Business Email Compromise: How One Email Can Cost Millions
5 June 2026 · 6 min read
The scam that doesn't need malware
Business Email Compromise (BEC) is fraud, not hacking in the Hollywood sense. An attacker impersonates someone your finance team trusts — the CEO, a supplier, a law firm — and convinces them to send money or change payment details. Because there's no malicious attachment or link, traditional antivirus and firewalls see nothing wrong. Gulf businesses are prime targets: high-value trade flows, frequent international transfers, and organizations where payment requests from senior leadership are acted on quickly.
How it actually unfolds
Most BEC attacks start with a quietly compromised mailbox — often via a phished password — or a lookalike domain one letter off from a real supplier's. The attacker then watches silently for weeks, reading invoice threads and learning who pays whom, how much, and in what tone. At exactly the right moment — a real pending invoice, a manager traveling — they slip in: 'Please note our bank account has changed for this payment.' The money leaves, and by the time anyone calls the real supplier, it has been moved through multiple accounts.
Red flags your team should know
Train your finance and admin staff to treat these as alarms: any change of bank details, however politely explained; urgency combined with secrecy ('please process today, don't discuss'); requests timed to weekends, holidays or when an approver is traveling; reply addresses that differ subtly from the display name; and suppliers who suddenly 'switched banks.' One simple rule prevents most losses: every change of payment details is verified by a phone call to a number you already have on file — never one provided in the email.
Defenses that actually work
Technical controls close the doors attackers use: multi-factor authentication on every mailbox, DMARC, SPF and DKIM to make your domain hard to spoof, and alerting on suspicious mailbox rules — attackers love auto-forwarding your invoices. Process controls catch what slips through: dual approval on payments above a threshold and the callback rule above. Finally, realistic awareness training makes the human layer skeptical at the right moments.
Data Shield deploys this full defense stack — email security, domain protection, monitoring and staff training — as part of our managed security service. If you'd like us to check how exposed your email environment is today, a free assessment takes less than a week.
Not Sure Where Your Risks Are?
Book a free, no-obligation security assessment. We'll review your environment and show you exactly where you stand — and what to fix first.
Book Your Free Assessment