Business Email Compromise: Protect Your Small Business
Business email compromise is one of the costliest cyber threats facing small businesses. Learn what BEC is, how it works, and how to stop it in South OC.
Business email compromise — BEC, in security shorthand — is one of the most financially damaging cyber threats targeting small businesses today, and it does not look like most people expect a cyberattack to look. There is usually no malware, no ransomware demand, and no suspicious attachment to scan. It is an email that appears to come from someone you trust, asking you to do something you might normally do. By the time anyone realizes something is wrong, the money is already gone.
We see BEC attempts aimed at South Orange County businesses regularly — from real estate offices in Laguna Niguel receiving fake wire instructions right before a closing to accounting firms in Mission Viejo getting spoofed invoices from vendors they work with every month. Understanding how these attacks work is the first step to stopping them before they cost you anything.
What Is Business Email Compromise?
Business email compromise is a social engineering attack in which a criminal impersonates a trusted contact — your CEO, a vendor, an attorney, or a business partner — and convinces someone in your organization to transfer money, redirect payroll, or share sensitive credentials. Unlike the phishing attacks that try to get you to click a bad link, BEC is built on deception and misplaced trust. The attacker’s goal is to make the request feel routine enough that the recipient acts without questioning it.
The FBI’s Internet Crime Complaint Center tracks BEC as a dedicated category of internet crime and identifies it as one of the most financially damaging online scams affecting American businesses. Their resource page at ic3.gov/CrimeInfo/BEC provides background on the scam and a place to report incidents if your business is targeted.
How Does a BEC Attack Work?
A BEC attack typically unfolds in one of two ways. In the first, the attacker compromises a real email account — usually through stolen credentials from a phishing attempt or a weak password — and then impersonates that person from inside the actual inbox. In the second, they create a lookalike domain or spoof the sender display name so the email appears legitimate at a quick glance.
Once they have a convincing identity, the attacker sends a carefully timed request. Timing is deliberate: before a deadline, during a busy stretch, or while the person being impersonated is traveling and unavailable to confirm by phone. The message almost always includes a reason to move fast and skip the normal process — “handle this before I land,” “do not loop the team in yet,” “I need this today.” The target, often someone in accounting, HR, or office administration, follows what appear to be instructions from a trusted source. The error surfaces later, when the real executive or vendor asks about the payment.
Why Small Businesses Are Common Targets
Small businesses in South Orange County are attractive BEC targets for a few specific reasons. Decision-making is centralized — an email appearing to come from the owner carries real weight with staff. There are fewer formal approval layers, so a wire transfer request can move through without the multiple sign-offs a larger organization would require. And small offices rely heavily on email to move quickly, which is exactly what attackers exploit.
Professional services firms are especially exposed. Law offices and accounting practices routinely process large transfers on behalf of clients. Real estate transactions regularly involve six-figure wire instructions where one redirected payment means a massive loss. Contractors and construction companies manage subcontractor payments and supplier invoices at high volume. Any of these can be targeted with a well-crafted impersonation at exactly the right moment in a transaction.
The Most Common BEC Attack Types
Knowing the playbook helps you recognize it when it shows up in your inbox.
- CEO fraud: An email appearing to come from the owner or a senior manager, asking an employee to wire funds urgently and bypass the usual approval process.
- Vendor impersonation: A spoofed invoice or payment update from a supplier you work with regularly, redirecting payment to an account the attacker controls.
- Payroll redirect: A request that appears to come from an employee, asking HR or payroll to update their direct deposit account to a new one before the next pay cycle.
- Attorney or title company fraud: Particularly common in real estate — a fake message from a title company, escrow officer, or attorney with revised wire instructions arriving right before closing.
- Account compromise: The attacker gets inside a real vendor or partner inbox and sends fraudulent requests from the legitimate account, making them nearly impossible to catch by appearance alone.
How Can You Tell If an Email Is a BEC Attempt?
BEC emails are designed to pass casual scrutiny, but there are patterns worth training your team to recognize.
- The email creates urgency and pushes for unusual speed on a financial action.
- It asks you to skip your normal approval or verification process, often with a reason that sounds plausible.
- The sender address is slightly off — a letter transposed, a dash added, or a domain that looks right but is not the one you normally see.
- Payment details — bank account or routing numbers — differ from what you have on file.
- The message includes a reason not to call or verify by phone before acting.
- The tone feels slightly off from how the person normally communicates.
None of these alone proves a BEC attempt, but any combination should trigger a pause. The right move is always to call the person directly at a number you already have on file — not one provided in the email in question.
What Defenses Actually Stop Business Email Compromise?
Stopping BEC requires a layered approach, because no single control catches everything.
Email authentication is the most important technical defense. Properly configured SPF, DKIM, and DMARC records on your domain make it significantly harder for attackers to send email that appears to come from your address, and they signal to receiving mail servers to reject or quarantine spoofed messages. This is something we configure as part of our cloud, email, and security work.
Multi-factor authentication on every email account is essential. If an attacker cannot log into a compromised account with a stolen password alone, they cannot launch BEC from inside the real inbox. We have covered why MFA matters and how to roll it out across a small business in more detail separately.
A verbal verification policy for wire transfers and account changes is often the single most effective procedural control. Any request to send money, change banking details, or redirect payroll should be confirmed by calling the requester at a number you already have — not one provided in the message asking for the change. This one policy stops a large portion of BEC attempts cold, because attackers rely on victims not making that call.
Security awareness training closes the gap that technical controls cannot fully cover. Staff who understand what BEC looks like — and who feel empowered to pause and verify without fear of embarrassing a manager — are significantly harder to fool. We go deeper on security awareness training for small business teams in a dedicated post.
What to Do If You Suspect a BEC Attack
If you receive a suspicious email or realize an attack may already be in progress, speed is everything. Contact your bank or financial institution immediately — if a transfer has not fully cleared the banking system, there may be a narrow window to recall or freeze it. Change the password on any email account that may have been accessed without authorization and enable multi-factor authentication if it is not already active. Document everything: the email headers, the account numbers involved, and the timeline of events. File a complaint with the FBI’s Internet Crime Complaint Center.
Every hour counts when recovering wired funds. Do not wait to see if something gets sorted on its own.
Building a Setup That Holds Up
The businesses that avoid BEC losses are not the ones that got lucky. They are the ones that built layered defenses before an attack arrived: email authentication configured correctly, MFA on every account, a clear standing policy around financial requests, and employees who know what to look for.
If your email security, account protections, or employee awareness have not been reviewed recently, that gap is worth closing now rather than after a loss. We work with small businesses across South Orange County — Laguna Hills, Mission Viejo, Aliso Viejo, Lake Forest, and the surrounding cities — to build practical security setups that hold up when real attacks arrive. If you want a second set of eyes on your current posture, get in touch through our managed IT and support page and we will start with a straightforward assessment.
- email security
- BEC
- cyber security
- phishing
- small business
Need a hand with this?
Coastal Growth Co. is your local IT department in South Orange County. Need help, or just have a question? Reach out, no pressure.
Let's talk arrow_forward