Our Company Lost Millions to an Email Scam—Here’s the Deceptively Simple Trick They Used

$2.4 billion was lost to business email compromise (BEC) in 2021 — nearly fifty times the losses from ransomware. That number is a sharp wake-up call about how a single convincing email can cost serious money.

Table of contents

An expert take by Ethan Cross, HakTechs.com Lead Analyst

We lost funds after one short message asked for a routine vendor change. The note looked normal. It urged speed and secrecy, and someone approved it without verifying the new account details.

This guide shows why targeted BEC, vendor impersonation, and invoice attacks succeed: they mirror everyday tasks and weaponize trust. Traditional security tools often miss them because the message comes from a familiar name or an account that looks real.

Read on to learn how the deception works, the tiny “thing” attackers add that makes a message convincing, and practical verification steps employees and leaders can use right away. For a quick primer on common phishing patterns, see guidance from the FTC at how to recognize and avoid phishing.

Key Takeaways

  • BEC attacks exploit urgency and trust, not malware.
  • One unchecked approval can cost a company millions.
  • Simple verification steps stop most impersonation attempts.
  • Finance, HR, and IT must share clear checks and pause rules.
  • Train employees to flag odd requests and confirm changes by phone.

The costly reality: why businesses keep falling for deceptively simple email requests

One brief, urgent note can convince good people to bypass normal checks. That pressure is the core tool attackers use: urgency plus faux authority makes a routine request feel like an order.

Urgency and a claimed role—often a CEO or finance lead—short-circuit normal controls. Attackers write terse messages like “need this today” or “don’t call me” to stop verification. Those cues push people to act fast, especially near month-end or close-of-quarter time.

The message anatomy is tidy: a plausible sum, an attached invoice, and a bank-change note framed as housekeeping. It looks normal, so standard defenses miss it because there is no malware to flag.

“Treat every payment-change request as a policy exception until you can verify it by a known phone number.”

What urgency, authority, and “just this once” requests look like

  • Urgency: “Approve wire now—vendor demands immediate payment.”
  • Authority: Claims from a CEO or director that short-circuit approvals.
  • Secrecy: “This is confidential—don’t loop others in.”

Targets include AP/AR, HR, and IT staff who see vendor names and invoices every day. A quick callback to a trusted directory or saved contact breaks the pressure. For more on how targeted spear-phishing preys on small organizations, see spear-phishing risks for small firms.

A digital warning screen displays a phishing email notification in the foreground. The email subject line reads "Important: Action Required" in an ominous red font, designed to create a false sense of urgency. The email sender's name and address are blurred, suggesting an attempt to conceal their true identity. In the middle ground, a shadowy figure hovers, symbolizing the deception and hidden motives behind the email. The background is shrouded in a hazy, ominous atmosphere, conveying the gravity of the situation and the potential consequences of falling for such a scam. Dramatic side lighting casts stark shadows, heightening the sense of tension and risk. The overall composition and mood evoke a powerful cautionary tale about the dangers of email impersonation.

Business email scam

What makes targeted BEC different and why simple checks beat broad filters.

A convincing, low-friction request often arrives at the moment someone is busiest—and that’s deliberate.

BEC vs. phishing: how targeted social engineering outsmarts mass attacks

Business email compromise is a focused attack where fraudsters impersonate a leader, vendor, or partner to move funds or expose data via email. It relies on context, timing, and relationship signals.

Mass phishing blasts generic messages to steal logins or drop malware. BEC uses precise social engineering: it cites real invoices, names, and cycles so the note looks routine.

The role of human factors—and why security tools alone won’t catch it

Traditional security stacks often miss BEC because there is no malicious attachment or exploit. Alerts stay quiet while the message reads like everyday correspondence.

That makes trained people the last line of defense. Verification routines, dual approval, and a pause-before-pay habit stop most attacks.

  • Example: impersonate a vendor, send new routing details, attach a genuine invoice, and pressure AP staff for a quick change.
  • Scammers collect org charts, contract calendars, and public signatures to increase trust.
Feature Phishing BEC
Targeting Broad Precision
Payload Malware or credential harvest Invoice or routing change
Detection Security tools flag anomalies Often silent to filters
Best defense User caution + tech Human verification + process controls

A fraudulent email with the subject "bec" (business email compromise) displayed on a sleek, modern computer screen. The screen is set against a dark, shadowy backdrop, creating an ominous and foreboding atmosphere. The email header is prominently featured, with the "bec" text in a bold, attention-grabbing font. Subtle lighting from the screen casts a soft glow, illuminating the deceptive nature of the scam. The entire scene is captured with a high-resolution, wide-angle lens, emphasizing the scale and impact of this type of cyber attack on unsuspecting businesses.

“Verification by a trusted phone number breaks the pressure attackers create.”

For a detailed legal and loss-allocation perspective on these incidents, see this analysis of fraudulent mail and recovery options at allocating loss after a business email.

How BEC scams work: impersonation, spoofing, and account takeover explained

These attacks move from simple tricks to full compromise by combining look‑alike senders, forged headers, and stolen access. The result is messages that appear normal but carry false instructions.

A single swapped character or added underscore can turn a routine request into fraud. Scammers craft near‑identical addresses like VendorOne@work.domain.com versus VendorOne@work_domain.com. That tiny change fools a quick glance.

A stark, minimalist office scene. A laptop sits on a sleek wooden desk, its screen displaying an open email interface. The email header shows a forged sender address, mimicking a trusted colleague or executive. The background is softly blurred, emphasizing the deceptive nature of the email content. Dramatic, moody lighting casts long shadows, evoking a sense of unease and subterfuge. The image conveys the sophisticated tactics used in business email compromise (BEC) scams, where impersonation and account takeover tricks unsuspecting victims.

How do impersonation and look‑alike addresses work?

Impersonation uses small visual edits to the sender line. Attackers swap periods, underscores, or letters (rn vs m) to mimic a trusted address or domain.

  • Look‑alikes exploit haste and familiar names.
  • Short, plausible domains magnify the effect.

How does spoofing hide forged origins?

With spoofing, headers and the envelope can be forged so a message appears internal. Without strict auth, a spoofed email slips past filters and into an approver’s inbox.

What happens in account takeover?

When attackers gain real mailbox access, the messages show authentic signatures and threads. Only odd wording, new payment details, or a callback reveal that the account was compromised.

Method How it looks Best check
Impersonation Near‑identical sender lines Compare full sender and domain
Spoofing Forged headers, appears internal Verify SPF/DKIM and ask by phone
Account takeover Real threads, real signature Out‑of‑band confirmation and MFA logs

“Treat routing or payment changes as high risk until independently verified.”

Spotting the scam in time: step-by-step verification before you send money

A calm, deliberate pause is the single best defense when a payment request arrives. Take time to verify, and treat routing or payroll changes as high risk until confirmed by an independent channel.

How do I control the impulse when a message demands urgency or secrecy?

Stop. If a request feels rushed or private, hit a hard stop. Walk away for a few minutes. That short pause breaks the pressure attackers rely on.

How should I confirm through a second channel I independently verify?

Call a known phone number from your directory or vendor contract. Do not use the number or contact in the suspicious emails.

If voice isn’t possible, message via an already‑trusted chat (Teams/Slack). Experts Larson and Tokazowski note attackers may register near‑match numbers, so confirm the number independently.

What checks should I perform on sender details and domains?

Verify the full email address, display name, and reply‑to for mismatches.

Paste the sender’s domain into a browser. If the site is missing or looks odd, treat the change as suspect. Use vendor paperwork or whois data for added information.

A crisp, close-up view of a smartphone screen displaying a "Verify Phone Number" prompt. The screen is sharply focused, with a clean, minimalist interface and a prominent, bold request for the user to confirm their phone number. The lighting is soft and diffused, creating a sense of clarity and authenticity. The smartphone is held at a slight angle, emphasizing the interactive nature of the verification process. The background is blurred, keeping the focus solely on the critical task at hand, with a subtle gradient providing a subtle, professional atmosphere.

  • Start with a hard stop: pause when an urgent payment request arrives.
  • Use a second channel: call a trusted phone or message a saved contact; never trust numbers inside the suspicious message.
  • Validate independently: confirm the number or address from contracts or your directory.
  • Challenge changes: any “change direct deposit” or new beneficiary must trigger a callback before touching account data.
  • Document and escalate: log who you contacted and alert IT/finance if you confirm a scam; follow guidance like Microsoft’s anti‑phishing steps and tips on stopping phishing from reaching your inbox.

“Verify out‑of‑band, every time, before irreversible payments—this single habit prevents most BEC scams.”

Common BEC playbooks your team must recognize

Fraudsters stage urgency around real events—payroll runs, month‑end closes, and travel days. Recognizing the playbook helps teams stop harm before money leaves the account or sensitive files are exposed.

A dimly lit office, with a laptop screen casting an eerie glow on the face of a malicious hacker. In the foreground, a web browser displays a meticulously crafted email, the subject line reading "Urgent Request" - the bait for a Business Email Compromise (BEC) scam. The hacker's fingers hover over the keyboard, crafting a deceptive message that will exploit the victim's trust. The middle ground shows documents and financial records, hinting at the sensitive data that could be compromised. The background is shrouded in shadows, symbolizing the hidden nature of these insidious attacks. The lighting is dramatic, creating a tense and unsettling atmosphere, reflecting the gravity of the situation. This image aims to capture the essence of a BEC scam, a threat that every organization must be vigilant against.

CEO fraud and executive impersonation

CEO impersonation pressures staff to wire funds or hand over W‑2s. Attackers discourage callbacks and use short, authoritative notes so people act fast.

Fake invoices and vendor banking changes

A forged “bank update” with a true-looking invoice moves funds to a mule account. Always confirm new beneficiary details by calling a known vendor number—not the one in the suspicious message.

Payroll diversion and direct deposit requests

Payroll diversion begins as an employee‑style request to change direct deposit. Verify any direct deposit information change by phone or HR portal before updating payroll.

Data theft via HR and finance targets

HR and finance hold lists and W‑2s that fuel later attacks. Treat bulk data or roster requests as high risk and require manager sign‑off.

Gift card requests and serial numbers

Attackers ask staff to buy a gift and send serials. Serial numbers are effectively cash—traceback and recovery are unlikely. Treat any card request as a red flag.

Playbook Typical goal Quick defense
CEO impersonation Urgent wire or sensitive records Out‑of‑band callback to known number
Vendor banking change Redirect payments to mule account Dual approval + vendor contract verification
Payroll diversion Change direct deposit for theft HR verification via employee file and phone
Data theft (HR/Finance) Harvest records for future fraud Manager approval + minimal data sharing

“Pause and verify: a quick call stops most compromise attempts.”

Prevention that works: controls, training, and tooling to reduce risk now

Small technical choices—where you host accounts and how you require sign‑ins—determine risk more than any single training session. Layered controls, clear checks, and tooling stop most compromise attempts before they reach payables.

A secure email gateway stands tall, its sleek chassis a testament to advanced cybersecurity. Glowing indicator lights pulse rhythmically, conveying a sense of vigilance. The device is captured in a crisp, high-resolution photograph, illuminated by soft, directional lighting that casts subtle shadows, emphasizing its robust construction. The background is slightly blurred, creating a sense of depth and focus on the gateway, which occupies the central frame. The overall mood is one of reassurance and confidence, reflecting the effectiveness of this crucial tool in safeguarding against email-based threats.

Own your identity: host critical workflows on your domain and deploy secure email gateways to block spoofed messages at the perimeter. Strong spam filters reduce noisy threats so analysts focus on real risks.

Harden access: enforce MFA/2FA and conditional access on email and finance apps. Watch for impossible travel and odd sessions; these signals catch unauthorized access early.

  • Dual control: require separate initiator and approver for wires/ACH and mandate an out‑of‑band callback to the vendor phone number on file before any beneficiary change.
  • Admin hygiene: restrict forwarding rules, monitor OAuth grants, and limit service account permissions used by finance tools.
  • Simulate and train: run tailored simulations and social engineering workshops; coach employees who fall for tests to raise overall resilience.

Operationalize defenses: standardize a one‑page payment checklist, enable bank positive‑pay/ACH filters, and align payment cutoffs so last‑minute requests hit stronger review gates.

“A pause backed by verification and tooling defeats most compromise scams.”

For advanced protection, consider vendor solutions for BEC and EAC protection that combine gateways, user education, and detection to reduce fraud and strengthen security.

Real losses, real lessons: recent BEC scams and what they teach

These incidents show how process gaps and timing let attackers convert routine payments into theft. Learn the patterns so you can spot and stop them.

When ordinary payment workflows meet crafted deception, the result can be millions lost.

Municipal and nonprofit targets face special risk. Peterborough, NH lost $2.3M in 2021 after paying forged invoices; funds moved to crypto and were unrecoverable. A San Francisco nonprofit lost $650K when attackers impersonated a contractor. Lean teams and mission pressure make these groups prime targets.

Global enterprises: vendor impersonation at massive scale

Large companies are not immune. Toyota Boshoku (Europe) reported about $37M lost after account details were altered. Between 2013–2015, one fraudster stole over $120M from Google and Facebook with forged supplier invoices.

A stark, realistic scene depicting the deceptive tactics of a Business Email Compromise (BEC) scam. In the foreground, a computer screen displays a fraudulent email, meticulously crafted to resemble a legitimate business communication. The middle ground reveals a perplexed office worker, brow furrowed, as they scrutinize the suspicious message. In the background, a shadowy figure lurks, the mastermind behind the scheme, casting an ominous presence. The lighting is somber, casting long shadows and emphasizing the gravity of the situation. The angle is slightly tilted, conveying a sense of unease and disorientation, mirroring the victim's experience. The overall mood is one of tension and cautionary tales, underscoring the very real consequences of falling prey to such deceptions.

Timing and tactics: why Fridays and holidays are prime time

Attackers pick moments that compress verification. Fridays, closings, and holidays create time pressure that pushes staff to approve changes without a callback.

“Out-of-band verification before funds leave is the single habit that prevents most losses.”

Case Loss Method Key lesson
Peterborough, NH $2.3M Forged invoices → crypto Public vendor processes need strict callbacks
Toyota Boshoku (Europe) ~$37M Altered account info Dual control and contract checks stop vendor edits
Facebook / Google example $120M+ Supplier impersonation Verify vendor details beyond thread context
Treasure Island (nonprofit) $650K Contractor impersonation Lean teams must adopt strict payment pause rules
  • Recovery is limited: once money converts to crypto or mule rails, it’s often gone.
  • Controls work: confirmed callbacks, dual approvals, and leader sponsorship (including the CEO) close the gap attackers exploit.

Conclusion

A simple two-minute check often costs attackers the window they need. Regular verification and clear rules protect funds and data more than any single tool.

Reinforce defaults: host critical workflows on your corporate domain, enforce 2FA, tighten account access, require dual control for wires/ACH, and mandate out‑of‑band callbacks for high‑risk requests.

Train people to confirm the full email address, domain, and reply‑to, then call a known phone number. Treat any “change direct deposit” or direct deposit information update as high risk.

Report incidents quickly to the FBI IC3, notify banks, and preserve logs. Vigilance, simple process checks, and consistent response make BEC and email compromise scams far less effective.

FAQ

How did a company lose millions to a deceptively simple email request?

Attackers combined urgency, authority, and a plausible payment request. They impersonated an executive or vendor using a look‑alike address, asked for an immediate wire or change to direct deposit information, and pressured staff to skip normal verification. The result: a fast transfer before anyone questioned the request.

What makes targeted compromise different from mass phishing?

Targeted compromise focuses on a specific organization and its people. Instead of bulk messages, attackers research roles, contacts, and payment procedures. They exploit trust and routine—sending tailored messages that mimic real workflows so recipients lower their guard.

What is email spoofing versus account takeover?

Spoofing forges headers or uses look‑alike domains to appear legitimate without accessing an account. Account takeover means the attacker has compromised valid credentials and can send authentic messages from a real inbox. Both deceive recipients, but takeover is harder to detect because messages look normal.

Which red flags should make staff pause before sending money?

Pause when a message demands secrecy, rapid payment, or bypasses normal approvals. Watch for mismatched reply‑to addresses, subtle domain typos, unusual signature changes, or last‑minute banking updates. Always verify outside the message before acting.

How should teams verify a suspicious payment request?

Use a second channel you independently trust—call a known number on file, not the one in the message. Confirm details with the requester’s manager and follow dual‑control procedures for outgoing wires or ACH. Document the verbal confirmation and the steps taken.

What common playbooks do attackers use against finance and HR?

Expect CEO impersonation, supplier invoice fraud, payroll diversion, and HR data requests. Attackers often request banking changes, tax forms, or employee lists. Gift card requests and emergency vendor payments are also frequent because they convert quickly to cash.

What technical controls reduce the risk of impersonation and spoofing?

Implement domain protections like SPF, DKIM, and DMARC to block forged senders. Host mail on a controlled domain and route through a secure email gateway. Enforce multi‑factor authentication (MFA) and conditional access to limit account takeover.

Which operational policies make wire transfers safer?

Require dual approvals for all wire and ACH transfers. Maintain an independent vendor contact list and mandate out‑of‑band callbacks to verified phone numbers. Log and review change requests to payment details before any execution.

How often should staff receive social engineering training and simulations?

Conduct initial onboarding training, then refresh at least quarterly. Run realistic simulations periodically—monthly or quarterly depending on risk—and review results with targeted coaching. Continuous reinforcement keeps verification habits sharp.

Why are Fridays and holidays high‑risk times for fraud?

Attackers exploit reduced staffing and urgency near deadlines. Teams are more likely to bypass checks to close tasks. Extra vigilance and stricter approval gates during these periods can prevent costly mistakes.

What should organizations do immediately after detecting a suspected compromise?

Isolate affected accounts, rotate credentials, and enforce MFA reset. Notify banking partners and place fraud alerts on pending transfers. Preserve logs, inform legal and incident response, and contact cybersecurity experts and law enforcement as needed.

Can secure email gateways stop these attacks entirely?

Gateways block many threats but cannot eliminate risks driven by human trust. They help detect spoofing, phishing links, and known malware. Combine tooling with policies, verification procedures, and employee training for effective defense.

How can companies limit the social information attackers use to impersonate staff?

Reduce public details on LinkedIn and corporate directories. Restrict who can view employee lists and vendor relationships. Teach staff to limit personal info online and to be mindful of what they share publicly.

What recovery options exist if funds are wired to a fraudster?

Contact the sending and receiving banks immediately to request a recall or freeze. File a police report and notify authorities such as the FBI’s Internet Crime Complaint Center (IC3). Time is critical; early action increases chances of recovery.

Who should I contact for expert help if my organization is targeted?

Engage your internal IT security team first. If the incident is complex, hire a reputable incident response firm and notify your bank and legal counsel. Report the incident to law enforcement and industry‑specific regulators where required.

Ethan Cross

Ethan Cross is a cybersecurity analyst and tech journalist with over a decade of experience in ethical hacking, malware analysis, and digital forensics. At HakTechs.com, he delivers in-depth reports, security tips, and expert analysis to help readers stay ahead of emerging cyber threats.