---
title: "Business email compromise examples and how to stop them"
description: "Seven business email compromise (BEC) examples finance teams see, the red flags in each, and the specific control that stops it before money moves."
url: https://realpayee.com/blog/business-email-compromise-examples
canonical: https://realpayee.com/blog/business-email-compromise-examples
date_published: 2026-10-05
date_modified: 2026-10-05
updated: 2026-10-05
author: "RealPayee"
site: RealPayee
---

# 7 business email compromise examples, and the control that stops each one

> Business email compromise (BEC) is fraud where a criminal impersonates a vendor, executive, lawyer or employee by email to redirect a payment or steal data. The common examples are fake vendor bank changes, urgent CEO wire requests, hijacked invoice threads and payroll diversion. Each is stopped by verifying the request with the real person through a channel you already trust.

_Fraud prevention · Published 2026-10-05 · 6 min read · By the RealPayee team_

## Key takeaways

- BEC rarely involves malware. It is a convincing request plus a payment process that trusts email.
- The FBI's IC3 recorded about **$3.0 billion** in reported BEC losses in 2025, from 24,768 complaints.
- Most examples share three tells: a change to where money goes, urgency, and a reason not to use the normal channel.
- The fix is the same every time: **confirm with the known person, on a channel you already had**, before money or data moves.

## What business email compromise looks like in practice

Business email compromise is a family of scams, not one trick. The attacker either spoofs an address (a lookalike domain such as acrne-supply.com for acme-supply.com), uses a display name over a free webmail account, or takes over a real mailbox at your company or a vendor. Then they ask for something that looks routine: update bank details, pay this invoice, send the W-2s, wire the deposit today.

The scale is large and steady. The FBI's Internet Crime Complaint Center counted **24,768 BEC complaints and roughly $3.0 billion in reported losses in 2025**, after $2.77 billion in 2024. In the AFP's 2026 payments fraud survey, **74% of organizations** reported being hit by BEC. The examples below are composites of patterns finance teams report, with the red flags and the control for each.

## Seven business email compromise examples

### 1. The vendor bank-detail change

An email arrives from your packaging supplier's accounts receivable contact: "We have moved our banking to a new provider. Please update our remittance details before the next payment. New bank letter attached." The domain is one letter off, or the vendor's real mailbox has been compromised and the email sits inside a genuine thread. The next payment run pays the new account. Nobody notices until the real vendor chases an overdue invoice weeks later.

- **Red flags:** change requested by email; attached bank letter or voided check; new bank in a different region; timing just before a large payment.
- **Control:** verify every bank-detail change with the known vendor contact on a phone number already in your vendor file, and hold payments until it is verified. See [vendor verification](https://realpayee.com/vendor-verification).

This is the single most common pattern. In the AFP's 2025 survey, 45% of organizations reported vendor imposter fraud, up 11 points from the prior year.

### 2. The urgent CEO wire

A message that appears to come from the CEO reaches the controller late on a Friday: "I'm in meetings all afternoon. We are closing a confidential acquisition and need a wire of $186,000 sent to the escrow agent today. Please handle it quietly and don't call, I can't talk."

- **Red flags:** secrecy, urgency, a reason the executive cannot be reached, a new payee, a request to skip the normal approval chain.
- **Control:** no wire to a new payee without out-of-band confirmation from the executive on a known number, plus normal dual approval. Our [CEO fraud guide](https://realpayee.com/ceo-fraud) has the full playbook.

### 3. The hijacked invoice thread

An attacker who has access to a vendor's mailbox watches real conversations for weeks. When a large invoice is discussed, they reply in the same thread with "updated payment instructions", sometimes setting up a mail rule so the vendor never sees your replies. Because the email comes from the real address and quotes the real thread, it passes every "check the sender" test.

- **Red flags:** payment instructions change mid-thread; a new person is cc'd; replies arrive at odd hours compared with earlier messages.
- **Control:** the same as example 1. A real sender address proves nothing when the mailbox itself is compromised. Only an independent callback or a verification bound to the known contact does.

### 4. The fake attorney or advisor

Someone claiming to be outside counsel, an M&A advisor or an auditor contacts finance about a time-sensitive settlement or deal deposit, often referencing an email "from the CEO" authorizing them to give instructions directly.

- **Red flags:** a third party giving payment instructions on an executive's behalf; pressure to keep it confidential; an unfamiliar law firm.
- **Control:** payment instructions only come from the internal owner of the deal, and are confirmed with that person directly.

### 5. Payroll diversion

HR receives: "Hi, I've changed banks. Can you update my direct deposit before this Friday's payroll?" It comes from a personal webmail address with the employee's name, or from the employee's real but compromised account.

- **Red flags:** change requested by email rather than through the HR system; request close to a payroll cutoff; the employee is remote or traveling.
- **Control:** direct deposit changes only through the authenticated HR portal, plus a confirmation to the employee by phone or in person, and a notice to the old account details on file.

### 6. W-2 and data theft

Not every BEC scam asks for money. A message from the "CFO" asks payroll for a PDF of all employee W-2s for a "review". The stolen data is later used for tax refund fraud and identity theft.

- **Red flags:** bulk personal data requested by email; an unusual reason; pressure to send it fast.
- **Control:** sensitive data exports require a ticket or approval in a system other than email, and a verbal confirmation with the requester.

### 7. The gift card or small-favor request

"Are you at your desk? I need a quick favor." The "executive" then asks for gift cards for a client event, to be bought now and the codes sent by email. It is small money, which is the point: it tests who responds, and the same person is targeted again later with a bigger request.

- **Red flags:** "are you available" openers; requests for gift cards or crypto; the executive is unreachable by phone.
- **Control:** a standing rule, communicated by leadership, that executives never ask for gift cards or payments by email or text.

## The red flags all seven examples share

| Signal | What it looks like | Why it matters |
| --- | --- | --- |
| Where the money goes changes | New bank details, new payee, new escrow agent | Every BEC payout needs an account the criminal controls |
| Urgency | Today, before close, before the weekend | Urgency is how the attacker skips your checks |
| Channel avoidance | Can't talk, in meetings, reply only by email | A phone call to the real person ends the scam |
| Secrecy | Confidential deal, don't involve others | Isolates the target from people who would spot it |
| Authority | CEO, CFO, outside counsel, a key supplier | People hesitate to question senior or important senders |

## How to prevent business email compromise

Email security filters help, and you should have them: DMARC enforcement on your own domain, external-sender banners, alerts for lookalike domains and multi-factor authentication on every mailbox. But a well-made BEC email from a compromised real account will get through, so the controls that matter most sit in the payment process:

1. **Never act on payment instructions received by email alone.** Bank-detail changes, new payees and urgent wires all need an independent confirmation.
2. **Verify with the known person, on a channel you already had.** Use the phone number in your vendor or employee file, not the one in the email signature.
3. **Hold before you pay.** A change is not live until it is verified; the next payment to that payee waits.
4. **Split duties.** Whoever changes bank details or sets up a payee does not approve or release the payment.
5. **Set thresholds.** Payments above an amount you choose need a second approver and a confirmation from the requester.
6. **Train with real examples**, like the seven above, and make it safe to slow down a request from an executive.
7. **Record every verification.** Auditors and cyber insurers increasingly ask to see evidence that the callback happened.

> [!TIP]
> **Start with the written rule**
> If your team has no written callback policy, start with our free [vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy). It takes an afternoon to adapt and closes the gap behind example 1 and example 3.

Manual callbacks work, but they are the step that gets skipped at quarter end or when the request looks like it came from the CFO. RealPayee makes the check automatic: it holds bank-detail changes and high-value payments in your ERP, confirms them with the real contact out-of-band and stores the evidence. [Compare the approaches](https://realpayee.com/compare) or [book a demo](https://realpayee.com/demo).

## Frequently asked questions

### What is an example of business email compromise?

The most common example is a fake vendor email asking accounts payable to update bank details before the next payment. The next payment goes to the criminal's account, and the real vendor is still owed.

### What is another name for business email compromise?

BEC is also called CEO fraud, executive impersonation, whaling (when executives are targeted), vendor email compromise or invoice fraud, depending on who is impersonated.

### How is business email compromise different from phishing?

Phishing usually tries to steal credentials or install malware with a link or attachment. BEC usually contains no malware: it is a plausible request that persuades someone to send money or data.

### Can email security tools stop BEC on their own?

No. Filters catch many spoofed and lookalike domains, but not requests from a compromised real mailbox. You also need a payment-side control: verifying changes with the known person before paying.

### What should we do if we paid a BEC scammer?

Call your bank's fraud line immediately to request a recall, file a complaint at ic3.gov, preserve the emails with headers, and notify your insurer. Speed matters: funds are moved quickly.

## Sources

- [FBI IC3 2025 report: business email compromise losses (McDonald Hopkins summary)](https://www.mcdonaldhopkins.com/insights/news/the-sobering-truth-of-the-fbis-2025-internet-crime-complaint-center-report)
- [Nacha: FBI IC3 finds almost $8.5 billion lost to business email compromise in last three years](https://www.nacha.org/news/fbis-ic3-finds-almost-85-billion-lost-business-email-compromise-last-three-years)
- [AFP: over 75 percent of US firms experienced payments fraud in 2025](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/over-75-percent-of-us-firms-experienced-payments-fraud-in-2025-while-ai-adoption-for-fraud-mitigation-lags)

## Related

- [Deepfake scams: how AI voice and video fraud targets finance](https://realpayee.com/blog/deepfake-scams) - How deepfake scams and AI voice cloning target finance teams, what the Arup and Ferrari cases teach, and a verification protocol your team can run today. (markdown: https://realpayee.com/blog/deepfake-scams.md)
- [ACH fraud: how it works and how to prevent it](https://realpayee.com/blog/ach-fraud-prevention) - The four kinds of ACH fraud that hit businesses, why ACH credits are hard to recover, and a practical prevention checklist for AP and treasury teams. (markdown: https://realpayee.com/blog/ach-fraud-prevention.md)
- [Vendor fraud: types, examples and how to prevent it](https://realpayee.com/vendor-fraud) - What vendor fraud is, the most common schemes (vendor impersonation, fake bank changes, fake invoices) and the controls that stop them. (markdown: https://realpayee.com/vendor-fraud.md)
- [CEO fraud and deepfake executive calls: how finance teams stop them](https://realpayee.com/ceo-fraud) - How CEO fraud works - from spoofed emails to deepfake video calls - and the verification steps that stop fake payment requests. (markdown: https://realpayee.com/ceo-fraud.md)
- [Free vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) - A free, copy-ready vendor bank-detail change and callback verification policy template plus checklist for AP teams. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/blog/business-email-compromise-examples · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
