Technology Advisor Blog



Business Email Compromise: A Tale of Three Businesses

Posted by Ann Westerheim on 8/20/26, 3:55 PM

Imagine three small businesses facing the exact same cyber threat.

An attacker gets access to an employee’s email account. Maybe a password was stolen through phishing. Maybe the attacker found credentials from an earlier breach. However they got in, they now have something incredibly valuable: access to a real business email account.

From there, they can quietly watch.

They can learn who handles invoices. Who approves payments. Which vendors the company works with. How the owner communicates. They may even watch an existing email conversation and wait for exactly the right moment to step in.

This is Business Email Compromise, or BEC. And it’s one of the most financially damaging forms of cybercrime facing businesses today.

According to the FBI’s 2025 Internet Crime Complaint Center (IC3) Annual Report, Business Email Compromise was the second-highest crime type by reported financial losses, behind investment fraud. Businesses and individuals reported approximately $3.05 billion in BEC losses in 2025 from 24,768 complaints.  Read the full FBI report here.

That’s billion with a “B.”

But statistics don’t always make cyber risk feel real.

So let’s look at what happens when the same kind of threat hits three different businesses.

Business #1: The Attack Is Spotted Early

We recently shared a short video about two local businesses that faced similar cybersecurity threats but experienced very different outcomes.  These are real cases from local businesses.  For security reasons, the actual identifying data is redacted, but you can see the key points.

 

In the first business, security systems provided visibility into what was happening.

Something unusual was detected.

There was an alert. There was information to investigate. And there were systems in place paying attention who could take action. - QUICKLY!

That doesn't mean the business was magically immune from cybercrime. No cybersecurity system can promise that.

What it means is that they had a chance to see the warning signs and respond before a security incident became a financial disaster.

NO emails or files accessed, sent, modified, or deleted!

That distinction matters.

Business #2: Same Threat, Very Different Outcome

The second business didn't have the same level of protection and visibility.

And that's where a Business Email Compromise can become particularly dangerous.

Once criminals gain access to a legitimate mailbox, they don't necessarily do something obvious. In fact, doing nothing for a while may be part of the plan.

They can watch.

They can read.

They can learn how the business operates.

Then, when the timing is right, an email that looks completely normal can appear in an existing conversation:

"We've changed banks. Please use these new payment instructions for this invoice."

The employee receiving that message recognizes the vendor. They recognize the conversation. The invoice may even be legitimate.

The only thing that's changed is where the money is going.

And by the time someone realizes what happened, tens or hundreds of thousands of dollars could be gone.

In this case, the user thought they may have clicked on something wrong, and called us soon after so we could run an investigation.  Unfortunately, 214 emails were read, but no emails or files were sent or modified.  Five were deleted, and we could identify them from the logs.

But There's a Third Business We Need to Talk About

This is the business that worries us the most.

Business #3 doesn't know there's a problem at all.

There are no meaningful security alerts being monitored. No one is looking for unusual activity in Microsoft 365. No one is investigating suspicious logins or unexpected changes inside email accounts.  Sadly, this is the typical scenario for most local businesses. 

Everything appears to be working just fine.

Email comes in.

Email goes out.

Employees log in every morning and get their work done.

From the business owner's perspective, everything is fine.  No news is good news, right?

But would they know if someone else were inside their email?

That's the question.

For some businesses, the first cybersecurity "alert" they receive isn't an alert at all.

It's a phone call from a vendor:

"We never received your payment."

Or an employee asking:

"Did you really ask me to change that bank account?"

Or an accounting team discovering that a $50,000 invoice was paid to a criminal instead of a trusted vendor.  Or one of your long term customers is tricked into paying a criminal.  

That's a terrible way to discover that an email account has been compromised.  Beyond the immediate financial loss, there is also loss of trust and reputation.

"We Have Microsoft 365" Isn't the Same as "Someone Is Watching"

This is an important distinction for small businesses.

Having email security features available, such as STRONG passwords and Multifactor Authentication MFA, isn't necessarily the same as having someone actively monitoring and responding to security events.

Think about a burglar alarm.

You can have sensors on every door and window in your building. But if the alarm goes off at 2:00 a.m. and nobody receives the alert, investigates it, or responds, how much protection did the alarm really provide?

Cybersecurity works the same way.

The goal isn't simply to collect more security tools.

The goal is to have the right protections and the visibility to recognize when something isn't right.

Why Business Email Compromise Works So Well

The FBI describes BEC as a sophisticated scam that often involves compromising legitimate business email accounts through social engineering or computer intrusion.

That's what makes it so effective.

The criminal doesn't always need to create an obviously fake email.

If they're actually inside someone's account, they may be able to understand the context of real conversations and use that trust against the business.

That's also why technology alone isn't enough.

Businesses need good technical protections, including multi-factor authentication and appropriate email security. But they also need strong business processes.

If a vendor suddenly asks you to send payments to a different bank account, verify the change using another trusted method of communication.

  • Don't simply reply to the email.

  • Call a phone number you already have on file. Talk to the person you normally work with. Confirm the change before the money moves.

  • A two-minute phone call can prevent a very expensive mistake.

Which of the Three Businesses Are You?

That's the question we'd encourage every small business owner to consider.

If someone gained access to one of your employees' email accounts today, how would you know?

Would someone receive an alert?

Would someone understand what the alert meant?

Would someone investigate?

Would someone take action?

Or would everything continue looking perfectly normal until an invoice was paid to the wrong bank account?

You don't need to become a cybersecurity expert to answer these questions.

But someone needs to be paying attention.

Ekaru Is Here to Help

At Ekaru, we work with small and midsized businesses every day, and we know cybersecurity can feel overwhelming. Our goal isn't to scare people or bury them in technical jargon.

It's to help businesses understand their risks, put practical protections in place, and know that someone is watching when something doesn't look right.

If you're not sure which of these three businesses looks most like yours, that's a great place to start a conversation.

We're happy to talk through what you have today, where there may be gaps, and what practical next steps might make sense for your business.

No scare tactics. No strings attached.

Just a conversation with a local team that wants to help keep your business,  and the people who depend on it,  safe.

 

About the author:

Ann Westerheim, PhD is the Founder and President of Ekaru, a Technology Service Provider of cybersecurity and IT services for small and medium businesses in the greater Boston area. Ann is an accomplished technology innovator and leader with three engineering degrees from MIT. She has twenty years of high tech experience in research, advanced development, product development, and as an entrepreneur. Her career has spanned a vast range of technology endeavors including research in thin film semiconductors and superconductors, microprocessor fabrication, development of early Internet medical applications, and now focusing on the application of technology in business. She has an avid focus on the "last mile" of technology and decreasing the digital divide.

Topics: eMail, cybersecurity, business email compromise

Subscribe by Email





    Browse by Tag

    See all tags...


    Posts by Month

    See all months...


    Connect With Us



    Older Blog Posts

    For older Ekaru blog posts, go to ekaru.blogspot.com.