Business payments

Business email compromise

An email appears to come from an executive, vendor or client. The request sends a business payment or sensitive information to a criminal.

Two people reviewing and writing on paper beside laptops

Recognize the pattern

How it starts

Familiar email threads, executive messages or work communications.

The promise

A confidential urgent project needs immediate payment.

What happens next

Knowledge of the organization and its business makes impersonated messages convincing, using hierarchy and urgency to bypass approvals.

Signs to watch for

  • Secrecy or bypassed finance procedures
  • Subtle email address changes
  • Unexpected gift card or staff data requests

Start with what you can do now

If this happened to you

  1. Contact the bank immediately about the fraudulent transfer.

  2. Notify your security and finance teams and preserve the original email.

  3. File a report at IC3.gov with the transfer details.

More steps for your payment method

What to save

Keep the original records. Use copies to organize the details.

  • Original emails and headers
  • Approvals and verification records
  • Login or forwarding rule changes
  • Recipient details and transfer IDs
Build your record checklist

Before you send money

  • Verify through a known number or in person
  • Require independent payment review
  • Enable MFA and check unusual mailbox rules

These guides explain common patterns. The facts of your situation and your payment provider’s rules determine which steps are available.

A clearer place to start

Your next step starts
with the facts.

Tell us what happened. We’ll review where an analysis may help.

Request a Case Review