Business email compromise

Also called: BEC · CEO fraud · payment redirection · invoice fraud · mandate fraud · email account compromise

Business email compromise redirects a legitimate payment by impersonating an executive, a supplier or a lawyer, usually from inside a mailbox the attacker has already compromised. There is often no malware and nothing obviously wrong with the message — only the bank details are changed. The FBI has recorded $55.5 billion in global exposed losses over a decade.

Key facts

Category
Business & payments
First documented
2013
Typical loss
$25k–$1500k USD, per victim
Main channels
email, lookalike domain, compromised mailbox, phone call, SMS, WhatsApp
Who is targeted
Finance and accounts-payable staff at organisations of any size; Small businesses without a second-approver rule — the median victim is not a large corporation; Conveyancers, law firms and estate agents holding client funds at completion; Charities, schools, churches and local government bodies with lean finance teams; Individuals in the middle of a property purchase
Documented origins
Nigeria, Ghana, South Africa, United Kingdom, United States, Romania
Main targets
United States, United Kingdom, Canada, Australia, Germany, Netherlands, Singapore, Ireland, New Zealand
Case files
10 documented cases
Last reviewed
2026-09-06
Anatomy of a business email compromiseAnatomy of a business email compromise. No malware, no bad grammar. Someone reads a real payment conversation and joins it at the right moment. 1. Reconnaissance: Who signs off payments, who the suppliers are, when invoices fall due. 2. A mailbox is taken: Credential phishing or password reuse. Often the supplier's, not yours. 3. Quiet reading: Rules hide replies. The attacker learns tone, approvals and payment cycles. 4. The real thread is joined: A genuine invoice conversation gets a revised invoice, or a lookalike domain replies. 5. Urgency arrives: A closing deadline, a chief executive travelling, a supplier threatening to halt work. 6. The payment goes out: Correctly authorised, to the wrong account. Nothing in the system flags it. 7. Discovery, days later: The real supplier chases the unpaid invoice. By then the money has moved on. The diagram marks stage 4 as the point where the scheme can still be stopped: A change of bank details is the whole scam, whatever the reason given. Confirm every change of payment details by calling a number you already had for that supplier — never a number in the email, and never by replying to the thread, which the attacker may be reading.Anatomy of a business email compromiseNo malware, no bad grammar. Someone reads a real payment conversation and joins it at the right moment.1ReconnaissanceWho signs off payments, whothe suppliers are, wheninvoices fall due.Weeks2A mailbox is takenCredential phishing orpassword reuse. Often thesupplier's, not yours.One login3Quiet readingRules hide replies. Theattacker learns tone,approvals and paymentcycles.Days to months4The real thread isjoinedA genuine invoiceconversation gets a revisedinvoice, or a lookalikedomain replies.One email5Urgency arrivesA closing deadline, a chiefexecutive travelling, asupplier threatening tohalt work.Hours6The payment goes outCorrectly authorised, tothe wrong account. Nothingin the system flags it.Minutes7Discovery, days laterThe real supplier chasesthe unpaid invoice. By thenthe money has moved on.Days to weeksWhere it can still be stopped — stage 4A change of bank details is the whole scam, whatever the reason given. Confirm every change of payment details by calling a number you already had for thatsupplier — never a number in the email, and never by replying to the thread, which the attacker may be reading.Stages documented in FBI IC3 business email compromise advisories, 2023 to 2024, and in US Department of Justice prosecutions.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

Business email compromise is the theft of a payment that was going to happen anyway.

Nobody is tricked into buying something imaginary. An organisation owes money to a supplier, or is completing a property purchase, or is paying a contractor. All of that is real. The only thing the attacker changes is where the money goes — and they change it from inside the conversation in which the payment was already being arranged.

That is what makes it so hard to catch at the message level. The classic mental model of a scam email — odd grammar, a strange address, an attachment you were not expecting — describes a different crime. In its most damaging form, BEC involves no malware and no forged branding. Someone has read a genuine thread from inside a genuine mailbox, learned the tone and the timing, and sent a revised invoice at the moment it was expected.

The scale is difficult to overstate. Across complaints filed between October 2013 and December 2023, the FBI recorded $55.5 billion in global exposed losses, including 158,436 US victims and $20.1 billion in US exposed loss. In 2025 alone, IC3 recorded $3.05 billion from 24,768 complaints — fewer complaints than almost any consumer scam category, and the second-largest loss total of all of them.

How it actually works

  1. Reconnaissance

    Who approves payments, who the suppliers are, when invoices fall due, who is travelling. Most of this is public: company filings, a website’s team page, LinkedIn, an out-of-office reply.

  2. A mailbox is taken

    Credential phishing or a reused password, occasionally a stolen session token that walks past multi-factor authentication. Critically, it is often not your mailbox — it is a supplier’s, a conveyancer’s, or a smaller partner’s.

  3. Quiet reading

    The attacker does nothing for days or months. Inbox rules divert replies so the real owner never sees the thread. This is where the tone, the approval chain and the payment cycle are learned, and it is why the eventual email reads correctly.

  4. The real conversation is joined

    A genuine invoice thread receives a revised invoice with different bank details. Or a reply arrives from a lookalike domain — one character different, or a different top-level domain — that continues the thread as though nothing changed.

    Where it could have stopped

    The change of bank details is the scam, whatever explanation accompanies it. Confirm every change of payment details by calling a number you already had for that supplier — never a number in the email, and never by replying to the thread, which the attacker may be reading.

  5. Urgency, applied to the right person

    A completion deadline. An executive travelling and unreachable. A supplier threatening to stop work. The pressure is designed to remove the step where somebody would have checked.

  6. The payment goes out

    Correctly authorised, through the normal process, by someone doing their job properly. No control fires, because from the system’s point of view nothing anomalous happened.

  7. Discovery, days or weeks later

    The real supplier chases an unpaid invoice. By then the money has usually left the receiving account. IC3 records BEC funds increasingly going straight to custodial accounts at payment processors and crypto exchanges, which is precisely where a recall stops being possible.

Why it works

It exploits a correct process, not a mistake. Someone whose job is to pay invoices paid an invoice. There is no moment of carelessness to point at, which is one reason victims of BEC are so often blamed unfairly and so rarely willing to discuss it.

The trust is pre-existing. The supplier is real, the project is real, the amount is right, the thread has your own earlier messages in it. Everything checks out except the eleven digits nobody verifies.

Authority is applied where it is hardest to refuse. In the CEO-fraud variant the request comes from someone whose emails are not usually questioned, and questioning it has a social cost inside an organisation. That cost is the attack surface.

Urgency arrives at a real deadline. BEC does not have to invent time pressure. Completions, month end and payment terms supply it, and the attacker only has to arrive at the right moment — which reading the mailbox tells them.

Small organisations have no second person. The single control that reliably stops this is another human confirming the change on a different channel. Charities, schools, small contractors and conveyancers are over-represented in enforcement records because that person does not exist.

And detection is aimed at the wrong layer. Email security is built to find bad messages. This is a good message with wrong bank details, sent by an account that is entitled to send it.

Where it comes from

The enforcement record on BEC is unusually rich, because unlike compound-based fraud, the money side of it touches the US and European banking systems directly, and that is where prosecutions start.

Documented networks have repeatedly involved West African organised crime, particularly Nigerian groups operating both from Nigeria and from diaspora communities in the United States, Canada and Europe. That is not a generalisation from a stereotype — it is the pattern in the case record, and it is a statement about specific criminal enterprises and their structure, not about a nationality. The Justice Department action documented on this page involved a Houston-based conspiracy of at least seven people in the United States and Nigeria, coordinating over WhatsApp.

The structure of that record is more useful than the geography. The people who compromise mailboxes, the people who send the emails, the people whose accounts receive the money and the people who convert it into exportable goods are usually different people, connected loosely and paid in shares. The conspiracy prosecuted in Houston laundered proceeds from business email compromise, romance fraud and unemployment insurance fraud — it was a laundering service, not part of any single scheme.

Eastern European and Russian-speaking groups appear more often in the credential-theft and initial-access half of the market, selling mailbox access rather than running the fraud themselves. The division of labour is why disrupting one part of the chain moves the problem rather than ending it.

Real cases

Laundering $3.1m of scam proceeds through salvaged cars shipped to West Africa

2026 US · NG Sentenced $3.1m

In August 2026 a Nigerian national living in Houston was sentenced to 95 months in prison for leading a conspiracy that laundered more than $3.1 million in proceeds from business email compromise, romance and unemployment insurance fraud. The method was mundane and effective: buy used and salvaged cars with the stolen money, ship them to West Africa, and sell them there. One traced victim was a Puerto Rican renewable energy company tricked into wiring about $280,000.

Read the case file · 1 source

Consent phishing: access that a password change does not revoke

2026 US Ongoing

In September 2026 the FBI warned about OAuth consent phishing — a technique that obtains lasting access to an account without ever taking a password. The victim is sent a link that asks them to approve an application, and the resulting token cannot be cancelled by changing the password. Since late 2025 the FBI has observed actors impersonating government officials, media figures and event organisers on messaging apps to deliver these requests.

Read the case file · 1 source

Ten times fewer reports, ten times the loss each

2025 CA · AU Ongoing $1.8m

Canadian vendor fraud reports fell from 4,120 in 2021 to 426 in the first nine months of 2025 — a fall of about 90% — while loss per victim rose from roughly C$3,200 to roughly C$8,500, and spiked to C$15,500 in 2024. Australia's false billing category shows the same divergence. Invoice fraud is reaching far fewer businesses and taking far more from each.

Read the case file · 2 sources

$893 million in AI-involved fraud, and where it actually shows up

2025 US Ongoing $893.3m

The FBI received more than 22,000 complaints reporting AI-related information in 2025, with adjusted losses of $893,346,472. Its breakdown is more useful than the headline: over $30 million in AI-linked business email compromise, over $19 million in romance and confidence scams with a likely AI nexus, over $5 million in voice-cloned distress scams, and almost $13 million in employment scams where voice spoofing was used in interviews.

Read the case file · 2 sources

Property fraud losses rose 58% in a year

2025 US Ongoing $275.1m

US real estate fraud complaints rose from 9,359 in 2024 to 12,368 in 2025, and losses rose from $173.6 million to $275.1 million — a 58% increase in a single year, after being roughly flat the year before. Property fraud spans two very different crimes: rental listings for homes that are not available, and wire fraud aimed at the deposit or completion payment in a real purchase.

Read the case file · 2 sources

Payment redirection: the only major Australian scam category still growing

2025 AU Ongoing $107.5m

Australia's National Anti-Scam Centre reported combined losses of A$166.8 million to payment redirection scams in 2025, up 9.3% on 2024. Every other category in the country's top five fell or grew more slowly: investment losses dropped 11.4% and romance 10.8%, while remote access fell 34.1%. Payment redirection — the Australian name for business email compromise — was the outlier.

Read the case file · 1 source

The Ohio–Ghana romance conspiracies: eleven defendants, seven years

2025 US · GH Charged — allegation, not conviction

Between May and June 2025 the US Attorney's Office for the Northern District of Ohio unsealed charges against eleven people over wire fraud and money laundering conspiracies that ran from December 2017 through March 2024. Prosecutors say the defendants used romance fraud schemes, frequently against elderly Americans, and shared the proceeds with co-conspirators in Ghana.

Read the case file · 1 source

Extradited from Malaysia: romance victims used as unwitting money mules

2025 KE · MY · US Charged — allegation, not conviction

On 22 May 2025 Malaysia extradited Kenyan national John Muriuku Wamuigah to stand trial in the District of Connecticut on a wire fraud charge. Prosecutors allege he and others executed a scheme using both business email compromise and romance scams, and that the scheme involved exploiting elderly victims through romance fraud so that they would serve as unwitting money mules.

Read the case file · 1 source

Ten years of business email compromise: $55.5 billion in global exposed losses

2024 US Ongoing $55.5bn

In September 2024 the FBI's Internet Crime Complaint Center published a decade of business email compromise figures: $55.5 billion in global exposed losses across complaints filed between October 2013 and December 2023, including 158,436 US victims and $20.1 billion in US exposed losses. The same advisory records a 9% increase in identified global exposed losses in a single year, and a shift in where the stolen money is sent.

Read the case file · 2 sources

50 fraudulent accounts, $9.5 million, and a 25-year sentence

2022 US Sentenced $9.5m

Elvis Eghosa Ogiekpolor, 46, of Norcross, Georgia, was sentenced in October 2022 to 25 years in federal prison for opening and directing others to open at least 50 fraudulent business bank accounts that received more than $9.5 million from romance scams and business email compromise fraud. Thirteen romance fraud victims testified at his trial; one described sending nearly $70,000 to a man she met on eHarmony. He moved the money on through dozens of accounts, including several overseas, before it reached the people who took it from victims in the first place.

Read the case file · 2 sources

Red flags

  • Any change of bank details. New account, new bank, “our usual account is under audit”. This is the scam. There is no benign version that arrives by email.
  • Pressure to pay before a deadline that has just been brought forward, or that you are hearing about for the first time.
  • A request that arrives while the approver is travelling, at a conference, or otherwise hard to reach by phone.
  • A reply-to address that differs from the sender, or a domain that is one character out — a swapped letter, an added hyphen, .co instead of .com.
  • Instructions not to discuss the payment because of an acquisition, a legal matter or an audit.
  • A thread that resumes after a gap with a slightly different writing style, or that suddenly drops other recipients.
  • An invoice for the right amount at the right time that you were not expecting to receive quite yet.
  • A phone call confirming the emailed details using a number supplied in the email. That is not verification; it is the same channel twice.
  • Payroll change requests asking to redirect someone’s salary to a new account.
  • Conveyancing details arriving by email at all, close to completion. This variant costs individuals their entire deposit.

If it’s happening to you

If you think a payment has just gone to the wrong account, the next hour matters more than anything else you will do.

  1. Call your bank immediately and ask for a recall of the funds, plus any indemnification paperwork they need. Say the words “business email compromise” — most banks have a specific process.
  2. Ask the bank to contact the receiving bank directly. Speed is everything: IC3’s recovery process works on funds that are still sitting in the receiving account.
  3. Report it the same day. In the US, file at ic3.gov — the FBI’s Recovery Asset Team works through a Financial Fraud Kill Chain that needs the report fast. Elsewhere, see where to report. IC3 advises filing regardless of the amount.
  4. Assume the mailbox is still compromised. Do not discuss the incident on the affected email system. Reset passwords, revoke sessions, and check for forwarding and inbox rules the attacker created — those rules are often the only artefact left behind.
  5. Warn the counterparty on a known-good number. If the compromise was theirs, other customers are being targeted right now.
  6. Preserve the emails with full headers, not screenshots. They are the evidence.
  7. Tell your insurer if you hold cyber or crime cover; many policies have short notification windows.

Preventing the next one. One rule does most of the work: a change of payment details is confirmed by voice, on a number you already held, by a second person, before the payment goes out. Everything else — payment thresholds, sender warnings on external email, blocking lookalike domains, phishing- resistant MFA — helps, but that one rule is the control that has to hold.

Where the money goes

A redirected payment lands in a receiving account that has been prepared for it — sometimes a mule account, sometimes a real company’s account whose owner has been recruited or deceived. It rarely stays there for more than a few hours.

From there the money splits and converts. IC3 records a growing share going directly to institutions holding custodial accounts for third-party payment processors, to peer-to-peer processors and to cryptocurrency exchanges — routes that were not the norm when the recall process was designed. In 2025, 86% of reported BEC transactions went by wire transfer or ACH, the fastest and least reversible conventional rail.

The end of the chain is often physical. The Houston conspiracy converted its share into salvaged cars bought at US auctions and shipped to Nigeria — a legitimate export, with paperwork, a real buyer and a value that survives the crossing.

The other half of this story

Our sibling site Clean on Paper explains how redirected payments are laundered through goods, exports and invoicing — and why converting stolen money into something with a shipping manifest is so much harder to unwind than moving it between accounts.

By the numbers

No agency publishes a line item for most of the schemes on this site, so these charts show the official categories that contain this scheme. Each series is labelled with the agency's own category name. See how the mapping works.

How contact was made, CA, 2025Horizontal bars of reported losses by contact channel in 2025, led by Email at $22m.How contact was made, CA, 2025Reported losses by the channel the scammer used, for the agency categories covering this scheme.Email$22mEmail: $22mText message$3.2mText message: $3.2mOther/unknown$3.0mOther/unknown: $3.0mDirect call$1.6mDirect call: $1.6mNot Available$490,240Not Available: $490,240Internet-social network$11,052Internet-social network: $11,052Door to door/in person$6,936Door to door/in person: $6,936Mail$1,431Mail: $1,431$0$10m$20mAggregated across every agency category that maps to this scheme, so it inherits those categories’ breadth.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP. Pulled 2026-09-06.
Full dataset, methodology and downloads
Reported losses over timeLine chart of reported losses from 2021 to 2025 for the agency categories that cover this scheme: BEC (US); Payment redirection (AU); Spear Phishing (CA).Reported losses over timeEach line is one agency category that covers this scheme. Agency categories are usually broader than the scheme itself.$0$1.0bn$2.0bn$3.0bnBEC (US), 2023: $2.9bnBEC (US), 2024: $2.8bnBEC (US), 2025: $3.0bnPayment redirection (AU), 2024: $101mPayment redirection (AU), 2025: $115mSpear Phishing (CA), 2021: $43mSpear Phishing (CA), 2022: $45mSpear Phishing (CA), 2023: $44mSpear Phishing (CA), 2024: $49mSpear Phishing (CA), 2025: $30m20212022202320242025BEC (US)Payment redirection (AU)Spear Phishing (CA)Categories are the publishers’ own and are broader than this scheme, so these lines bound it rather than measure it exactly. Lines are notcomparable to each other: different countries, different reporting systems.Reported losses only. Every agency here says most fraud is never reported to it, so treat these as a floor, not a total.Sources: Canadian Anti-Fraud Centre / RCMP; FBI Internet Crime Complaint Center (IC3); National Anti-Scam Centre (ACCC), Australia(transcribed from the published report). Pulled 2026-09-06.
Full dataset, methodology and downloads

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. Business Email Compromise: The $55 Billion Scam. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $55.5bn global exposed loss 2013–2023; US victim and loss counts; the 9% year-on-year rise; the shift to custodial and crypto recipients; recall guidance.
  2. 2025 Internet Crime Report. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 2025 BEC losses of $3,046,598,558 from 24,768 complaints; the 86% wire/ACH payment split for BEC.
  3. Nigerian National Sentenced for Laundering $3.1M in Scam Proceeds. US Department of Justice. Accessed 2026-09-06. Supports: The $280,000 BEC against a Puerto Rican renewable energy company and the laundering method.
  4. Targeting scams: report of the National Anti-Scam Centre on scams data and activity 2025. National Anti-Scam Centre (ACCC), Australia. Accessed 2026-09-06. Supports: A$166.8m Australian payment redirection losses in 2025, up 9.3%, and the reporting-channel split.
  5. Fraud remains a national security threat as criminals steal almost £1.3 billion. UK Finance. Accessed 2026-09-06. Supports: UK authorised push payment fraud totals for 2025.
  6. Canadian Anti-Fraud Centre Fraud Reporting System Dataset. Canadian Anti-Fraud Centre / RCMP. Accessed 2026-09-06. Supports: Canadian spear phishing category volumes and losses, which is where the CAFC files BEC.

Common questions

What is the difference between business email compromise and CEO fraud?

CEO fraud is one variety of BEC: an email that appears to come from a senior executive telling someone in finance to make an urgent payment. BEC also covers supplier-invoice redirection, payroll diversion and conveyancing fraud. Australia calls the whole family payment redirection; UK Finance splits it between invoice and mandate fraud and CEO fraud.

How does the attacker get into the mailbox?

Usually credential phishing or a reused password, occasionally a session-token theft that defeats multi-factor authentication. Frequently it is not your mailbox at all but a supplier's, which is why an organisation with excellent security can still be hit through a smaller partner.

Can the money be recovered?

Sometimes, if you move within hours. Contact your bank immediately and ask for a recall and the indemnity paperwork; in the United States, filing at ic3.gov the same day can trigger the FBI's Recovery Asset Team. Recovery drops sharply once funds move onward, and IC3 records BEC money increasingly going straight into custodial and crypto accounts, where the recall process does not reach.

What single control prevents most of this?

Confirming every change of bank details by voice, on a number you already held for that supplier, before the payment goes out. Not a number in the email, and not by replying to the thread — the attacker may be reading it.

Are deepfakes involved now?

In some documented corporate frauds, yes. That removes video calls as a verification step, which makes callbacks on a pre-existing number more important rather than less. A cloned voice cannot answer a number the attacker does not control.

Why do small organisations get hit hardest?

Because the control that stops BEC is a second person, and small finance teams often do not have one. Charities, schools, small builders and conveyancers appear repeatedly in enforcement records for exactly this reason.

Where a redirected payment goesWhere a redirected payment goes. The recall window closes at the first hop. Everything after it is an investigation. Where a redirected payment goesThe recall window closes at the first hop. Everything after it is an investigation.The paying businessWire or transfer,correctly authorisedReceiving account,often a real company'sOnward within hours,often to a custodialaccountPayment processor orcrypto exchangeConverted into cars,electronics or cryptoGoods bought andexportedReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.How redirected payments are laundered — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/trade-based-money-laundering/Path documented in FBI IC3 advisories on BEC recipients and in the August 2026 sentencing of a conspiracy that laundered proceeds by shipping salvaged cars to West Africa.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.