Also called: BEC · CEO fraud · payment redirection · invoice fraud · mandate fraud · email account compromise
Business email compromise redirects a legitimate payment by impersonating an executive, a supplier or a lawyer, usually from inside a mailbox the attacker has already compromised. There is often no malware and nothing obviously wrong with the message — only the bank details are changed. The FBI has recorded $55.5 billion in global exposed losses over a decade.
Finance and accounts-payable staff at organisations of any size; Small businesses without a second-approver rule — the median victim is not a large corporation; Conveyancers, law firms and estate agents holding client funds at completion; Charities, schools, churches and local government bodies with lean finance teams; Individuals in the middle of a property purchase
Documented origins
Nigeria, Ghana, South Africa, United Kingdom, United States, Romania
Main targets
United States, United Kingdom, Canada, Australia, Germany, Netherlands, Singapore, Ireland, New Zealand
Case files
10 documented cases
Last reviewed
2026-09-06
The stages of the scheme, in order, with the point where it can still be stopped.
What it is
Business email compromise is the theft of a payment that was going to happen anyway.
Nobody is tricked into buying something imaginary. An organisation owes money to a supplier, or is
completing a property purchase, or is paying a contractor. All of that is real. The only thing the
attacker changes is where the money goes — and they change it from inside the conversation in which
the payment was already being arranged.
That is what makes it so hard to catch at the message level. The classic mental model of a scam email
— odd grammar, a strange address, an attachment you were not expecting — describes a different crime.
In its most damaging form, BEC involves no malware and no forged branding. Someone has read a genuine
thread from inside a genuine mailbox, learned the tone and the timing, and sent a revised invoice at
the moment it was expected.
The scale is difficult to overstate. Across complaints filed between October 2013 and December 2023,
the FBI recorded $55.5 billion in global exposed losses, including 158,436 US victims and $20.1
billion in US exposed loss. In 2025 alone, IC3 recorded $3.05 billion from 24,768 complaints —
fewer complaints than almost any consumer scam category, and the second-largest loss total of all of
them.
How it actually works
Reconnaissance
Who approves payments, who the suppliers are, when invoices fall due, who is travelling. Most of
this is public: company filings, a website’s team page, LinkedIn, an out-of-office reply.
A mailbox is taken
Credential phishing or a reused password, occasionally a stolen session token that walks past
multi-factor authentication. Critically, it is often not your mailbox — it is a supplier’s, a
conveyancer’s, or a smaller partner’s.
Quiet reading
The attacker does nothing for days or months. Inbox rules divert replies so the real owner never
sees the thread. This is where the tone, the approval chain and the payment cycle are learned,
and it is why the eventual email reads correctly.
The real conversation is joined
A genuine invoice thread receives a revised invoice with different bank details. Or a reply
arrives from a lookalike domain — one character different, or a different top-level domain —
that continues the thread as though nothing changed.
Where it could have stopped
The change of bank details is the scam, whatever explanation accompanies it. Confirm every change of payment details by calling a number you already had for that supplier — never a number in the email, and never by replying to the thread, which the attacker may be reading.
Urgency, applied to the right person
A completion deadline. An executive travelling and unreachable. A supplier threatening to stop
work. The pressure is designed to remove the step where somebody would have checked.
The payment goes out
Correctly authorised, through the normal process, by someone doing their job properly. No
control fires, because from the system’s point of view nothing anomalous happened.
Discovery, days or weeks later
The real supplier chases an unpaid invoice. By then the money has usually left the receiving
account. IC3 records BEC funds increasingly going straight to custodial accounts at payment
processors and crypto exchanges, which is precisely where a recall stops being possible.
Why it works
It exploits a correct process, not a mistake. Someone whose job is to pay invoices paid an
invoice. There is no moment of carelessness to point at, which is one reason victims of BEC are so
often blamed unfairly and so rarely willing to discuss it.
The trust is pre-existing. The supplier is real, the project is real, the amount is right, the
thread has your own earlier messages in it. Everything checks out except the eleven digits nobody
verifies.
Authority is applied where it is hardest to refuse. In the CEO-fraud variant the request comes
from someone whose emails are not usually questioned, and questioning it has a social cost inside an
organisation. That cost is the attack surface.
Urgency arrives at a real deadline. BEC does not have to invent time pressure. Completions, month
end and payment terms supply it, and the attacker only has to arrive at the right moment — which
reading the mailbox tells them.
Small organisations have no second person. The single control that reliably stops this is another
human confirming the change on a different channel. Charities, schools, small contractors and
conveyancers are over-represented in enforcement records because that person does not exist.
And detection is aimed at the wrong layer. Email security is built to find bad messages. This is a
good message with wrong bank details, sent by an account that is entitled to send it.
Where it comes from
The enforcement record on BEC is unusually rich, because unlike compound-based fraud, the money side
of it touches the US and European banking systems directly, and that is where prosecutions start.
Documented networks have repeatedly involved West African organised crime, particularly Nigerian
groups operating both from Nigeria and from diaspora communities in the United States, Canada and
Europe. That is not a generalisation from a stereotype — it is the pattern in the case record, and it
is a statement about specific criminal enterprises and their structure, not about a nationality. The
Justice Department action documented on this page involved a Houston-based conspiracy of at least
seven people in the United States and Nigeria, coordinating over WhatsApp.
The structure of that record is more useful than the geography. The people who compromise mailboxes,
the people who send the emails, the people whose accounts receive the money and the people who convert
it into exportable goods are usually different people, connected loosely and paid in shares. The
conspiracy prosecuted in Houston laundered proceeds from business email compromise, romance fraud
and unemployment insurance fraud — it was a laundering service, not part of any single scheme.
Eastern European and Russian-speaking groups appear more often in the credential-theft and
initial-access half of the market, selling mailbox access rather than running the fraud themselves.
The division of labour is why disrupting one part of the chain moves the problem rather than ending it.
In August 2026 a Nigerian national living in Houston was sentenced to 95 months in prison for leading a conspiracy that laundered more than $3.1 million in proceeds from business email compromise, romance and unemployment insurance fraud. The method was mundane and effective: buy used and salvaged cars with the stolen money, ship them to West Africa, and sell them there. One traced victim was a Puerto Rican renewable energy company tricked into wiring about $280,000.
In September 2026 the FBI warned about OAuth consent phishing — a technique that obtains lasting access to an account without ever taking a password. The victim is sent a link that asks them to approve an application, and the resulting token cannot be cancelled by changing the password. Since late 2025 the FBI has observed actors impersonating government officials, media figures and event organisers on messaging apps to deliver these requests.
Canadian vendor fraud reports fell from 4,120 in 2021 to 426 in the first nine months of 2025 — a fall of about 90% — while loss per victim rose from roughly C$3,200 to roughly C$8,500, and spiked to C$15,500 in 2024. Australia's false billing category shows the same divergence. Invoice fraud is reaching far fewer businesses and taking far more from each.
The FBI received more than 22,000 complaints reporting AI-related information in 2025, with adjusted losses of $893,346,472. Its breakdown is more useful than the headline: over $30 million in AI-linked business email compromise, over $19 million in romance and confidence scams with a likely AI nexus, over $5 million in voice-cloned distress scams, and almost $13 million in employment scams where voice spoofing was used in interviews.
US real estate fraud complaints rose from 9,359 in 2024 to 12,368 in 2025, and losses rose from $173.6 million to $275.1 million — a 58% increase in a single year, after being roughly flat the year before. Property fraud spans two very different crimes: rental listings for homes that are not available, and wire fraud aimed at the deposit or completion payment in a real purchase.
Australia's National Anti-Scam Centre reported combined losses of A$166.8 million to payment redirection scams in 2025, up 9.3% on 2024. Every other category in the country's top five fell or grew more slowly: investment losses dropped 11.4% and romance 10.8%, while remote access fell 34.1%. Payment redirection — the Australian name for business email compromise — was the outlier.
Between May and June 2025 the US Attorney's Office for the Northern District of Ohio unsealed charges against eleven people over wire fraud and money laundering conspiracies that ran from December 2017 through March 2024. Prosecutors say the defendants used romance fraud schemes, frequently against elderly Americans, and shared the proceeds with co-conspirators in Ghana.
2025KE · MY · USCharged — allegation, not conviction
On 22 May 2025 Malaysia extradited Kenyan national John Muriuku Wamuigah to stand trial in the District of Connecticut on a wire fraud charge. Prosecutors allege he and others executed a scheme using both business email compromise and romance scams, and that the scheme involved exploiting elderly victims through romance fraud so that they would serve as unwitting money mules.
In September 2024 the FBI's Internet Crime Complaint Center published a decade of business email compromise figures: $55.5 billion in global exposed losses across complaints filed between October 2013 and December 2023, including 158,436 US victims and $20.1 billion in US exposed losses. The same advisory records a 9% increase in identified global exposed losses in a single year, and a shift in where the stolen money is sent.
Elvis Eghosa Ogiekpolor, 46, of Norcross, Georgia, was sentenced in October 2022 to 25 years in federal prison for opening and directing others to open at least 50 fraudulent business bank accounts that received more than $9.5 million from romance scams and business email compromise fraud. Thirteen romance fraud victims testified at his trial; one described sending nearly $70,000 to a man she met on eHarmony. He moved the money on through dozens of accounts, including several overseas, before it reached the people who took it from victims in the first place.
Any change of bank details. New account, new bank, “our usual account is under audit”. This is the scam. There is no benign version that arrives by email.
Pressure to pay before a deadline that has just been brought forward, or that you are hearing about for the first time.
A request that arrives while the approver is travelling, at a conference, or otherwise hard to reach by phone.
A reply-to address that differs from the sender, or a domain that is one character out — a swapped letter, an added hyphen, .co instead of .com.
Instructions not to discuss the payment because of an acquisition, a legal matter or an audit.
A thread that resumes after a gap with a slightly different writing style, or that suddenly drops other recipients.
An invoice for the right amount at the right time that you were not expecting to receive quite yet.
A phone call confirming the emailed details using a number supplied in the email. That is not verification; it is the same channel twice.
Payroll change requests asking to redirect someone’s salary to a new account.
Conveyancing details arriving by email at all, close to completion. This variant costs individuals their entire deposit.
If it’s happening to you
If you think a payment has just gone to the wrong account, the next hour matters more than anything
else you will do.
Call your bank immediately and ask for a recall of the funds, plus any indemnification
paperwork they need. Say the words “business email compromise” — most banks have a specific
process.
Ask the bank to contact the receiving bank directly. Speed is everything: IC3’s recovery
process works on funds that are still sitting in the receiving account.
Report it the same day. In the US, file at ic3.gov — the FBI’s Recovery Asset Team works
through a Financial Fraud Kill Chain that needs the report fast. Elsewhere, see
where to report. IC3 advises filing regardless of the amount.
Assume the mailbox is still compromised. Do not discuss the incident on the affected email
system. Reset passwords, revoke sessions, and check for forwarding and inbox rules the attacker
created — those rules are often the only artefact left behind.
Warn the counterparty on a known-good number. If the compromise was theirs, other customers are
being targeted right now.
Preserve the emails with full headers, not screenshots. They are the evidence.
Tell your insurer if you hold cyber or crime cover; many policies have short notification
windows.
Preventing the next one. One rule does most of the work: a change of payment details is confirmed
by voice, on a number you already held, by a second person, before the payment goes out. Everything
else — payment thresholds, sender warnings on external email, blocking lookalike domains, phishing-
resistant MFA — helps, but that one rule is the control that has to hold.
Where the money goes
A redirected payment lands in a receiving account that has been prepared for it — sometimes a mule
account, sometimes a real company’s account whose owner has been recruited or deceived. It rarely
stays there for more than a few hours.
From there the money splits and converts. IC3 records a growing share going directly to institutions
holding custodial accounts for third-party payment processors, to peer-to-peer processors and to
cryptocurrency exchanges — routes that were not the norm when the recall process was designed. In 2025,
86% of reported BEC transactions went by wire transfer or ACH, the fastest and least reversible
conventional rail.
The end of the chain is often physical. The Houston conspiracy converted its share into salvaged cars
bought at US auctions and shipped to Nigeria — a legitimate export, with paperwork, a real buyer and a
value that survives the crossing.
The other half of this story
Our sibling site Clean on Paper explains how redirected payments are laundered through goods, exports and invoicing — and why converting stolen money into something with a shipping manifest is so much harder to unwind than moving it between accounts.
By the numbers
No agency publishes a line item for most of the schemes on this site, so these charts show the
official categories that contain this scheme. Each series is labelled with the agency's
own category name. See how the mapping works.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.
Business Email Compromise: The $55 Billion Scam.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: $55.5bn global exposed loss 2013–2023; US victim and loss counts; the 9% year-on-year rise; the shift to custodial and crypto recipients; recall guidance.
2025 Internet Crime Report.
FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: 2025 BEC losses of $3,046,598,558 from 24,768 complaints; the 86% wire/ACH payment split for BEC.
What is the difference between business email compromise and CEO fraud?
CEO fraud is one variety of BEC: an email that appears to come from a senior executive telling someone in finance to make an urgent payment. BEC also covers supplier-invoice redirection, payroll diversion and conveyancing fraud. Australia calls the whole family payment redirection; UK Finance splits it between invoice and mandate fraud and CEO fraud.
How does the attacker get into the mailbox?
Usually credential phishing or a reused password, occasionally a session-token theft that defeats multi-factor authentication. Frequently it is not your mailbox at all but a supplier's, which is why an organisation with excellent security can still be hit through a smaller partner.
Can the money be recovered?
Sometimes, if you move within hours. Contact your bank immediately and ask for a recall and the indemnity paperwork; in the United States, filing at ic3.gov the same day can trigger the FBI's Recovery Asset Team. Recovery drops sharply once funds move onward, and IC3 records BEC money increasingly going straight into custodial and crypto accounts, where the recall process does not reach.
What single control prevents most of this?
Confirming every change of bank details by voice, on a number you already held for that supplier, before the payment goes out. Not a number in the email, and not by replying to the thread — the attacker may be reading it.
Are deepfakes involved now?
In some documented corporate frauds, yes. That removes video calls as a verification step, which makes callbacks on a pre-existing number more important rather than less. A cloned voice cannot answer a number the attacker does not control.
Why do small organisations get hit hardest?
Because the control that stops BEC is a second person, and small finance teams often do not have one. Charities, schools, small builders and conveyancers appear repeatedly in enforcement records for exactly this reason.
Where the money goes after it leaves, and where it becomes hard to recover.
Reporting is what produces the enforcement data on this page. Find the right agency and phone
number for your country on the report page. If money moved in the last
few hours, call your bank first.