{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/business-email-compromise-payment-verification-playbook/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/",
        "slug": "business-email-compromise-payment-verification-playbook",
        "url": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/business-email-compromise-payment-verification-playbook/"
        },
        "title": "Stop business email compromise at the payment process",
        "summary": "Business email compromise succeeds when a convincing message can change where money goes. Add independent verification, separation of duties, evidence, and rapid bank-and-IC3 response to the payment process.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-07-28T14:22:00+00:00",
        "modified_at": "2026-07-28T14:22:00+00:00",
        "reviewed_on": "2026-07-28",
        "reading_minutes": 3,
        "word_count": 478,
        "potentially_affected": "Accounts payable, payroll, treasury, executives, purchasing, vendor managers, financial institutions, email accounts, payment platforms, gift-card purchasing, and employees who can change bank details.",
        "dse_recommendation": "Require a second trusted channel for new or changed payment destinations, use established contacts, separate request and approval duties, record verification, and rehearse immediate funds-recovery and mailbox-containment steps.",
        "primary_source": {
            "name": "FBI Internet Crime Complaint Center: Business Email Compromise",
            "url": "https://www.ic3.gov/CrimeInfo/BEC",
            "published_on": null,
            "authority": "www.ic3.gov"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source fact: the message can look authentic</h2>\n<p>The FBI describes business email compromise as a sophisticated fraud that targets organizations and individuals who perform legitimate transfers of funds. Attackers may compromise a real mailbox, imitate a supplier or executive, alter an invoice, request a payroll change, or redirect a closing or purchase payment. Familiar wording and a correct email thread can therefore be part of the fraud, not evidence that the request is safe.</p>\n<p>The FBI Internet Crime Complaint Center&#8217;s <a href=\"https://www.ic3.gov/CrimeInfo/BEC\" target=\"_blank\" rel=\"noopener noreferrer\">business email compromise guidance</a> says to use a secondary channel or two-factor authentication to verify requests that change account information. It also says victims should contact the originating financial institution as soon as fraud is recognized and file a detailed IC3 complaint. Recovery becomes harder as money moves, so the finance and incident-response paths must be able to operate at the same time.</p>\n\n<h2>Move trust out of the email conversation</h2>\n<p>Maintain authoritative vendor, employee, executive, and bank contact records separately from incoming messages. A phone number printed on the changed invoice, supplied in the requesting email, or provided by the caller is not an independent verification channel. Changes to payee name, routing or account number, payment platform, payroll deposit, gift-card request, urgency, confidentiality, or ordinary approval route should trigger verification using a previously established contact.</p>\n<p>Separate who receives a change, who verifies it, who updates the master record, and who releases funds where staffing permits. Configure payment limits and dual approval outside the mailbox. Record the request, trusted contact used, person reached, date, result, approvers, changed fields, and payment reference. Do not approve because a senior person&#8217;s apparent message asks staff to bypass the control.</p>\n\n<h2>DSE recommendation: rehearse the first hour</h2>\n<ol>\n<li>Pause the transaction and related pending payments. Preserve the message, headers, invoice, payment instructions, chat records, call details, and approval history.</li>\n<li>Use a trusted directory or contract record to contact the purported sender and payee. Confirm the request and every changed destination field without replying to the suspect conversation.</li>\n<li>If funds were sent, call the financial institution&#8217;s fraud channel immediately. Request a recall, reversal, freeze, or Financial Fraud Kill Chain action as applicable and capture the case number.</li>\n<li>Report promptly to the Internet Crime Complaint Center with accurate transaction, beneficiary-bank, account, date, amount, and communication details. Coordinate with local law enforcement and counsel as the situation requires.</li>\n<li>Contain affected identities: revoke sessions, reset compromised credentials, review multifactor and recovery methods, mailbox rules, forwarding, delegates, sent and deleted items, OAuth grants, and relevant sign-ins.</li>\n<li>Search for related requests sent to other employees or vendors, notify affected parties through trusted channels, and document funds recovered, data exposed, and remaining risk.</li>\n</ol>\n<p>Exercise the process with finance, payroll, executives, and the help desk at least annually and after banking or workflow changes. Measure verification exceptions, attempts caught before release, time to bank contact, and control bypasses—not only employee training completion.</p>",
        "content_text": "Source fact: the message can look authentic\nThe FBI describes business email compromise as a sophisticated fraud that targets organizations and individuals who perform legitimate transfers of funds. Attackers may compromise a real mailbox, imitate a supplier or executive, alter an invoice, request a payroll change, or redirect a closing or purchase payment. Familiar wording and a correct email thread can therefore be part of the fraud, not evidence that the request is safe.\nThe FBI Internet Crime Complaint Center’s business email compromise guidance says to use a secondary channel or two-factor authentication to verify requests that change account information. It also says victims should contact the originating financial institution as soon as fraud is recognized and file a detailed IC3 complaint. Recovery becomes harder as money moves, so the finance and incident-response paths must be able to operate at the same time.\n\nMove trust out of the email conversation\nMaintain authoritative vendor, employee, executive, and bank contact records separately from incoming messages. A phone number printed on the changed invoice, supplied in the requesting email, or provided by the caller is not an independent verification channel. Changes to payee name, routing or account number, payment platform, payroll deposit, gift-card request, urgency, confidentiality, or ordinary approval route should trigger verification using a previously established contact.\nSeparate who receives a change, who verifies it, who updates the master record, and who releases funds where staffing permits. Configure payment limits and dual approval outside the mailbox. Record the request, trusted contact used, person reached, date, result, approvers, changed fields, and payment reference. Do not approve because a senior person’s apparent message asks staff to bypass the control.\n\nDSE recommendation: rehearse the first hour\n\nPause the transaction and related pending payments. Preserve the message, headers, invoice, payment instructions, chat records, call details, and approval history.\nUse a trusted directory or contract record to contact the purported sender and payee. Confirm the request and every changed destination field without replying to the suspect conversation.\nIf funds were sent, call the financial institution’s fraud channel immediately. Request a recall, reversal, freeze, or Financial Fraud Kill Chain action as applicable and capture the case number.\nReport promptly to the Internet Crime Complaint Center with accurate transaction, beneficiary-bank, account, date, amount, and communication details. Coordinate with local law enforcement and counsel as the situation requires.\nContain affected identities: revoke sessions, reset compromised credentials, review multifactor and recovery methods, mailbox rules, forwarding, delegates, sent and deleted items, OAuth grants, and relevant sign-ins.\nSearch for related requests sent to other employees or vendors, notify affected parties through trusted channels, and document funds recovered, data exposed, and remaining risk.\n\nExercise the process with finance, payroll, executives, and the help desk at least annually and after banking or workflow changes. Measure verification exceptions, attempts caught before release, time to bank contact, and control bypasses—not only employee training completion.",
        "content_markdown": "## Source fact: the message can look authentic\n\nThe FBI describes business email compromise as a sophisticated fraud that targets organizations and individuals who perform legitimate transfers of funds. Attackers may compromise a real mailbox, imitate a supplier or executive, alter an invoice, request a payroll change, or redirect a closing or purchase payment. Familiar wording and a correct email thread can therefore be part of the fraud, not evidence that the request is safe.\n\nThe FBI Internet Crime Complaint Center’s [business email compromise guidance](https://www.ic3.gov/CrimeInfo/BEC) says to use a secondary channel or two-factor authentication to verify requests that change account information. It also says victims should contact the originating financial institution as soon as fraud is recognized and file a detailed IC3 complaint. Recovery becomes harder as money moves, so the finance and incident-response paths must be able to operate at the same time.\n\n## Move trust out of the email conversation\n\nMaintain authoritative vendor, employee, executive, and bank contact records separately from incoming messages. A phone number printed on the changed invoice, supplied in the requesting email, or provided by the caller is not an independent verification channel. Changes to payee name, routing or account number, payment platform, payroll deposit, gift-card request, urgency, confidentiality, or ordinary approval route should trigger verification using a previously established contact.\n\nSeparate who receives a change, who verifies it, who updates the master record, and who releases funds where staffing permits. Configure payment limits and dual approval outside the mailbox. Record the request, trusted contact used, person reached, date, result, approvers, changed fields, and payment reference. Do not approve because a senior person’s apparent message asks staff to bypass the control.\n\n## DSE recommendation: rehearse the first hour\n\n- Pause the transaction and related pending payments. Preserve the message, headers, invoice, payment instructions, chat records, call details, and approval history.\n\n- Use a trusted directory or contract record to contact the purported sender and payee. Confirm the request and every changed destination field without replying to the suspect conversation.\n\n- If funds were sent, call the financial institution’s fraud channel immediately. Request a recall, reversal, freeze, or Financial Fraud Kill Chain action as applicable and capture the case number.\n\n- Report promptly to the Internet Crime Complaint Center with accurate transaction, beneficiary-bank, account, date, amount, and communication details. Coordinate with local law enforcement and counsel as the situation requires.\n\n- Contain affected identities: revoke sessions, reset compromised credentials, review multifactor and recovery methods, mailbox rules, forwarding, delegates, sent and deleted items, OAuth grants, and relevant sign-ins.\n\n- Search for related requests sent to other employees or vendors, notify affected parties through trusted channels, and document funds recovered, data exposed, and remaining risk.\n\nExercise the process with finance, payroll, executives, and the help desk at least annually and after banking or workflow changes. Measure verification exceptions, attempts caught before release, time to bank contact, and control bypasses—not only employee training completion."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo.png"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/",
                "url": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-07-28"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Stop business email compromise at the payment process",
                        "item": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/#article",
                "identifier": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/",
                "url": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/",
                "headline": "Stop business email compromise at the payment process",
                "description": "Business email compromise succeeds when a convincing message can change where money goes. Add independent verification, separation of duties, evidence…",
                "abstract": "Business email compromise succeeds when a convincing message can change where money goes. Add independent verification, separation of duties, evidence, and rapid bank-and-IC3 response to the payment process.",
                "articleBody": "Source fact: the message can look authentic\nThe FBI describes business email compromise as a sophisticated fraud that targets organizations and individuals who perform legitimate transfers of funds. Attackers may compromise a real mailbox, imitate a supplier or executive, alter an invoice, request a payroll change, or redirect a closing or purchase payment. Familiar wording and a correct email thread can therefore be part of the fraud, not evidence that the request is safe.\nThe FBI Internet Crime Complaint Center’s business email compromise guidance says to use a secondary channel or two-factor authentication to verify requests that change account information. It also says victims should contact the originating financial institution as soon as fraud is recognized and file a detailed IC3 complaint. Recovery becomes harder as money moves, so the finance and incident-response paths must be able to operate at the same time.\n\nMove trust out of the email conversation\nMaintain authoritative vendor, employee, executive, and bank contact records separately from incoming messages. A phone number printed on the changed invoice, supplied in the requesting email, or provided by the caller is not an independent verification channel. Changes to payee name, routing or account number, payment platform, payroll deposit, gift-card request, urgency, confidentiality, or ordinary approval route should trigger verification using a previously established contact.\nSeparate who receives a change, who verifies it, who updates the master record, and who releases funds where staffing permits. Configure payment limits and dual approval outside the mailbox. Record the request, trusted contact used, person reached, date, result, approvers, changed fields, and payment reference. Do not approve because a senior person’s apparent message asks staff to bypass the control.\n\nDSE recommendation: rehearse the first hour\n\nPause the transaction and related pending payments. Preserve the message, headers, invoice, payment instructions, chat records, call details, and approval history.\nUse a trusted directory or contract record to contact the purported sender and payee. Confirm the request and every changed destination field without replying to the suspect conversation.\nIf funds were sent, call the financial institution’s fraud channel immediately. Request a recall, reversal, freeze, or Financial Fraud Kill Chain action as applicable and capture the case number.\nReport promptly to the Internet Crime Complaint Center with accurate transaction, beneficiary-bank, account, date, amount, and communication details. Coordinate with local law enforcement and counsel as the situation requires.\nContain affected identities: revoke sessions, reset compromised credentials, review multifactor and recovery methods, mailbox rules, forwarding, delegates, sent and deleted items, OAuth grants, and relevant sign-ins.\nSearch for related requests sent to other employees or vendors, notify affected parties through trusted channels, and document funds recovered, data exposed, and remaining risk.\n\nExercise the process with finance, payroll, executives, and the help desk at least annually and after banking or workflow changes. Measure verification exceptions, attempts caught before release, time to bank contact, and control bypasses—not only employee training completion.",
                "datePublished": "2026-07-28T14:22:00+00:00",
                "dateModified": "2026-07-28T14:22:00+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/business-email-compromise-payment-verification-playbook/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@id": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": "https://update.dsesecurity.com/assets/dse-updates-share.png",
                "articleSection": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Business Continuity",
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 478,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "FBI Internet Crime Complaint Center: Business Email Compromise",
                    "url": "https://www.ic3.gov/CrimeInfo/BEC"
                }
            }
        ]
    }
}