The most dangerous phishing email in your business may not contain a suspicious link. It may not contain a link at all.
It may arrive in the middle of a genuine conversation, from an address your accounts team already knows, carrying an invoice that looks exactly as it should. The only unusual detail is a request to pay into a different account. There is an explanation. The timing makes sense. Someone approves it.
That is business email compromise (BEC): a form of targeted email fraud in which an attacker impersonates or takes control of a trusted account to persuade someone to transfer money, change banking details or disclose sensitive information. It works because the message does not feel like a cyber attack. It feels like work.
The email is only the final step
Business email compromise is often described as an email problem, but the email is usually the last visible part of a much longer process.
An attacker may spoof a supplier’s address, compromise a real mailbox through phishing, or gather enough information from public sources to convincingly imitate a familiar person. In more patient attacks, they monitor genuine conversations and learn how the business operates: who approves payments, when invoices are expected, which suppliers are used, and what language people normally use with one another.
Then they wait for a believable moment. A supplier’s banking details change just before payment. A managing director needs an urgent transfer while travelling. Payroll receives a request to update an employee’s account. None of these requests are extraordinary on their own, which is precisely the point.
Why business email compromise gets through good security
Email filtering, endpoint protection, and multi-factor authentication remain essential. They stop enormous volumes of malicious activity before employees ever see it. But BEC is designed to reach the part of the process where technology has less certainty.
A message sent from a genuinely compromised mailbox may pass the usual sender checks. A payment instruction may contain no malware, attachment or malicious URL to detect. Even a spoofed message can look convincing on a phone screen, where the full sender address is easy to miss. To a security tool, the email may be merely unusual. To the recipient, it may be entirely plausible.
This does not mean the tools have failed. It means the attack has moved from testing the security stack to testing the business process.
The real target is the way your business gets things done
Every organisation has shortcuts that exist for good reasons. A trusted supplier is paid without a lengthy discussion. A senior person’s urgent request receives priority. Someone helps a colleague who is under pressure. These behaviours keep a business moving, but they can also be studied and imitated.
Attackers are looking for the distance between the written policy and the way work happens on a busy day. A bank-detail verification rule may be perfectly sensible on paper. The question is whether it survives at 16:45 on a Friday, when the person who normally approves the payment is unavailable, and the supplier says the order cannot be released until proof of payment arrives.
That is why telling staff to ‘be careful’ has limited value. The request has been built to feel safe. People need a repeatable action that does not depend on whether the email happens to make them uneasy.
Verification only works when it leaves the email thread
The most effective interruption is also one of the simplest: verify changes to banking details and unusual payment requests through a separate, trusted channel.
That means calling a known contact on a number already held by the business, not a number supplied in the email being checked. It may mean confirming an executive request through an established internal channel, or requiring a second approver when supplier details change. Replying to the same email thread is not independent verification. If the mailbox is compromised, the attacker may be waiting for the reply.
The control should be designed for the real working day. Staff must know which requests require verification, whom they can contact, what happens if that person is unavailable, and whether they are allowed to delay a payment that feels wrong. A control that depends on improvisation will eventually be improvised away.
Why once-off phishing training does not survive a busy day
Most employees already know, in the abstract, that phishing exists. The difficulty is recognising it when the message uses a real relationship, arrives at a believable time, and asks for something that falls within the recipient’s job scope.
That judgement improves through repetition. Short, regular training keeps the patterns familiar. Simulated phishing gives people practice in context, and the results show which teams or types of requests need more attention. Just as importantly, a well-run programme makes reporting normal. Staff should feel able to pause and ask without being treated as an obstacle to the business.
KnowBe4’s 2025 benchmarking report analysed 67.7 million simulated phishing tests across 62 400 organisations. It found an average baseline susceptibility rate of 33.1%, falling to 4.1% after 12 months of continuous training and simulation. Because the data comes from a security awareness training provider and its customers, it is better read as evidence of the direction and scale of improvement than as a guaranteed result for every organisation.
What should a business do if it suspects BEC?
If a suspicious payment has been made, speed matters. Contact the bank immediately and ask whether the transfer can be stopped or recalled. At the same time, alert the internal IT team or service provider, preserve the relevant messages and payment records, secure affected accounts, revoke active sessions, review mailbox forwarding rules and check whether other contacts have received fraudulent instructions.
Do not continue recovery discussions inside a thread that may be compromised. Move the conversation to trusted contact details and follow the organisation’s incident response, legal, and regulatory notification requirements. Even when no money has moved, a suspected compromise should trigger a review of what the attacker may have read and what other requests they may be preparing.
A stronger security culture creates a moment of hesitation
The goal of security awareness training is not to turn every employee into a cyber security analyst. It is to build a small number of reliable habits into ordinary work: stop when a request changes the expected process, verify through another channel, and report quickly when something feels wrong.
For many SMEs, the obstacle is not understanding the value of training. It is running the programme consistently enough for those habits to take hold. Modules have to be scheduled, simulations need to be relevant, completions must be followed up, and the results need to be documented. When that work is managed, training is less likely to disappear behind the next urgent IT issue.
IronTree’s Security Awareness Training is delivered as a fully managed service. We schedule the training, run realistic phishing simulations, follow up on completion, and provide clear reporting, so your team can build safer habits without adding another recurring administrative task to your IT function.
Not sure how exposed your business is? Get your free Phishing Risk Score. It takes about five minutes, with no obligation.