Business Email Compromise: The Wire-Fraud Banks Miss

Business email compromise, known as BEC, is a scam where an attacker impersonates a trusted contact, often by email, to trick someone into wiring money or sharing sensitive data. It does not require breaking into your network, which is exactly why it is harder to catch, and for many community banks, more expensive than ransomware.

The FBI’s Internet Crime Complaint Center logged $3.046 billion in reported BEC losses across nearly 25,000 complaints in 2025, up from $2.77 billion the year before. That works out to roughly $123,000 per case on average, and 86 percent of that money moved by wire transfer or ACH, the exact payment rails community banks and credit unions handle every day (FBI IC3 2025 Internet Crime Report, released April 2026).

How a BEC Scam Actually Works

There is no malware to detect in a typical BEC attempt. An attacker researches a real vendor relationship or a specific executive, then sends an email from a look-alike domain or a compromised real account. The request usually asks for a wire transfer, a change to payment instructions, or sensitive account information. It looks routine because the attacker built it to look routine, often mirroring the tone and format of a message that person has actually sent before.

This overlaps with vendor risk in cases where the attacker impersonates a vendor rather than an executive. Our piece on vendor cyber incidents covers what to do when the compromise sits on the vendor’s side rather than in your own inbox.

Why Community Banks and Credit Unions Are a Target

Smaller institutions often route wire transfers through fewer layers of approval than larger banks do. Staff frequently cover several roles at once, so an urgent request from someone who sounds like the CEO or a familiar vendor does not always get the scrutiny it needs. Community banking runs on local, name-recognition-based trust, and that same trust is exactly what a BEC scam is built to exploit.

Attackers also know that community institutions tend to have long-standing relationships with local businesses, contractors, and vendors. A request that references a real project, a real invoice number, or a name your staff genuinely recognizes is far more convincing than a generic phishing attempt, and it is exactly the kind of detail an attacker can gather from a public website, a press release, or a compromised inbox at the vendor’s end.

What a BEC Attempt Can Cost You Beyond the Wire Itself

The wired funds are usually the most visible loss, but they are rarely the only one. Recovering a wire after it has cleared is difficult and time-sensitive, and many institutions never recover the full amount. Beyond the dollar loss, a successful BEC attempt raises hard questions from your board about internal controls, can affect your standing with a business customer who trusted you to catch the fraud, and often triggers additional scrutiny at your next exam. Treating BEC prevention as a routine control, not a one-time reaction to a close call, is what keeps those secondary costs from compounding the financial one.

The Warning Signs Employees Miss

  • A request for urgency or secrecy, such as being told not to loop in anyone else on the request
  • A last-minute change to payment or account details on an otherwise familiar, routine request
  • A reply-to address that is subtly different from the sender’s real address
  • Pressure to skip a normal approval step just this one time, because the request is supposedly too urgent to wait

Controls That Actually Stop BEC

  • Out-of-band verification: confirm any wire change or new payment instruction by phone, using a number you already have on file, never one included in the email itself.
  • Multi-factor authentication on email and financial systems, so a compromised password alone is not enough to get in.
  • A hard rule that no wire or account-detail change proceeds without that callback, regardless of who is asking or how urgent the request sounds.
  • Regular training built around real BEC examples specific to banking, since generic phishing training rarely covers this exact pattern.

Why This Belongs in Your Broader Security Program

Stopping BEC is not a one-time training session. It works best as part of a layered program that includes email authentication protocols such as SPF, DKIM, and DMARC, ongoing account monitoring, and a documented verification procedure that every employee actually follows, not just the ones handling wires directly.

Our Advanced Cybersecurity and Compliance program builds these controls into your existing workflow instead of adding a separate process that gets forgotten within a month. When wire-fraud prevention sits inside your broader security program rather than as a standalone policy, it holds up better under both real attempts and examiner review. Our NCUA IT Requirements guide covers what examiners now expect incident response playbooks to say specifically about BEC, rather than generic language.

What to Do If You Suspect a BEC Attempt

  1. Stop. Do not send the wire or reply to the email until you have verified the request independently.
  2. Contact your bank’s fraud department immediately. If a transfer already went out, request an emergency recall right away.
  3. Preserve the original email and any related correspondence rather than deleting it.
  4. Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and loop in your IT or security partner.

Frequently Asked Questions

What is business email compromise?

BEC is a scam in which an attacker impersonates a trusted person or vendor by email to trick an employee into wiring money, changing payment details, or sharing sensitive information. It relies on social engineering rather than malware.

How is BEC different from phishing?

Phishing typically casts a wide net to harvest credentials or deliver malware. BEC is targeted and research-driven, usually aimed at a specific financial transaction, and often does not involve any malicious link or attachment at all.

What is the single most effective control against BEC?

Out-of-band verification: confirming any payment or account-detail change by phone, using a number you already have on file, before acting on the request.

Can BEC losses be recovered?

Sometimes, if you act within hours and your bank can initiate a wire recall before the funds move again. The odds drop quickly after the first day, which is why verifying before you send is far more reliable than trying to recover afterward.

Get It Touch

Don't hesitate to contact us any time.

Whether you have questions, need support, or are ready to explore new IT solutions, our team is here and eager to help. Reach out to us anytime—we’re just a call or message away!

Let's Work Together

Schedule a discovery meeting with one of our Advanced Cybersecurity Experts to discuss how First Call can help you start YOUR Security Transformation!