The most expensive attack on small businesses does not involve malware, hacking tools, or anything a spam filter would flag. It is an ordinary-looking email that says: our banking details have changed, please use the new account for the attached invoice. The money leaves by wire or ACH, and by the time anyone notices, it has been moved through three more accounts.
This is business email compromise, and the FBI consistently ranks it as the most costly cybercrime by dollar losses, ahead of ransomware. It works on careful people. Here is how the scam actually runs, and the three rules that stop it regardless of how convincing the email is.
How the scam actually works
The attacker starts by getting eyes on real email. Sometimes that means compromising a mailbox at your company, often through a leaked password (our breach check guide covers how those get out). Just as often it is a mailbox at one of your vendors, which means you can do everything right and still be targeted through them.
Then they wait. They read invoice threads, learn who pays whom, how invoices are formatted, and when payments go out. When a real invoice is due, they step into the conversation: sometimes from the real compromised mailbox, sometimes from a lookalike domain with one letter changed. The message matches the thread, references the real invoice number, and asks for one small thing: updated payment details.
Nothing about this trips a spam filter. There is no attachment full of malware, no suspicious link. It is a plain business email that happens to be a lie.
The three variants to warn your team about
- Vendor impersonation. The classic described above. The red flag is always a change: new bank account, new remittance address, new urgency.
- Executive impersonation. A text or email that appears to come from the owner: I am in a meeting, I need you to handle a payment or buy gift cards, keep it quiet. New employees in their first weeks are the favorite target, which is why attackers watch LinkedIn for job announcements, as covered in our business exposure guide.
- Payroll diversion. An email to whoever runs payroll, appearing to come from an employee, asking to update their direct deposit. The paycheck lands in the attacker’s account on payday.
The three rules that stop it
Technology helps, but this scam is beaten by process. Three rules, written down and followed without exception.
- Rule 1: Payment details never change on the strength of a message alone. Any request to change a bank account, remittance address, or direct deposit gets verified by a phone call to a number you already had on file. Not the number in the email signature, which the attacker controls. This single rule defeats the core of the scam.
- Rule 2: Two people approve any payment above a threshold you choose. Pick a number that fits your business. Dual approval means the scam has to fool two people instead of one busy person having a hectic afternoon.
- Rule 3: Gift cards are never a business purchase. No legitimate boss asks an employee to buy gift cards and send photos of the codes. Say it once at a team meeting and this variant dies.
The rules cost nothing, and they work even when the email comes from a genuinely compromised real mailbox, which is the case no technology reliably catches.
The technical layer behind the rules
- MFA on email, so a leaked password is not enough to read your invoice threads in the first place. Our Microsoft 365 MFA guide is the step-by-step.
- SPF, DKIM, and DMARC on your domain, so criminals cannot send mail that appears to come from you to your own customers. Ask your IT provider to confirm all three are in place.
- External sender tagging, so a lookalike domain pretending to be a coworker arrives visibly marked as external.
- Bank-side controls. Ask your bank about positive pay, ACH filters, and transaction alerts. Many small business accounts have these available and unused.
If money already left
Speed matters more than anything. Call your bank immediately and ask for a recall and a fraud freeze; wires can sometimes be clawed back within the first 24 to 72 hours. File a complaint at the FBI’s ic3.gov the same day, because rapid IC3 reports feed the recovery process. Preserve the emails untouched, including headers, and then have the compromised mailbox investigated, because the attacker who diverted one invoice has read everything else in that inbox too.
Key Takeaways
- Business email compromise is the most expensive cybercrime, and it arrives as a normal-looking email with no malware to detect.
- The attack can originate from your vendor’s mailbox, so your own security is only half the picture.
- Payment changes get verified by a call to a known number, always, with no exceptions for urgency.
- Dual approval above a threshold and a blanket no-gift-cards rule close the other two variants.
- If money moves, the first 24 hours decide whether you get it back: bank first, then ic3.gov.
Our free 30-minute security awareness session walks your team through these scams with real examples, in English, Spanish, or Portuguese. Book it at /free-training/, no obligation.
LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.