Business Email Compromise: How One Email Redirects a Payment
Business email compromise needs no malware and no hacking skill, just a believable email to the person who moves money. Here is how it works and the controls that stop it.

Most attacks on a business need something technical: a malicious attachment, a stolen password, a weakness in a server. Business email compromise needs none of that. It needs one well-timed email to the person who can move money, written so that paying it feels like the obvious thing to do.
That is why it works on careful people in well-run companies. Nothing in the message trips a filter, because there is nothing in it but words.
What business email compromise looks like
The pattern is almost always the same. Someone in finance, procurement or an executive's office receives an email that appears to come from a person they trust, asking for a payment or a change to one. The request is plausible, it is urgent, and it comes with a reason not to check.
- The executive request. "I'm in a meeting all afternoon. We need to settle this supplier today to secure the deal. Send it to the account below and I'll explain later."
- The supplier update. A regular supplier writes to say their bank details have changed, with a new account for all future invoices.
- The payroll switch. An employee asks HR to pay this month's salary into a new account.
- The lawyer or auditor. A confidential transaction that "must not be discussed internally yet".
The tell is never the grammar. These emails are short, polite and correctly written. The tell is the combination of money, urgency and a reason to skip your normal checks.
How the attacker gets in position
Some attackers simply register a domain that looks like yours or your supplier's, such as a letter swapped or a hyphen added, and send from it. Others break into a real mailbox, often through an earlier phishing email, and then wait. They read the conversations, learn who approves what, and strike when a genuine invoice is due, replying inside a thread your team already trusts.
When the message comes from a real account inside a real thread, looking at the sender address tells you nothing. That is why the defence has to be a process, not an eye for detail.
Controls that actually stop it
1. Verify every change of bank details by phone
Call the supplier or colleague on a number you already hold, not one in the email. Make this a rule with no exceptions for seniority or urgency. A genuine supplier will not mind; an attacker cannot answer that phone.
2. Require two people for new payees and large transfers
A second approver breaks the attacker's plan, which depends on one person acting quickly and alone. Set the threshold low enough that it catches the payments that would hurt.
3. Make "the CEO said so" a reason to check, not a reason to skip
Leaders should tell their teams, out loud, that they will never ask for a payment by email that bypasses the normal process, and that anyone who calls to check will be thanked. Attackers rely on juniors feeling unable to question a senior name.
4. Protect the mailboxes themselves
Turn on multi-factor authentication for every email account, and alert on new forwarding rules, which attackers add so they can keep reading after a password change.
5. Train the people who move money first
Finance, procurement, HR and executive assistants are the targets. They should see realistic examples of these requests before a real one arrives, and practise the habit of stopping to verify.
If money has already gone: call your bank immediately and ask them to recall the transfer. Speed matters more than anything else. Then report it to the police, reset the passwords of any mailbox involved, and check it for forwarding rules.
Where CyberWatch AI fits
CyberWatch AI lets an organization send its own staff realistic practice emails, including payment and supplier requests, and see who pauses and who pays. The people who need it get short training on exactly that pattern, and anyone unsure about a real message can check it and report it to the security team in one step. The result is a team that treats an urgent payment email as a reason to pick up the phone.


