DLC Tech Solutions - IT Support for Small Business
    Back to Blog

    Business Email Compromise: The Scam Costing UK Businesses Millions and How It Works

    BEC is quiet, patient, and devastatingly effective. Here is how it works, the red flags to watch for, and the two or three process changes that stop it in its tracks.

    10 May 20269 min read

    It does not come with a skull and crossbones. There is no ransom demand, no system shutdown, no dramatic moment where something obviously goes wrong. Business email compromise, BEC, is quiet, patient, and devastatingly effective.

    It is also one of the fastest growing cybercrime categories in the UK, and it disproportionately hits small and medium businesses.

    What Is It, Exactly?

    Business email compromise is fraud that uses email, either a real hacked account or a convincingly spoofed one, to trick someone into transferring money or sharing sensitive information.

    The classic scenario: an attacker gains access to, or convincingly impersonates, a senior person in your business or a supplier. They send an email to your finance team, or directly to you, requesting an urgent bank transfer. The email looks right. The language feels right. The urgency feels plausible. And the money leaves your account.

    There are variations:

    • Invoice fraud: attackers intercept or fake invoices and change the bank account details
    • Payroll fraud: they redirect salary payments to accounts they control
    • Supplier impersonation: they pose as a known supplier and request a payment method change

    Why It Works

    BEC succeeds because it exploits trust and urgency rather than technical vulnerabilities. The emails are often well crafted, personalised, contextually appropriate, and timed to catch people off guard.

    An attacker who has had access to a compromised email account for weeks will know who the MD is, who handles payments, what tone the business uses, and what projects are currently in flight. They will wait for the right moment, then they will move.

    The social engineering is the attack. The email just delivers it.

    Real World Red Flags

    • Urgency. "This needs to happen today", "don't mention this to anyone else". Always pause.
    • Changed bank details. Any request to change payment details should be verified over the phone, using a number you already have on file. Not the number in the email.
    • Slight email oddities. Look carefully at the actual sender address, not just the display name. Attackers use domains like company-name.co.uk (note the hyphen) or companyname.net.
    • Pressure to bypass process. Legitimate urgent requests rarely require you to skip your normal approvals.

    What Actually Prevents It

    • Dual authorisation for payments above a threshold. Two people approve, using two different channels. This alone kills most BEC attempts.
    • A clear policy: any change to supplier bank details requires a phone verification call, using a number from your existing records. Not email, not WhatsApp, a call.
    • Staff training that makes these scenarios feel familiar. Pausing and checking should be the expected behaviour, not an insult to the requester.
    • MFA on email. If attackers can't get into your email, they can't impersonate you from within it.

    If It Happens to You

    Contact your bank immediately if a transfer has gone. Banks have fraud teams, and if you move fast there is sometimes a possibility of recovering funds. Do not wait. Do not try to handle it quietly. Call.

    Then report it to Action Fraud. BEC is a crime, and reporting it contributes to the intelligence picture that helps tackle it.

    We have helped businesses navigate the aftermath of BEC fraud. The financial loss is bad enough. The erosion of trust between staff, and between a business and its suppliers, is often harder to recover from. Prevention is considerably cheaper.

    If you would like help reviewing your payment processes and email security, get in touch.

    Stay informed

    Get expert cyber security insights delivered to your inbox.

    Stay Updated

    Subscribe to receive the latest insights on cyber security, compliance, and data protection.