The request is the attack
Business email compromise uses a seemingly legitimate business communication to influence a payment or information-sharing decision. A message can impersonate a colleague, executive, or supplier.
A changed instruction deserves verification
Pay attention to unexpected changes in payment instructions, especially when the message discourages normal checks. Verify changes with the relevant person through an established contact method.
Keep a second check in the workflow
A consistent approval process helps teams avoid making exceptions under pressure. If money has already been sent, contact the financial institution promptly and follow the incident-reporting process.
Further reading: FBI: Business Email Compromise. This external reference does not imply a partnership or integration.
Browse all resources