Business Email Compromise in the UK: How to Detect and Prevent It in 2026

How can UK businesses detect and prevent Business Email Compromise?

UK businesses can reduce the risk of Business Email Compromise (BEC) by combining strong email security, multi-factor authentication (MFA), employee awareness and clear payment verification procedures. BEC attacks are often highly targeted and rely on impersonation, social engineering or compromised email accounts rather than obvious malware. Businesses should therefore verify unexpected financial requests, protect email accounts, monitor for unusual activity and encourage employees to report suspicious communications quickly.

What is Business Email Compromise?

Business Email Compromise is a form of cyber-enabled fraud in which criminals deceive employees into transferring money, changing payment details or disclosing sensitive information. Attackers may impersonate senior executives, suppliers, clients or other trusted contacts, or compromise a genuine business email account and use it to make fraudulent requests.

BEC attacks are typically targeted rather than sent indiscriminately. Criminals may research an organisation and its employees using publicly available information, previous communications or compromised accounts to make fraudulent messages appear more credible.

This means businesses of all sizes need both technical safeguards and processes that make suspicious financial or information requests harder to approve without verification.

Why Business Email Compromise remains a serious business risk

BEC attacks can exploit weaknesses in email security, account protection and internal approval processes at the same time. A convincing request may appear to come from a familiar supplier or senior employee, while the actual objective is to redirect a payment or obtain access to sensitive information.

Common BEC scenarios include:

  • Urgent payment requests.
  • Supplier bank account changes.
  • Fake or altered invoices.
  • Payroll redirection requests.
  • Executive impersonation.
  • Requests for confidential business information.
  • Compromised accounts used to continue existing email conversations.

The NCSC recommends a layered approach to email security, including strong authentication, anti-spoofing controls and measures that make phishing more difficult.

Common Business Email Compromise techniques

CEO fraud

In CEO fraud, criminals impersonate a senior executive and request an urgent payment, confidential information or another sensitive action.

The message may create pressure by presenting the request as confidential or time-sensitive. Employees may feel reluctant to question a request that appears to come directly from a senior leader, which is why independent verification should form part of the payment process.

Invoice and payment diversion fraud

Attackers may impersonate a legitimate supplier and request that future payments are sent to a different bank account.

This type of payment diversion can be particularly difficult to identify when the fraudulent request appears within an existing business relationship. Action Fraud recommends independently verifying requests involving changes to supplier bank details or unusual payments.

Payroll fraud

Criminals may target HR or payroll teams with requests to change an employee’s salary payment details.

If the request is accepted without independent verification, future salary payments could be redirected to an account controlled by the criminal.

Compromised email accounts

Some BEC attacks involve genuine business email accounts rather than spoofed addresses. Criminals may obtain access through phishing, stolen credentials or other methods and then use the account to monitor conversations, impersonate the account owner or manipulate payment-related communications.

This is one reason why protecting business email accounts should be treated as part of the organisation’s wider cyber security strategy.

Warning signs employees should recognise

BEC messages can be convincing, but certain requests should trigger additional verification.

Employees should be cautious when an email:

  • Requests an urgent or unusual financial transaction.
  • Asks for supplier bank details to be changed.
  • Attempts to bypass established approval procedures.
  • Requests confidential information unexpectedly.
  • Creates pressure to act immediately.
  • Appears unusual compared with the sender’s normal communication style.
  • Comes from a compromised or unfamiliar account.

When there is uncertainty, employees should not rely on the email itself for verification. Instead, they should contact the supposed sender through a trusted telephone number or another established communication channel.

Strengthen email security controls

Technology cannot prevent every BEC attempt, but strong email and account security can reduce the opportunities available to attackers.

Businesses should consider implementing:

  • Multi-factor authentication for business email and other important online services.
  • SPF, DKIM and DMARC to reduce email spoofing.
  • Effective email filtering and anti-phishing controls.
  • Appropriate access and conditional access policies.
  • Strong password or passkey protection.
  • Monitoring for unusual account activity.
  • Regular review of email forwarding rules and account settings.

The NCSC recommends MFA for online services containing sensitive information and recommends anti-spoofing controls such as SPF, DKIM and DMARC to make it harder for criminals to impersonate an organisation’s domain.

A wider security review can also help organisations understand how email, identity, access controls and other systems fit into their overall risk profile. Businesses looking for broader guidance can explore cyber security consulting.

Train employees to identify BEC attacks

Even with effective technical controls, employees remain an important part of the defence against BEC. Finance, HR, procurement, payroll and senior management teams can be particularly exposed because they handle payments, supplier relationships or sensitive information.

Effective awareness training should teach employees how to:

  • Verify unusual payment requests.
  • Recognise impersonation attempts.
  • Confirm supplier bank account changes independently.
  • Identify suspicious or unexpected requests for information.
  • Report suspicious emails quickly.
  • Follow established approval and escalation procedures.

Security awareness should also be reinforced regularly rather than treated as a one-time exercise. Guidance on security awareness training can help organisations consider how awareness programmes should adapt to different working environments.

Introduce stronger payment verification procedures

BEC often succeeds because a fraudulent request passes through a legitimate business process. Technical security therefore needs to be supported by financial controls that make unauthorised changes harder to approve.

Businesses should establish procedures that require:

  • Independent verification of unusual payment requests.
  • Secondary approval for high-value or exceptional transactions.
  • Independent confirmation of supplier bank account changes.
  • Verification of urgent executive requests through another communication channel.
  • Clear documentation of payment approvals.
  • Restricted access to systems used to change payment information.

For important financial requests, the person approving the payment should not rely solely on the email as evidence that the request is genuine. Independent verification can prevent a convincing impersonation attempt from becoming a completed fraudulent transaction.

Prepare an incident response plan

Strong preventive controls reduce risk, but businesses should also know what to do if a BEC attack succeeds.

If a fraudulent payment has been made, the business should act quickly. The NCSC recommends reporting the incident internally and contacting the bank directly using official contact details.

An incident response process should consider:

  • Reporting the incident immediately.
  • Contacting the bank or relevant financial institution if funds have been transferred.
  • Securing or resetting compromised accounts.
  • Reviewing affected email accounts and account activity.
  • Checking forwarding rules and other suspicious configuration changes.
  • Preserving relevant emails and evidence.
  • Assessing whether personal or confidential data has been exposed.
  • Informing relevant stakeholders where appropriate.

Businesses can also review practical guidance on responding during the first hour of a cyber incident to understand the importance of early containment, documentation and escalation.

Strengthen wider cyber resilience

BEC should not be treated as an isolated email problem. A compromised email account can provide access to sensitive information, business communications and other online services.

Organisations should therefore consider email security alongside broader cyber risk management, access control, employee awareness, incident response and business continuity.

Building stronger data breach resilience can help businesses prepare for the wider operational and information-security consequences of an incident.

Frequently asked questions

What is the difference between phishing and Business Email Compromise?

Phishing is a broad category of attacks that attempt to deceive people into revealing information, accessing malicious websites, transferring money or taking another harmful action. BEC is generally more targeted and often involves impersonating a trusted individual or compromising a genuine business email account to influence a financial or sensitive business decision.

Which departments are most at risk?

Finance, HR, procurement, payroll and senior management teams can be attractive targets because they may authorise payments, manage supplier relationships or handle sensitive information. However, BEC can affect employees across an organisation.

Can multi-factor authentication prevent Business Email Compromise?

MFA can significantly reduce the risk of account compromise, particularly when strong, phishing-resistant authentication is used, but it does not eliminate every form of BEC. Attackers may still attempt to deceive employees into approving legitimate-looking transactions or exploit other weaknesses in business processes. The NCSC recommends combining strong authentication with other security measures.

What should employees do if they suspect a BEC attack?

Employees should avoid relying on the suspicious email for verification, report it through the organisation’s established process and verify any related payment or information request through a trusted communication channel. If money has already been transferred, the business should contact its bank immediately using official contact details.

Protecting Your Business from Business Email Compromise

Business Email Compromise combines social engineering, impersonation and, in some cases, compromised accounts to target financial transactions and sensitive business information. Preventing it requires more than a single security control.

By combining strong authentication, email security, employee awareness and independent payment verification, UK businesses can make BEC attacks harder to execute successfully. Clear reporting procedures and a tested incident response process are equally important because early action can limit the consequences when an attack succeeds.

For organisations, the objective is not simply to identify suspicious emails but to build processes where unusual requests are routinely verified before they can cause financial or operational harm.