Business email compromise: trust, redirected
Business email compromise (BEC) turns a familiar conversation into a fraudulent instruction. The message may be technically authentic, visually convincing and timed perfectly. None of that proves the person behind it is authorised.
What BEC is
BEC is targeted impersonation conducted through business communications. Criminals may enter a real mailbox through stolen credentials, or imitate one with a lookalike address and familiar display name. They observe normal work, then intervene when a payment, document or sensitive request is expected.
The most dangerous messages rarely look extraordinary. They continue a genuine invoice thread, mention a real matter, copy a writing style and arrive at a plausible time. That context lowers suspicion precisely when the requested change deserves the strongest check.
BEC is broader than invoice fraud. It includes executive impersonation, payroll redirection, supplier-account changes, settlement diversion, credential theft and requests for confidential client material. The common element is an identity claim carried by a channel the attacker controls.
The control question
Can we prove this instruction came from the real authorised person without using contact details contained in the instruction itself?
How the BEC kill chain works
A compromised inbox supplies context. Patient observation turns that context into a credible moment to intervene.
- 01
Reconnaissance
The attacker studies staff, suppliers, clients, transaction timing and approval roles. A breached mailbox may expose months of genuine conversation.
- 02
Mailbox or identity control
They compromise an account, register a lookalike domain, alter a display name or create a convincing reply that appears to remain inside a real thread.
- 03
The instruction
At the right moment they insert changed bank details, a confidential transfer, a payroll update or a request for documents and credentials.
- 04
Confirmation and payment
They answer questions from the false mailbox and may call to confirm the change. Money is sent before the real participant notices.
The Australian context
The National Anti-Scam Centre's Targeting Scams 2025 report records $2.18 billion in combined reported scam losses across participating Australian organisations. Payment redirection remains among the top loss categories. Those figures span many scam methods, but they show the scale of the environment in which BEC operates.
Scamwatch and the Australian Signals Directorate's Australian Cyber Security Centre both describe BEC as an attacker impersonating a trusted business representative to redirect money or information. Their practical advice is consistent: confirm unusual or changed payment requests using independently sourced contact details, not the details in the suspect message.
Reported figures cannot tell a firm its individual exposure, and they do not capture every attempt or unreported loss. A safer risk decision starts from the transaction: if acting on the request would move money, data or authority, verify the person before acting.
Who is targeted
Accounts teams, conveyancers, brokers, bookkeepers, payroll staff, executive assistants and partners all sit near valuable instructions. An attacker does not need administrator access if one employee can be persuaded to approve a plausible change.
Professional firms are attractive because their ordinary work moves client money and confidential documents. They also hold a position of trust. A criminal who impersonates the firm can use that relationship against clients, suppliers and counterparties as well as against the firm itself.
Smaller firms are not protected by being less visible. Public staff pages, social media, tender notices and email signatures can reveal enough structure to build a tailored request. Larger firms offer more targets and more complex approval paths to study.
What compromise can cost
The immediate loss may be an unrecoverable transfer. The secondary costs include incident response, legal advice, notification work, operational delay, insurance involvement and damaged client confidence. A mailbox may also expose information useful for later fraud.
Time matters after payment. Contact the sending bank's fraud team immediately and ask whether a recall or freeze is possible, preserve messages and access logs, secure affected accounts, and report the event through ReportCyber. These steps do not guarantee recovery but delay can narrow the options.
Prevention is therefore not only an email-security problem. Multi-factor authentication, domain controls and monitoring reduce compromise; an independent verification procedure limits what a successful compromise can authorise.
Who pays when money is redirected?
There is no universal answer. Responsibility can depend on the contract, the facts of the compromise, warnings given, the payment process, each party's conduct and the law that applies. The payer may say it discharged a valid debt; the intended recipient may say payment to an attacker was no payment at all. Banks, insurers and other participants may also have relevant obligations.
Disputes often examine whether the changed instruction should have triggered a reasonable independent check. Was the change unusual? Did the payer call a trusted number already held on file? Did either party warn that bank details would not change by email? Was there a documented approval trail? Those questions make verification evidence important even though it cannot decide liability by itself.
A firm should not promise that one control transfers or eliminates legal responsibility. It should make the defensible practice routine: agree payment-change procedures at engagement, verify every change out of band, record who completed the check, and seek legal and insurance advice when an incident occurs.
The HWL Ebsworth legal-position article identified for this topic could not be verified by automated access, so this page relies on official Scamwatch and cyber.gov.au prevention guidance and states the liability issue conservatively rather than presenting a case outcome.
The email-to-phone pivot
An attacker may follow the false email with a call: “I just sent the new account details,” “the settlement is urgent,” or “finance asked me to confirm.” That second channel feels like corroboration, but it is not independent when the same criminal controls both.
A callback only helps when the number comes from a trusted record established before the request. Calling a number in the email footer, invoice or current conversation keeps the target inside the attacker's environment. Likewise, asking questions based on details visible in the compromised mailbox may test knowledge the attacker already has.
Vericode uses possession-based verification. A code goes to the verified phone number held for the real person, not to the contact details supplied in the suspicious request. The attacker's mailbox access, persuasive call and knowledge of the transaction do not establish possession of that device. This breaks both the email instruction and its phone confirmation at the same identity boundary.
Verification is one layer. High-value transfers should still use appropriate dual approval, separation of duties, transaction limits and bank controls. The goal is to prevent a believable message from becoming sufficient authority on its own.
How verification interrupts BEC
The attacker's advantage is control of context. Verification deliberately steps outside that context. Staff pause, use a pre-established identity record and require possession before accepting the instruction. A failed check reveals no extra information: the request stops, evidence is preserved and the real person can be contacted through trusted details.
BEC red flags
- Bank details change inside an otherwise ordinary invoice or settlement conversation.
- The sender asks for secrecy, unusual speed or an exception to dual approval.
- The display name looks right but the full address or reply-to domain differs.
- Language, signature blocks, timing or account names differ subtly from earlier messages.
- A senior person appears to request a transfer they would not normally initiate by email.
- The sender discourages contact through the phone number already held on file.
- A confirming call relies on the email thread itself as proof of identity.
BEC affects every professional vertical that moves money or sensitive information. Dedicated vertical guides are planned; no unbuilt guide is linked here.