Business Email Compromise: How Small Businesses Can Spot Fake Payment Requests

I’ve seen this happen multiple times at multiple companies. A payment gets made, and only afterward does someone realize something was wrong.

But I’ve also seen the other side. Large payments have been stopped because someone noticed something was off and a process was in place to protect the organization.

Sometimes, one simple verification step is the difference.

What if an email from your boss, vendor, or accountant looked completely normal?

The name is right.

The message sounds like them.

The request even makes sense.

There is just one problem.

The person sending it isn't really them.

This type of scam is often called business email compromise, or BEC. Unlike some cyberattacks, it doesn't always require malware, a suspicious attachment, or an obvious fake website.

Sometimes the attacker simply needs to convince one employee to send money, change banking information, or share something sensitive.

For a small business, one convincing email can become a very expensive mistake.

The good news?

A few simple habits can make these scams much harder to pull off.

What Is Business Email Compromise?

Business email compromise is a type of scam where a criminal pretends to be someone you trust to convince you to take an action.

That person might appear to be:

  • Your boss

  • A coworker

  • A vendor

  • A customer

  • An accountant

  • Someone from payroll or HR

  • Another company you regularly do business with

The attacker usually wants money, account access, or sensitive information.

You might receive a request to pay an invoice, update banking information, change an employee's direct deposit, purchase gift cards, or send confidential documents.

And the email may not look suspicious at first.

That's what makes these attacks so effective.

What Can a Fake Payment Request Look Like?

Imagine you handle invoices for a small business.

A vendor you've worked with for years sends you an email:

“We've changed banks. Please use the attached banking information for all future payments.”

The invoice looks normal.

The vendor's name looks right.

Maybe the email even references a real project.

Would you make the change?

That's exactly the decision criminals are hoping you'll make without checking first.

The message might come from a fake email address that looks almost identical to the real one.

But there is another possibility.

The vendor's actual email account may have been compromised.

I've seen an increase in this type of vendor compromise. In some cases, we've contacted a vendor to tell them something appeared wrong with their account. In others, we've contacted them and they've confirmed the problem themselves: don't click the link or open the attachment because the account has been compromised.

That's an important distinction.

Sometimes the suspicious message isn't coming from an obviously fake address. It may actually be coming from a real vendor's compromised account.

If a criminal has access to a real mailbox, the messages can be much harder to spot. They may come from the correct address and even appear inside an existing conversation.

That's why checking the sender's address alone isn't enough.

Common Business Email Compromise Scams

Business email compromise doesn't always look the same.

Here are several situations small businesses should recognize.

1. The Fake Vendor Payment

A vendor emails saying its banking information has changed.

The employee updates the payment information and sends the next payment.

But the new account belongs to the criminal.

The business may not realize what happened until the real vendor asks:

“Why haven't you paid our invoice?”

2. The Urgent Request From the Boss

An employee receives a message that appears to come from the owner or another executive.

It might say:

“I'm in a meeting. I need this payment handled immediately.”

Or:

“Can you purchase several gift cards for a customer? I need them today.”

The attacker uses authority and urgency to make the employee act before stopping to think.

3. The Direct Deposit Change

We tend to see more of these requests around the beginning of the year and during tax season, when employees may legitimately be making changes to payroll and financial information.

Payroll receives an email that appears to come from an employee.

The message asks to have the employee's direct deposit moved to a new bank account.

Everything seems routine.

But the employee never requested the change.

The next paycheck goes to the criminal.

4. The Fake Invoice

A criminal sends an invoice that appears to come from a company the business already works with.

It may use a familiar company name, logo, or description.

The amount may even be reasonable enough that nobody questions it.

The goal is simple:

Get the business to pay before anyone realizes something is wrong.

Why Are These Emails So Convincing?

We often imagine scam emails as obvious.

Bad spelling.

Strange links.

Unusual attachments.

Those warning signs still exist, but criminals have become much better at making messages look normal.

They may research a company online and learn:

  • Employee names

  • Job titles

  • Vendors

  • Business relationships

  • Upcoming events

  • Who handles finances

  • Who has authority to approve payments

Information from company websites, LinkedIn, social media, and other public sources can make a fake request sound much more believable.

AI tools can also make it easier to create polished messages without the spelling and grammar mistakes people traditionally associate with scams.

The message doesn't have to be perfect. It only has to be believable enough for someone to act.

This is called social engineering. Instead of only attacking technology, criminals target people and try to convince them to take an action.

Security tools can help, but they can't prevent every action someone might be tricked into taking.

That's why cybersecurity needs both technical protections and good everyday habits.

To learn more about why technical protections are only part of the solution, read our previous blog, Why Multi-Factor Authentication Alone Is No Longer Enough for Small Businesses.

Use the STOP → VERIFY → ACT Rule

Small businesses don't need a complicated cybersecurity process for every email.

They need a simple rule employees can remember.

STOP

Slow down when a message asks you to:

  • Send money

  • Change banking information

  • Change direct deposit

  • Purchase gift cards

  • Share passwords or login codes

  • Send sensitive business information

  • Provide employee or customer information

  • Make an unusual financial transaction

Pay particular attention when the request is unexpected or urgent.

VERIFY

Confirm the request using a communication method you already trust.

Do not use the contact information provided in the questionable message to verify the request.

If a vendor sends new banking instructions, call the vendor using the phone number you already have on file.

If your boss suddenly requests an unusual payment, call them directly or verify it in person.

If an employee asks to change direct deposit information, follow your normal payroll verification process.

Ask yourself:

“Can I prove this request came from the person I think it did?”

ACT

Once the request has been independently verified, continue with the transaction.

That's it.

STOP. VERIFY. ACT.

That small pause can prevent a very expensive mistake.

Simple Ways Small Businesses Can Reduce the Risk

You don't need a large security department to make business email compromise harder.

A few basic protections can make a significant difference.

Require Extra Approval for Large or Unusual Payments

Consider requiring a second person to approve payments over a certain amount or transactions that fall outside your normal process.

One person receives the request.

Another reviews or approves it.

That gives your business another opportunity to catch something that doesn't look right.

Protect Email Accounts With MFA

MFA can't prevent every BEC scam, but it can make it harder for criminals to take over an employee's real email account.

That's especially important because, as we've already seen, a message from a compromised real account can be much harder to recognize as malicious.

Teach Employees to Question Urgency

Attackers don't want employees thinking carefully.

They want them reacting.

Messages such as:

“I need this immediately.”

“Don't call me. I'm in a meeting.”

“This needs to be paid before the end of the day.”

should make employees slow down, not speed up.

Urgency doesn't automatically mean something is a scam.

But urgency involving money or sensitive information should make someone stop and check.

Create Clear Rules for High-Risk Requests

Don't make employees guess when they should question a request.

Set a simple company rule for unusual payments, banking changes, direct-deposit changes, and requests for sensitive information.

Most importantly, employees should know they are allowed to stop a transaction when something doesn't feel right.

Your process should support the person who asks the extra question, not make them afraid that they're slowing everyone down.

A security process only works when people feel comfortable using it.

What If You Already Sent the Money?

If you discover that money may have been sent to a criminal, act quickly.

Contact your bank or financial institution immediately. Tell them you believe the transaction may be fraudulent and ask what options are available to stop or recover the payment.

Then:

  • Preserve the suspicious emails and other evidence

  • Notify the appropriate people inside your business

  • Determine whether an email account may have been compromised

  • Change affected credentials when necessary

  • Review MFA and account security

  • Check email settings for suspicious forwarding rules or other changes

  • Document what happened

  • Report the incident to appropriate authorities when applicable

Don't spend hours trying to investigate everything before contacting the financial institution.

Stopping the movement of money should be one of the first priorities.

You can also report business email compromise and other internet crimes to the FBI's Internet Crime Complaint Center (IC3).

Final Thoughts

Business email compromise targets something every business depends on:

Trust.

We trust our coworkers.

We trust our vendors.

We trust familiar names in our inbox.

Cybercriminals try to use that trust against us.

The answer isn't to become suspicious of every email. It's to recognize the types of requests that deserve an extra check.

When money, banking information, account access, or sensitive information is involved, taking a moment to question an unusual request can make all the difference.

Sometimes one person noticing that something feels wrong, slowing down, and asking one more question can stop a very expensive mistake.

Keep Learning

A Fake Email Almost Cost This Business Everything

Learn how one convincing message can put a small business at risk and what simple habits can help employees recognize suspicious requests.

Why Multi-Factor Authentication Is No Longer Enough for Small Businesses

MFA is essential, but attackers have developed ways to target the person behind the login. Learn why businesses need additional layers of protection.

Want Simple, Practical Cybersecurity Tips Delivered to Your Inbox?

Cyber threats continue to evolve, but protecting your business doesn't have to be complicated.

Join the SimplifySec email list for practical cybersecurity tips, new articles, and actionable advice for small businesses and families.

No spam. Just simple, practical cybersecurity advice you can actually use.

Stay safe,
The SimplifySec Team
Simple. Practical. Cybersecurity.

Disclaimer

The content on this blog is published by SimplifySec Group LLC for general educational and informational purposes only. It is not legal, financial, or professional cybersecurity advice, and reading a blog post does not create a professional-client relationship between you and SimplifySec.

Cybersecurity risks depend on your specific environment, and recommendations that work for one system or business may not be appropriate for yours. You should evaluate your own circumstances and consult a qualified professional before acting on anything you read here. SimplifySec makes no warranty that the information is complete, current, or error-free, and to the fullest extent permitted by law disclaims liability for any loss arising from your reliance on it.

This blog may link to or reference third-party tools, vendors, or resources for convenience. SimplifySec does not endorse, control, or assume responsibility for those third parties or their content.

© 2026 SimplifySec Group LLC. All rights reserved.

This article may not be copied, reproduced, distributed, or republished, in whole or in part, without prior written permission from SimplifySec Group LLC, except as permitted by applicable copyright law.

Previous
Previous

Locked Out or Hacked? How to Protect and Recover Your Online Accounts

Next
Next

Before You Post That Back-to-School Photo: What Parents Should Check First