Documentation8 min read

Wire Fraud & BEC: How Attackers Steal Millions Over Email

Business Email Compromise is the #1 cause of financial cybercrime losses — over $2.9 billion in 2023 alone. Learn how wire fraud schemes work, the red flags your staff must recognize, and the technical and procedural controls that stop them.

Published August 7, 2026Updated August 25, 2026
Wire FraudBECBusiness Email CompromisePhishingFinancial FraudCybersecurity

What is Business Email Compromise?

Business Email Compromise (BEC) is a targeted fraud scheme in which an attacker impersonates a trusted party — your CEO, CFO, a vendor, or an attorney — to trick an employee into wiring money or disclosing sensitive information. Unlike ransomware, BEC often contains no malware and no malicious link. It is a social engineering attack delivered over email, which is why traditional spam filters miss it entirely.

The FBI's Internet Crime Complaint Center (IC3) reported $2.9 billion in BEC losses in 2023. The average loss per incident exceeds $120,000. Healthcare, real estate, and professional services are the most targeted sectors.

BEC WIRE FRAUD — ATTACK ANATOMY STEP 1 Reconnaissance LinkedIn, website, public filings STEP 2 Account Access Phish exec or vendor, or spoof domain STEP 3 Inbox Monitoring Read emails, learn payment patterns STEP 4 Fraudulent Request "Update bank details" "Wire funds urgently" STEP 5 Wire Sent Funds gone within minutes Where defenses break the chain Steps 1–2: Technical Controls MFA · DMARC enforcement · Defender 365 Step 3: Detection SIEM anomaly alerts · inbox rule monitoring Steps 4–5: Process Controls Callback verification · dual approval · training Most Common BEC Scenarios CEO fraud / wire transfer Vendor payment diversion Payroll redirect Real estate closing fraud Figure 1 — BEC attack anatomy and the three defense layers that break the chain before funds are wired.

Figure 1 — BEC wire fraud attack anatomy. The attack has five stages; defenses must operate at all three layers — technical, detection, and process — to be effective.

The five most common BEC scenarios

ScenarioHow it worksTypical loss
CEO / executive fraudAttacker impersonates CEO and emails CFO or AP: "Wire $85,000 to this account today — confidential."$50K–$500K
Vendor payment diversionAttacker compromises or spoofs a vendor's email and sends updated banking instructions before a large invoice payment.$20K–$2M
Payroll redirectAttacker impersonates an employee and emails HR/payroll to change direct deposit to an attacker-controlled account.$5K–$50K per employee
Real estate closing fraudAttacker intercepts closing communications and sends fraudulent wire instructions for the down payment or closing funds.$50K–$1M+
Attorney / legal impersonationAttacker poses as outside counsel and requests urgent wire transfer related to a pending deal or settlement.$100K–$5M

Technical controls that stop BEC

  • DMARC enforcement (p=reject): Stops exact-domain spoofing. Without this, anyone can send email appearing to come from your CEO's address.
  • Microsoft Defender for Office 365 — impersonation protection: Uses AI to detect display-name spoofing and lookalike domains that DMARC cannot catch.
  • MFA on all email accounts: Prevents account takeover, which is the prerequisite for the most convincing BEC attacks (where the attacker sends from a real, compromised account).
  • SIEM inbox rule monitoring: Attackers often create inbox rules to hide their activity (e.g., auto-delete replies from the real vendor). Adlumin alerts on suspicious new inbox rules.
  • Conditional Access: Block email access from unexpected geographies or unmanaged devices.
The most dangerous BEC attacks come from compromised accounts — not spoofed ones. When an attacker has actually logged into your vendor's email account, the message passes every technical filter. The only defenses at that point are process controls: callback verification and dual approval for wire transfers.

Process controls — the human layer

Technical controls alone cannot stop BEC. These procedural controls must be in place:

  • Out-of-band callback verification: Any request to change banking information or initiate a wire transfer must be verified by calling the requestor at a known phone number — not a number provided in the email.
  • Dual approval for wire transfers: No single employee should be able to authorize a wire transfer above a defined threshold (e.g., $5,000) without a second approver.
  • Vendor banking change policy: Changes to vendor payment details require written confirmation plus a phone call to the vendor's main number on file — not the number in the change request.
  • Security awareness training: Staff must recognize urgency and secrecy as BEC red flags. "Do this now and don't tell anyone" is the attacker's script.

If a wire transfer has already been sent

Time is critical. Contact your bank immediately and request a SWIFT recall. The FBI's IC3 operates a Recovery Asset Team (RAT) that has recovered hundreds of millions in fraudulent wire transfers — but only when notified within hours. File a complaint at ic3.gov and contact your cyber insurance carrier.

See our Email Spoofing & Domain Impersonation article for the technical details on DMARC enforcement, and our Security Awareness Training guide for building the human firewall.

Contact our engineers to assess your BEC exposure and implement the technical controls that stop wire fraud before it starts.

About the Author