A locked file icon representing a compromised business email account used to redirect a company payment

Business email compromise, often shortened to BEC, generated $3.05 billion in reported losses in the United States in 2025 across nearly 25,000 complaints, according to the FBI's Internet Crime Complaint Center, making it the second most financially damaging category of cybercrime tracked in the agency's annual report. Unlike a ransomware attack or a wallet hack, BEC does not rely on breaking any technical system at all. It relies on a convincingly worded email arriving at exactly the right moment, and it is increasingly ending with company funds converted into cryptocurrency before anyone realizes what happened.

How a business email compromise attack unfolds

  • Reconnaissance, where the attacker researches a target company's staff, vendors, invoicing patterns, and leadership structure, often using publicly available information
  • Either a spoofed email domain that looks nearly identical to a real one, or an actual compromised email account belonging to an employee, executive, or vendor
  • A message timed around a real event, an upcoming payment, a closing deal, or an executive who is traveling and hard to reach directly
  • A request to change payment details, approve an urgent transfer, or send funds to a new account or wallet address
  • Pressure to act quickly and quietly, often citing confidentiality around a deal or an executive's unavailability to confirm by phone

Why crypto is increasingly the destination

Traditional BEC schemes historically relied on wire transfers, which the FBI's own reporting still identifies as the primary mechanism in most cases. But cryptocurrency has become an increasingly common destination once funds are moved, precisely because it settles quickly and offers attackers a faster path to laundering proceeds through cross chain swaps and international exchanges before a company or bank can intervene. In cases where an attacker convinces a finance team to pay a vendor invoice directly in cryptocurrency, rather than converting stolen funds afterward, there is often no bank in the transaction chain at all to flag or reverse anything.

The invoice and vendor impersonation pattern

This version targets the relationship between a company and a vendor it already pays regularly. An attacker who has compromised either party's email account monitors real invoice conversations, then inserts a message at the right moment claiming that payment details have changed, sometimes specifically requesting a cryptocurrency wallet address in place of the usual bank account. Because the request arrives inside an existing, legitimate email thread, referencing real invoice numbers and real prior conversations, it rarely raises suspicion the way a cold message would.

The executive impersonation pattern

This version relies on hierarchy rather than an existing vendor relationship. An email appears to come from a senior executive, often timed for when that person is traveling or otherwise difficult to reach directly, requesting an urgent and confidential transfer. Employees asked to act quickly on behalf of a superior are often reluctant to question the request or verify it through a second channel, which is precisely the dynamic the scheme depends on.

A step by step walkthrough of a vendor impersonation attack

Walking through a real attack sequence in order shows how ordinary each individual step looks in isolation, which is a large part of why these schemes succeed against companies with otherwise solid security practices.

  • An attacker gains access to a vendor's email account, often through a simple phishing email or reused password, and quietly monitors incoming and outgoing invoice correspondence for weeks
  • Once a real, active invoice conversation with a paying client is identified, the attacker waits for a natural point in the exchange, often right before a payment is due
  • A message is sent from the compromised account, indistinguishable from the vendor's real address, stating that banking details have changed and providing new payment instructions or a wallet address
  • The message often includes a plausible reason for the change, a new accountant, a banking system migration, a merger, to preempt the obvious follow up question
  • The client's accounts payable team, seeing a message inside a real, ongoing thread referencing real invoice numbers, updates its records and sends the next payment to the new destination
  • The vendor eventually follows up asking why payment has not arrived, at which point both parties realize the funds went to an attacker instead

Warning signs employees can learn to recognize

  • A request to change payment or wallet details that arrives by email only, with no accompanying phone call from a known contact
  • Subtle spelling differences in a sender's email domain that are easy to miss at a glance, such as a swapped letter or an added dash in the company name
  • Unusual urgency paired with a request for confidentiality, particularly language discouraging the recipient from mentioning the request to a manager or colleague
  • A change in writing style, tone, or email signature format compared to previous correspondence with the same vendor or executive
  • A request timed suspiciously close to a public event, a holiday, an executive's known travel schedule, or a company announcement that made the timing easy to predict

Why these attacks succeed against sophisticated companies

BEC does not fail because a company lacks technical security. It succeeds because it targets a normal business process, an executive request, an invoice update, a vendor relationship, and simply inserts a fraudulent instruction into that process at a moment when questioning it feels awkward or slow. Once a payment is sent in cryptocurrency, the company faces the same underlying problem covered in our guide on preserving evidence after a business wallet incident, since what happens in the hours immediately afterward has an outsized effect on whether any part of the loss can be traced or recovered.

Key Point

A change to payment instructions, whether a new bank account or a new wallet address, should always be confirmed through a phone call to a known, previously verified number, never through a reply to the same email thread where the change was requested.

The scale of the problem

The FBI's 2025 data shows BEC complaints and losses both rising for the third consecutive year, and the agency has separately noted that cryptocurrency now plays a role in the majority of its highest loss fraud categories overall. Companies of every size are targeted, though small and mid sized businesses are often hit hardest relative to their size, since they frequently lack a formal, mandatory verification step for changes to payment instructions.

Larger organizations are not immune, since attackers specifically research public information such as press releases, earnings calls, and executive travel announcements to time their messages convincingly. A finance department handling dozens of vendor relationships and frequent executive requests can find it genuinely difficult to apply the same level of scrutiny to every single payment change request, which is precisely the volume and pace that these schemes are designed to exploit.

How businesses can reduce exposure

  • Require a phone call to a previously verified number for any change to payment instructions or wallet addresses, with no exceptions regardless of urgency
  • Use a dual approval process for any transfer above a set threshold, requiring sign off from two people who are not both reachable through the same compromised inbox
  • Maintain an allowlist of approved wallet addresses for recurring vendor payments and treat any deviation as an automatic red flag requiring manual review
  • Train finance staff specifically on the pattern of urgent, confidential requests that discourage verification, since this is the mechanism the scheme depends on rather than any technical flaw
  • Monitor for lookalike domains registered close to your own company's domain, which are commonly used to send convincing spoofed emails

When a payment has already gone out in cryptocurrency, the destination wallet can often still be traced even though the transfer itself cannot be reversed, and firms like Coin Trace work with businesses to document that trail for law enforcement and exchange reporting purposes, without ever promising a guaranteed recovery outcome.

What to do in the hours immediately after a fraudulent payment

Speed matters more in a business email compromise case than almost any other type of fraud, because the window in which funds can potentially be frozen at an exchange or intercepted at a bank closes quickly. As soon as a fraudulent payment is suspected, the finance team should immediately halt any further payments to the same account or wallet address and preserve the original email, including full headers, rather than only the message body, since headers often contain technical details that help investigators trace the true origin of the message.

  • Contact your bank or, for a cryptocurrency payment, the receiving exchange if one can be identified, to request an emergency freeze on the destination account
  • File a report with the FBI's Internet Crime Complaint Center as soon as possible, since the agency's recovery asset team has successfully frozen funds in some cases when notified within hours
  • Notify your company's legal counsel and cyber insurance provider immediately, since many policies have strict, short reporting windows that affect whether a claim can be paid
  • Preserve the compromised email account exactly as it is, including full message headers, rather than deleting or resetting it before a forensic review can occur
  • Notify the vendor or executive whose identity was impersonated, since their own systems may also be compromised and other clients could be targeted with the same scheme
business email compromiseBEC fraudcrypto payment fraudinvoice fraudcorporate security

Frequently asked questions

Phishing typically tries to trick a broad group of people into clicking a malicious link or entering credentials. Business email compromise is more targeted, often using a genuinely compromised or convincingly spoofed account belonging to a specific executive or vendor to request a fraudulent payment through what looks like a normal business process.

In most documented cases, the attacker frames the change as a routine update to payment details inserted into an existing, legitimate invoice conversation. Because the request appears to come from a trusted, already established relationship, finance staff often do not apply the scrutiny they would to an unfamiliar payment request.

It depends heavily on speed. Cryptocurrency transactions cannot be reversed once confirmed, but funds sometimes remain briefly at an exchange that can freeze an account if notified quickly. Documenting the transaction and wallet addresses immediately and reporting to the FBI's Internet Crime Complaint Center gives the best chance of any partial recovery.

Requiring a phone call to a previously verified, known number before acting on any change to payment instructions, regardless of how urgent or official the email requesting the change appears. This single step defeats the majority of documented BEC schemes because it removes the compromised email channel from the verification process entirely.

Yes. The FBI's Internet Crime Complaint Center aggregates reports across many victims, which sometimes allows investigators to connect a small individual loss to a larger, active criminal operation they are already pursuing. A report filed quickly can also occasionally support a recovery asset request even for modest amounts, and it always contributes to the broader data used to track and disrupt these schemes.


Sources and further reading


Related reading

What Evidence to Preserve When a Business Wallet Is CompromisedInside a Ransomware Payment InvestigationHow and Where to Report Cryptocurrency TheftInside a Cross Border Asset Tracing Investigation