Stop business email compromise at the payment process

Business email compromise succeeds when a convincing message can change where money goes. Add independent verification, separation of duties, evidence, and rapid bank-and-IC3 response to the payment process.

Executive summary

What you need to know

Business email compromise succeeds when a convincing message can change where money goes. Add independent verification, separation of duties, evidence, and rapid bank-and-IC3 response to the payment process.

Potentially affected

Accounts payable, payroll, treasury, executives, purchasing, vendor managers, financial institutions, email accounts, payment platforms, gift-card purchasing, and employees who can change bank details.

DSE recommendation

Require a second trusted channel for new or changed payment destinations, use established contacts, separate request and approval duties, record verification, and rehearse immediate funds-recovery and mailbox-containment steps.

Source fact: the message can look authentic

The FBI describes business email compromise as a sophisticated fraud that targets organizations and individuals who perform legitimate transfers of funds. Attackers may compromise a real mailbox, imitate a supplier or executive, alter an invoice, request a payroll change, or redirect a closing or purchase payment. Familiar wording and a correct email thread can therefore be part of the fraud, not evidence that the request is safe.

The FBI Internet Crime Complaint Center’s business email compromise guidance says to use a secondary channel or two-factor authentication to verify requests that change account information. It also says victims should contact the originating financial institution as soon as fraud is recognized and file a detailed IC3 complaint. Recovery becomes harder as money moves, so the finance and incident-response paths must be able to operate at the same time.

Move trust out of the email conversation

Maintain authoritative vendor, employee, executive, and bank contact records separately from incoming messages. A phone number printed on the changed invoice, supplied in the requesting email, or provided by the caller is not an independent verification channel. Changes to payee name, routing or account number, payment platform, payroll deposit, gift-card request, urgency, confidentiality, or ordinary approval route should trigger verification using a previously established contact.

Separate who receives a change, who verifies it, who updates the master record, and who releases funds where staffing permits. Configure payment limits and dual approval outside the mailbox. Record the request, trusted contact used, person reached, date, result, approvers, changed fields, and payment reference. Do not approve because a senior person’s apparent message asks staff to bypass the control.

DSE recommendation: rehearse the first hour

  1. Pause the transaction and related pending payments. Preserve the message, headers, invoice, payment instructions, chat records, call details, and approval history.
  2. Use a trusted directory or contract record to contact the purported sender and payee. Confirm the request and every changed destination field without replying to the suspect conversation.
  3. If funds were sent, call the financial institution’s fraud channel immediately. Request a recall, reversal, freeze, or Financial Fraud Kill Chain action as applicable and capture the case number.
  4. Report promptly to the Internet Crime Complaint Center with accurate transaction, beneficiary-bank, account, date, amount, and communication details. Coordinate with local law enforcement and counsel as the situation requires.
  5. Contain affected identities: revoke sessions, reset compromised credentials, review multifactor and recovery methods, mailbox rules, forwarding, delegates, sent and deleted items, OAuth grants, and relevant sign-ins.
  6. Search for related requests sent to other employees or vendors, notify affected parties through trusted channels, and document funds recovered, data exposed, and remaining risk.

Exercise the process with finance, payroll, executives, and the help desk at least annually and after banking or workflow changes. Measure verification exceptions, attempts caught before release, time to bank contact, and control bypasses—not only employee training completion.

Primary reference

Review the official source

FBI Internet Crime Complaint Center: Business Email Compromise · Verified July 28, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE