Business email compromise and payment fraud FAQ
Business email compromise (BEC) uses trusted identities and familiar business processes to persuade people to send money or sensitive information. The attack may involve a real compromised mailbox, a lookalike domain or simple impersonation.
6 practical answers.
### What is business email compromise?
BEC is a form of fraud where criminals impersonate or take over a trusted email identity to influence payments, obtain information or gain access to systems.
### How does invoice redirection fraud work?
An attacker impersonates a supplier, employee or executive and asks for bank details to be changed, an urgent payment to be made or an invoice to be redirected.
### What is the best defence against payment fraud?
Use layered controls: secure email and accounts, MFA, restricted admin access, staff training and an independent payment-verification process. Bank-detail changes and unusual payments should be verified using a trusted route that does not rely on the same email thread.
### Can attackers use a real supplier mailbox?
Yes. A genuine supplier mailbox can be compromised, making the request look convincing. That is why finance procedures should verify unusual changes independently rather than treating a familiar email address as proof.
### What should we do after a fraudulent payment?
Contact the bank or payment provider immediately through a trusted channel, preserve the emails and related evidence, investigate whether business accounts are compromised and follow the appropriate fraud and incident-reporting process.
### How can email security help?
Email controls can reduce spoofing, malicious links, lookalike messages and known threats, but finance procedures and user reporting remain important because a technically genuine mailbox can still be abused.