Business Email Compromise: Anatomy of a Six-Figure Loss

Business email compromise is a fraud in which a criminal uses a compromised or convincingly spoofed email account to trick an employee into sending a legitimate payment to the wrong bank account. No system is hacked at the moment the money moves — an authorized person sends a real wire through real channels — which is why it is both the most common way mid-sized businesses lose six figures to cybercrime and one of the most misunderstood losses in insurance.

The loss does not begin the day the wire is sent. It begins weeks earlier, when a criminal quietly takes over a vendor’s email account and starts reading. This article walks through the anatomy of a representative vendor-takeover loss stage by stage — the reconnaissance, the false banking change, the wire, and the discovery — then maps which insurance coverages respond at each stage, where the money gets stuck, and the handful of verification controls that would have stopped the entire chain for the cost of a phone call.

A railroad turnout at dusk with the switch points thrown toward a diverging track, a ground-throw switch stand beside the rails, and a dwarf signal glowing steady green — a visual metaphor for a legitimate payment quietly rerouted to the wrong destination while every indicator reads normal.
A business email compromise loss breaks into nothing — a routine, fully authorized payment is quietly rerouted to a criminal’s account — which is why the coverage analysis turns on deception and verification rather than network intrusion.

What is business email compromise?

Business email compromise (BEC) is the use of a trusted email channel — a real account that has been taken over, or a lookalike domain built to imitate one — to deliver a fraudulent payment instruction that an employee then carries out voluntarily. There is no ransomware note, no locked server, and often no malware anywhere in the victim’s own systems. That absence of a break-in is what separates BEC from most of what a cyber liability policy was originally built to cover, and it shapes every coverage question that follows.

The scale is not theoretical. The FBI’s Internet Crime Complaint Center logged 21,442 BEC complaints in 2024 with reported losses near $2.8 billion — the second-costliest crime category it tracks, per the IC3 2024 Annual Report. Averaged out, that is a loss well into six figures per reported incident — and those are only the losses reported to the FBI.

Most businesses discover where BEC sits in their commercial insurance program only after the money is gone. A fast quote never surfaces the question; it prices a limit and moves on. Understanding how the loss actually unfolds — the risk you are keeping versus the risk you are transferring — is most of the protection, which is why the anatomy matters more than the premium.

Stage one: how does the vendor takeover start?

The most damaging BEC variant does not start in your systems at all. It starts in a vendor’s.

A criminal phishes credentials from someone at a supplier, subcontractor, or service firm you already pay — often a smaller company with weaker email security than yours. With mailbox access, the criminal does something most people don’t expect: nothing. For weeks, they read.

They learn which of your invoices are open and for how much. They learn who on your side approves payments, what the vendor’s invoice template looks like, how the vendor’s project manager signs off, and when the next big draw or settlement is due. They often set mailbox rules that hide replies, so the vendor’s own employee never sees the conversation happening in their name. This patience is the reason the eventual instruction looks perfect: it is assembled from real correspondence.

This stage matters for Iowa businesses for a second, less obvious reason. A compromised mailbox is itself a data breach — and if it contained personal information, Iowa Code chapter 715C notification duties can apply to the mailbox owner regardless of whether any money ever moves. The wire is the headline loss; the breach obligations run on their own track.

Stage two: what does the fraudulent instruction look like?

Vendor email compromise is the variant in which the fraudulent banking change arrives from the vendor’s real email account — real thread, real invoice, real amounts — with only the remittance details altered. It is the hardest variant to catch precisely because everything except the account number is true.

The message lands in accounts payable mid-project, referencing the correct open invoice. It explains that the vendor has changed banks — an audit, a new treasury platform, an acquisition — and asks that the pending payment go to the new account. The tone matches. The signature block matches. There is usually gentle time pressure tied to a real deadline your team already knows about.

For a business in the payment chains that define the Midwest economy — a general contractor funding a subcontractor draw, a manufacturer settling with a supplier, a firm wiring a closing — the instruction imitates a transaction the team executes routinely. An AP clerk updates the vendor record, the controller approves the batch, and a genuine six-figure payment leaves through the bank exactly as designed.

Stage three: what happens after the wire is sent?

Silence — and the silence is engineered. The criminal, still inside the vendor’s mailbox, intercepts the follow-up traffic. Days or weeks pass until the real vendor calls about the unpaid invoice, and both companies simultaneously discover the payment went somewhere neither of them controls.

The first hours after discovery matter more than anything that follows. Banks can sometimes freeze or recall a wire if notified fast enough — recovery windows are measured in hours, not weeks — and the FBI’s IC3 operates a recovery-asset process for exactly this scenario. After that window closes, the funds have typically hopped through several accounts and out of practical reach. The business has now paid the invoice once to a criminal and still owes it once to the vendor — the six-figure loss, doubled in effect if the underlying obligation still stands.

Which insurance coverages actually respond — and where does the money get stuck?

This is where the anatomy turns into a coverage analysis, and the answer is less comforting than most buyers assume.

The stolen wire itself is a deception loss, not an intrusion loss. On a cyber policy it falls under the social engineering or fraudulent-instruction insuring agreement — which, as we covered in why most cyber policies sublimit social engineering and wire fraud, is commonly capped at $100,000 to $250,000 regardless of the headline limit. A crime policy may respond through its own social engineering endorsement, typically sublimited as well, and the two policies do not stack automatically — which policy pays, and in what order, is a program-design decision made before the loss or not at all.

The surrounding costs sort differently. If your own mailbox was compromised, forensics and legal guidance on notification duties generally sit in the cyber policy’s breach-response coverage — the same machinery that responds to a ransomware event, and usually at full limits rather than the deception sublimit. If the takeover happened entirely on the vendor’s side, your breach-response coverage may never trigger at all, and the vendor’s insurance becomes a recovery question your attorney pursues, not a coverage you control.

So a business carrying a $1 million cyber limit can walk through a textbook BEC loss and find that the coverage actually reaching the stolen money is a fraction of what the declarations page suggested. Coverage that looked fine on paper, failing when it actually mattered — that seam is exactly what this cluster of articles exists to map.

What would have prevented the loss?

Almost everything about this loss is preventable, and the controls are procedural rather than technological.

Callback verification is the discipline of confirming any new payee or banking change by phone, using a number already on file — never a number supplied in the requesting email — before any payment moves. One two-minute call to the vendor’s known number collapses the entire scheme at stage two. Around that anchor control sit the supporting cast: dual authorization above a dollar threshold, a mandatory waiting period on vendor bank-detail changes, external-email flagging, multi-factor authentication on your own mailboxes, and payment-change training for everyone in the approval chain.

These controls do double duty. They prevent the loss, and they are also frequently written into the policy as conditions — many social engineering insuring agreements pay only if the verification procedure was followed, a fine-print reality covered in how sublimits, exclusions, and conditions actually work. An unenforced procedure can cost a business the loss and the coverage in the same afternoon. The same controls are also what persuade an underwriter to raise the deception sublimit — and in the current cyber market, which has softened substantially as of mid-2026, documented payment controls buy more coverage improvement than they ever have.

What should you do before this email arrives?

Trace the money before a criminal does. Write down every path a payment can leave your business — who can initiate, who approves, what verifies a banking change — and then read the social engineering language in your cyber and crime policies against that map: the sublimits, the conditions, and the largest wire you sent last year.

That exercise is a core module of the Business Risk Diagnostic™, Avanti Group’s pre-quote due diligence: mapping how money actually moves through your business against how your cyber liability coverage would respond at each stage of the loss you are statistically most likely to suffer. Most of the market quotes fast and hopes; the Diagnostic reads the seams in your commercial program before an underwriter — or a criminal — reads them first.

Frequently Asked Questions

What is business email compromise in simple terms?

A criminal uses a trusted email account — hacked or convincingly faked — to send a payment instruction that looks legitimate, and an employee with real authority sends real money to the criminal’s bank account. No malware or system intrusion is required on the victim’s side; the fraud runs entirely on trust in the email channel.

What is vendor email compromise, and why is it harder to catch?

Vendor email compromise is the variant in which the fraudulent banking change comes from a vendor’s genuine email account after a criminal takes it over. The invoice, amounts, thread history, and signature are all real — only the remittance details are false — so standard red-flag training built around suspicious senders and bad grammar never fires.

Does cyber insurance cover a business email compromise loss?

Partially, in most cases. The stolen funds fall under the policy’s social engineering or fraudulent-instruction insuring agreement, which is commonly sublimited to $100,000–$250,000 regardless of the full policy limit. Breach-response costs for a compromised mailbox generally sit at full limits, but the wire itself usually does not. Crime policies add a second, also-sublimited path, and the two must be coordinated deliberately.

What should a business do in the first hours after discovering a BEC loss?

Call the bank immediately and request a recall or freeze on the wire, file a complaint with the FBI’s IC3 — which operates a financial fraud recovery process for rapid reports — notify your insurance broker so claim conditions are preserved, and preserve the emails rather than deleting them. Recovery odds drop sharply after the first 24 to 72 hours.

What single control prevents most business email compromise losses?

Callback verification: confirming every new payee or banking-detail change by phone to a number already on file — never one supplied in the email requesting the change — before any money moves. It defeats even a perfect vendor-takeover email, and many insurers make it a condition of social engineering coverage, so it protects the claim as well as the cash.

Want to compare your options?

Click the button below to head to our quotes page where you can enter some basic information to have our team help with your insurance!

Ready to get started?

Start Your Quotes Today

Enter some basic information below to get the process started.

Service Options