Business Email Compromise: The Billion-Rand Scam
Hiding in Your Inbox
When One Email Changes Everything
It begins like any other working day.
Your finance manager receives an email from the Chief
Executive Officer requesting an urgent payment to secure a confidential
acquisition. The message is professional, the writing style is familiar, and
the timing seems plausible—the CEO is travelling overseas and asks that the
transaction be handled discreetly. With deadlines looming and authority rarely
questioned, the payment is approved.
Hours later, the real CEO calls.
They never sent the email.
The money is gone.
This is Business Email Compromise (BEC)—a form of
cyber-enabled fraud that relies not on sophisticated malware or ransomware, but
on deception, trust and human behaviour. Unlike many cyberattacks that seek to
disrupt systems, BEC is designed to manipulate people into willing authorising
fraudulent transactions or disclosing sensitive information.
The financial impact has been staggering. According to the
FBI's Internet Crime Complaint Center (IC3), BEC has resulted in more than US$55
billion in reported global exposed losses between October 2013 and December
2023, making it one of the most financially damaging forms of cybercrime
reported to law enforcement
A common misconception is that BEC targets only large
multinational organisations. In reality, businesses of every size are potential
victims. Criminals understand that even organisations with modest payment
processes can become lucrative targets when verification procedures are weak.
South African organisations are no exception. Banks,
municipalities, professional service firms, healthcare providers and small
businesses have all been targeted through invoice fraud, supplier banking
detail changes and executive impersonation schemes. As digital communication
becomes central to business operations, these attacks continue to evolve in
sophistication, making fraudulent correspondence increasingly difficult to
distinguish from legitimate requests
BEC is not merely an information technology issue. It is a governance issue, an internal control issue and, ultimately, a business risk that demands the attention of executives, boards and every employee entrusted with financial decision-making.
More Than Just a Fake Email
Despite its name, Business Email Compromise rarely begins
with a fraudulent payment request.
Modern cyber-attacks are carefully planned operations that
often begin weeks—or even months—before any payment request is made. Criminals
study their targets, analyse organisational structures, identify key
decision-makers, system administrators, observe communication patterns and
staff movements. They study company websites, domains, wifi, LinkedIn profiles,
social media activity, and publicly available information to understand
reporting lines, executive travel schedules, supplier relationships and
financial processes. In some cases, they gain access to legitimate email
accounts through phishing, stolen credentials or malware, allowing them to
monitor genuine conversations before striking
Rather than relying on technical exploits, Business Email
Compromise succeeds by exploiting human psychology. Authority, urgency,
familiarity and perceived legitimacy are powerful influences in any workplace.
An email that appears to come from a Chief Executive Officer, Chief Financial
Officer or trusted supplier can easily override caution—especially when the
request seems routine, time-sensitive or comes from someone in a position of
authority.
The attack itself may take several forms. A criminal may
impersonate a senior executive and instruct the finance department to process
an urgent payment. A supplier's email account may be compromised so that
legitimate invoices are intercepted and banking details quietly substituted.
Payroll departments may receive convincing requests to amend employee banking
information, while procurement teams may be directed to settle invoices into
fraudulent accounts. In many cases, the emails contain no malicious links or
attachments at all—they simply exploit familiarity and confidence.
This is precisely why business email compromise continues to
evade traditional cybersecurity controls. Firewalls cannot assess intent.
Antivirus software cannot recognise deception. Even advanced email security
platforms may struggle when criminals communicate from compromised, legitimate
accounts or use domain names that differ by only a single character.
The defining characteristic of business email compromise is therefore not the technology used by the attacker, but the manipulation of legitimate business processes. Criminals understand that they do not need to compromise an organisation’s systems if they can persuade an authorised employee to bypass established controls.
The Cost of One Click
Business Email Compromise is not a theoretical cyber risk—it is a proven criminal enterprise that has cost organisations billions of dollars worldwide. Unlike ransomware attacks, which often announce themselves loudly, BEC succeeds quietly. By the time the fraud is detected, the payment has usually been authorised, processed and transferred through multiple accounts, making recovery extremely difficult.
One of the most widely reported examples occurred when
global engineering consultancy Arup fell victim to an elaborate social
engineering attack. An employee participated in what appeared to be a
legitimate video conference with senior executives and authorised multiple
fraudulent payments, resulting in losses of approximately US$25 million.
The attackers reportedly combined compromised communications with AI-generated
deepfake technology to convince the employee that the requests were
genuine. Although the attack incorporated deepfake elements, its ultimate
objective was classic Business Email Compromise—persuading an authorised
employee to approve fraudulent transactions
The incident demonstrates how Business Email Compromise has
evolved beyond fraudulent emails alone. Modern attacks increasingly combine
compromised email accounts, voice cloning, AI-generated executive
impersonation (synthetic cyber ID theft) and carefully crafted social
engineering techniques to create highly convincing scenarios that are difficult
to distinguish from legitimate business communications.
The FBI continues to identify Business Email Compromise as
one of the most financially damaging forms of cybercrime. Between October 2013
and December 2023, reported BEC incidents resulted in more than US$55
billion in exposed losses, underscoring the scale, persistence and
profitability of these attacks
Perhaps the most concerning aspect of Business Email
Compromise is not the technology itself, but the simplicity of the attack.
There are often no malicious attachments, suspicious hyperlinks or obvious
technical indicators of compromise. Instead, cybercriminals exploit familiar
business processes, organisational hierarchies and human judgement to persuade
well-intentioned employees to authorise fraudulent payments. The attack
succeeds not because security systems fail, but because a legitimate business
process has been manipulated.
Governance is the Strongest Defence
While technology remains an essential component of any
cybersecurity strategy, it cannot prevent an employee from approving a
fraudulent payment of changing banking details based on convincing email.
Business Email Compromise succeeds because it exploits judgement rather than
systems, making governance, effective internal controls and disciplined
decision-making the organisation's most powerful defence.
Strong financial controls should never be viewed as
administrative obstacles—they are critical safeguards against fraud.
High-value payments, changes to supplier banking details and requests that
deviate from normal business processes should always be subject to independent
verification, regardless of who appears to have made the request. A simple
telephone call using a trusted contact number or confirmation through an
alternative communication channel can prevent losses that even the most
advanced email security solutions may fail to detect.
Equally important is cultivating a culture where employees
are encouraged to question unusual instructions without fear of criticism or
delay. Cybercriminals deliberately create a sense of urgency, authority and
confidentiality to persuade individuals to bypass established controls.
Resilient organisations respond differently. They embed verification into
everyday decision-making, apply controls consistently and recognise that
accountability should never be compromised for convenience or speed.
Ultimately, Business Email Compromise serves as a reminder
that the greatest organisational vulnerability is not technology—it is the
failure to follow trusted processes. Organisations that build resilience
through strong governance, sound financial oversight and a culture of
verification are far better positioned to detect and prevent these attacks
before financial losses occur. In today's digital environment, the most
resilient organisations are not those that trust more—they are those that
verify first.
D-finitive Insight
Business Email Compromise is often described as a
cybersecurity threat, but its true impact extends far beyond technology. It is
a governance challenge, a fraud risk and an internal control failure waiting to
be exploited.
At D-finitive Advisory, our experience has consistently
shown that Business Email Compromise is most effectively managed as an
enterprise risk rather than simply a cybersecurity issue. Effective prevention
requires more than secure email systems – it demands strong governance, clearly
defined financial controls, regular fraud awareness training, and a culture
that empowers employees to verify unusual requests without hesitation.
As cybercriminals continue to refine their tactics,
organisations must move beyond reactive security measures and build resilience
through robust governance frameworks. Business Email Compromise succeeds when
people are persuaded to bypass the very controls designed to protect the
organisation. The strongest defence is not suspicion — it is a culture where
verification is routine, accountability is shared and every employee
understands that even the most convincing request must be confirmed before
action is taken.
Delivering Clarity. Protecting
Integrity. Driving Accountability.
