Common indicators include unrecognized payments, vendors asking about overdue invoices, phishing emails sent from a compromised mailbox, and unexpected mail rules that forward, delete, or hide messages. Detection is often delayed because these attacks can stay quiet for weeks or months, so by the time someone notices, logs may already have rolled over.
What to look for when BEC is already in motion
A business email compromise incident rarely starts with obvious sabotage. The earliest signs are usually operational anomalies that do not fit normal finance or mail behaviour, especially when they cluster around payments, inbox controls, or unexpected replies from trusted contacts. Treat one odd event as a lead, but treat several together as evidence of active compromise.
The most important signal is a mismatch between process and behaviour. If a vendor suddenly asks about overdue invoices you know were paid, if a payment request changes bank details without the usual verification path, or if a mailbox begins sending messages the user did not write, the incident may already be beyond the initial foothold stage.
- Unrecognized or redirected payments, especially where approval was bypassed.
- Unexpected vendor follow-ups about invoices, remittance, or account changes.
- Mailbox activity that does not match the owner’s normal send pattern.
- New forwarding, deletion, hiding, or inbox rule changes that reduce visibility.
These indicators often appear before defenders see a clear alert, because the attacker’s first objective is usually to preserve access and exploit trust rather than trigger obvious disruption. That is why BEC investigations should focus on mailbox changes, payment anomalies, and cross-checking whether a trusted sender is actually the source of the request.
Why the warning signs are easy to miss
BEC is effective because it blends into normal business flow. The attacker may not need malware or a noisy login failure if they can use a legitimate mailbox, a compromised session, or a spoofed but trusted relationship to nudge one payment through. The result is that the business sees a routine finance or email event, while the attacker is already inside the communication path.
Mailbox rule abuse is especially important. Rules that forward messages externally, move payment-related mail into a different folder, mark items as read, or delete alerts can suppress the very evidence teams rely on. Once that happens, the compromise may persist long enough for logs, message traces, or audit history to become incomplete.
- Short, plain-language requests that bypass normal approval language.
- Reply-chain manipulation, where the conversation looks familiar but the content changes.
- Permission changes, delegated access, or suspicious session behaviour in the affected account.
- Missing mail that should have been seen by finance, AP, or leadership.
When these signs appear together, the issue is not just a suspicious email, it is a live trust failure across mailbox, identity, and payment workflow. That is the point where teams should assume the attacker is trying to convert access into financial loss, not merely send phishing mail.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1114 — Email Collection | BEC often depends on monitoring or abusing mailbox content and mail flow. |
| T1098 — Account Manipulation | Unexpected inbox rules and delegated access are common BEC persistence tactics. | |
| Recommendation — Monitor mailboxes for abnormal forwarding, hiding, or collection patterns. Alert on suspicious rule changes and delegated mailbox access. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | BEC investigations depend on knowing which mail and finance accounts should exist and be active. |
| 6.3 — Require MFA for Externally-Exposed Applications | Compromised email access is a common precursor to BEC and needs stronger access protection. | |
| Recommendation — Maintain an authoritative account inventory and investigate unexpected mailbox access. Require MFA on email and remote access paths to reduce account takeover risk. | ||
| NIST CSF 2.0 | DE.CM — Continuous Monitoring | BEC warning signs are detected through mailbox, payment, and identity monitoring. |
| Recommendation — Correlate mail, finance, and identity telemetry to spot active BEC. | ||
Practitioner Guidance
What to verify: Confirm whether the apparent sender, invoice, and bank-account change all align across an independent channel before treating the request as legitimate. Check mailbox rules, delegated access, and recent sign-in history on the suspected account at the same time, because a payment anomaly without mailbox evidence can still indicate a compromise path that has not yet been fully exposed.
Decision rule: If a payment request, vendor change, or executive instruction arrives with any mailbox-rule tampering or message-history anomaly, treat it as an active compromise investigation rather than a simple fraud review. The fastest containment step is to stop the payment path, preserve email evidence, and validate whether other inboxes received the same lure or reply-chain manipulation.
Practitioner takeaway: BEC is underway when business process, mailbox behaviour, and message provenance stop agreeing with each other. The more those signals cluster, the less useful it is to ask whether the email “looks suspicious” and the more important it becomes to contain the account, the payment flow, and the audit trail together.
Related resources from NHI Mgmt Group
- How do attackers turn a supply-chain incident into wider NHI compromise?
- What are the signs that a CI/CD supply chain compromise is already underway?
- What are the signs that SaaS supply chain compromise is already underway?
- What are the signs that supplier account compromise is being used to drive business email compromise?