Business Email Compromise doesn't rely on malware, doesn't need to bypass antivirus, and often doesn't trip a single security alert — because the attack isn't technical at all. It's a convincing email, sent at a plausible moment, asking someone to do something they'd normally do anyway: pay an invoice, wire a deposit, update a vendor's banking details. That's what makes BEC one of the costliest categories of cybercrime for small and medium businesses despite requiring the least technical sophistication of almost any attack in this guide series — it exploits trust and urgency, not a software vulnerability, and no firewall or antivirus product is positioned to stop a legitimate-looking request that a human being simply approves.
This guide covers what BEC actually is and how attackers pull it off, the main categories of BEC attack and how each one works, realistic Canadian wire transfer fraud scenarios with real dollar figures, why dual-channel verification is the one habit that reliably stops nearly all of it, a prevention checklist covering both technical and procedural defenses, honest CAD cost ranges, and Canadian fraud-reporting resources. If your business sends or receives wire transfers, changes vendor payment details, or processes payroll — which is to say, nearly every business — this is worth reading closely.
Who wrote this guide
This guide was written and reviewed by IT Cares certified technicians based on helping Canadian SMBs respond to (and, more often, successfully avoid) BEC fraud attempts across a range of industries. The dual-channel verification approach described here is the same practical framework we help clients implement directly — it requires no specialized software and can be adopted by a business of any size starting today.
How BEC Attacks Actually Work
A BEC attack typically unfolds in a sequence that looks nothing like the "obvious phishing email" most people picture when they think about email fraud. There's usually no misspelled subject line, no dramatic urgency about a locked account, and often no attachment or link at all — just a well-written, contextually plausible message.
Step one: research
Attackers frequently research their target before sending a single email — scanning a company's website for executive names and titles, checking LinkedIn for who handles finance or accounts payable, and sometimes monitoring publicly available information about ongoing deals, acquisitions, or major purchases that would make a large wire transfer request seem contextually normal rather than suspicious.
Step two: access or impersonation
The attacker then either compromises a real email account (often through a previous, unrelated phishing attack or a leaked password reused across services) or registers a lookalike domain designed to pass a casual glance — swapping a letter, using a different top-level domain, or inserting an extra character that's easy to miss in a busy inbox.
Step three: the request
The email itself arrives with three ingredients that make BEC effective: a plausible sender (a real executive, a real vendor, a real legal contact), a plausible reason (an urgent deal closing, a vendor's "updated" banking details, a payroll change), and urgency or authority pressure (an executive asking for something quickly, or a tone that discourages the recipient from questioning the request or looping in a colleague).
Step four: the transfer
If the target complies, funds move — often to an account the attacker controls that's designed to be quickly emptied and difficult to trace, sometimes routed through several intermediate accounts before the fraud is even discovered. Because wire transfers clear quickly and are difficult to reverse, the window to catch and recall a fraudulent transfer is often measured in hours, not days.
📊 IT Cares field note: One of the more sobering patterns we see is how little "obviously wrong" there usually is in the email itself. In hindsight, clients often say the request felt slightly off — a bit more formal than usual, oddly timed, or the executive was "traveling and hard to reach by phone" — but nothing that would have stopped a busy employee from acting on it in the moment. That's exactly why a verification habit that doesn't depend on spotting something wrong is the defense that actually works.
Why Small and Medium Businesses Are Prime BEC Targets
It's a common misconception that sophisticated fraud like BEC mainly targets large corporations with deep pockets. In practice, small and medium businesses are disproportionately targeted, for reasons that have nothing to do with the size of a potential payout and everything to do with structural weaknesses BEC attackers specifically look for.
Small businesses frequently lack a formal, written verification policy at all — payment approval often lives entirely in one or two people's heads rather than in a documented, enforced process, which means there's no institutional habit standing between a convincing email and a completed transfer. Segregation of duties, a standard control at larger companies where the person who approves a payment is different from the person who executes it, is often impossible at a ten-person company where one bookkeeper handles the entire accounts payable process alone. And because small business owners are frequently visible online — active on LinkedIn, quoted in local press, listed by name on the company website — the research phase of a BEC attack is often trivially easy, giving the attacker exactly the real names, titles, and relationship context needed to make an impersonation attempt convincing.
None of this means small businesses are somehow more careless than large ones — it means the structural defenses that happen automatically at a larger organization (multiple approval layers, dedicated finance teams, formal procurement policies) need to be deliberately and explicitly built at a small business, since they won't emerge on their own from a lean, informal operating style that works well for almost everything else the business does.
Warning Signs Inside the Email Itself
While dual-channel verification is the defense that matters most because it doesn't depend on spotting something wrong, it's still worth training staff to recognize the patterns that show up disproportionately often in real BEC attempts — not as a replacement for verification, but as an additional layer that can prompt someone to verify even when a request doesn't officially cross a dollar threshold requiring it.
- Urgency paired with secrecy. A request that's both time-pressured ("needs to go out today") and asks the recipient not to discuss it with colleagues is one of the most consistent patterns across real BEC cases, because both elements work together to prevent the normal, healthy instinct to double-check with someone else.
- An unusual reason the sender is hard to reach. "I'm in a meeting all day," "my phone is dead," or "I'm traveling internationally and can only respond by email" are extremely common because they preemptively explain away the recipient's natural urge to just call and confirm.
- A slightly altered email domain. A domain that's one character different, uses a different top-level domain (.co instead of .com, for example), or substitutes a visually similar character is a hallmark of lookalike domain attacks — genuinely difficult to catch by eye, which is exactly why it works.
- A request that deviates from the normal process. A vendor that has always invoiced through a specific portal suddenly emailing new banking details directly, or an executive who never personally handles wire approvals suddenly doing so, is a pattern worth noticing even when nothing else about the email looks wrong.
- Reply-to address that doesn't match the display name. Checking the actual reply-to or sending address, not just the display name shown in the inbox, occasionally reveals a mismatch — though sophisticated attacks increasingly avoid this particular tell, so its absence proves nothing on its own.
The honest framing for staff training: these signs help catch some attempts, but a well-executed BEC email may show none of them. That's precisely why verification procedure, not pattern recognition, needs to be the primary control.
Want to close your BEC exposure before it's tested for real?
Our certified technicians can review your email security and verification procedures — from $119.99.
The Main Types of BEC Attacks
| Attack Type | How It Works | Red Flags | Typical Target |
|---|---|---|---|
| CEO / Executive Fraud | Attacker impersonates a company owner or executive, requesting an urgent, confidential wire transfer, often claiming to be traveling or unreachable by phone | Urgency, secrecy requests ("don't mention this to anyone yet"), executive unusually hard to reach for verification | Finance staff, bookkeepers, office managers |
| Vendor / Invoice Fraud | Attacker impersonates a real, existing supplier and sends "updated" banking details for an upcoming legitimate payment | Banking detail change request via email only, slightly altered vendor email domain, request timed near a real invoice due date | Accounts payable staff |
| Payroll Diversion | Attacker impersonates an employee, requesting their direct deposit details be changed to a new account | Request comes from a personal-looking email rather than the employee's normal address, unusual timing near a pay run | HR / payroll staff |
| Real Estate / Legal Transaction Fraud | Attacker impersonates a lawyer, notary, or title company during a closing, redirecting a large deposit or closing payment to a fraudulent account | Last-minute banking detail change close to closing date, pressure to act same-day | Buyers, sellers, and law firm staff during a transaction |
What all four share is the same underlying vulnerability: a request to move money or change payment details, communicated through a channel the attacker either controls or has compromised. That common thread is exactly why a single defense — dual-channel verification, covered in depth below — is effective across every category, rather than needing a separate specialized defense for each attack type.
A less common but growing fifth category worth mentioning is gift card and prepaid instrument fraud, where the attacker impersonates an executive requesting the urgent purchase of gift cards — often framed as a client gift or employee reward — and asks the recipient to photograph and send the card codes directly. While the dollar amounts involved are typically far smaller than wire fraud, this variant specifically targets employees who may not have direct access to company bank accounts at all, expanding the pool of potential victims within an organization beyond just finance staff, and it succeeds through the identical psychological pattern of urgency and authority rather than any new technique.
Why Dual-Channel Verification Is the Defense That Actually Works
Dual-channel verification means confirming any payment request or banking-detail change through a communication channel that is completely separate and independent from the one that made the request. If the request arrived by email, verification happens by phone — using a phone number the business already had on file before the request arrived, never a number supplied in the email itself.
The reason this specific defense is so effective, where spam filters and awareness training alone fall short, is structural: the attacker controls or has compromised the email channel. No matter how convincing the email is, no matter how well-timed or well-written, the attacker cannot also control a phone call placed to a number your business already had on file weeks or months earlier. The fraud simply cannot survive contact with an independent verification channel, which is why this single habit stops the overwhelming majority of BEC attempts regardless of how sophisticated the email itself was.
Define which requests require verification
Decide which categories of request always require dual-channel verification: any new banking detail, any change to existing banking details, and any wire transfer above a set dollar threshold your business chooses.
Collect verified phone numbers in advance
Maintain a list of verified phone numbers for vendors, executives, and finance staff obtained outside of email — from a signed contract, a business card, or a prior verified call — so you always have a trusted number to call rather than one supplied in the request itself.
Call the known number before acting
Before processing any qualifying request, call the pre-verified number and confirm the request verbally. Never reply to the same email thread and never call a phone number provided inside the request — both can lead straight back to the attacker.
Document the verification
Log who verified the request, when, and how, so there's a clear record and the habit becomes an expected, unremarkable part of the process rather than an occasional extra step someone might skip under time pressure.
Train the team to expect pushback-free verification
Make it explicit company policy that anyone can pause a payment to verify without fear of upsetting a client or executive — this removes the social pressure and urgency that BEC scams are specifically engineered to exploit.
The one-sentence version
If a request to move money or change payment details arrived by email, verify it by phone using a number you already had — not one the email gave you. That single habit, applied consistently, stops nearly every BEC attempt regardless of how convincing the email itself looked.
Segregation of Duties: A Second Layer Worth Building
Beyond dual-channel verification, segregation of duties is the classic financial control that makes BEC fraud structurally harder to pull off, even when a verification step is skipped or bypassed under pressure. The principle is simple: the person who initiates a payment should not be the same person who has sole authority to approve and release it. At a small business where one bookkeeper genuinely handles the entire payment process alone, this can feel impractical — but even a lightweight version delivers real protection.
A workable small-business version might look like this: any payment above a set threshold requires a second person's sign-off before release, even if that second person is the owner reviewing a simple summary rather than a dedicated finance controller. For businesses too small to split roles meaningfully, an alternative is a mandatory 24-hour hold on any new banking detail or large wire request — a short delay that creates space for a second look, a phone call, or simply time for urgency-driven pressure to fade, without requiring additional staff. Combined with dual-channel verification, segregation of duties or a mandatory hold period creates two independent points where a fraudulent request has to survive scrutiny, rather than one.
None of this needs to be bureaucratic. The goal isn't to slow down every legitimate payment — it's to ensure that no single email, however convincing, can move money entirely on its own without at least one other person or one verification step standing between the request and the transfer.
Real-World Fraudulent Wire Transfer Scenarios
The following are composite scenarios based on patterns IT Cares technicians have encountered and reviewed with Canadian SMB clients, anonymized and combined rather than describing any single identifiable client.
Case study 1: The "urgent acquisition" wire (Toronto, ON)
A 22-person marketing agency's controller received an email that appeared to come from the company's owner, marked urgent, requesting a same-day wire of $47,000 CAD to close on a "confidential acquisition" the owner claimed to be finalizing while traveling and difficult to reach by phone. The email referenced real, publicly available details about the company's recent growth, which made it feel contextually plausible. The controller, following the firm's dual-channel policy adopted only two months earlier after a prior close call, called the owner's known cell number rather than replying to the email — reaching the actual owner within minutes, who confirmed no such acquisition existed. The transfer was never sent. A near-identical scenario at a similar-sized firm without a verification policy in place, reviewed separately, resulted in a completed loss of $52,000 CAD that was never recovered.
Case study 2: The vendor "banking update" (Brampton, ON)
An accounts payable clerk at a mid-sized construction supply company received an email appearing to come from a long-standing supplier's accounts receivable contact, stating the supplier had "switched banks" and providing new wire instructions for an upcoming $31,500 CAD payment already due that week. The email came from a domain one character different from the real vendor's domain — a difference invisible at a glance in a busy inbox. Because company policy required a phone call to a previously verified vendor contact before any banking change was applied, the clerk called the real supplier directly and learned no such change had been requested. The fraudulent request was reported and blocked before any funds moved.
Case study 3: The payroll diversion that wasn't caught in time (Winnipeg, MB)
An HR coordinator at a 35-person logistics company received what appeared to be a routine email from an employee requesting their direct deposit be updated to a new bank account ahead of the next pay run. No phone verification process existed at the time for payroll changes specifically — only for larger wire transfers — so the change was processed based on the email alone. The employee's next paycheque, roughly $2,800 CAD, was deposited into the fraudulent account instead, and the real employee only discovered the issue when their pay didn't arrive as expected. The loss was relatively small compared to wire fraud cases, but it revealed a real gap: the company's verification policy covered large transfers but had never been extended to payroll changes, a category BEC attackers specifically target because it's often overlooked.
Case study 4: The lookalike-domain closing fraud (Halifax, NS)
A small real estate law practice in Halifax was mid-way through a residential property closing when the buyer received what appeared to be an email from the firm's own trust account coordinator, providing updated wire instructions for the closing deposit of $68,000 CAD, sent from a domain that replaced a single lowercase "l" with a capital "I" — nearly indistinguishable in most email fonts. The buyer, unfamiliar with the firm's normal process and eager to complete the closing on schedule, wired the funds directly based on the email alone rather than calling the number listed on the firm's official engagement letter. The fraud was discovered only when the real firm followed up two days later asking why the deposit hadn't arrived, by which point the funds had already been moved through several intermediary accounts and were not recoverable. This case illustrates a variation worth noting: BEC defenses need to extend to clients and external parties involved in a transaction, not just internal staff, since the fraud in this case succeeded by targeting the buyer rather than anyone inside the firm itself.
BEC Prevention Checklist
- ☐ SPF, DKIM, and DMARC are properly configured on our domain to reduce direct domain spoofing
- ☐ Our email platform flags external senders and lookalike domains clearly
- ☐ We have a written policy requiring dual-channel verification for any new banking detail or change
- ☐ We have a written policy requiring dual-channel verification for wire transfers above a set threshold
- ☐ Our payroll/HR process requires phone verification for any direct deposit change request
- ☐ We maintain a list of verified phone numbers for key vendors and executives, obtained outside of email
- ☐ Staff know never to call a number supplied inside a suspicious request
- ☐ Staff are explicitly told they will never be penalized for pausing a payment to verify it
- ☐ We've run at least one internal awareness session specifically covering BEC (not just generic phishing)
- ☐ Multi-factor authentication is enabled on all email accounts to reduce the risk of real account compromise
- ☐ We know who to call at our bank immediately if a fraudulent transfer is suspected
- ☐ We know how to report a BEC incident to the Canadian Anti-Fraud Centre
- ☐ Our cyber insurance policy (if we have one) has been reviewed specifically for social engineering / funds transfer fraud coverage
Cost Reality Check for Canadian SMBs
The good news about BEC defense is that the single most effective control — dual-channel verification — costs nothing beyond the discipline to implement and follow it consistently. The remaining spend goes toward supporting layers:
- Very small business (1–10 employees): Dual-channel verification policy: $0 (procedural, not a purchased tool). Email authentication (SPF/DKIM/DMARC) setup: often a one-time $150–$500 CAD configuration if not already in place. Basic security awareness training: $0–$50 CAD/employee/year for lightweight subscription tools.
- Small business (10–30 employees): A more complete email security platform with advanced phishing/lookalike-domain detection: roughly $3–$8 CAD/user/month. Formal awareness training with BEC-specific simulations: $20–$60 CAD/employee/year.
- Growing SMB (30–75 employees): Enterprise-grade email security plus a managed security service that monitors for account compromise indicators: typically $8–$20 CAD/user/month depending on scope, alongside more formal, recurring awareness training programs.
Weighed against the potential loss from even a single successful BEC incident — commonly tens of thousands of dollars in a single wire transfer, as the case studies above illustrate — the cost of the supporting layers is modest, and the core defense of dual-channel verification is, again, entirely free to implement. Our cybersecurity budget guide covers how email security spending typically fits into a broader security budget.
It's worth being explicit about where the real return on investment sits in this particular budget category, because it differs from most other cybersecurity spending. With ransomware defense or endpoint protection, spending more generally buys a measurably stronger technical barrier. With BEC, the most expensive layer — a premium email security platform with advanced lookalike-domain detection — meaningfully reduces risk but does not eliminate it, while the cheapest layer — a written, consistently enforced verification policy — is often the single most effective control in the entire stack. A very small business on a tight budget that can only afford one of these two investments should prioritize building and enforcing the verification policy first, since it costs nothing beyond internal discipline and closes the gap that technical tools alone cannot: a well-executed lookalike-domain attack or a genuinely compromised account will pass most email security filters without triggering a single alert, precisely because nothing about the message is technically malformed.
Building an Effective BEC Awareness Training Program
Generic phishing awareness training — the kind that focuses on spotting misspellings, suspicious links, and urgent subject lines — only partially prepares staff for BEC, because a well-crafted BEC email frequently contains none of those tells. A training program that's actually effective against BEC specifically needs a few distinct elements.
First, it needs real, relevant simulated scenarios rather than generic phishing templates — a simulated "executive requesting an urgent wire while traveling" email is dramatically more useful preparation than a simulated "your account will be suspended" email, since the two represent genuinely different attack patterns with different psychological levers. Second, it needs to explicitly cover the verification policy itself as a memorized habit, not just an abstract concept — staff should be able to state, without hesitation, what the policy requires and who to call, the same way they'd know the fire evacuation route without needing to look it up. Third, it needs leadership buy-in and visible modeling: if an executive publicly complains about being "hassled" with a verification call for a legitimate request, that single moment can undo months of training by teaching staff that verification is an inconvenience to be skipped rather than a protected, expected step.
Refresher training on a recurring basis — at minimum annually, ideally alongside new hire onboarding and any time a new BEC pattern becomes publicly known — keeps the awareness current, since attackers continuously adapt their approach as older tricks become widely recognized.
Want help closing your BEC exposure?
IT Cares' cybersecurity services include email authentication setup, phishing-resistant email security configuration, and help building a real dual-channel verification policy your team will actually follow. Our security audits can also assess your current exposure to BEC-style fraud specifically.
Canadian Reporting and Government Resources
If your business suspects or confirms a BEC incident, or wants to understand your exposure and reporting obligations, the following Canadian resources are directly relevant:
- Canadian Anti-Fraud Centre (antifraudcentre-centreantifraude.ca): Canada's central body for reporting fraud, including BEC and wire transfer fraud. Reporting an incident helps law enforcement track patterns and can support recovery efforts in some cases, even when funds cannot be fully recovered.
- BDC (Business Development Bank of Canada, bdc.ca): Publishes small business fraud prevention and financial risk management resources relevant to protecting payment and banking processes.
- ISED (Innovation, Science and Economic Development Canada, ised-isde.canada.ca): Canada's federal innovation department publishes small business cybersecurity resources, including guidance touching on email fraud and financial cybercrime prevention.
Speed matters more than almost anything else if a fraudulent transfer has already occurred: contacting your bank immediately to attempt a wire recall, before filing any reports, gives the best remaining chance of recovering funds, since the window for a successful recall typically closes within hours.
What Happens After You Call Your Bank
Understanding the wire recall process in advance — rather than learning it for the first time during a genuine emergency — can shave critical minutes off the response when they matter most. When you contact your bank about a suspected fraudulent transfer, they will typically attempt to issue a recall request to the receiving bank, asking that institution to freeze or return the funds before they're withdrawn or moved further. This process depends entirely on speed: many fraudulent BEC transfers are moved out of the receiving account within hours specifically because the schemes are built around that exact window, sometimes routed through several accounts in different institutions or even different countries to make tracing and recovery progressively harder.
Have your account details, the exact transfer amount, the date and time it was sent, and the receiving account information (if visible in your records) ready before calling, since the bank's fraud team will need these immediately to initiate a recall attempt. Ask explicitly for a wire recall or SWIFT recall request, and get a reference or case number for your own records, since you'll likely need it for insurance claims and for your report to the Canadian Anti-Fraud Centre. If your bank's regular branch staff seem unfamiliar with the process, ask specifically to be escalated to their fraud or wire operations department, which handles this specific procedure far more routinely than general branch staff.
It's important to set realistic expectations: even a fast, well-executed recall attempt does not guarantee recovery, particularly once funds have already been withdrawn or moved to a further account by the time the receiving bank is notified. This is precisely why prevention — dual-channel verification, segregation of duties, and staff training — carries so much more weight than any post-incident response, however well executed. The honest goal of understanding the recall process is to maximize your odds in the worst case, not to treat it as a reliable safety net that makes prevention optional.
Frequently Asked Questions
Want an Honest Read on Your BEC Exposure?
IT Cares reviews your email security setup and verification procedures, then helps you build a real, low-friction defense your team will actually follow.
Comments (3)
We had almost the exact "owner traveling, urgent wire" scenario described here. Thankfully our controller called my actual cell instead of replying. That call took two minutes and saved us $40K+.
Didn't realize how close our vendor banking domain was spoofed until I compared the two side by side. One letter different. Genuinely unsettling how easy it is to miss.
We only had verification rules for wire transfers, not payroll changes. This article is why we're extending the policy to cover direct deposit changes too.
Leave a Comment