The silent threat to UK businesses: what you need to know about business email compromise
Published: 27 June 2025Read Time: 4 minutes

Picture this: an urgent email arrives from your Managing Director asking for a swift payment to a supplier. It sounds authentic, uses familiar language, and even mentions a real project. Everything looks legitimate, until you realise it’s a scam. It’s a carefully crafted attack known as Business Email Compromise (BEC). By the time anyone notices, the money has already disappeared.
Why decision-makers should pay attention
BEC is now one of the most financially damaging cyberattacks globally, costing organisations over $50 billion to date. Unlike traditional phishing emails with dodgy links or obvious red flags, BEC is subtle, targeted, and effective.
These attacks are not random. They target organisations with:
- Financial authority or supplier relationships
- Publicly available contact information for executives
- Gaps in email verification and process controls
In short: if your business sends payments via email, you’re a target.

What exactly is Business Email Compromise (BEC)?
BEC is a form of cyber fraud where attackers impersonate a senior colleague, supplier, or legal contact to manipulate staff into transferring money or sharing sensitive data.
What makes it especially dangerous?
- No links to click, no attachments to scan
- Emails appear to come from trusted sources
- Language and timing are highly convincing
- It often happens when staff are busiest or under pressure
This is social engineering at its most dangerous. It exploits human trust rather than technical weaknesses.
The five most common BEC scenarios
CEO Fraud
Attackers pose as the MD or CFO and request urgent payments. These messages often bypass usual checks under the guise of discretion or time sensitivity.
Account Compromise
A real company email account is hijacked. Messages are then sent from this address, making them indistinguishable from legitimate internal communication.
Vendor Payment Diversion
A supplier’s bank details are “updated” via a realistic-looking invoice or message. Finance staff believe they’re paying a regular vendor but are in fact sending funds to a fraudster.
Solicitor Impersonation
Fraudsters pretend to be legal advisers. Using urgency and confidentiality, they pressure staff to act quickly without verification.
Data Theft
Rather than money, attackers seek sensitive information such as payroll or HR data. This is used in future attacks or sold on the dark web.

How do these attacks happen?
BEC scams rarely happen overnight. Attackers will often:
- Research your company and staff roles
- Learn how your emails are written and when transactions are made
- Use spoofed domains or hijacked accounts to appear authentic
- Apply pressure through urgency or confidential tone
These emails are designed to bypass spam filters and anti-virus software by following convention. They may be technically clean but emails of this type are socially manipulative.
Case studies: When BEC hits home
- Toyota’s European Supplier lost $37 million in 2019 after a convincing email asked finance to update a bank account. No red flags were noticed until the money had vanished.
- Facebook and Google lost a combined $100 million to a scammer who sent routine-looking invoices from a spoofed supplier domain.
- The Puerto Rican government lost over $4 million to similar tactics, with several departments falling for fake vendor messages.
If it can happen to them, it can happen to any organisation that pays suppliers by email.

How to protect your organisation: Six essential actions
Enable Email Authentication (SPF, DKIM, DMARC)
These protocols help verify senders and block spoofed domains from reaching your inbox.
Implement Multi-Factor Authentication (MFA)
Secure access to business email accounts, especially for senior personnel, with an extra layer of protection.
Create Robust Financial Controls
Set clear procedures for payment approvals and bank detail changes. Never approve via email alone.
Invest in Email Security Software
Advanced tools can detect behavioural anomalies and flag suspicious messages before they do harm.
Train Your Team Regularly
Staff should be confident in recognising red flags and encouraged to verify anything that seems off.
Have a Response Plan Ready
If something goes wrong, act fast. Freeze transactions, alert your bank, and report to Action Fraud or the National Cyber Security Centre (NCSC).
Final thought: It’s not if, It’s when
BEC is a real and growing threat to UK businesses. Cybercriminals don’t need technical expertise. They just need a well-written email, good timing, and someone too busy or too polite to challenge it.
With the right combination of awareness, process, and technology, your organisation can stay one step ahead.
Adoptive Technologies supports UK businesses with email security, employee training, and tailored IT protection. We provide complimentary reviews to help empower your organisation. Simply use the form below to book yours.

