Business email compromise in the AI era: what small businesses must change in 2026
Business email compromise (BEC) is a fraud technique in which an attacker uses email to impersonate someone your company trusts — an executive, a vendor, a payroll provider, an attorney — and convinces an employee to send money or sensitive data to the wrong place. There is usually no malware to detect and no system breach to find: the attack succeeds by getting a legitimate person to take a legitimate-looking action.
Why BEC is the most expensive threat most small businesses face
Ransomware gets the headlines, but business email compromise quietly extracts more money from ordinary companies than almost any other cybercrime. The FBI's Internet Crime Complaint Center has attributed roughly $2.8 billion in reported U.S. losses to BEC in 2024 alone — and reported losses understate the real number, because many businesses never file.
BEC hits small and mid-sized businesses disproportionately hard for a structural reason: the entire attack rests on payment and approval processes, and smaller companies often run those processes through one or two people, over email, with no independent verification step. A fraudulent $80,000 wire is a bad quarter for an enterprise; for a 30-person company it can be the year's profit.
How AI changed business email compromise
Until recently, employees were taught to spot BEC by its seams: odd grammar, strange phrasing, generic greetings. Generative AI removed the seams. Three shifts matter for 2026:
- Flawless, personalized lures at scale. Attackers now draft fluent, context-aware messages that reference real projects, real colleagues, and real vendor relationships scraped from LinkedIn, press releases, and prior breach data. The "bad English" tell is gone.
- Voice cloning. Current voice models can produce a usable clone of a person's voice from a short sample of clean audio — a podcast appearance, webinar recording, or voicemail greeting is enough. The follow-up phone call that used to confirm a suspicious email can now itself be the attack.
- Deepfake video calls. In the most widely reported case, an employee at the engineering firm Arup transferred roughly $25 million after a video call in which every other participant — including the CFO — was an AI-generated imitation. The tooling behind that attack has only become cheaper and easier since.
The practical conclusion: you can no longer train people to recognize fakes by looking or listening harder. Defenses have to move from "spot the fraud" to processes that stay safe even when the message, the voice, and the face are all convincing.
The five BEC playbooks to brief your team on
- Vendor invoice fraud. The attacker impersonates (or quietly compromises) a real supplier and sends updated bank details before a genuine invoice is due. Often the most expensive variant, because the payment itself is expected.
- Executive impersonation. A message that appears to come from the CEO or CFO asks for an urgent, confidential transfer — increasingly reinforced by a cloned voice call.
- Payroll diversion. "HR" receives a request, apparently from an employee, to change direct-deposit details before the next pay run.
- Account takeover. The attacker gains access to a real mailbox, watches payment conversations for weeks, then inserts new bank details at the decisive moment — from the genuine address, with genuine thread history.
- Professional-services urgency. An "attorney" or "M&A advisor" invokes a confidential, time-critical deal that requires an immediate wire and forbids discussing it with colleagues.
Defenses that survive convincing fakes
The controls below are ordered by leverage. None of them require an enterprise budget; all of them assume the fraudulent message itself may be undetectable.
- Out-of-band payment verification. Any new payee, any change of bank details, and any payment above a set threshold gets verified by calling a number you already had on file — never one supplied in the email or by the caller. This single rule defeats most BEC variants, including deepfakes.
- Dual approval for transfers. Two people, independently, for wires above a threshold. Urgency and confidentiality demands are themselves treated as red flags that trigger more verification, not less.
- Enforced email authentication. SPF, DKIM, and a DMARC policy at
p=quarantineorp=rejectmake it materially harder to spoof your own domain against your employees, customers, and vendors. Guidance from CISA treats this as baseline hygiene. - Phishing-resistant MFA on email accounts. Account takeover is the hardest BEC variant to catch, so preventing the takeover matters most: security keys or passkeys on mailboxes, and alerts on new mailbox forwarding rules — the classic sign an attacker has moved in.
- A vendor bank-change protocol. Agree with your key suppliers, in advance and in writing, how bank-detail changes will be communicated and verified on both sides. It protects both parties and takes an afternoon.
- A finance-team tabletop. Walk your actual approvers through the five playbooks above against your actual payment process once or twice a year. The goal is that "this is exactly what the exercise looked like" fires before the money moves.
If money has already moved: the first hours
Speed matters more than anything else, because recalled wires are recovered wires. Call your bank's fraud line immediately and request a recall and a SWIFT recall message if international. File a complaint at ic3.gov right away — the FBI's Recovery Asset Team has frozen substantial sums when notified within the first 48–72 hours. Preserve the original emails (full headers, not forwards), notify your cyber insurer and counsel, and reset credentials on any mailbox involved before assuming the incident is over: if the root cause was account takeover, the attacker is often still reading.
Where this fits in a broader security program
BEC controls are a subset of a question every growing business eventually has to answer deliberately: which failure modes could materially hurt us, and who owns preventing them? That is the purpose of a structured cybersecurity risk assessment — and as companies adopt AI assistants and agents that read email and take actions, the same impersonation problem extends to software identities, which is the domain of AI agent security. If no one in the business owns these decisions end to end, that gap — not any single tool — is usually the real exposure, and it is the problem fractional security leadership exists to solve.
Common questions
What is the difference between phishing and business email compromise?
Phishing is the broad technique of using deceptive messages to steal credentials or deliver malware, usually at scale. Business email compromise is a targeted fraud that uses impersonation — of executives, vendors, or employees — to trigger payments or data transfers. BEC often involves no malware and no link at all, which is why it slips past technical filters.
Does cyber insurance cover business email compromise losses?
Sometimes, and the details matter. Funds-transfer fraud and social-engineering losses are often sub-limited or excluded unless specifically endorsed, and insurers increasingly require controls like dual approval and out-of-band verification as a condition of coverage. Review the social-engineering endorsement and its limit specifically — not just the headline policy limit.
Does DMARC stop business email compromise?
DMARC prevents attackers from sending mail that spoofs your exact domain, which closes one important route. It does not stop lookalike domains, compromised real accounts, or fraud conducted from a vendor’s genuine mailbox — which is why payment-process controls remain the backbone of BEC defense.
How do deepfake voice and video calls fit into BEC?
They are used to defeat the verification step. The fraudulent email creates the request, and the cloned voice or deepfake video call "confirms" it. That is why callback verification must use a number you already had on file — the security of the check comes from the channel you chose, not from recognizing the person.
What should a small business do first if it has no BEC controls today?
Adopt one rule this week: no new payee and no bank-detail change is acted on without a verification call to a previously known number, and no exceptions for urgency or confidentiality. It costs nothing, requires no software, and defeats the majority of BEC attempts on its own. Build dual approval and email authentication after that.
Talk it through with an operator
If security leadership is becoming a business question for your company, a risk-priority conversation is the fastest way to see whether fractional leadership fits.
Request a risk-priority call