Quick answer
In a BEC scam, an attacker either impersonates a supplier or colleague, or quietly gets inside a real mailbox, then sends a believable message changing the bank details on an invoice. The money lands in the criminal's account. The fix is process, not just technology: always verify any bank-detail change or payment by phone, to a number you already know.
THE TWO FLAVOURS
Two ways it plays out.
Almost every BEC scam falls into one of two buckets — and one is far harder to catch:
- ▸ Impersonation. A look-alike email address pretends to be one of your suppliers, or the boss. Nothing has actually been broken into — the attacker is simply wearing a convincing costume and hoping you don't check the details.
- ▸ Account takeover. The attacker is genuinely inside a real mailbox and replies within an authentic email thread — which is far more convincing. This often follows token theft or a stolen login, so the criminal is reading real conversations and timing their move.
THE CLASSIC PLAY
How the money goes missing.
The attacker watches a real invoice conversation and waits for exactly the right moment — a genuine bill is due, everyone is expecting a payment. Then they send the line that does the damage: "our bank details have changed — please use these for this invoice."
It looks routine, so the payment gets made — straight into the criminal's account. Worse still, it's often not spotted for weeks, until the real supplier chases the unpaid bill and everyone realises the money went somewhere else entirely.
WARNING SIGNS
Red flags to train your team on.
None of these are proof on their own — but any of them should stop a payment until it's verified:
- ▸ A bank-detail change requested by email. This is the single biggest red flag. Real suppliers change accounts rarely, and never mind a phone call to confirm.
- ▸ Unusual urgency. "Please process today", "the boss needs this before the deadline" — pressure is designed to stop you checking.
- ▸ A slightly different email address or reply-to. A single swapped letter, an extra word, or a reply that quietly goes to a different address.
- ▸ Emails disappearing, or mailbox rules you didn't create. A sign a real mailbox may have been taken over and the attacker is hiding their tracks.
- ▸ The supplier says they never sent it. If in any doubt, ask — a quick call often unravels the whole thing.
HOW TO PREVENT IT
Make the scam fail.
The good news: a few simple habits make BEC very hard to pull off.
- Verify every payment or bank-detail change by phoneMake it a firm, no-exceptions rule — confirm on a number you already know, never the number written in the email. This one habit stops the vast majority of BEC scams cold.
- Require dual approval for larger paymentsFor any payment above a set amount, insist a second person signs off. Two sets of eyes catch what a single, busy person might miss.
- Train staff to expect and question these requestsWhen your team knows exactly what a "new bank details" scam looks like, they stop being an easy target — and start being your best defence.
- Add the technical layersEmail authentication, impersonation protection, MFA and monitoring all help — catching look-alike domains and spotting a mailbox takeover early, before it turns into a redirected payment.
Why "it looked completely legitimate" is the whole point. The account-takeover version is so convincing because it comes from a real address, inside a real thread — which is exactly why victims describe it as looking completely legitimate. You can't spot it by reading the email harder. Verifying by phone, to a number you already know, is what saves you.