Business Email Compromise Anatomy and SMB Prevention
Low-frequency phishing attacks that bypass tech defenses cost SMBs disproportionately.

Business email compromise doesn't rely on malware, exploits, or anything a firewall would catch. It relies on a well-timed email landing in front of someone with the authority to move money, and that's what makes it so hard to stop with technology alone.
Why BEC costs so much while staying so rare
That's a real jump, but the ratio is the number that actually explains why this crime deserves attention, not the total. That ratio is the number that explains why this crime deserves attention.
Microsoft's Digital Defense Report found BEC makes up just 2% of observed threats, yet it drives 21% of attack outcomes Microsoft Digital Defense Report 2025. Low frequency, wildly disproportionate damage.
FRSecure's analysis of 162 incident response cases in the SMB market over a two-year period found that token theft attacks accounted for 62% of BEC root causes and no MFA accounted for 12%, together representing nearly three-quarters of observed compromise Microsoft Digital Defense Report 2025 spacelift.io. A long tail of real estate closings and large vendor wires drags the mean upward, while the typical incident is smaller and far more common than the headline number suggests FBI IC3 2025 Annual Report xtendedview.com.
That 2%-to-21% split is the whole thesis in miniature Microsoft Digital Defense Report 2025. This is a trust problem you can't solve by filtering more spam. It's a trust problem, and trust doesn't get caught by a spam filter Microsoft Digital Defense Report 2025. BEC accounts for 2.5% of cybercrime complaints yet nearly 15% of all cybercrime losses, a case of low frequency producing outsized financial destruction cnicsolutions.com.
Why SMBs absorb the worst of these losses
Small and mid-sized businesses account for 28% of BEC victims overall, and in professional services specifically, 33% of breaches involved BEC, at an average cost of $50,000 per event Verizon Data Breach Investigations Report chargebacks911.com xtendedview.com. For a firm running on thin margins, that's not a rounding error on the balance sheet.
It can be the whole balance sheet. Coalition's Cyber Claims Report found that 60% of small businesses hit by a severe cyberattack close within six months Coalition 2025 Cyber Claims Report xtendedview.com. A single BEC event isn't an inconvenience to absorb and move past Microsoft Digital Defense Report 2025. For a lot of these companies, it's an extinction event Coalition 2025 Cyber Claims Report xtendedview.com.
Abnormal AI's 2026 Attack Landscape Report, built on nearly 800,000 email attacks observed in the second half of 2025, found that VIP impersonation drops from 43% down to 7% of named-identity BEC as company size grows. At a large enterprise, an attacker impersonating the CEO has to get past a chief of staff, an executive assistant, a finance director who's seen this trick before. At an SMB, there's often no one in between Microsoft Digital Defense Report 2025 spacelift.io. The email goes straight from "impersonated founder" to "person who can wire money," with nobody positioned to be skeptical.
None of this is a failure of will. SMBs account for 28% of BEC victims; for professional-services SMBs, 33% of breaches involved BEC at a $50,000 average cost per event Verizon Data Breach Investigations Report chargebacks911.com xtendedview.com. And those structural gaps aren't scattered at random. The structural vulnerabilities just described are not random, they map directly onto the stages of the BEC attack chain covered next.
Stage 1, Reconnaissance: what attackers learn before sending a single email
Before an attacker sends anything, they build a dossier. This runs entirely on open-source intelligence: LinkedIn profiles, earnings call transcripts, org charts, social posts. Nothing here requires breaking in anywhere. It's all public, or cheap enough to buy.
The goal is simple. Find out who approves wires, who runs payroll, which vendors get paid on a recurring schedule, and when the next big invoice is due. No malware touches a single machine at this point, because none is needed. Every piece of this dossier is sitting out in the open already.
Thin org charts make this stage fast at SMBs. A single LinkedIn search can surface the founder's name, the finance contact's name, and the company's top vendors, all in one sitting. That job posting mentioning your invoicing software by name? That press release naming your payment terms? Both are now part of somebody's toolkit. What gets posted publicly by employees, titles, tools, workflows, becomes raw material for the next stage.
Stage 2, Getting inside the mailbox: credential theft, phishing, and account takeover
Getting into the mailbox usually comes down to credential harvesting, phishing, password spraying, session hijacking, or simply buying stolen credentials off a dark web marketplace. BEC, in the majority of documented cases, follows a successful account takeover rather than a spoofed lookalike domain.
FRSecure's analysis of 162 incident response cases in the SMB market over a two-year period found token theft accounted for 62% of BEC root causes, with no MFA at all responsible for another 12% Microsoft Digital Defense Report 2025 spacelift.io. Together, those two vectors explain nearly three-quarters of the compromises FRSecure looked at Microsoft Digital Defense Report 2025 spacelift.io.
Token theft deserves a second look, because it's the one that catches people off guard. It doesn't steal a password. It steals the session token generated after a user has already logged in and passed MFA. The attacker inherits an authenticated session outright, so MFA never even gets a chance to fire. FRSecure also flagged legacy protocols (2%) and vulnerability exploits (3%) as entry points Microsoft Digital Defense Report 2025. The surface here is wider than phishing alone Microsoft Digital Defense Report 2025. MFA is necessary, but it's not sufficient on its own if the implementation is one that token theft can slip past. How it's configured matters just as much as whether it exists at all.
Stage 3, Living inside the mailbox: inbox rules, silence, and patience
Getting into the mailbox is rarely followed by immediate action. Attackers wait, and they watch.
Invictus IR's case analysis lays this out in detail FBI IC3 2025 Annual Report xtendedview.com. After gaining access, the threat actor read through emails and studied the environment over an extended stretch of time, specifically watching for invoices coming due from suppliers. Once the moment was close, they set up a malicious inbox rule that routed replies to a specific message, and eventually all incoming mail, into the RSS feed folder, a place nobody checks. The victim never saw the replies that would have exposed the fraud, because the attacker had quietly muted them.
Microsoft's 2025 threat reporting ties BEC directly to this kind of inbox-rule manipulation, along with thread hijacking, unauthorized SharePoint access, and MFA tampering. One documented Microsoft campaign involved roughly 17,000 multitenant OAuth applications and more than 927,000 phishing emails, all while inbox rules kept the activity hidden from view.
The attacker's patience, sustained over months, is easy to underestimate. In the Invictus case, the attacker studied communications for months, mimicked the real writing style of the people involved, referenced actual ongoing projects, and waited specifically for a high-value payment to come due. Most SMBs go blind at this exact point. There's usually no visibility into inbox rule changes, no monitoring of OAuth grants, no review of SharePoint access logs. The attacker stays invisible right up until the wire goes out the door.
Stage 4, The payment redirect: how the fraud is executed
Foley Hoag's fictionalized scenario captures the moment with uncomfortable precision. An attacker who's been monitoring communications for four months intercepts a $2.4 million payment, sending updated wire instructions to the buyer three days before it's due. The email comes from what looks like the seller's controller, from a familiar address, referencing a transaction that's real and genuinely expected.
The FBI recognizes five subtypes of this same basic move: CEO fraud, where an executive's identity is used against a subordinate; attorney or legal impersonation; W-2 and data theft; false invoice schemes; and straight account compromise. Different costumes, same core mechanic.
AFP's Payments Fraud and Control Survey found wire transfers are the payment method BEC targets most, at 63%, with vendor imposter fraud at 45% and invoice fraud at 24%. Once the money's gone, getting it back is a long shot. Only 22% of victims recovered 75% or more of what they lost Microsoft Digital Defense Report 2025. The FBI's Financial Fraud Kill Chain data recorded 3,900 incidents in 2025 involving $1.164 billion in attempted theft, with a 58% recovery success rate, and that rate depends entirely on how fast the victim calls their bank FBI IC3 2025 Annual Report. Speed is the only lever left to pull at this stage.
The uncomfortable truth in the Foley Hoag scenario is that the clerk who processed the payment didn't break any rule that existed. There was no process in place to verify a change in payment instructions through a separate channel, so nothing caught it.
How AI has changed the economics of running these attacks at scale
Generative AI has stripped out the friction that used to cap how many of these attacks a single actor could run. Research, language polish, personalization, all of it used to eat hours per target. Now the same tools produce dozens of personalized, grammatically clean, contextually accurate messages in minutes.
The open rates make the shift concrete. AI-generated phishing emails see open rates between 54% and 78%, compared to roughly 12% for the traditionally handcrafted version Microsoft Digital Defense Report 2025 spacelift.io. And they're cheaper to make, too: 95% less costly to produce and 40% faster to turn around spacelift.io. The skill floor that used to separate a competent attacker from an amateur has basically disappeared.
Small businesses are feeling this directly. AI-powered cyberattacks against small businesses rose 340% in 2025, and 41% of all cyberattack incidents against small businesses that year were attributed to AI-driven methods spacelift.io. The frontier keeps moving, too. The largest documented deepfake CFO scam in 2024 pulled $25 million through a fabricated video call CrowdStrike. The old advice, look for typos, watch for stilted phrasing, doesn't hold anymore. That filter is gone. According to IBM's Cost of a Data Breach Report, 16% of all data breaches in 2025 involved attackers using AI, and 37% of those attacks involved AI-generated phishing or other communications FBI IC3 2025 Annual Report IBM Cost of a Data Breach Report 2025 spacelift.io.
The controls that interrupt the chain (mapped to the stages where they work)
Each stage above has a control that closes it off, and they map directly onto the anatomy just described rather than sitting apart from it as a generic checklist.
Against reconnaissance, the fix is reducing what's visible from the start. Audit what roles, reporting lines, and payment processes show up publicly on the company website, in job postings, on LinkedIn, and stop naming accounts-payable staff and their titles where anyone can find them.
Against initial access, MFA still matters, but only the right kind Microsoft Digital Defense Report 2025 spacelift.io. Since FRSecure's data shows token theft driving 62% of root causes, phishing-resistant MFA, hardware keys or passkeys, holds up materially better than SMS codes or app push notifications Microsoft Digital Defense Report 2025. Conditional access policies that restrict which devices and applications are allowed to authenticate close the gap further. Email authentication, DMARC, DKIM, and SPF, blocks spoofed versions of your own domain from ever reaching an inbox, which is the control that stops display-name fraud before it starts.
Against mailbox persistence, the fix is visibility that most SMBs have simply never switched on: regular audits of inbox rules, monitoring for unexpected OAuth grants, reviews of SharePoint and delegated access, alerts the moment a new rule gets created.
Against the payment redirect itself, confirming any change to banking or payment instructions by phone, to a number already on file, blocks the redirect more effectively than any other control. Any change to banking or payment instructions gets confirmed by phone, to a number already on file, never to a number sitting in the email that's requesting the change. Dual approval above a set dollar threshold backs this up, along with a written policy that no payment change goes through without two-factor human confirmation.
Security awareness training must evolve past looking for grammar errors and simulate BEC scenarios. FRSecure's data shows that 45% of cases resulted in no further action, because in all of those cases the compromised account was quickly discovered. Speed of discovery is its own control. None of these, on their own, closes every door. The attacker only needs one stage to work, so the defense has to interrupt more than one, independently.
What an integrated platform does that a checklist cannot
Look at that list of controls again: device management, identity configuration, email authentication, inbox monitoring, policy enforcement. For an SMB without a dedicated security team, each item there is its own tool, its own vendor, its own person responsible for keeping it current.
The Stage 3 visibility gap, inbox rules, OAuth grants, delegated access, almost never gets closed by point solutions, because nobody's actually watching those logs day to day. An integrated platform surfaces that activity without needing a dedicated analyst behind it. Identity protection paired with device management shuts down the token-theft vector specifically: a managed, known device running phishing-resistant MFA and conditional access doesn't hand an attacker an authenticated session to walk away with. Compliance automation keeps the DMARC, DKIM, and SPF stack configured correctly over time, and misconfiguration is the single most common reason that stack fails when it's needed.
That timeline matters because it means the controls are live before the next attack occurs, not after a long consulting engagement wraps. The goal was to have controls running in the background that don't require a founder to become a security expert. It's to have controls running in the background that don't require one. The platform approach described here (device management, endpoint security, identity protection, and compliance automation in one place) is what a platform like Zip is built to deliver for SMBs running without a dedicated security team, and deployment in two weeks rather than two months means the controls are live before the next attack arrives, not after a long professional-services engagement.
The first 24 hours after a suspected BEC
None of what follows is an incident response playbook written for trained responders. It's the action list for a founder or operations lead who just spotted a wire that looks wrong.
Call the bank first, immediately, before doing anything else. FBI Financial Fraud Kill Chain data shows recovery hinges entirely on how fast a funds-recall request reaches the receiving bank, and that 58% recovery rate from 2025 is only reachable with near-immediate notification. Don't touch the suspicious emails beyond that. Don't delete them, don't forward them around the office. Preserve them as evidence for law enforcement and for whatever legal process follows.
File a complaint with the FBI's IC3 at ic3.gov FBI IC3 2025 Annual Report. The Financial Fraud Kill Chain only activates through an IC3 report, and a lot of SMBs skip this step entirely, cutting off their own shot at recovery before it starts. Revoke every active session tied to the compromised account, check for any inbox rules created after the suspected date of access and delete them, and audit OAuth grants for anything that shouldn't be there. If cyber insurance coverage exists, notify the carrier, and check breach notification obligations given what data sat exposed during the dwell period.
Foley Hoag's 2026 legal analysis adds a piece that companies need to know ahead of time, not after. BEC lawsuits are fact-intensive, and courts tend to apply either an "imposter rule," asking who was best positioned to prevent the loss, or a straightforward breach-of-contract analysis. What controls existed at the time of the incident shapes how liability gets divided up. Having them in place beforehand is the legal defense, built in advance, for the day prevention doesn't fully work. It's the legal defense, built in advance, for the day prevention doesn't fully work.
Sources
- Business Email Compromise Statistics 2026: BEC Fraud & Wire Scams
- Significant Business Email Compromise Payloads: 2025 State of InfoSec Series | FRSecure
- Business Email Compromises: Current Legal Trends and Key Strategies
- Business Email Compromise: Stats & Financial Impact for 2026
- cnicsolutions.com
- abnormal.ai
- app.stationx.net
- paubox.com


