Most people picture a cyberattack as something technical. Malware. A breached server. An alert going off somewhere.

The most expensive attack on American businesses looks nothing like that. It arrives as an email. It contains no attachment, no malicious link, and nothing an antivirus product would flag. It asks a reasonable person to do something they do routinely — pay an invoice, update a vendor’s bank details, approve a transfer.

The FBI’s 2025 Internet Crime Report recorded $3,046,598,558 in reported losses to business email compromise across 24,768 complaints. That is an average of roughly $123,000 per incident, and it made BEC the second-costliest category of internet crime in the United States — behind only investment fraud.

This article explains the mechanism. The companion piece covers the defenses that actually work.


The Shape of the Attack

BEC is fraud, not hacking. The technical component is minimal and often absent entirely. What it exploits is a business process — specifically, the moment when money moves based on an emailed instruction.

The pattern is consistent:

  1. Reconnaissance. The attacker learns who pays the bills, who approves them, who your vendors are, and how your organisation writes emails. Much of this is public. Some comes from a mailbox they already have access to.
  2. Position. They either compromise a real mailbox — usually via a stolen password — or register a domain that reads correctly at a glance. socialpovver.tech for socialpower.tech. @company-inc.com for @companyinc.com.
  3. Timing. The request arrives when it is plausible. During a real project. Near a real invoice date. While the person who would normally check is travelling.
  4. The ask. Change the wire instructions on this payment. Process this vendor invoice. The CEO needs this handled before the close of business.

The FBI reports that wire transfers and ACH payments carried 86% of BEC losses in 2025. The attack targets the payment rail, because that is where money moves fast and reverses slowly.

Why the usual defenses do not engage

This is the part that catches organisations with genuinely good security posture.

There is often no malware for endpoint protection to detect. There is often no malicious link for a filter to score. When a real mailbox has been compromised, the email passes every authentication check, because it is genuinely from that domain — the attacker is sending it from the account.

And a compromised vendor’s mailbox is worse still. The invoice arrives from the vendor you have paid for six years, in the thread where you discussed the actual work, with the actual invoice number, and one line changed.


What Has Changed Recently

Two developments in the current data are worth flagging.

Volume is rising after a plateau. BEC complaints held roughly steady at 21,489 in 2023 and 21,442 in 2024, then jumped to 24,768 in 2025 — a 15.5% increase. Losses climbed from $2.77 billion to $3.05 billion.

AI has entered the process. The FBI attributed over $30 million in 2025 BEC losses specifically to scams with a confirmed AI component. That figure is small against the $3.05 billion total, and we would rather report it accurately than inflate it. But the direction matters more than the magnitude right now.

The practical implication is that the traditional detection advice is expiring. “Watch for bad grammar and awkward phrasing” worked when attackers wrote in a second language without tooling. It is no longer a reliable signal. Neither is a familiar voice on the phone — voice cloning from a few seconds of public audio is now routine.

Verification has to move from stylistic judgement to process. You cannot reliably detect these by how they read anymore.


Where Small Businesses Are Most Exposed

Large organisations have segregated duties, approval thresholds, and a finance department where two people touch every payment. Small businesses usually have one person handling payments, and that person is often the owner.

That structure is efficient. It is also exactly the target profile:

  • One approver means no second set of eyes by default
  • Direct owner involvement means an email appearing to come from the owner carries immediate authority
  • Vendor familiarity means changed bank details from a long-standing supplier feel routine
  • Speed as a value means “handle this quickly” is culturally normal rather than suspicious

Recovery is possible but far from assured. The FBI’s Financial Fraud Kill Chain handled 3,900 incidents in 2025 involving $1.16 billion in attempted theft and froze $679 million — a 58% success rate on the cases it reached in time. That last clause is the whole game. Funds recovery depends almost entirely on how fast the bank and the FBI are notified.


The Controls That Actually Work

The effective defenses against BEC are procedural, not technical. They are also unglamorous, which is probably why they get skipped.

1. Out-of-band verification for any change to payment details. Any request to change bank account information, wire instructions, or payment routing gets verified by phone — to a number you already have on file, never a number in the email. No exceptions, no matter who appears to be asking. This single rule stops the majority of BEC attempts.

2. A second approver above a dollar threshold. Pick a number appropriate to your business. Above it, two people sign off. The threshold matters less than the existence of the rule.

3. Multi-factor authentication on every mailbox. Stolen credentials remain the most common initial access vector. MFA turns a stolen password into a failed login. If you do one technical thing, do this one.

4. Alerting on mailbox forwarding rules. A standard persistence trick is a rule that silently forwards or auto-deletes messages, letting an attacker monitor a thread without the owner noticing. Most business email platforms can alert on rule creation. Most have it switched off.

5. A written, rehearsed response plan. Who calls the bank. Who calls the FBI at ic3.gov. Who informs leadership. Written down in advance, because the window where money is recoverable is measured in hours and nobody improvises well at that moment.


What This Is Not

A few honest boundaries.

This is not an argument that a specific product will solve it. BEC is a process vulnerability, and no software fully closes a gap that lives between two people’s assumptions. Vendors who claim otherwise are selling.

It is also not an argument that anyone who falls for this was careless. These attacks succeed against sophisticated finance teams at large companies. They are designed to look exactly like legitimate work, arriving at a moment when legitimate work is expected. Treating it as a competence failure is both unkind and analytically wrong — it leads organisations to blame individuals instead of fixing processes.

And it is not the same problem as securing your website, though the two get bundled together. A compromised website and a compromised mailbox are different attacks with different remedies. The email side is where the money actually goes.


The Practical Next Step

If you take one thing from this: write down the verification rule and tell the person who pays your bills.

Not a policy document. One sentence: Any change to payment details gets a phone call to a number we already have, before anything moves.

That rule costs nothing, takes two minutes to implement, and addresses the mechanism behind the majority of a $3 billion annual loss category.

The companion article covers the technical layer that stops your domain from being impersonated in the first place — a genuinely useful complement, though it protects your customers and partners more than it protects you.

If you would like us to look at how your business email is currently configured and tell you where the gaps are, we will do that and give you a straight answer.