Intelligence Library
Financial Fraud

Business Email Compromise: The Most Expensive Fraud Your Finance Team Has Not Fully Planned For

Business email compromise consistently generates more corporate financial losses than ransomware. The attack does not touch your systems. It targets your people, your processes, and the gaps between them.

Business email compromise is consistently identified by financial crime authorities as the most financially damaging category of cybercrime affecting organisations. The FBI Internet Crime Complaint Center has reported BEC losses exceeding USD $2.7 billion in a single year in the United States alone, and that figure reflects only reported cases. Ransomware, which commands the majority of security budgets and media coverage, produces a fraction of these losses. BEC receives less attention partly because it leaves no ransomware note, no encrypted files, and no visible breach — only a wire transfer to a jurisdiction from which recovery is rarely possible.

BEC works because it does not attempt to compromise systems. It compromises people and processes. The attack surface is human trust, organisational hierarchy, and the pressure on finance and operations staff to execute transactions accurately and quickly. A well-constructed BEC attack is indistinguishable from a legitimate internal instruction, because it is built from real intelligence: genuine names, actual relationships, authentic internal vocabulary, and awareness of live processes. The attacker has done their research. The email reads exactly as the CFO would write it.

The most common variants exploit the same structural gaps: a CFO is impersonated in an instruction to a financial controller for an urgent wire transfer ahead of a sensitive acquisition; a vendor's email account is compromised and payment details on outstanding invoices are silently updated; a CEO's communication style is mimicked in a request for gift card purchases for a client. In each case the attack combines the appearance of legitimate authority with a framing of urgency that makes verification feel unnecessary and potentially embarrassing. The employee who pauses to verify appears to be questioning their senior's judgment.

The financial exposure is compounded by the near-zero recovery rate. Wire transfers executed to foreign jurisdictions are rarely recoverable once the funds have moved. Gift card purchases are irreversible. The window between execution and detection is typically measured in hours. Every BEC case Custodia One has reviewed in a post-incident capacity had a process gap that was either known or discoverable before the fraud occurred. The gap was not a technical failure. It was a procedural one.

Effective defence is procedural rather than technical. It requires: mandatory dual-authorisation for transfers above defined thresholds; out-of-band verification as standard for any change to payment details, regardless of how the request arrives; a culture in which finance staff are explicitly empowered and expected to challenge and verify, including requests from senior leadership; and regular simulation exercises that test whether those processes hold under realistic pressure and urgency.

"BEC does not hack your system. It hacks your process. Every organisation that has lost money to BEC had a procedural gap that a single phone call to a known number would have closed."

Custodia One Advisory Perspective

What Your Organisation Should Do

  • Implement mandatory out-of-band verification for all changes to payment details — a call to a number already on file, not a number provided in the instruction

  • Establish and enforce dual-authorisation thresholds with no exceptions for urgency or seniority

  • Explicitly empower finance and operations staff to challenge and delay any payment instruction that has not been verified — organisations where this is culturally difficult have structurally elevated BEC exposure

  • Run BEC simulation exercises that test procedural compliance under realistic urgency and authority pressure, not just phishing awareness

Advisory Enquiries

Facing this issue in your organisation?

Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.