Business Email Compromise (BEC): How to Protect Your SMB

Reviewed by IT Cares certified technicians · Updated July 2026

Canadian business owner reviewing a suspicious wire transfer email request on a laptop before calling to verify it
The email that requests a wire transfer can look perfect. The phone call that verifies it is what actually stops the fraud.
✉️
Not sure your team would catch a convincing BEC email? Our certified technicians can review your email security setup and verification habits.
Get a Free Assessment →

Business Email Compromise doesn't rely on malware, doesn't need to bypass antivirus, and often doesn't trip a single security alert — because the attack isn't technical at all. It's a convincing email, sent at a plausible moment, asking someone to do something they'd normally do anyway: pay an invoice, wire a deposit, update a vendor's banking details. That's what makes BEC one of the costliest categories of cybercrime for small and medium businesses despite requiring the least technical sophistication of almost any attack in this guide series — it exploits trust and urgency, not a software vulnerability, and no firewall or antivirus product is positioned to stop a legitimate-looking request that a human being simply approves.

This guide covers what BEC actually is and how attackers pull it off, the main categories of BEC attack and how each one works, realistic Canadian wire transfer fraud scenarios with real dollar figures, why dual-channel verification is the one habit that reliably stops nearly all of it, a prevention checklist covering both technical and procedural defenses, honest CAD cost ranges, and Canadian fraud-reporting resources. If your business sends or receives wire transfers, changes vendor payment details, or processes payroll — which is to say, nearly every business — this is worth reading closely.

Who wrote this guide

This guide was written and reviewed by IT Cares certified technicians based on helping Canadian SMBs respond to (and, more often, successfully avoid) BEC fraud attempts across a range of industries. The dual-channel verification approach described here is the same practical framework we help clients implement directly — it requires no specialized software and can be adopted by a business of any size starting today.

How BEC Attacks Actually Work

A BEC attack typically unfolds in a sequence that looks nothing like the "obvious phishing email" most people picture when they think about email fraud. There's usually no misspelled subject line, no dramatic urgency about a locked account, and often no attachment or link at all — just a well-written, contextually plausible message.

Step one: research

Attackers frequently research their target before sending a single email — scanning a company's website for executive names and titles, checking LinkedIn for who handles finance or accounts payable, and sometimes monitoring publicly available information about ongoing deals, acquisitions, or major purchases that would make a large wire transfer request seem contextually normal rather than suspicious.

Step two: access or impersonation

The attacker then either compromises a real email account (often through a previous, unrelated phishing attack or a leaked password reused across services) or registers a lookalike domain designed to pass a casual glance — swapping a letter, using a different top-level domain, or inserting an extra character that's easy to miss in a busy inbox.

Step three: the request

The email itself arrives with three ingredients that make BEC effective: a plausible sender (a real executive, a real vendor, a real legal contact), a plausible reason (an urgent deal closing, a vendor's "updated" banking details, a payroll change), and urgency or authority pressure (an executive asking for something quickly, or a tone that discourages the recipient from questioning the request or looping in a colleague).

Step four: the transfer

If the target complies, funds move — often to an account the attacker controls that's designed to be quickly emptied and difficult to trace, sometimes routed through several intermediate accounts before the fraud is even discovered. Because wire transfers clear quickly and are difficult to reverse, the window to catch and recall a fraudulent transfer is often measured in hours, not days.

📊 IT Cares field note: One of the more sobering patterns we see is how little "obviously wrong" there usually is in the email itself. In hindsight, clients often say the request felt slightly off — a bit more formal than usual, oddly timed, or the executive was "traveling and hard to reach by phone" — but nothing that would have stopped a busy employee from acting on it in the moment. That's exactly why a verification habit that doesn't depend on spotting something wrong is the defense that actually works.

Why Small and Medium Businesses Are Prime BEC Targets

It's a common misconception that sophisticated fraud like BEC mainly targets large corporations with deep pockets. In practice, small and medium businesses are disproportionately targeted, for reasons that have nothing to do with the size of a potential payout and everything to do with structural weaknesses BEC attackers specifically look for.

Small businesses frequently lack a formal, written verification policy at all — payment approval often lives entirely in one or two people's heads rather than in a documented, enforced process, which means there's no institutional habit standing between a convincing email and a completed transfer. Segregation of duties, a standard control at larger companies where the person who approves a payment is different from the person who executes it, is often impossible at a ten-person company where one bookkeeper handles the entire accounts payable process alone. And because small business owners are frequently visible online — active on LinkedIn, quoted in local press, listed by name on the company website — the research phase of a BEC attack is often trivially easy, giving the attacker exactly the real names, titles, and relationship context needed to make an impersonation attempt convincing.

None of this means small businesses are somehow more careless than large ones — it means the structural defenses that happen automatically at a larger organization (multiple approval layers, dedicated finance teams, formal procurement policies) need to be deliberately and explicitly built at a small business, since they won't emerge on their own from a lean, informal operating style that works well for almost everything else the business does.

Warning Signs Inside the Email Itself

While dual-channel verification is the defense that matters most because it doesn't depend on spotting something wrong, it's still worth training staff to recognize the patterns that show up disproportionately often in real BEC attempts — not as a replacement for verification, but as an additional layer that can prompt someone to verify even when a request doesn't officially cross a dollar threshold requiring it.

The honest framing for staff training: these signs help catch some attempts, but a well-executed BEC email may show none of them. That's precisely why verification procedure, not pattern recognition, needs to be the primary control.

Want to close your BEC exposure before it's tested for real?

Our certified technicians can review your email security and verification procedures — from $119.99.

The Main Types of BEC Attacks

Attack Type How It Works Red Flags Typical Target
CEO / Executive Fraud Attacker impersonates a company owner or executive, requesting an urgent, confidential wire transfer, often claiming to be traveling or unreachable by phone Urgency, secrecy requests ("don't mention this to anyone yet"), executive unusually hard to reach for verification Finance staff, bookkeepers, office managers
Vendor / Invoice Fraud Attacker impersonates a real, existing supplier and sends "updated" banking details for an upcoming legitimate payment Banking detail change request via email only, slightly altered vendor email domain, request timed near a real invoice due date Accounts payable staff
Payroll Diversion Attacker impersonates an employee, requesting their direct deposit details be changed to a new account Request comes from a personal-looking email rather than the employee's normal address, unusual timing near a pay run HR / payroll staff
Real Estate / Legal Transaction Fraud Attacker impersonates a lawyer, notary, or title company during a closing, redirecting a large deposit or closing payment to a fraudulent account Last-minute banking detail change close to closing date, pressure to act same-day Buyers, sellers, and law firm staff during a transaction

What all four share is the same underlying vulnerability: a request to move money or change payment details, communicated through a channel the attacker either controls or has compromised. That common thread is exactly why a single defense — dual-channel verification, covered in depth below — is effective across every category, rather than needing a separate specialized defense for each attack type.

A less common but growing fifth category worth mentioning is gift card and prepaid instrument fraud, where the attacker impersonates an executive requesting the urgent purchase of gift cards — often framed as a client gift or employee reward — and asks the recipient to photograph and send the card codes directly. While the dollar amounts involved are typically far smaller than wire fraud, this variant specifically targets employees who may not have direct access to company bank accounts at all, expanding the pool of potential victims within an organization beyond just finance staff, and it succeeds through the identical psychological pattern of urgency and authority rather than any new technique.

Why Dual-Channel Verification Is the Defense That Actually Works

Dual-channel verification means confirming any payment request or banking-detail change through a communication channel that is completely separate and independent from the one that made the request. If the request arrived by email, verification happens by phone — using a phone number the business already had on file before the request arrived, never a number supplied in the email itself.

The reason this specific defense is so effective, where spam filters and awareness training alone fall short, is structural: the attacker controls or has compromised the email channel. No matter how convincing the email is, no matter how well-timed or well-written, the attacker cannot also control a phone call placed to a number your business already had on file weeks or months earlier. The fraud simply cannot survive contact with an independent verification channel, which is why this single habit stops the overwhelming majority of BEC attempts regardless of how sophisticated the email itself was.

1

Define which requests require verification

Decide which categories of request always require dual-channel verification: any new banking detail, any change to existing banking details, and any wire transfer above a set dollar threshold your business chooses.

2

Collect verified phone numbers in advance

Maintain a list of verified phone numbers for vendors, executives, and finance staff obtained outside of email — from a signed contract, a business card, or a prior verified call — so you always have a trusted number to call rather than one supplied in the request itself.

3

Call the known number before acting

Before processing any qualifying request, call the pre-verified number and confirm the request verbally. Never reply to the same email thread and never call a phone number provided inside the request — both can lead straight back to the attacker.

4

Document the verification

Log who verified the request, when, and how, so there's a clear record and the habit becomes an expected, unremarkable part of the process rather than an occasional extra step someone might skip under time pressure.

5

Train the team to expect pushback-free verification

Make it explicit company policy that anyone can pause a payment to verify without fear of upsetting a client or executive — this removes the social pressure and urgency that BEC scams are specifically engineered to exploit.

The one-sentence version

If a request to move money or change payment details arrived by email, verify it by phone using a number you already had — not one the email gave you. That single habit, applied consistently, stops nearly every BEC attempt regardless of how convincing the email itself looked.

Segregation of Duties: A Second Layer Worth Building

Beyond dual-channel verification, segregation of duties is the classic financial control that makes BEC fraud structurally harder to pull off, even when a verification step is skipped or bypassed under pressure. The principle is simple: the person who initiates a payment should not be the same person who has sole authority to approve and release it. At a small business where one bookkeeper genuinely handles the entire payment process alone, this can feel impractical — but even a lightweight version delivers real protection.

A workable small-business version might look like this: any payment above a set threshold requires a second person's sign-off before release, even if that second person is the owner reviewing a simple summary rather than a dedicated finance controller. For businesses too small to split roles meaningfully, an alternative is a mandatory 24-hour hold on any new banking detail or large wire request — a short delay that creates space for a second look, a phone call, or simply time for urgency-driven pressure to fade, without requiring additional staff. Combined with dual-channel verification, segregation of duties or a mandatory hold period creates two independent points where a fraudulent request has to survive scrutiny, rather than one.

None of this needs to be bureaucratic. The goal isn't to slow down every legitimate payment — it's to ensure that no single email, however convincing, can move money entirely on its own without at least one other person or one verification step standing between the request and the transfer.

Real-World Fraudulent Wire Transfer Scenarios

The following are composite scenarios based on patterns IT Cares technicians have encountered and reviewed with Canadian SMB clients, anonymized and combined rather than describing any single identifiable client.

Case study 1: The "urgent acquisition" wire (Toronto, ON)

A 22-person marketing agency's controller received an email that appeared to come from the company's owner, marked urgent, requesting a same-day wire of $47,000 CAD to close on a "confidential acquisition" the owner claimed to be finalizing while traveling and difficult to reach by phone. The email referenced real, publicly available details about the company's recent growth, which made it feel contextually plausible. The controller, following the firm's dual-channel policy adopted only two months earlier after a prior close call, called the owner's known cell number rather than replying to the email — reaching the actual owner within minutes, who confirmed no such acquisition existed. The transfer was never sent. A near-identical scenario at a similar-sized firm without a verification policy in place, reviewed separately, resulted in a completed loss of $52,000 CAD that was never recovered.

Case study 2: The vendor "banking update" (Brampton, ON)

An accounts payable clerk at a mid-sized construction supply company received an email appearing to come from a long-standing supplier's accounts receivable contact, stating the supplier had "switched banks" and providing new wire instructions for an upcoming $31,500 CAD payment already due that week. The email came from a domain one character different from the real vendor's domain — a difference invisible at a glance in a busy inbox. Because company policy required a phone call to a previously verified vendor contact before any banking change was applied, the clerk called the real supplier directly and learned no such change had been requested. The fraudulent request was reported and blocked before any funds moved.

Case study 3: The payroll diversion that wasn't caught in time (Winnipeg, MB)

An HR coordinator at a 35-person logistics company received what appeared to be a routine email from an employee requesting their direct deposit be updated to a new bank account ahead of the next pay run. No phone verification process existed at the time for payroll changes specifically — only for larger wire transfers — so the change was processed based on the email alone. The employee's next paycheque, roughly $2,800 CAD, was deposited into the fraudulent account instead, and the real employee only discovered the issue when their pay didn't arrive as expected. The loss was relatively small compared to wire fraud cases, but it revealed a real gap: the company's verification policy covered large transfers but had never been extended to payroll changes, a category BEC attackers specifically target because it's often overlooked.

Case study 4: The lookalike-domain closing fraud (Halifax, NS)

A small real estate law practice in Halifax was mid-way through a residential property closing when the buyer received what appeared to be an email from the firm's own trust account coordinator, providing updated wire instructions for the closing deposit of $68,000 CAD, sent from a domain that replaced a single lowercase "l" with a capital "I" — nearly indistinguishable in most email fonts. The buyer, unfamiliar with the firm's normal process and eager to complete the closing on schedule, wired the funds directly based on the email alone rather than calling the number listed on the firm's official engagement letter. The fraud was discovered only when the real firm followed up two days later asking why the deposit hadn't arrived, by which point the funds had already been moved through several intermediary accounts and were not recoverable. This case illustrates a variation worth noting: BEC defenses need to extend to clients and external parties involved in a transaction, not just internal staff, since the fraud in this case succeeded by targeting the buyer rather than anyone inside the firm itself.

BEC Prevention Checklist

Cost Reality Check for Canadian SMBs

The good news about BEC defense is that the single most effective control — dual-channel verification — costs nothing beyond the discipline to implement and follow it consistently. The remaining spend goes toward supporting layers:

Weighed against the potential loss from even a single successful BEC incident — commonly tens of thousands of dollars in a single wire transfer, as the case studies above illustrate — the cost of the supporting layers is modest, and the core defense of dual-channel verification is, again, entirely free to implement. Our cybersecurity budget guide covers how email security spending typically fits into a broader security budget.

It's worth being explicit about where the real return on investment sits in this particular budget category, because it differs from most other cybersecurity spending. With ransomware defense or endpoint protection, spending more generally buys a measurably stronger technical barrier. With BEC, the most expensive layer — a premium email security platform with advanced lookalike-domain detection — meaningfully reduces risk but does not eliminate it, while the cheapest layer — a written, consistently enforced verification policy — is often the single most effective control in the entire stack. A very small business on a tight budget that can only afford one of these two investments should prioritize building and enforcing the verification policy first, since it costs nothing beyond internal discipline and closes the gap that technical tools alone cannot: a well-executed lookalike-domain attack or a genuinely compromised account will pass most email security filters without triggering a single alert, precisely because nothing about the message is technically malformed.

Building an Effective BEC Awareness Training Program

Generic phishing awareness training — the kind that focuses on spotting misspellings, suspicious links, and urgent subject lines — only partially prepares staff for BEC, because a well-crafted BEC email frequently contains none of those tells. A training program that's actually effective against BEC specifically needs a few distinct elements.

First, it needs real, relevant simulated scenarios rather than generic phishing templates — a simulated "executive requesting an urgent wire while traveling" email is dramatically more useful preparation than a simulated "your account will be suspended" email, since the two represent genuinely different attack patterns with different psychological levers. Second, it needs to explicitly cover the verification policy itself as a memorized habit, not just an abstract concept — staff should be able to state, without hesitation, what the policy requires and who to call, the same way they'd know the fire evacuation route without needing to look it up. Third, it needs leadership buy-in and visible modeling: if an executive publicly complains about being "hassled" with a verification call for a legitimate request, that single moment can undo months of training by teaching staff that verification is an inconvenience to be skipped rather than a protected, expected step.

Refresher training on a recurring basis — at minimum annually, ideally alongside new hire onboarding and any time a new BEC pattern becomes publicly known — keeps the awareness current, since attackers continuously adapt their approach as older tricks become widely recognized.

Want help closing your BEC exposure?

IT Cares' cybersecurity services include email authentication setup, phishing-resistant email security configuration, and help building a real dual-channel verification policy your team will actually follow. Our security audits can also assess your current exposure to BEC-style fraud specifically.

Canadian Reporting and Government Resources

If your business suspects or confirms a BEC incident, or wants to understand your exposure and reporting obligations, the following Canadian resources are directly relevant:

Speed matters more than almost anything else if a fraudulent transfer has already occurred: contacting your bank immediately to attempt a wire recall, before filing any reports, gives the best remaining chance of recovering funds, since the window for a successful recall typically closes within hours.

What Happens After You Call Your Bank

Understanding the wire recall process in advance — rather than learning it for the first time during a genuine emergency — can shave critical minutes off the response when they matter most. When you contact your bank about a suspected fraudulent transfer, they will typically attempt to issue a recall request to the receiving bank, asking that institution to freeze or return the funds before they're withdrawn or moved further. This process depends entirely on speed: many fraudulent BEC transfers are moved out of the receiving account within hours specifically because the schemes are built around that exact window, sometimes routed through several accounts in different institutions or even different countries to make tracing and recovery progressively harder.

Have your account details, the exact transfer amount, the date and time it was sent, and the receiving account information (if visible in your records) ready before calling, since the bank's fraud team will need these immediately to initiate a recall attempt. Ask explicitly for a wire recall or SWIFT recall request, and get a reference or case number for your own records, since you'll likely need it for insurance claims and for your report to the Canadian Anti-Fraud Centre. If your bank's regular branch staff seem unfamiliar with the process, ask specifically to be escalated to their fraud or wire operations department, which handles this specific procedure far more routinely than general branch staff.

It's important to set realistic expectations: even a fast, well-executed recall attempt does not guarantee recovery, particularly once funds have already been withdrawn or moved to a further account by the time the receiving bank is notified. This is precisely why prevention — dual-channel verification, segregation of duties, and staff training — carries so much more weight than any post-incident response, however well executed. The honest goal of understanding the recall process is to maximize your odds in the worst case, not to treat it as a reliable safety net that makes prevention optional.

Frequently Asked Questions

What is Business Email Compromise (BEC)?
Business Email Compromise is a type of fraud where an attacker impersonates a trusted party — typically an executive, a vendor, or a legal or financial contact — usually via a spoofed or compromised email account, to trick an employee into making a fraudulent wire transfer, changing payment details, or disclosing sensitive information. Unlike broad, low-effort phishing, BEC attacks are often carefully researched and targeted, referencing real names, real deals, and realistic timing to appear legitimate, which is exactly why they succeed against otherwise careful employees.
What is dual-channel verification and why does it stop BEC fraud?
Dual-channel verification means confirming any payment or banking-detail-change request through a second, independent communication channel before acting on it — for example, calling a pre-verified phone number rather than replying to the email that made the request. It stops BEC fraud because the attacker controls or has compromised the email channel; if verification happens through a completely separate channel the attacker doesn't control, the fraudulent request simply cannot be confirmed, and the scam fails at that step regardless of how convincing the email itself was.
How much money do businesses actually lose to BEC fraud?
Individual BEC incidents commonly range from a few thousand dollars up to hundreds of thousands of dollars in a single fraudulent transfer, with the amount usually tied to the size of a real, plausible transaction the business would normally process. Industry-cited figures consistently identify BEC as one of the costliest categories of cybercrime by total dollar loss, in part because a successful BEC scam often involves a single large transfer rather than many small ones, and because wire transfers are difficult or impossible to reverse once completed and cleared.
How do attackers actually get access to send convincing BEC emails?
Two main methods: account compromise, where the attacker gains actual access to a real email account (often through a prior phishing attack or credential leak) and sends fraudulent messages from the genuine address; and spoofing or lookalike domains, where the attacker registers a domain that looks almost identical to the real one (swapping a letter, using a different top-level domain) and sends from an address that looks correct at a glance. Both methods are why visual inspection of an email address alone is not a reliable defense — the email can look completely legitimate under casual review either way.
What are the most common types of BEC attacks?
The most common categories are CEO/executive fraud (impersonating a company leader requesting an urgent wire transfer), vendor or invoice fraud (impersonating a real supplier to redirect a legitimate payment to a fraudulent account), payroll diversion (impersonating an employee to redirect their direct deposit), and real estate or legal transaction fraud (impersonating a lawyer or title company during a closing to redirect a large deposit or closing payment). Each exploits a different real business process, which is why a single generic defense rarely covers all of them — the common thread across every type is a request to move money or change payment details communicated through a channel the attacker controls.
Can email authentication tools like SPF, DKIM, and DMARC fully prevent BEC?
No, though they meaningfully reduce one category of BEC risk. SPF, DKIM, and DMARC help prevent attackers from successfully spoofing your exact domain, which blocks a specific and common BEC technique. They do not stop lookalike domain attacks (a different but similar domain), and they do nothing at all if the attacker has compromised a real account and is sending from the genuine, authenticated address. Email authentication is a necessary layer, not a complete defense on its own — it needs to be paired with verification procedures like dual-channel confirmation.
What should we do immediately if we suspect a BEC fraud just happened?
Contact your bank immediately to attempt a wire recall — the odds of recovery drop sharply with every hour that passes, so speed matters more than almost anything else in the first response. Report the incident to the Canadian Anti-Fraud Centre and to local law enforcement, preserve the fraudulent emails and any related communication without deleting anything, and change passwords and review account activity for the email account involved in case it was actually compromised rather than merely spoofed. Notify your cyber insurance provider if you have a policy, since BEC fraud is commonly a covered event.
Is BEC fraud typically covered by cyber insurance?
Often yes, though coverage terms vary significantly between policies and insurers, and some policies cap BEC-related fraud coverage lower than other cyber incident categories or require specific verification procedures to have been followed for a claim to be honoured. It's worth reviewing your specific policy language for social engineering or funds transfer fraud coverage rather than assuming a general cyber policy automatically covers a BEC loss at full value — this is a common and costly point of confusion after an incident.

Want an Honest Read on Your BEC Exposure?

IT Cares reviews your email security setup and verification procedures, then helps you build a real, low-friction defense your team will actually follow.

Comments (3)

RG
Robert G., Toronto
July 25, 2026

We had almost the exact "owner traveling, urgent wire" scenario described here. Thankfully our controller called my actual cell instead of replying. That call took two minutes and saved us $40K+.

NP
Nadia P., Brampton
July 24, 2026

Didn't realize how close our vendor banking domain was spoofed until I compared the two side by side. One letter different. Genuinely unsettling how easy it is to miss.

JW
Jordan W., Winnipeg
July 23, 2026

We only had verification rules for wire transfers, not payroll changes. This article is why we're extending the policy to cover direct deposit changes too.

Leave a Comment

Protect My Business