Would you lock your front door at night, then leave a window wide open?
Of course you would not. But many small businesses do the digital equivalent every day. They use strong passwords, install antivirus software, and lock their office doors: then trust an email that quietly redirects a payment, changes payroll information, or asks an employee to buy gift cards.
That is business email compromise, or BEC.
And it is costing businesses billions.
The $3 billion warning for Missouri businesses
The FBI’s 2025 Internet Crime Report shows that BEC caused approximately $3.05 billion in reported U.S. losses from 24,768 complaints.
That is up from roughly $2.77 billion in 2024. The average reported loss was about $123,000 per complaint.
BEC was the second-highest loss category in the report, behind investment fraud.
Think about that for a moment. One convincing email can create more damage than years of ordinary business expenses.
And the reported numbers do not capture every incident. Many companies do not report fraud because they feel embarrassed, worry about reputational damage, or assume the money cannot be recovered.
The problem is not limited to large corporations. Attackers increasingly target smaller organizations and individual transactions because small businesses often have fewer payment controls, fewer layers of approval, and less time to question an urgent request.
Whether you operate in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, or elsewhere in Missouri, your email deserves the same attention as your front door.
How BEC happens: three familiar scenarios
BEC does not always begin with a dramatic ransomware attack. Often, it looks like a normal workday.
1. The supplier invoice change
You receive an email from a supplier you know.
The logo looks right. The signature looks right. The invoice matches a real project. The message says the supplier has changed banks and asks you to send the next payment to a new account.
You update the payment details.
The supplier never sent the message. The money goes to the attacker.
This is one of the most dangerous forms of invoice fraud because the request fits into an existing business process. Nothing appears obviously strange: until the real supplier calls asking why the invoice is overdue.

2. The fake CEO request
You receive a short email that appears to come from the owner, president, or manager.
“Are you available?”
Then comes the request:
- Purchase gift cards for a client event.
- Send a wire transfer immediately.
- Keep the request confidential.
- Handle it before the end of the day.
The attacker is using authority and urgency together. You may want to help your manager quickly, especially when the message arrives during a busy afternoon.
You open the message without thinking twice… and just like that, a routine task becomes a financial loss.
3. Payroll diversion
An attacker impersonates an employee and asks payroll to change direct-deposit information.
Sometimes the request comes from a compromised employee account. Sometimes it comes from a lookalike address with one altered letter. The payroll team makes the change, and the next paycheck goes somewhere else.
The employee may not realize what happened until payday.
That is sensitive financial information leaving the safety of your business.
Why are small businesses targeted?
It makes sense to assume attackers prefer large companies with bigger bank accounts, right?
Not always.
A small business may have:
- One person handling accounts payable
- One person approving payroll
- Limited separation between requesting and approving payments
- No formal callback procedure
- Basic email filtering
- Shared passwords or unmanaged accounts
- Little time for security training
Attackers do not need to break through every layer of a large enterprise if a smaller transaction can be redirected with one convincing conversation.
Here’s the uncomfortable truth: BEC attacks exploit trust more than technology.
Email authentication is important: but it is not enough
You may have heard of SPF, DKIM, and DMARC.
These are email-authentication controls:
- SPF helps identify which mail servers are allowed to send email for your domain.
- DKIM adds a digital signature that helps confirm a message was authorized.
- DMARC tells receiving mail systems what to do when messages fail authentication and helps protect your domain from impersonation.
You should configure all three.
But here’s the problem: passing SPF, DKIM, and DMARC does not prove that an email is honest.
In 2026, invoice-fraud campaigns have increasingly used legitimate mailing lists and email platforms. These messages may pass SPF, DKIM, and DMARC because the sending service is properly authenticated: even though the content is fraudulent.
Recent phishing campaigns have also used invisible Unicode characters, sometimes called ASCII smuggling, to hide parts of words from security filters. The email may visibly say “invoice” or “payment,” while the underlying text contains invisible characters that interfere with keyword detection.
Researchers have warned that attackers can use these techniques to evade traditional and AI-based email filters unless the email system normalizes the text before analyzing it.
The message may look normal.
The filter may see something else.
Your practical BEC protection playbook
So, what can you do?
Start with controls that slow down high-risk transactions and make unusual requests harder to complete.
Verify payment changes by phone
Never verify a banking change by replying to the email that requested it.
Instead:
- Call the supplier using a known phone number from your records.
- Speak with your usual contact.
- Confirm the new banking information verbally.
- Document who approved the change.
- Use a second person for high-dollar payments.
Do not use a phone number included in the suspicious message. It may belong to the attacker.
Configure SPF, DKIM, and DMARC
Ask your IT provider to review your domain’s email-authentication settings.
DMARC should be monitored and eventually configured to reject unauthorized messages when appropriate. Your provider should also confirm that legitimate services: such as accounting platforms, customer relationship tools, and marketing systems: are properly included.
This helps protect your domain from being used in impersonation attacks.
Use advanced email filtering
Basic spam protection is not enough for modern BEC.
Advanced email security should examine:
- Sender behavior
- Display-name impersonation
- Lookalike domains
- Unusual login locations
- Suspicious forwarding rules
- Malicious links and attachments
- Invoice and payment language
- Hidden Unicode and invisible characters
- Messages sent through legitimate but unexpected platforms
This is where managed cybersecurity services can provide practical value. Security tools need configuration, monitoring, and timely response.
Require MFA everywhere it matters
Multi-factor authentication, or MFA, adds another verification step beyond a password.
Enable it for:
- Business email
- Microsoft 365 or Google Workspace
- Banking and accounting platforms
- Payroll systems
- Cloud storage
- Remote access
- Administrative accounts
If an attacker steals a password, MFA can prevent that password from being enough.
Train employees without blaming them
Most people do not fall for BEC because they are careless. They are trying to help, move quickly, and keep work moving.
It is not about blame: it is about awareness.
Teach your team to pause when a message involves:
- A payment change
- A wire transfer
- Gift cards
- Payroll updates
- Confidentiality
- Unusual urgency
- A request to bypass normal procedures
Give employees a simple way to report suspicious messages. If someone clicks a link or responds to an attacker, you want them to tell you immediately: not hide the mistake until the damage spreads.

What to do if money was sent
Here’s where speed matters.
If you believe your business has experienced BEC:
- Contact your bank immediately and request a wire recall or payment reversal.
- Ask the bank’s fraud department about freezing or tracing the funds.
- Secure the affected email account, reset credentials, and revoke suspicious sessions.
- Check for unauthorized forwarding rules and mailbox access.
- Preserve emails, headers, invoices, payment details, and logs.
- Notify your IT provider, cyber insurer, legal counsel, and leadership team.
- Report the incident to the FBI’s Internet Crime Complaint Center.
The FBI’s Financial Fraud Kill Chain may help financial institutions and law enforcement act on reported fraudulent transfers. Do not wait to report because the amount seems too small or because you feel embarrassed.
Build stronger email security for your Missouri business
BEC prevention is not about expecting every employee to become a cybersecurity expert.
It is about combining good habits with reliable technology:
- Verify payment changes through a trusted channel.
- Use MFA.
- Configure SPF, DKIM, and DMARC.
- Deploy advanced email filtering.
- Train employees regularly.
- Separate payment duties where possible.
- Maintain a clear incident response plan.
For a broader review of your business defenses, read The 2026 Cybersecurity Checklist for St. Louis Small Businesses.
If your business needs St. Louis cybersecurity, St. Louis managed IT services, managed cybersecurity services, or practical IT support for small business, Platinum Web Services can help you build a personalized, proactive plan.
We support businesses across St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and Missouri with 24/7 support.
Our headquarters is located at:
Platinum Web Services
7827 Town Square Ave, 104-1184
O’Fallon, MO 63368
You lock your doors because protection is easier before a break-in. Your email and payment systems deserve the same preparation.
If you would like help reviewing your email security, contact Platinum Web Services.


0 Comments