3. Beyond email
Business email compromise and payment fraud
Business email compromise (BEC) is where social engineering gets expensive. Rather than casting a wide net, the attacker studies one organisation and goes after its money directly. BEC consistently causes some of the largest financial losses of any cybercrime category, and small firms are targeted as readily as large ones.
CEO fraud
An email arrives appearing to come from your chief executive or another senior figure: "Are you at your desk? I need an urgent payment made and I'm about to go into a meeting, so I can't talk. Keep this between us for now." It combines authority, urgency, and secrecy, the exact levers from Section 1, and it is aimed at staff who can move money or buy gift cards.
The sender may be a lookalike domain, a spoofed address, or occasionally the executive's genuinely compromised account. Either way the defence is the same: verify any unusual payment instruction with the person directly, by phone or in person, using contact details you already hold. A real executive will thank you. Only a fraudster is harmed by a thirty-second phone call.
Invoice and payment diversion fraud
The most damaging variant often starts with a quietly compromised mailbox, yours or a supplier's. The attacker reads correspondence for weeks, learning who bills whom, for how much, and in what format. Then, at the right moment, they send a perfectly plausible message: the supplier has "changed banks", and here are the new account details for the invoice that really is due.
Everything about the email can be genuine except the sort code and account number. Sometimes the attacker hijacks a real email thread, so the fraudulent message sits underneath months of authentic conversation.
The controls that stop it
- Treat any change of bank details as high risk, always. Verify by phone on a number from your own records, not from the email requesting the change
- Follow your organisation's payment process every time. Dual approval for payments exists precisely for this scenario, and "the CEO said skip it" is a red flag, not an authorisation
- Be suspicious of pressure, secrecy, and end-of-week or end-of-day timing, which attackers use to shorten your thinking time
Process beats judgement here. The whole attack is designed to look legitimate, so the defence cannot rely on spotting it by eye.
› Course contents
How social engineering works
Spotting phishing emails
Beyond email
Responding and reporting
Putting it into practice