Press Release

Cybersecurity Resource Examines Business Email Compromise and Payment Fraud Risks

New guidance outlines email-security practices, payment verification procedures and common warning signs associated with business email compromise

A new cybersecurity resource examines business email compromise (BEC) and outlines steps organizations can take to reduce exposure to payment fraud, account compromise and email impersonation.

Business email compromise remains a significant category of reported cybercrime. According to the FBI’s Internet Crime Complaint Center (IC3), reported losses associated with BEC exceeded $3 billion in 2025.

BEC attacks frequently rely on social engineering and impersonation rather than malware or software vulnerabilities. Fraudulent messages may appear to come from a supplier, executive, business partner or other trusted contact and can involve requests to change banking information, redirect payments or complete an urgent transaction.

Why Business Email Compromise Remains a Challenge

BEC attacks can involve information gathered from publicly available sources, including company websites, supplier relationships, professional profiles and business announcements. This information can help attackers construct messages that resemble legitimate business communications.

Small and mid-sized organizations may face additional challenges when they have fewer formal payment controls or security resources. Establishing clear procedures for verifying unusual requests can provide an additional layer of protection.

Email authentication is another consideration. Organizations using their own business domains can implement authentication and administrative controls designed to help reduce unauthorized use of their domains for impersonation.

Steps Organizations Can Take to Reduce Risk

The resource identifies several practices organizations can use as part of their email and payment-security procedures.

Use Business Email With Appropriate Security Controls

Business email services can provide administrative controls, access-management features and security settings that may not be available through personal email accounts.
Organizations using a company-controlled domain can also configure email-authentication measures intended to help recipients distinguish authorized messages from unauthorized messages.

Enable Multi-Factor Authentication

Multi-factor authentication requires an additional form of verification beyond a password and can reduce the risk associated with compromised credentials.
Organizations should consider enabling multi-factor authentication for business email accounts and encouraging employees to use authentication applications or hardware security keys where supported.

Independently Verify Payment Changes

Payment-related changes should be independently verified before they are implemented.

Employees can contact a supplier, customer or executive using previously verified contact information rather than relying on a telephone number, email address or link contained in the message requesting the change.

This procedure can help identify fraudulent requests before a payment is released.

Common Warning Signs

  • The resource identifies several indicators that may warrant additional review:
  • Unexpected changes to payment or banking information
  • Requests involving unusual urgency or secrecy
  • Email addresses that closely resemble legitimate domains
  • Reply addresses that differ from the sender’s displayed identity
  • Requests that bypass established approval procedures

 

Organizations can establish internal procedures requiring employees to stop and verify unusual payment requests before taking action.

Turning Verification Into a Business Procedure

BEC prevention does not depend solely on individual employees recognizing fraudulent messages.

Organizations can establish written procedures explaining when payment information must be verified, who is authorized to approve changes and which contact information should be used for independent verification.

Employees should also be encouraged to report suspicious messages and confirm unusual requests without concern that verification will delay legitimate business.
Combining technical email-security measures with employee awareness and payment-verification procedures can help organizations address multiple aspects of business email compromise.

Protecting Business Communications

The resource emphasizes that no single security measure eliminates the risk of business email compromise. Organizations can instead combine domain and account protections with multi-factor authentication, employee awareness and independent verification of financial requests.

Regularly reviewing these procedures can also help businesses adapt their controls as impersonation techniques and payment-fraud methods evolve.

About

This cybersecurity resource provides information about business email compromise, email security, digital threats and payment-fraud prevention. The material is intended to help organizations understand common risks and consider security practices for protecting business communications and financial processes.

Media Contact

Contact Person Name: IC3

Organization Name: IC3

Email: [email protected]/

Website: https://www.ic3.gov/

Country: United States

Author:

Related Articles

Back to top button