Cyber security
Business email compromise: verify the payment, not the email
11 August 2026 · 7 min read · 3 public sources

Business email compromise is the fraud that does not look like an attack. There is no malware to find and often no system to rebuild. Someone receives an instruction that appears to come from a supplier, an executive, or a colleague, and acts on it. The FBI’s Internet Crime Complaint Center recorded $3,046,598,558 in verified BEC losses during 2025, from 24,768 complaints — an average well above $100,000 per reported incident, and second only to investment fraud in its dataset.
Reporting is not recovery
The Uganda Police Force’s Annual Crime Report 2025 recorded 412 cybercrime cases, down 13.1% from 474 in 2024. Of those, 101 were taken to court and 26 secured convictions, while 247 remained under inquiry at the time of reporting. Read that as an operating constraint rather than a criticism: a case that reaches court is slow, and by then the transfer has usually cleared. Prevention and the first hour after a suspected transfer are where the money is actually saved.
Make the payment path the control point
BEC succeeds at the point where finance acts on instructions received by email. That is where the procedure has to sit, and it has to apply to everyone, including whoever appears to be asking urgently.
- Treat any change to supplier bank details as a request to be verified, never as an update to be applied.
- Call back on the number already held in the supplier record — not a number in the email, its signature, or the attached invoice.
- Require a second authoriser above a defined value, and for every first payment to a new account.
- Match invoices to purchase orders and delivery records before release, so an unexpected invoice has to explain itself.
- Give staff an explicit mandate to delay a payment for verification without needing to justify the delay to the requester.
Take the credential out of reach
Most BEC begins with access to a real mailbox, which is what makes the message convincing. Phishing and spoofing produced 191,561 complaints in the same IC3 dataset — the largest complaint count of any category. CISA’s guidance is direct about the remedy: FIDO and WebAuthn credentials, including passkeys and hardware security keys, are the widely available forms of multi-factor authentication that resist phishing, because the credential is bound to the real domain and will not release on a lookalike site.
- Move administrators, finance, and anyone who can approve payments to phishing-resistant authentication first.
- Where push-based MFA must remain for now, enable number matching as the interim mitigation CISA recommends, and plan the migration.
- Disable legacy authentication protocols that bypass MFA entirely.
- Alert on new mailbox forwarding and inbox rules — hiding replies from the real supplier is how the fraud stays quiet.
- Publish and enforce SPF, DKIM, and DMARC so your own domain is harder to impersonate.
Rehearse the first hour
Speed decides recovery. The bank should be contacted immediately to request a recall while funds may still be held, the receiving institution notified, and the original message preserved with full headers rather than forwarded and deleted. Decide now who makes that call outside working hours, and confirm your bank’s escalation contact before you need it.
None of this depends on new technology. It depends on a written payment procedure that survives urgency, authentication that cannot be handed to a convincing website, and a rehearsed response for the hour when the transfer has already left.
Sources and further reading
This article summarizes publicly available research. Source findings retain their original geographic and sector scope.
- [01]2025 IC3 Annual ReportFBI Internet Crime Complaint Center · 2025
- [02]Annual Crime Report 2025Uganda Police Force · 2025
- [03]Implementing Phishing-Resistant MFACISA · 2022
Put this thinking to work
Tell us about your estate and we’ll map what to build, secure, or fix first.
Keep reading
More insights

Infrastructure
AI’s electricity bill, and why power now decides where compute goes
10 August 2026 · 8 min read

Infrastructure
When the cable breaks: designing for connectivity that will fail
6 August 2026 · 7 min read
