Business Email Compromise Red Flags: How to Catch Invoice and Payroll Fraud Early
BECemail fraudsmall businessinvoice scamsfinance security

Business Email Compromise Red Flags: How to Catch Invoice and Payroll Fraud Early

TThreat News Editorial
2026-06-09
11 min read

How finance and ops teams can spot business email compromise early and stop invoice, vendor, and payroll fraud before funds move.

Business email compromise does not always look like a dramatic cyberattack. In many cases, it arrives as a routine payment request, a last-minute payroll change, or a short email from an executive who appears to be in a hurry. This guide explains the practical red flags behind invoice fraud email, payroll diversion scam attempts, and other vendor payment scam patterns, then shows finance, operations, and IT teams how to verify requests early enough to stop losses before money leaves the business.

Overview

Business email compromise, often shortened to BEC, is a category of fraud where an attacker uses email impersonation, account access, or social engineering to trick a company into sending money or sensitive data. Unlike broad phishing campaigns, BEC is usually targeted. The message is crafted to fit a real business process: invoice approval, vendor payment updates, executive requests, W-2 handling, or payroll changes.

That is what makes BEC expensive and persistent. The attacker does not need advanced malware if they can fit neatly into an existing workflow. A believable message sent at the right time can bypass technical controls if the human process around it is weak.

For small and midsize organizations, the risk is often concentrated in a few roles:

  • Accounts payable staff who process invoices and banking changes
  • HR or payroll staff who handle direct deposit updates
  • Operations teams that coordinate vendors and contractors
  • Executives whose identities are impersonated for urgency-based requests
  • IT admins who manage the email environment and account security

The good news is that most BEC attempts reveal themselves before the transfer happens. The trick is knowing what to look for and having a simple verification process that people can use under pressure.

If your team already thinks of phishing as a link-clicking problem, it helps to widen the lens. Many BEC messages contain no malicious link or attachment at all. They rely on trust, timing, and process gaps. That means the best defense is a mix of email security, identity protection, and payment verification discipline.

For broader account hardening, it is worth reviewing Password Manager vs Built-In Browser Passwords: Security Tradeoffs That Matter and MFA Fatigue Attacks Explained: How Push Bombing Works and How to Stop It, since compromised credentials often sit behind successful impersonation attempts.

Core framework

The most useful way to catch business email compromise red flags is to review requests through four lenses: identity, context, payment change, and pressure. If two or more lenses show something unusual, treat the request as suspicious until it is independently verified.

1. Identity: who is really sending the request?

Start with the sender, but do not stop at the display name. Attackers know that many employees glance only at the visible name and subject line.

Identity red flags include:

  • A familiar name with an unfamiliar email address or domain
  • A domain that looks close to a real one, with a single extra letter, swapped character, or different top-level domain
  • A reply-to address that differs from the visible sender address
  • Unexpected use of a personal mailbox for business requests
  • An email that appears to come from an executive or vendor contact who normally communicates through another channel

Also consider the possibility of a real mailbox being compromised. If the message comes from the correct address but the tone, timing, or request is unusual, do not assume it is safe.

2. Context: does the request fit normal business behavior?

BEC works best when staff are busy and pattern-matching. A request may look legitimate at first glance because it uses real vendor names, invoice references, or employee details pulled from prior correspondence. Your job is to test whether the request belongs in the current workflow.

Context red flags include:

  • A payment request that arrives outside the normal invoicing cycle
  • A message that references a project, executive, or deadline in a vague way without the usual details
  • A vendor contact suddenly changing communication style, signature block, or formatting
  • An employee asking for a payroll update through an unusual channel or at an unusual time
  • A request that bypasses the normal approver or skips required documentation

A useful question for finance teams is simple: If this email were genuine, what would normally accompany it? A purchase order, signed approval, contract reference, vendor portal update, or voice confirmation may all be expected. Missing process artifacts are often the first clue.

3. Payment change: what exactly is being altered?

The highest-risk BEC messages often center on changing where money goes. The fraud can be framed as an urgent vendor bank account update, a correction to invoice instructions, or a payroll direct deposit change for an employee.

Payment change red flags include:

  • Requests to update bank account details by email alone
  • Instructions to pay a new account for an existing vendor
  • A last-minute demand to reroute a payment already in process
  • Payroll direct deposit changes submitted close to payday
  • Requests to split a payment across multiple accounts without a clear business reason

As a rule, any change to payment destination should trigger an out-of-band verification step. “Out-of-band” means using a channel other than the one that carried the request, such as calling a known phone number already on file.

4. Pressure: why does the sender want speed, secrecy, or exceptions?

Urgency is one of the most consistent features of BEC. The attacker wants the recipient to act before they verify.

Pressure red flags include:

  • Language like “process today,” “confidential,” or “I’m in a meeting, just handle it”
  • Instructions not to call, or to keep the request off normal channels
  • Claims that a vendor relationship, employee paycheck, or executive deadline will be harmed unless the request is rushed
  • Attempts to flatter authority or exploit fear of delay
  • Requests sent late in the day, before holidays, or during travel periods when verification may be harder

If a message creates emotional pressure to skip controls, that is itself a control signal. The proper response is not speed. It is verification.

A simple BEC review checklist

Before approving a payment or account change, ask:

  1. Is the sender identity verified beyond display name?
  2. Does the request fit the normal workflow and timing?
  3. Does it change where money or sensitive data will go?
  4. Is there any pressure to bypass normal approval or verification?
  5. Has someone verified the request through a trusted second channel?

If the answer to the last question is no, stop the process until it is completed.

For teams building stronger recurring controls, this article pairs well with Small Business Cybersecurity Checklist: Essential Controls to Review Every Quarter.

Practical examples

These examples show how BEC often appears in real workflows. The details vary, but the decision points stay consistent.

Example 1: The vendor bank account update

An accounts payable specialist receives an email from a long-term supplier saying the company has changed banks and future invoices should be paid to a new account. The email includes a professional-looking letterhead and updated remittance instructions.

What looks normal: the vendor name is correct, the message references existing invoices, and the tone is businesslike.

What should trigger concern: the sender domain is slightly different from the real vendor domain, the request arrives only by email, and the message urges immediate update to avoid service interruption.

Correct response: do not use any phone number in the email. Call the known vendor contact using the number already stored in your system or contract file. If the contact cannot confirm the change through established channels, freeze the update.

Example 2: Executive impersonation for urgent transfer

A finance manager receives a short message that appears to come from the CEO: “Need this wire handled discreetly today. I’m tied up. Reply when ready.” The sender asks to continue over email and provides payment instructions in the next message.

What looks normal: the executive is traveling and sometimes sends brief requests.

What should trigger concern: the message emphasizes secrecy, bypasses normal approval, and introduces a payment outside standard procurement processes.

Correct response: verify live through a known internal method, such as a direct call, secure chat, or executive assistant confirmation. If policy does not require a second approver for exceptional transfers, that policy needs to change.

Example 3: Payroll diversion scam

An HR staff member receives an email from an employee asking to change direct deposit information before the next payroll run. The note is polite and includes the employee’s full name and partial identifying details.

What looks normal: employees do update bank details from time to time.

What should trigger concern: the message comes from a personal email account, arrives right before payroll processing, and asks for speed due to an alleged banking issue.

Correct response: require the employee to use the approved payroll portal or submit the change through a documented HR process with identity verification. Email alone should not be enough to reroute pay.

Example 4: Compromised mailbox, real thread

An attacker gains access to a vendor or employee mailbox and inserts themselves into an existing email thread. Because the message comes from the real account and references a real invoice, it can be especially convincing.

What looks normal: correct email address, correct thread history, familiar names.

What should trigger concern: sudden request to change payment details, subtle changes in writing style, unusual urgency, or attachment naming that differs from prior practice.

Correct response: treat account-change requests as high risk even when they arrive from a legitimate mailbox. Process controls matter precisely because email identity can fail.

Example 5: Text and email combination

An attacker sends a spoofed text message to a payroll admin saying an executive needs a favor, then follows up by email with instructions. Multi-channel social engineering can make the request feel more real.

Correct response: verify through a known number, not by replying to the text or the email. For SMS red flags, see Is This Text a Scam? A Red-Flag Checklist for Suspicious SMS Messages.

Practical controls that stop these examples early

  • Require dual approval for first-time payments, bank detail changes, and urgent wires
  • Maintain a trusted vendor contact list with independently verified phone numbers
  • Separate invoice entry, vendor master changes, and payment release across different roles where possible
  • Disable email-only approval for payroll direct deposit changes
  • Train staff to slow down when a message asks them to move faster than policy allows
  • Flag lookalike domains and external senders in the mail client
  • Review mailbox forwarding rules and sign-in activity when compromise is suspected

Common mistakes

Most successful BEC incidents do not happen because a team had no controls at all. They happen because a sensible control was easy to bypass in one rushed moment.

Trusting familiarity too much

Staff often trust messages that mention real projects, vendors, or executives. Attackers count on that. Familiarity should prompt verification, not replace it.

Checking only the sender name

A display name match is not identity proof. Teams need the habit of checking full addresses, reply-to fields, and whether the request matches established behavior.

Allowing email to change payment destinations

If email alone can update bank details or payroll information, the process is fragile. These changes should require a separate verification path.

Overriding process for senior staff

Many fraud attempts use executive authority as leverage. A healthy process protects executives too. No one should be able to bypass payment controls through urgency alone.

Relying on one person to catch everything

BEC prevention fails when all judgment sits with one busy employee. Shared checklists, second approvers, and clear escalation paths reduce single-point mistakes.

Ignoring account compromise after a near miss

If an attacker used a real mailbox or replied inside a legitimate thread, the problem may be larger than one email. Review account security, MFA posture, forwarding rules, and recent sign-ins. If credentials may have been exposed, use a response process similar to your broader account exposure playbook, and consider reviewing Have I Been Breached? How to Check Exposure and Secure Your Accounts.

Treating BEC as only a finance problem

Finance may be the target, but IT, HR, procurement, and leadership all shape the environment that allows or blocks fraud. Strong BEC prevention is cross-functional.

When to revisit

BEC defenses should be revisited whenever your business process changes or attackers gain a new way to impersonate trust. This is not a one-time training topic. It is a recurring operational control.

Review your process again when:

  • You add a new payment platform, ERP, or payroll system
  • You onboard new finance, HR, or procurement staff
  • You start using a new vendor portal or invoice automation tool
  • Your executives change travel patterns or delegate approvals differently
  • You detect lookalike domains, phishing, or suspicious mailbox activity
  • You experience a data breach, credential exposure, or account takeover concern
  • Your company grows and one-person approval steps are no longer safe

A practical quarterly review can be short:

  1. Test whether bank account changes still require out-of-band verification
  2. Confirm vendor contact records use trusted numbers, not numbers copied from recent emails
  3. Audit who can change vendor master data and payroll settings
  4. Review mail security settings for external sender banners, forwarding rules, and MFA coverage
  5. Run a tabletop exercise: a fake executive wire request, a vendor bank update, and a payroll change request
  6. Make sure staff know how to escalate suspicious requests without delaying legitimate work

If you suspect a live BEC attempt:

  1. Pause the payment or account change immediately
  2. Verify through a known second channel
  3. Alert finance lead, IT, and the process owner
  4. Check whether any mailbox or account may be compromised
  5. Preserve the email and headers for internal review
  6. If funds were sent, contact the financial institution right away and document the timeline
  7. Reset credentials and review MFA if account misuse is possible

The goal is not to make every payment process slow. It is to make risky changes deliberate. The strongest BEC prevention programs are usually simple: clear approval thresholds, mandatory second-channel verification for payment changes, protected accounts, and a team culture that treats urgency as a reason to verify.

That combination stays useful even as attacker tactics evolve. The wording of the scam may change. The core warning signs usually do not.

For organizations tightening adjacent controls, it may also help to review Passkeys Explained: Where They Work, Where They Don’t, and When to Switch and What To Do After a Data Breach: Priority Checklist for the First 24 Hours, especially if your concern extends beyond payment fraud into account security and incident response.

Related Topics

#BEC#email fraud#small business#invoice scams#finance security
T

Threat News Editorial

Security Editor

Senior editor and content strategist. Writing about technology, design, and the future of digital media. Follow along for deep dives into the industry's moving parts.