Dfinitive Logo
+27765215042
info@d-finitive.com
Business Email Compromise can turn a convincing email into a devastating financial loss. Discover how cybercriminals exploit authority, urgency and familiar business processes—and why strong governance, financial controls and independent verification remain among the most effective defences.

Business Email Compromise: The Billion-Rand Scam Hiding in Your Inbox

When One Email Changes Everything

It begins like any other working day.

 

Your finance manager receives an email from the Chief Executive Officer requesting an urgent payment to secure a confidential acquisition. The message is professional, the writing style is familiar, and the timing seems plausible—the CEO is travelling overseas and asks that the transaction be handled discreetly. With deadlines looming and authority rarely questioned, the payment is approved.

 

Hours later, the real CEO calls.

They never sent the email.

The money is gone.

 

This is Business Email Compromise (BEC)—a form of cyber-enabled fraud that relies not on sophisticated malware or ransomware, but on deception, trust and human behaviour. Unlike many cyberattacks that seek to disrupt systems, BEC is designed to manipulate people into willing authorising fraudulent transactions or disclosing sensitive information.

 

The financial impact has been staggering. According to the FBI's Internet Crime Complaint Center (IC3), BEC has resulted in more than US$55 billion in reported global exposed losses between October 2013 and December 2023, making it one of the most financially damaging forms of cybercrime reported to law enforcement (Federal Bureau of Investigation Internet Crime Complaint Center (IC3), 2024).

 

A common misconception is that BEC targets only large multinational organisations. In reality, businesses of every size are potential victims. Criminals understand that even organisations with modest payment processes can become lucrative targets when verification procedures are weak.

 

South African organisations are no exception. Banks, municipalities, professional service firms, healthcare providers and small businesses have all been targeted through invoice fraud, supplier banking detail changes and executive impersonation schemes. As digital communication becomes central to business operations, these attacks continue to evolve in sophistication, making fraudulent correspondence increasingly difficult to distinguish from legitimate requests (Newzroom Afrika, 2019).

 

BEC is not merely an information technology issue. It is a governance issue, an internal control issue and, ultimately, a business risk that demands the attention of executives, boards and every employee entrusted with financial decision-making.

 

More Than Just a Fake Email

Despite its name, Business Email Compromise rarely begins with a fraudulent payment request.

 

Modern cyber-attacks are carefully planned operations that often begin weeks—or even months—before any payment request is made. Criminals study their targets, analyse organisational structures, identify key decision-makers, system administrators, observe communication patterns and staff movements. They study company websites, domains, wifi, LinkedIn profiles, social media activity, and publicly available information to understand reporting lines, executive travel schedules, supplier relationships and financial processes. In some cases, they gain access to legitimate email accounts through phishing, stolen credentials or malware, allowing them to monitor genuine conversations before striking (Federal Bureau of Investigation (FBI), n.d.).

 

Rather than relying on technical exploits, Business Email Compromise succeeds by exploiting human psychology. Authority, urgency, familiarity and perceived legitimacy are powerful influences in any workplace. An email that appears to come from a Chief Executive Officer, Chief Financial Officer or trusted supplier can easily override caution—especially when the request seems routine, time-sensitive or comes from someone in a position of authority.

 

The attack itself may take several forms. A criminal may impersonate a senior executive and instruct the finance department to process an urgent payment. A supplier's email account may be compromised so that legitimate invoices are intercepted and banking details quietly substituted. Payroll departments may receive convincing requests to amend employee banking information, while procurement teams may be directed to settle invoices into fraudulent accounts. In many cases, the emails contain no malicious links or attachments at all—they simply exploit familiarity and confidence.

 

This is precisely why business email compromise continues to evade traditional cybersecurity controls. Firewalls cannot assess intent. Antivirus software cannot recognise deception. Even advanced email security platforms may struggle when criminals communicate from compromised, legitimate accounts or use domain names that differ by only a single character.

 

The defining characteristic of business email compromise is therefore not the technology used by the attacker, but the manipulation of legitimate business processes. Criminals understand that they do not need to compromise an organisation’s systems if they can persuade an authorised employee to bypass established controls.

The Cost of One Click

Business Email Compromise is not a theoretical cyber risk—it is a proven criminal enterprise that has cost organisations billions of dollars worldwide. Unlike ransomware attacks, which often announce themselves loudly, BEC succeeds quietly. By the time the fraud is detected, the payment has usually been authorised, processed and transferred through multiple accounts, making recovery extremely difficult.

 

One of the most widely reported examples occurred when global engineering consultancy Arup fell victim to an elaborate social engineering attack. An employee participated in what appeared to be a legitimate video conference with senior executives and authorised multiple fraudulent payments, resulting in losses of approximately US$25 million. The attackers reportedly combined compromised communications with AI-generated deepfake technology to convince the employee that the requests were genuine. Although the attack incorporated deepfake elements, its ultimate objective was classic Business Email Compromise—persuading an authorised employee to approve fraudulent transactions (Arup, n.d.)

 

The incident demonstrates how Business Email Compromise has evolved beyond fraudulent emails alone. Modern attacks increasingly combine compromised email accounts, voice cloning, AI-generated executive impersonation (synthetic cyber ID theft) and carefully crafted social engineering techniques to create highly convincing scenarios that are difficult to distinguish from legitimate business communications.

 

The FBI continues to identify Business Email Compromise as one of the most financially damaging forms of cybercrime. Between October 2013 and December 2023, reported BEC incidents resulted in more than US$55 billion in exposed losses, underscoring the scale, persistence and profitability of these attacks (Federal Bureau of Investigation Internet Crime Complaint Center (IC3), 2024). In South Africa, the Information Regulator is responsible for monitoring and reporting of cyber breaches and has yet to develop systems that distinguish between cyber attacks and business email compromise.

 

Perhaps the most concerning aspect of Business Email Compromise is not the technology itself, but the simplicity of the attack. There are often no malicious attachments, suspicious hyperlinks or obvious technical indicators of compromise. Instead, cybercriminals exploit familiar business processes, organisational hierarchies and human judgement to persuade well-intentioned employees to authorise fraudulent payments. The attack succeeds not because security systems fail, but because a legitimate business process has been manipulated.


Governance is the Strongest Defence
While technology remains an essential component of any cybersecurity strategy, it cannot prevent an employee from approving a fraudulent payment of changing banking details based on convincing email. Business Email Compromise succeeds because it exploits judgement rather than systems, making governance, effective internal controls and disciplined decision-making the organisation's most powerful defence.


Strong financial controls should never be viewed as administrative obstacles—they are critical safeguards against fraud. High-value payments, changes to supplier banking details and requests that deviate from normal business processes should always be subject to independent verification, regardless of who appears to have made the request. A simple telephone call using a trusted contact number or confirmation through an alternative communication channel can prevent losses that even the most advanced email security solutions may fail to detect.

 

Equally important is cultivating a culture where employees are encouraged to question unusual instructions without fear of criticism or delay. Cybercriminals deliberately create a sense of urgency, authority and confidentiality to persuade individuals to bypass established controls. Resilient organisations respond differently. They embed verification into everyday decision-making, apply controls consistently and recognise that accountability should never be compromised for convenience or speed.

 

Ultimately, Business Email Compromise serves as a reminder that the greatest organisational vulnerability is not technology—it is the failure to follow trusted processes. Organisations that build resilience through strong governance, sound financial oversight and a culture of verification are far better positioned to detect and prevent these attacks before financial losses occur. In today's digital environment, the most resilient organisations are not those that trust more—they are those that verify first.

 
D-finitive Insight

Business Email Compromise is often described as a cybersecurity threat, but its true impact extends far beyond technology. It is a governance challenge, a fraud risk and an internal control failure waiting to be exploited.

 

At D-finitive Advisory, our experience has consistently shown that Business Email Compromise is most effectively managed as an enterprise risk rather than simply a cybersecurity issue. Effective prevention requires more than secure email systems – it demands strong governance, clearly defined financial controls, regular fraud awareness training, and a culture that empowers employees to verify unusual requests without hesitation.

 

As cybercriminals continue to refine their tactics, organisations must move beyond reactive security measures and build resilience through robust governance frameworks. Business Email Compromise succeeds when people are persuaded to bypass the very controls designed to protect the organisation. The strongest defence is not suspicion — it is a culture where verification is routine, accountability is shared and every employee understands that even the most convincing request must be confirmed before action is taken.

 

Delivering Clarity. Protecting Integrity. Driving Accountability.