Business Email Compromise: the threat that uses no malware

No exploit, no virus — just trust and a weak payment process.

Many people picture a cyberattack as malicious code breaking through defences. Business Email Compromise does not work like that: there is no exploit, and often no malware at all. There is a person persuaded to do something that looks entirely normal — approve a transfer, update a supplier’s bank details — to the wrong recipient.

Precisely because it uses no technical tools, BEC slips under the controls built for malware. The antivirus has nothing to flag: the email is genuine or nearly so, the request is plausible, the tone is the usual one. It is an attack on process and trust, not on the system — and for that reason it is defended above all with process.

How it shows up

The variants recur. CEO fraud: an executive appears to request, urgently and confidentially, an out-of-process payment. Supplier fraud: someone, in the name of a real supplier, announces a change of bank details shortly before an expected invoice. Payment hijacking: the attacker, after reading the real correspondence for weeks, steps in at the exact moment of the transaction. In every case the lever is the same: a believable request that bypasses the usual controls.

There is often a compromised account behind it

The most effective BEC does not merely spoof an address: it starts from a real mailbox already compromised, usually via credential phishing. From there the attacker observes, learns the language and the timing, and strikes from the inside. A recurring sign is the creation of hidden mail rules that automatically move or delete certain messages, so the victim never sees the replies that would expose the fraud.

The defence is in the payment process

Against an attack on the process, the most effective control is a process one. Every change of bank details and every payment above a threshold must be verified on an independent channel: a phone call to an already known number — never the one given in the suspicious email — to a confirmed contact. Add dual authorisation for significant payments, so no single person can order a transfer alone. These are simple controls that neutralise the very lever BEC relies on: urgency and the bypassing of verification.

Detection and reducing the surface

On the technical side, multi-factor authentication reduces the value of stolen credentials; monitoring mail rules and anomalous sign-ins — such as logins from geographically incompatible locations within the same window — helps uncover a compromised account before it acts. Authenticating your own domain with SPF, DKIM and DMARC makes outbound spoofing harder. None of these controls stops BEC on its own: together they shrink the surface and speed up discovery.

If the transfer has already gone out

Speed is everything. If you notice quickly, contact your bank immediately to attempt a recall of the funds: in the first hours the chances of freezing or recovering them are much higher. Report the event to the competent authorities, change the compromised credentials and look for the mail rules the attacker left behind. And treat it as a real incident, with the same care for evidence: understanding how it happened is what stops it happening again.

The problem is not the person who clicked

After a fraud it is easy to point the finger at whoever authorised the payment. That is a mistake, for two reasons. First, the best attacks are built precisely to deceive careful people: they strike at the right moment, in the right tone, riding a real and expected transaction. Second, if a single trusting person can move funds alone, the flaw is in the process, not the individual. Training helps people recognise the signs, but it is a fragile control if it is the only one: people have bad days, and attackers count on exactly those. Process controls, by contrast, hold even when attention slips.

The takeaway

Business Email Compromise is a cyber threat that almost never uses cyber tools: it exploits trust and the gaps in the payment process. It is defended less with a product and more with a rule: verify every change of details and every significant payment on an independent channel, require dual authorisation, and treat verification as normal. If the request is legitimate, a phone call costs nothing. If it is not, that phone call is everything.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.