QG Professional Services
- Cybersecurity
- Microsoft & Cloud
Ransomware gets the headlines; business email compromise (BEC) quietly takes more money. It is the fraudulent-payment attack (a finance team wires funds to a criminal because an email convincingly told them to) and its danger is that it often involves no malware at all. There is nothing for antivirus to catch, because the attack is social: a legitimate-looking instruction, sometimes from a genuinely compromised internal mailbox, to change bank details or approve an urgent transfer. Defending against it requires breaking the chain at several points, because any single control can be talked around.
Here is the anatomy, and the controls that actually work.
How BEC unfolds
BEC follows recognisable patterns:
- CEO/executive fraud. An email appearing to come from a senior executive instructs finance to make an urgent, confidential payment. Urgency and authority suppress the verification instinct, deliberately.
- Vendor/invoice fraud. The attacker, often inside a compromised supplier or internal mailbox, sends a real-looking invoice or a "we've changed our bank details" notice. The payment goes to the criminal's account. Because it often originates from a genuinely compromised legitimate mailbox, it passes every "does this look real?" test: it is real, just controlled by the wrong person.
- Account compromise as the enabler. Frequently the attacker has already taken over a mailbox (usually via AiTM phishing that stole a session) and spends days reading, learning the payment processes, the tone, the relationships, before striking with perfect context. Hidden inbox rules quietly divert the replies that might expose them.
The through-line: BEC exploits trust and process, not software vulnerabilities. That is why it evades malware defences and why the controls span both technology and human process.
The technical controls
- Stop the account takeover upstream. Most serious BEC starts with a compromised mailbox, so phishing-resistant MFA and Conditional Access are the foundational BEC controls even though they look like identity controls. No mailbox compromise, no insider-grade fraud.
- Defender for Office 365 impersonation protection. Configure anti-phishing policies to detect display-name and domain impersonation of your executives and key suppliers the spoofing BEC relies on. Check your entitlement carefully here: it comes with Defender for Office 365 P1, which Business Premium has always included but which Microsoft 365 E3 only gained in the July 2026 packaging update. E3 tenants that assumed they had impersonation protection before that rollout did not. Once you have it, it still needs configuring: the default policy does not name your executives or your suppliers.
- Email authentication: SPF, DKIM, DMARC: enforced. DMARC at enforcement (reject/quarantine) stops attackers spoofing your own domain to your staff and partners. Most domains publish DMARC in monitor-only and never enforce it; monitor-only stops nothing.
- Hunt for malicious inbox rules. Rules that auto-forward externally or hide replies are a hallmark of an active mailbox compromise. Alert on their creation (Defender and Sentinel can flag it) and review them during any incident.
- External sender warnings and first-contact safety tips. Native banners flagging external and unusual senders give the human a prompt at the decision moment.
The process controls that actually stop the payment
Because the fraudulent email may be genuinely authentic, the payment process itself must be the backstop:
- Out-of-band verification for bank-detail changes and large transfers: mandatory, no exceptions. A call to a known, previously held number (never the number in the email) to confirm any change of banking details or unusual payment. This single control defeats most vendor-fraud BEC, and it must be a rule that urgency cannot override, because manufactured urgency is the whole technique.
- Dual authorisation for payments above a threshold and for all banking-detail changes.
- A culture where verifying an executive's "urgent, confidential" request is expected, not insubordinate. BEC weaponises hierarchy; the counter is explicit permission (and instruction) to verify up the chain.
Why both layers are non-negotiable
Technical controls reduce how many fraudulent emails reach a human and how often mailboxes get compromised. Process controls catch the ones that get through, and some always will, because a payment instruction from a truly compromised CFO mailbox is technically indistinguishable from a real one. Organisations that invest only in email filtering and skip the payment-process controls lose to the vendor-fraud variant specifically, every time.
Practical steps
Check whether your DMARC is at enforcement or merely monitoring: if you are unsure, it is monitoring and stopping nothing. Confirm impersonation protection is configured for your executives and top suppliers. Then verify the one control that matters most: does your finance process require out-of-band verification for banking-detail changes, with no urgency exception? If not, that policy change is the highest-value hour available to you. QG hardens Microsoft 365 against BEC and email-based fraud across both the technical and identity layers, as part of security engagements grounded in how the attack actually plays out.