Iron Cove Solutions Logo
  • MIGRATION
Email Security · Threat Intelligence

Business Email Compromise: How Hackers Trick Companies Into Wiring Millions

The Wall Street Journal recently reported on a business executive who lost $450,000 in three days — while he was asleep on a business trip. Hackers had silently taken over his email, studied his accounts, and sent convincing wire requests to his assistant. The FBI received nearly $1.8 billion in reported losses from this type of scam in 2019 alone. Here is how it works — and how to stop it.

Iron Cove Solutions·Email Security·8 min read·Updated June 2026
Call (213) 545-0601View Email Security Plans
$1.8B in BEC losses reported to the FBI in 2019✦BEC is now organized crime — not random hackers✦Proofpoint blocks phishing before it reaches your inbox✦Okta MFA stops account takeover even with a stolen password✦Wire transfers rarely reversed — prevention is the only option✦Microsoft 365 + Proofpoint + Okta = layered email defense✦$26B in estimated worldwide BEC losses 2016–2019✦$1.8B in BEC losses reported to the FBI in 2019✦BEC is now organized crime — not random hackers✦Proofpoint blocks phishing before it reaches your inbox✦Okta MFA stops account takeover even with a stolen password✦Wire transfers rarely reversed — prevention is the only option✦Microsoft 365 + Proofpoint + Okta = layered email defense✦$26B in estimated worldwide BEC losses 2016–2019✦
$1.8BFBI-reported BEC losses in 2019
$26BEstimated global losses 2016–2019
23,775FBI complaints received in 2019
<2%Of stolen funds ever recovered
Home›Blog›Business Email Compromise

Business Email Compromise (BEC) is not your grandfather's email scam. These are not badly-worded messages full of typos from a foreign prince. They are meticulously researched attacks, carried out from legitimate, compromised email accounts, written in your exact voice, with accurate knowledge of your banking relationships, travel schedule, and pending transactions. The FBI considers them one of the most financially destructive cybercrime categories in the world.

“Unlike cruder scams that might ask for money in broken English, the note sounded just like him. An attachment with transfer instructions showed intimate knowledge of his accounts.”

— Wall Street Journal, Feb. 2020, reporting on a $450,000 BEC loss

How a BEC Attack Actually Works

BEC attacks have evolved far beyond simple spoofed email addresses. Modern attackers compromise real accounts, then operate silently inside them for weeks before making their move.

01

Account Compromise

Attackers gain access to a real email account — often through a phishing link or by testing passwords exposed in previous data breaches. Once inside, the victim has no idea.

02

Reconnaissance

The attacker reads through weeks or months of email threads, learning communication styles, vendor relationships, travel calendars, and pending financial transactions.

03

Impersonation

Using the real account (not a spoofed address), the attacker sends convincing wire transfer requests to finance staff, assistants, or vendors — in the executive's voice, with accurate context.

04

Cover Their Tracks

Email rules are created to silently delete any replies or bank confirmations, so the real account owner never sees what's happening. The fraud continues undetected for days.

05

Wire Transfer

The money lands in an overseas account — typically in Hong Kong or mainland China — where recovery is nearly impossible. The FBI estimates less than 2% of BEC losses are ever recovered.

Who Gets Targeted

The FBI is unequivocal: anyone with an email account and access to money is a potential target.

🏢

CEOs & Executives

Their authority is impersonated to authorize large transfers.

💼

Finance & Accounting

Accounts payable staff receive fraudulent vendor payment instructions.

🏠

Real Estate Transactions

Closing funds are diverted by compromising agent or title company email.

👤

HR & Payroll

Direct deposit details are changed before payday via fake employee emails.

⚖️

Law Firms & Nonprofits

Trust accounts and wire-heavy operations make attractive targets.

🏪

Small Businesses

Smaller IT budgets and less security awareness make them easier marks.

The Three-Layer Defense That Stops BEC

No single tool stops BEC entirely — but combining these three layers creates a defense that breaks the attack chain at every stage.

Layer 1: Stop Threats Before They ArriveProofpoint logo

Proofpoint Essentials

Email Security & Anti-Phishing

Proofpoint Essentials sits in front of your inbox and filters every inbound message against real-time threat intelligence from 3+ billion emails daily. It catches the phishing emails that attackers use to steal credentials in the first place — breaking the attack chain before an account is ever compromised.

  • ✓Blocks credential-harvesting phishing links before delivery
  • ✓Detects executive impersonation and display-name spoofing
  • ✓Flags emails that mimic your internal domain
  • ✓Provides full email archiving for forensic investigation
See Proofpoint Essentials Plans →
Layer 2: Lock Down Account AccessOkta logo

Okta

Multi-Factor Authentication & Identity

The single most effective technical control against BEC is multi-factor authentication. Even if an attacker obtains an employee's password through a data breach or phishing, Okta's MFA makes that credential useless — they can't complete the login without the second factor that only the real user controls.

  • ✓Requires a second factor (push, TOTP, or hardware key) for every login
  • ✓Blocks login attempts from unrecognized devices or locations
  • ✓Provides a real-time audit trail of every authentication event
  • ✓Single sign-on across Microsoft 365, Google Workspace, and hundreds of apps
Learn About Okta MFA →
Layer 3: Harden Your Email PlatformMicrosoft 365 logo

Microsoft 365

Secure Cloud Email

For organizations running Microsoft 365, built-in security features provide an additional defense layer. Microsoft Defender for Office 365 adds AI-powered anti-phishing rules, Safe Links URL scanning, and anomalous login detection. Combined with Proofpoint and Okta, it creates a defense-in-depth email environment.

  • ✓Advanced anti-phishing policies with AI-based impersonation detection
  • ✓Safe Links rewrites and scans URLs at click time
  • ✓Conditional Access blocks logins from untrusted networks or devices
  • ✓Admin audit logs capture all mailbox permission changes
Explore Microsoft 365 Plans →

Once the Wire Is Sent, the Money Is Gone

Under decades-old banking law, wire transfers authorized by a customer — even one who was deceived — are generally not covered by consumer fraud protections. Courts have repeatedly sided with banks over victims. One law firm called Bank of America within one hour of a fraudulent wire request and still lost $500,000. The attacker in the WSJ story had already cleaned out the funds before anyone realized what had happened. Recovery requires law enforcement action across international borders, and the chances are slim. The only reliable strategy is prevention.

The FBI estimates total worldwide BEC losses between June 2016 and July 2019 reached $26 billion. Funds primarily flow to banks in Hong Kong and mainland China, where recovery efforts rarely succeed.

Frequently Asked Questions

Common questions from business owners and IT leaders who are evaluating their exposure to BEC attacks.

How do attackers get into a real email account in the first place?

Two main methods: phishing emails that trick users into entering their password on a fake login page, and credential stuffing — testing username/password combinations leaked in prior data breaches. Because many people reuse passwords across services, a breach at one site can unlock email accounts at another.

How is BEC different from a regular phishing email?

Traditional phishing is broadcast spam with low success rates. BEC is targeted and surgical. Attackers research the victim, compromise a real account, read actual email threads, and send requests that perfectly match the victim's writing style, relationships, and context. There is no generic "Nigerian prince" warning sign.

Can a bank reverse a fraudulent wire transfer?

Rarely. Consumer protection laws that cover unauthorized card charges generally do not apply to wire transfers — especially when the customer voluntarily authorized the transfer (even under false pretenses). If the money has already reached an overseas account, recovery odds are very low. The FBI estimates global BEC losses between 2016 and 2019 totaled $26 billion.

Will my business email provider (Microsoft or Google) protect me on its own?

Basic plans include spam filtering but are not designed to stop sophisticated BEC. A dedicated email security layer like Proofpoint Essentials is trained specifically on BEC patterns, impersonation tactics, and emerging threats at a scale that generic inbox providers cannot match.

What is the fastest thing we can do right now?

Enable multi-factor authentication on every email account, without exception. It is the single control that most directly breaks the BEC attack chain. If an attacker cannot log in to the account even with a stolen password, the reconnaissance and impersonation steps never happen.

Free Consultation · No Commitment

Is Your Business Protected Against Email Account Takeover?

Iron Cove Solutions helps businesses deploy Proofpoint Essentials, Okta MFA, and Microsoft 365 security features as a layered defense against BEC. We will assess your current email environment and tell you exactly where you are exposed — at no cost.

Call (213) 545-0601View Email Security Plans →

Talk to us

Email

sales@ironcovesolutions.com

Phone & Hours

(213) 545-0601
Monday-Friday: 9am to 5pm

Address

8117 W. Manchester Ave
Suite 915
Playa Del Rey, CA 90293
Hello! My name is
and I work at
I heard about you from
and I'm looking for someone to help with
To start the conversation, you can reach me at:
Additionally:

Join Our Newsletter

Expert Cloud Consulting

  • Descope Identity Solutions
  • Dropbox Business
  • Google Workspace
  • Global Relay
  • Microsoft 365 & Office 365
  • Okta IAM Solutions
  • Proofpoint Email Security

Workflow Automation

  • BambooHR to Okta Integration
  • Microsoft 365 Workflows
  • Okta Business Process Automation
  • Okta Workflow Consulting
  • Workday to Okta Integration

Cost & ROI Calculators

  • Okta Savings Calculator
  • Workday to Okta ROI Calculator
  • Email Migration Cost Estimator

Managed Cloud Services

  • Application SSO Security
  • Cloud Infrastructure Management
  • Cybersecurity Solutions
  • Google Workspace
  • Microsoft Office 365 Managed Service
  • Okta Managed Service Provider

Cloud Technologies

  • Cloud Orchestration Engine
  • Cloud Products
  • Dropbox Business Platform
  • Google Workspace SMB
  • Microsoft 365 Platform
  • Microsoft Copilot AI
  • Okta Identity Platform
  • Proofpoint Email Security

Migration & Infrastructure

  • Email Migration
  • Email Migration to Exchange Online
  • Exchange to Exchange Online Migration

Connect With Us

  • X
  • Facebook
  • LinkedIn
  • YouTube

Microsoft Solutions

  • Exchange Online Plan 1
  • Exchange Online Plan 2
  • Microsoft 365 & Office 365
  • Microsoft 365 E3 Enterprise
  • Microsoft 365 E5 Enterprise
  • Microsoft 365 Kiosk
  • Office 365 E1 Business
  • Office 365 E3 Enterprise
  • Office 365 E5 Premium
  • View All Microsoft Plans & Pricing

Resources & Insights

  • Blog & Articles
  • Case Studies & Success Stories
  • Video Tutorials

Company Information

  • About Our Company
  • Careers & Opportunities
  • Project Management Portal
  • Technical Support

© 2026 | Iron Cove Solutions| Privacy | Simplifying Cloud-Based Intention

HomeEmailCall

  • Home
  • Consulting
  • Technology
  • Email Migration
  • Workflow
  • Resources
  • Support
  • Contact
Close