unusual requests. MFA reduces account takeover risk; it does not establish whether an individual payment instruction is valid. Clear verification and approval rules remain necessary.
Check your knowledge · 3
of 5
Your turn to choose the next step.
Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.
Questions and explanations are also available without JavaScript.
Without JavaScript, the full bank of 5 questions is shown.
A manager emails an urgent payment request and tells you to skip normal approval. What do you do?
Why does this matter? The request uses a manager’s authority and urgency to bypass payment checks. If the instruction is false, normal approval and an independent call can interrupt the fraud before money is sent.
-
Pay because I recognise their name.
A name can be imitated, and a real account can be compromised. A familiar name encourages trust, but does not show who wrote this particular payment instruction.
-
Reply to the same email and ask if they are sure.
If the account is compromised, the attacker may provide the confirmation in the same thread. The person who sent a false request could confirm their own story without the real manager being consulted.
-
Pause and verify through a known channel while following the normal process.Correct answer
An independent check and normal approval reduce the risk of following a fraudulent instruction. You separate identity checking from the suspicious exchange and retain the control meant to check whether the payment is justified.
A request comes from the correct email address of a long-standing partner. Does that confirm the new payment instruction?
Why does this matter? Taking over a real business account gives an attacker a convincing channel for false instructions. Checking the address is therefore different from confirming that the partner authorised a change.
-
Yes, the correct address is enough.
A correct address does not rule out account takeover. If an attacker is using the account, even a technically correct address can carry a request to pay an account they control.
-
No, the account may be compromised and the change needs an independent check.Correct answer
A real account can send false instructions when an attacker controls it. You check the change that affects the money rather than treating a trusted address as approval for every future request.
-
Yes, if there are no spelling mistakes.
Accurate spelling does not establish authenticity. Good grammar checks neither the writer’s identity nor the account that will receive the money.
After making a payment, you learn the request was probably fraudulent. What do you arrange first?
Why does this matter? Once money reaches the wrong account, further movement can make action harder. Prompt contact and retained correspondence help establish the transaction and how the request reached you.
-
Immediate contact with the bank and an internal report, preserving the message and payment details.Correct answer
The bank needs the payment details quickly, and the responsible team needs to preserve and assess evidence. Recovery is not guaranteed. Transaction details help the bank locate the payment, while the correspondence helps the internal team assess the incident’s scope.
-
Wait for the supposed sender to reply.
Waiting delays action; you may be communicating with the attacker. A reply may be another excuse that buys time while the bank remains unaware of the suspicious payment.
-
Delete the thread so colleagues cannot open it.
Deletion removes useful evidence. Follow the internal reporting process. Without the message, it is harder to establish what changed and warn colleagues about the specific request pattern.
A manager who is supposedly away asks for a confidential urgent payment without involving colleagues. What do you do?
Why does this matter? Unavailability, authority and secrecy are used to bypass normal controls.
-
Pay so I do not delay the manager.
Urgency does not remove a control that protects both the organisation and employee.
-
Keep the normal process and verify through a known contact.Correct answer
The process and separate channel verify identity and the request itself.
-
Ask for confirmation only in the same email thread.
An attacker controlling the thread can also send the confirmation.
A partner changes bank details on an invoice just before it is due. What must be checked?
Why does this matter? A changed financial detail is a high-risk moment even when the rest of the document looks familiar.
-
Only whether the invoice has the same logo.
A logo can be copied and does not verify the new account.
-
The change through a previously known contact and the normal approval process.Correct answer
An independent contact checks the specific change before money moves.
-
Whether the message says urgent.
An urgency label is not evidence of authenticity.
No registration. Your answers are not sent; the result is just for you.