← All postsFor Financial Institutions

Business Email Compromise in Plain English: How This Scam Actually Starts

Business Email Compromise in Plain English: How This Scam Actually Starts

The CFO is at a conference in Calgary. The accounts payable coordinator gets an email from her — urgent, brief, slightly more curt than usual. A vendor has changed their banking details. Can the coordinator update the file and send this week’s payment to the new account? It’s time-sensitive.

The coordinator has processed hundreds of payment changes. This feels like any other. She updates the file. The payment goes out — $43,000, to an account controlled by a fraudster.

The real CFO, still at the conference, has no idea.

This is Business Email Compromise (BEC). It is not a technical attack. It does not require the fraudster to break into your systems. It requires only that your organization follows its normal processes — and that one step is missing.


What BEC Is, and How It Works

BEC is a fraud in which someone impersonates an executive, vendor, or trusted colleague via email to authorize a payment or banking change that benefits the fraudster.

There are two common setups.

Email spoofing means the fraudster sends an email that appears to come from a legitimate address but doesn’t. The sender’s display name might read “Sarah Chen — CFO” but the actual email address is something like sarah.chen@companyname-ca.com — a domain that looks real at a glance but isn’t.

Account takeover is more sophisticated: the fraudster has actually gained access to a real email account — often through a phishing attack (a fake login page) — and is sending from the legitimate address. In this case, the email is indistinguishable from the real thing, because it is the real account.

In both cases, the request follows a predictable pattern: urgency, a plausible business context, and an instruction to transfer money or update payment details.


Why It Works

BEC is effective for a straightforward reason: it exploits the normal operation of a business.

Employees process payment requests. Finance teams update vendor banking details. Executives send urgent directives. None of this is suspicious — it is ordinary business activity. BEC succeeds by wrapping fraudulent instructions inside that ordinary activity, at a moment when verification feels like an unnecessary delay.

The “CEO is travelling” scenario is particularly well-designed. The executive being unavailable explains why you can’t call to confirm. The urgency explains why there’s no time to go through normal channels. The email looks real. Everything points toward processing it.

It targets organizations of all sizes. The Canadian Centre for Cyber Security has documented BEC cases involving Canadian law firms, construction companies, non-profits, and municipal governments — not just large corporations. Smaller organizations are often more vulnerable because they have fewer formal authorization controls.


What Actually Reduces the Risk

Two process changes stop the majority of BEC attempts.

Verbal confirmation of payment changes. Any request to change a vendor’s banking details — regardless of how it arrives, and regardless of who appears to be asking — should require a phone call to a known number for that vendor before the change is made. Not a reply email. Not a call to a number provided in the change request. A call to a number you already have on file, or that you look up independently.

This one step breaks the scam. A fraudster who has sent you a fake email cannot also intercept a call to your vendor’s real phone number.

Dual authorization for large or unusual transfers. Any wire transfer above a defined threshold, or any transfer to a new or recently changed banking destination, should require sign-off from two people before it goes out. This is not bureaucracy — it is a control that has prevented significant losses in Canadian organizations that have implemented it.

Neither of these controls is technically complex. Both require only a written policy and staff who understand why the policy exists.


One Thing to Do

If your organization currently changes a vendor’s banking details based on an email request alone — even an email that appears to come from the vendor — add one more step before the next change is made: a phone call to the vendor at a number you already have on file to confirm the change is real. This single addition costs two minutes and has stopped frauds worth hundreds of thousands of dollars at Canadian organizations.