Business email compromise attack illustration showing a spoofed CFO email requesting an urgent wire transfer

The email looked real. The CFO was on a plane. The money was gone. 📧🔓

Business email compromise attack explained for SMBs

At 11:14am on a Thursday, the accounts payable manager at a Barcelona property firm received an email from the CFO. The message was urgent: a supplier needed a wire transfer completed before close of business or a contract penalty would apply. The CFO's name, signature, and email address all looked correct. The CFO was on a flight to Dubai. He had sent no such email. By the time anyone realised, €87,000 had cleared to an account in Hong Kong. It was never recovered.

Business Email Compromise is not a technical hack. It is a precision fraud operation — and it causes more reported financial loss globally than ransomware.

How BEC attacks are engineered

BEC attacks succeed because they look legitimate. Attackers invest significant time in research and setup before any fraudulent email is sent.

The two most common technical approaches are:

Domain spoofing — the attacker registers a domain that looks almost identical to the target company's. andi-tech.com becomes andi-tec.com or anditech-group.com. The email looks real in a quick glance, and on mobile where full addresses are often truncated, it can be indistinguishable from the genuine thing.

Mailbox compromise — rather than spoofing, the attacker gains access to a real internal email account (typically through a phishing attack or credential breach) and monitors it silently for weeks. They learn the communication patterns, the tone, the names, the pending transactions. Then they act — from inside the legitimate account, with no spoofing required. These attacks are almost impossible to detect without technical controls in place.

Once inside, attackers frequently create mailbox rules that silently forward copies of incoming mail to external addresses and auto-delete replies — ensuring the real employee never sees the fraudulent conversation.

Real financial impact and why cyber insurance has loopholes

The FBI's Internet Crime Complaint Center consistently reports BEC as one of the highest-loss cybercrime categories. In 2023, reported US losses from BEC exceeded $2.9 billion. The actual figure, accounting for unreported incidents, is substantially higher.

The assumption many businesses carry is that cyber insurance covers BEC losses. It frequently does not — or does so only partially. Common policy exclusions include:

  • 💷 Social engineering sub-limits — many policies carry a separate, lower limit for social engineering fraud. A policy with a £1 million limit may cap social engineering losses at £50,000.
  • 🔄 Voluntary transfer exclusions — if an employee authorised the payment (even under false pretences), some insurers classify this as a voluntary transaction rather than a covered loss.
  • 📋 Failure to follow verification procedures — if the policy includes a requirement for dual authorisation on transfers above a threshold and that procedure was not followed, the claim may be denied.

A finance director at a UK manufacturing firm discovered this after a £220,000 BEC loss: her policy's social engineering clause capped at £25,000. The rest was unrecoverable.

Technical controls that stop BEC

The most effective technical defence against domain spoofing is a correctly configured email authentication stack. Three protocols work together:

  • 🔐 SPF (Sender Policy Framework) — publishes a DNS record specifying which mail servers are authorised to send email from your domain. Emails from unauthorised servers are flagged or rejected.
  • ✍️ DKIM (DomainKeys Identified Mail) — adds a cryptographic signature to outgoing emails that receiving servers can verify. If an email is modified in transit, the signature breaks.
  • 🛡️ DMARC (Domain-based Message Authentication, Reporting and Conformance) — ties SPF and DKIM together and tells receiving mail servers what to do with messages that fail authentication: monitor, quarantine, or reject. Critically, DMARC set to p=reject prevents spoofed emails from your domain reaching anyone's inbox.

Many businesses have SPF configured but leave DMARC in monitor mode indefinitely — which provides visibility but no protection. Moving DMARC to enforcement is the single highest-impact email security action most SMBs have not taken.

Additional Microsoft 365 controls worth enabling: Exchange Online Protection mail flow rules to block external senders spoofing internal display names, and Microsoft Defender for Office 365's impersonation protection for high-value accounts (executives, finance team members, IT administrators).

Verification protocols for finance teams

Technical controls reduce the attack surface but do not eliminate BEC risk — particularly when attackers use compromised internal accounts. Human verification procedures are the final layer.

Effective protocols for finance teams:

  • 📞 Out-of-band verification for all payment changes — any request to change payment account details, regardless of source, must be verified by phone using a number already on record. Not a number included in the email requesting the change.
  • 🔁 Callback verification for urgent wire transfers — any request framed as urgent automatically triggers a callback to the requestor before processing. Urgency is a manipulation technique; it should increase scrutiny, not accelerate action.
  • Dual authorisation above a threshold — no single employee should be able to authorise and execute a payment above a defined amount. The threshold should be documented in the finance policy and reflected in the cyber insurance terms.
  • 🎓 Executive impersonation awareness — finance teams should be explicitly briefed that executives will never request urgent wire transfers by email alone. This should be a stated policy, not an assumption.

A simple laminated card at the accounts payable workstation covering these four points has prevented more BEC losses than complex training programmes in organisations that have implemented it.

What to do if you have already been targeted

If a suspicious payment request has been identified — whether actioned or not — the response matters:

  1. Contact your bank immediately — SWIFT recall requests have a narrow window (often hours) in which recovery is possible. Speed is the only variable you control.
  2. Preserve all email evidence — do not delete, move, or reply to the suspect emails. Forward them to IT and preserve headers.
  3. Check for mailbox rules — have IT audit the affected mailbox for forwarding rules, filter rules, or delegates that should not be there.
  4. Report to law enforcement — in the US, file with the FBI IC3. In the UK, report to Action Fraud. Neither guarantee recovery, but reporting creates a record that supports insurance claims and may contribute to broader investigations.
  5. Notify your insurer — within the timeframe specified in your policy, even if you are unsure whether the loss is covered.

BEC is preventable when the right controls are in place before the email arrives. Andi-Tech's cybersecurity solutions include full Microsoft 365 email hardening — SPF, DKIM, and DMARC enforcement, impersonation protection, and mailbox audit configuration — so that a spoofed CFO email reaches the spam folder rather than the accounts payable inbox.

📧 A spoofed email that bypasses your defences can cost more than a ransomware attack — and insurance may not cover it.
Andi-Tech hardens Microsoft 365 email security for SMBs — implementing DMARC enforcement, impersonation protection, and mailbox audit rules to stop BEC attacks before they reach your finance team.

Contact us at info@andi-tech.com — let's make sure the next CFO email your finance team receives is actually from your CFO.