Most people picture scams targeting individuals — a fake text, a phishing email, a cold call. But one of the costliest categories of fraud specifically targets businesses, often exploiting nothing more sophisticated than a well-timed, convincing email. Business email compromise (BEC), also called payment diversion or invoice fraud, has cost businesses of every size real money, and small businesses without dedicated IT security teams are frequently among the most exposed.
How business email compromise works
The UK’s National Cyber Security Centre (NCSC) describes business email compromise as criminals manipulating email communication to deceive an organisation into sending money or sensitive information to the wrong place. Typically, this starts with a criminal impersonating someone the target regularly corresponds with — a supplier, a client, or even a colleague or senior manager within the same organisation — often using an email address that looks correct at a glance but is subtly altered, or by actually compromising a real account through a separate phishing attack.
From there, the criminal either sends a fake invoice designed to look exactly like a genuine one, sometimes containing malicious software, or — in what’s specifically called mandate or invoice fraud — asks the business to update the bank details on file for a supplier or contact, redirecting future legitimate payments straight into a fraudulent account. Because the email is tailored and the request often looks like a routine, plausible part of normal business communication, it can pass without the scrutiny a more obviously suspicious message would attract.
Why small businesses are particularly exposed
NCSC data shows that 32% of small UK businesses reported experiencing a cyber breach or attack in the past 12 months, and one of the most common techniques behind these incidents involves criminals sending fake emails impersonating the organisation or its regular contacts. Smaller businesses are often specifically targeted because they’re less likely to have dedicated IT security staff, formal payment-verification procedures, or the kind of layered checks larger finance departments build in as standard.
How to protect your business
The NCSC’s core recommendation is to build in a verification step for any request to change payment details or make an unusual payment, no matter how legitimate the request looks in writing. The single most effective habit is a simple one: if a supplier, client or colleague asks you to change bank details or process an unexpected payment, verify it through a separate channel — a phone call to a number you already have on file, not one provided in the email itself — before acting on it. This one step defeats the vast majority of BEC attempts, since it removes the criminal’s control over the verification channel.
Beyond that, the NCSC points businesses toward its wider phishing defence guidance, since BEC very often begins with a phishing email that compromises a genuine account or convincingly spoofs one. Multi-factor authentication on email accounts, staff training to recognise urgency and pressure tactics in payment-related emails, and basic technical protections for cloud email services (which the NCSC notes can meaningfully reduce risk for small organisations) are all part of a reasonable baseline defence.
A simple policy worth adopting
Many organisations that successfully avoid BEC losses do so with one formal, written policy rather than relying on individual staff judgement in the moment: any change to payment details, or any payment above a set threshold, must be verbally confirmed through a previously known contact number before it’s processed, no exceptions, regardless of how much time pressure the request seems to carry. Writing this down and making sure everyone who handles payments knows it exists removes the awkwardness of an individual employee having to decide, under pressure, whether to question what looks like a message from a senior colleague or a long-standing supplier.
What to do if you think you’ve been targeted or paid a fraudulent invoice
Speed matters enormously here. If you’ve made a payment you now suspect was fraudulent, contact your bank immediately — banks can sometimes recall a transfer if it’s caught quickly enough, though the window for this narrows fast. Notify your IT team or provider so they can check whether any account was actually compromised, rather than just impersonated, and change relevant passwords. Report the incident to Action Fraud, which is the UK’s official channel for reporting fraud of this kind, so the case is logged and can be linked to any wider pattern of similar attacks.
The bottom line
Business email compromise doesn’t rely on sophisticated hacking — it relies on a convincing email and the absence of a simple verification habit. Any request to change payment details or make an unexpected payment is worth a phone call to a known, independently sourced number before you act, regardless of how legitimate the email looks. That one habit is the most effective defence available, for businesses of any size.
