IT support. Cybersecurity. Business continuity.
Let’s talk

Business Email Compromise: How Invoice Fraud Hits Small Offices and How to Stop It

BEC cost US businesses $3.05 billion in 2025. Learn how invoice fraud works, the payment-change callback rule, key Microsoft 365 settings and a first-hour plan.

Bookkeeper at an office desk calling a vendor to verify a bank account change before paying an invoice
Published October 9, 2026

Quick answer: verify every payment change before money moves

BEC cost US businesses $3.05 billion in 2025. Learn how invoice fraud works, the payment-change callback rule, key Microsoft 365 settings and a first-hour plan.

The fix is procedural and technical

Business email compromise (BEC) is a scam where a criminal sends or hijacks a trusted email, usually from a vendor, executive or client, to redirect a payment. The FBI's IC3 logged 24,768 BEC complaints and $3.05 billion in losses in 2025. Verify every payment change by phone using a number you already had, use phishing-resistant MFA, block automatic external forwarding and enforce DMARC. The callback rule, Microsoft 365 checklist and first-hour response plan below show how.

How a BEC scam actually reaches a small office

Most small-office cases follow the same path. An attacker phishes one mailbox, often the owner, the bookkeeper or a vendor's accounts-receivable clerk. They sign in quietly, create an inbox rule that hides replies, and read mail for days or weeks. When a real invoice is due, they reply in the existing thread with "updated banking details." The email is not fake. It comes from the real account, in the real conversation, so it passes every spam filter.

That is why training people to spot typos is not enough. The FBI lists the common variants: a vendor invoice with a new bank account, a CEO asking for gift cards, and fake wire instructions on a real estate closing. All three end with money sent to an account the attacker controls.

PatternWhat arrivesWho it targetsControl that stops it
Vendor email compromiseA real supplier's mailbox sends "new remit-to" bank details on a real invoiceBookkeepers, AP clerksCallback to a number already on file before any bank change
Executive impersonation"Are you at your desk? I need gift cards / a quick wire" from the owner's nameOffice managers, new hiresWritten rule: no payment or gift card request is approved by email alone
Closing / settlement wire fraudSpoofed title company or attorney sends changed wiring instructions days before closingReal estate, law firms, their clientsVerbal confirmation of wiring instructions using a number from the engagement letter
Payroll diversionAn "employee" asks HR to change their direct deposit accountHR, payrollBank changes only through the payroll portal plus a call to the employee
The four BEC patterns we see most in VA, MD and DC offices

What business email compromise costs: the 2025 numbers

The FBI Internet Crime Complaint Center's 2025 report counted 24,768 BEC complaints with $3,046,598,558 in reported losses. Divide one by the other and the average reported BEC loss works out to about $123,000 per complaint.

The same report shows how busy our region is for internet crime overall (all crime types, not BEC alone):

JurisdictionComplaintsReported losses
Virginia25,314$476,120,025
Maryland19,430$390,242,821
Washington, DC3,113$97,368,097
IC3 2025 internet crime complaints and losses in the DMV (all crime types)

There is one hopeful number. In 2025 the IC3 Recovery Asset Team worked 3,900 Financial Fraud Kill Chain incidents covering $1.16 billion in attempted theft and froze $679 million, a 58% success rate. Freezes depend on speed, which is why the response plan below is measured in minutes.

Business email compromise prevention: the payment-change callback rule

If you adopt one control this week, make it this one. It costs nothing and it stops the most expensive pattern, invoice fraud through a compromised vendor. Write it down, get the owner to sign it, and give it to everyone who can move money.

  1. Any change to bank details is a stop event. New account, new routing number, "our bank changed," or "use this account just this once" all count. No payment goes out on new details until steps 2–4 are done.
  2. Call a number you already had. Use the phone number in your accounting system, contract or a past paper invoice. Never use a number, link or signature block from the email that asked for the change.
  3. Ask the vendor to confirm, not you. Say "Can you read me the account number you expect us to use?" rather than reading yours out for a yes.
  4. Second approver for changes and large payments. Pick a dollar threshold that fits your business. Above it, a second person signs off. In a three-person office, the owner is the second approver and a named backup covers vacations.
  5. Log it. Record the date, who called, the number used and who confirmed. Auditors, banks and cyber insurers will ask for this after an incident.
Urgency is the tell. Requests to skip the process because "the CEO is boarding a flight" or "the closing is today" are exactly when the callback matters most. The FBI's own guidance says to be especially cautious when someone pressures you to act quickly.

Microsoft 365 settings that block the takeover

The callback rule protects payments. These settings protect the mailbox the attacker needs. Most can be checked in an afternoon by whoever administers your tenant.

SettingWhereTarget state
MFA for every account, including shared and adminMicrosoft Entra ID (Conditional Access or security defaults)On for 100% of sign-ins; prefer app-based or phishing-resistant methods over SMS
Automatic external forwardingDefender outbound spam policyExplicitly set to Off - Forwarding is disabled, not left on the system-controlled default
Hidden inbox rulesExchange Online PowerShellReview monthly with Get-InboxRule -Mailbox user@domain -IncludeHidden
DMARC on your domainPublic DNS (_dmarc TXT record)Move from p=none to p=quarantine to p=reject after reviewing reports
External sender tagExchange OnlineOn, so lookalike domains show an "External" warning
Sign-in alertsEntra ID sign-in logs or your MDRAlerts for impossible travel and new-country sign-ins
Microsoft 365 BEC hardening checklist

With forwarding set to Off, any inbox rule that redirects mail to an outside address simply bounces with error 5.7.520, which shuts down the most common way attackers keep a copy of your conversations. Our MFA management service rolls out and enforces these controls across every user, and our phishing prevention training runs realistic BEC simulations so staff practice the callback before it is real.

Stolen passwords are often how the first mailbox falls. Dark web monitoring flags staff credentials that show up in breach dumps so you can reset them before someone tries them.

The first 60 minutes after a fraudulent payment

Print this and tape it next to the bookkeeper's monitor. The order matters: money first, mailbox second, paperwork third.

Timeline graphic of BEC response steps: call the bank, file at ic3.gov, revoke sessions, check inbox rules
WhenActionOwner
Minute 0–15Call your bank's fraud line. Ask them to recall the wire or ACH and contact the receiving bank.Owner or controller
Minute 15–30File a complaint at ic3.gov with the amount, date, receiving bank, account number and the emails.Owner
Minute 15–30Disable the compromised account and select Revoke sessions in the Microsoft Entra admin center, then reset the password and MFA.IT provider
Minute 30–60Check that mailbox for inbox rules, forwarding and app consents. Export the message trace and sign-in logs before deleting anything.IT provider
Same dayWarn vendors and clients that came through the hijacked thread. Notify your cyber insurer.Owner
Within a weekReview whether personal or client data was exposed and what notification rules apply to you.Owner with counsel
BEC response timeline for a small office

Revoking sessions matters because a password reset alone does not end an attacker's existing sign-in. Microsoft notes that access tokens stay valid until they expire, one hour by default, unless sessions are revoked. If you have an intrusion detection and response service, its team should run steps 3 and 4 for you.

Industries in the DMV with extra exposure

  • Accounting, tax and financial advisory firms. They move client money and hold tax data. The FTC Safeguards Rule names tax preparation firms as covered and requires a written information security program, MFA and staff security training. See our IT for financial services firms.
  • Real estate and title. Closing wire fraud is the classic BEC case. Brokerages should send clients a written "we will never change wiring instructions by email" notice at contract. Read more about IT for real estate offices.
  • Law firms. Settlement payouts and trust accounts are targets, and attorney impersonation is a named BEC variant. Our law firm IT support covers mailbox hardening alongside matter permissions.

Ask your cyber insurer whether your policy covers social engineering or funds transfer fraud. It is often a separate, sub-limited coverage, and many carriers require callback verification to pay a claim. Our guide to cyber insurance for small businesses lists the questions underwriters ask. For the wider baseline, work through our small business cybersecurity checklist.

How Genius Fixers protects offices in Virginia, Maryland and DC

From our office in Manassas, we set up the controls above for businesses across Northern Virginia, Maryland and Washington, DC. That includes MFA on every account, forwarding blocked, DMARC moved to enforcement, monthly inbox-rule reviews and a written payment-change policy your team can follow.

  • Core IT starts at $125 per workstation per month and includes email security, MFA configuration, cloud identity threat monitoring and dark web monitoring for your primary domain.
  • Complete IT starts at $150 per workstation per month and adds phishing training, vulnerability management and an annual risk assessment. Compare plans on our managed IT pricing page.

Want a second set of eyes on your Microsoft 365 tenant and payment process?

Book a free 10-minute call and we'll tell you which BEC controls you're missing.

Book a free consultation

Call 703-419-9000 or 1-800-949-6592 to review your BEC controls.

Frequently asked questions

What is a BEC scam?

A BEC scam is fraud where a criminal uses a hijacked or spoofed business email account to trick someone into sending money or sensitive data. Common versions are fake vendor invoices with new bank details, fake CEO requests for gift cards or wires, and fake closing wire instructions.

How much did BEC cost US businesses in 2025?

The FBI's IC3 2025 Internet Crime Report recorded 24,768 BEC complaints and $3,046,598,558 in reported losses. That averages about $123,000 per complaint.

How do you prevent invoice fraud from a compromised vendor?

Treat every change to a vendor's bank details as a stop event and confirm it by calling a phone number you already had on file, never one from the email. Add a second approver for bank changes and large payments, and log every verification call.

Can you get money back after wire transfer fraud?

Sometimes, if you act fast. Call your bank's fraud line immediately to request a recall, then file at ic3.gov. In 2025 the IC3 Recovery Asset Team froze $679 million of $1.16 billion in attempted theft, a 58% success rate.

Does MFA stop BEC?

MFA blocks most password-only takeovers of your own mailboxes, but it does not stop a compromised vendor from emailing you. You still need the callback rule for payment changes, and phishing-resistant MFA methods are stronger than SMS codes.

Who should a small business report BEC to?

Report it to your bank first, then to the FBI's Internet Crime Complaint Center at ic3.gov. Also notify your cyber insurer and any vendors or clients whose email threads were involved.

How do I check Microsoft 365 for malicious inbox rules?

In Exchange Online PowerShell, run Get-InboxRule -Mailbox followed by the user's address and add -IncludeHidden to show hidden rules. Look for rules that move, delete or forward messages containing words like invoice, payment or wire.

Sources

Last reviewed October 9, 2026 by the Genius Fixers IT Team, Manassas, VA.

Need a hand with this?
Talk to a Genius Fixers engineer, free.
Book a Phone / Zoom Call
Keep reading

Related posts

All articles →

Side-by-side comparison of a vulnerability scan report and a penetration test attack path for a small office network
Cybersecurity · October 8, 2026

Vulnerability Assessment vs Penetration Testing: What a Small Business Needs First

Vulnerability assessment vs penetration testing: what each finds, how often FTC, PCI DSS and HIPAA expect them, and which a VA, MD or DC office needs first.

Read More
In-house IT administrator and a managed service provider technician reviewing a shared task list for co-managed IT
Managed IT · October 7, 2026

Co-Managed IT vs Fully Managed IT: Which Fits a Business With One IT Person?

Co-managed IT vs fully managed IT for a business with one IT person: a who-does-what matrix, real cost math and a 30-day plan for VA, MD and DC offices.

Read More
Genius Fixers Managed Wi-Fi for Small Business guide with purple branding and a wireless access point
Managed IT · October 6, 2026

Managed Wi-Fi for Small Business: What You’re Actually Paying For

Business Wi-Fi supports cloud applications, voice, video, guest access and mobile devices, so reliability depends on more than the access point itself. A managed service should provide centralized administration, consistent configuration, monitoring, security oversight and a clear support path when connectivity problems occur.

Read More