All Articles

Cyber Security · September 2026

The email scam that costs more than ransomware

Business email compromise doesn't lock your files or crash your systems. It empties your bank account while looking exactly like a normal day at the office.

You get an email from your supplier. The message says their bank details have changed and asks you to update the information for the next invoice. You make the change. Two weeks later, your actual supplier calls asking where their payment is. The money is gone, and the bank won't reverse the transfer because you authorised it. This is business email compromise, and in 2022 the FBI handled complaints that added up to more than $590 million in losses. Those are just the domestic cases that got reported.

Why this lands differently than other threats

Ransomware makes noise. Your files stop opening, a screen pops up demanding payment, and everyone knows something is wrong. Business email compromise is the opposite. It uses your own email system, your own processes, and your own trust in the people you work with. There's no malware to detect. No files get encrypted. Someone just asks you to move money or share information, and because the request looks legitimate, you do it.

The attacker has often spent days or weeks watching. They know who approves invoices, who handles payroll, and what your usual payment process looks like. When they send the fraudulent email, it fits perfectly into your normal routine. That's why it works. And that's why most antivirus software won't catch it.

What it looks like when it happens to you

The most common version is the fake invoice. You get an email that looks like it's from a supplier you work with regularly. The tone is right, the signature block matches, and the request is reasonable. They're just updating their banking information. You forward it to accounting, the payment goes out, and nobody realises anything is wrong until the real supplier follows up on the unpaid bill.

Another version targets payroll. The attacker pretends to be an employee and sends an email to HR asking to update their direct deposit details. Paycheques start going to an account the attacker controls. Sometimes the attacker impersonates your own executive, sending an urgent request to transfer funds for a confidential deal or legal matter. The pressure and the authority make people act fast and skip the usual verification steps.

In 2022 there were 35 million business email compromise attempts. Not all of them succeeded, but enough did that it's now one of the costliest cyber threats facing small and mid-sized businesses.

The tactics that make detection harder

Attackers often set up automatic forwarding rules in a compromised email account. Every message that comes in gets copied to an address they control. Even if you change the password, they're still reading your mail. They create rules that hide specific emails or delete replies so the conversation stays invisible to everyone else in your organisation.

They also register domains that look almost identical to yours. If your domain is example.com, they might register examp1e.com and send emails from that address. At a glance, especially on a phone, it's easy to miss. These lookalike domains often lead to fake login pages designed to steal more credentials, which the attacker then uses to move deeper into your network or target your clients and colleagues.

What you can do starting Monday

The single most effective step is to verify any request involving money or sensitive information through a second channel. If you get an email asking you to change payment details, pick up the phone and call the person at a number you already have on file. Not the number in the email. This one habit stops most of these scams cold.

Turn on multi-factor authentication for every email account in your business. It won't stop a convincing impersonation email, but it makes it much harder for an attacker to take over a legitimate account in the first place. Use strong, unique passwords, and consider a password manager if you're not already using one.

Set up email authentication policies. SPF and DMARC are technical terms, but what they do is simple: they make it harder for someone outside your organisation to send email that looks like it came from your domain. Your IT provider or email host can set this up. It's not foolproof, but it closes one of the easier routes attackers use.

Train your team to recognise the warning signs. Urgent requests, pressure to skip normal procedures, unexpected changes to payment details, and messages that ask you not to verify with anyone else are all red flags. Make it easy for people to report suspicious emails without worrying they'll look foolish. The cost of a false alarm is zero. The cost of ignoring a real threat can be six figures.

What most Ontario businesses already have in place

If you're working with a managed IT provider, you likely already have email filtering that blocks obvious phishing attempts and alerts you to suspicious activity like new forwarding rules or logins from unfamiliar locations. Those defences matter, but they're not enough on their own because business email compromise doesn't rely on obvious technical tricks. It relies on human trust and normal business behaviour.

The businesses that handle this well are the ones that combine technical controls with clear, practiced procedures. Everyone knows that payment changes get verified by phone. Everyone knows that urgent requests from executives still go through a quick confirmation step. Everyone knows what to do if something feels off. That consistency turns your team into your best defence, and it's something you can start building this week without buying anything new.

Sources

See our security services

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.