Join our Newsletter — 33% off our NHI Course

Why do phishing and business email compromise keep producing such large losses even when complaint counts do not rise sharply?

Because these attacks are high-conversion, low-friction campaigns that exploit trust, urgency, and impersonation rather than volume alone. A single successful email compromise can trigger unauthorized payments, data exposure, or follow-on fraud. Losses scale when attackers target finance workflows, vendor communication, and payment approval processes that were never designed for adversarial manipulation.

Why losses keep outrunning complaint counts

Complaint volume is a weak proxy for loss when the underlying fraud is designed to convert only a small number of high-value targets. Phishing and business email compromise succeed by placing the attacker inside existing business trust paths, so the loss outcome is driven by who is reached, what authority they can influence, and how quickly the organization can be manipulated, not by raw campaign size.

This is why a flat or only modestly rising complaint rate can coexist with sharp dollar losses. The same pattern is visible in real-world compromise cases such as The 52 NHI Breaches Report, which shows how attacker value often comes from a small number of high-impact access paths rather than broad-volume intrusion.

How phishing and BEC convert trust into payment loss

These campaigns work because email is already a business workflow, not because the message itself is technically sophisticated. Once an attacker can impersonate a supplier, executive, or internal colleague, they can steer invoice changes, redirect payments, solicit payroll updates, or obtain credentials that open additional systems. The same trust path can also expose inbox data, contract details, and account recovery channels, which increases the downstream loss potential.

That conversion effect is amplified when the target environment treats email as an implicit approval layer. If finance, procurement, or executive assistants can move requests forward based on familiar tone and timing alone, the attacker only needs one believable interaction to trigger an expensive action.

A practical example is Arup deepfake fraud 2024, where impersonation and urgency drove a large transfer, and MailChimp Breach, where social engineering of credentials created broader exposure beyond the first mailbox.

Why the loss pattern is structurally different from the complaint pattern

Complaint counts mainly measure how many messages were reported or blocked, while losses measure how many fraudulent actions crossed a business control boundary. Those are different failure points. A campaign can generate many obvious phishing emails that are ignored or reported, yet still produce large losses if a smaller subset of messages reaches the right approvers, payment owners, or credential holders.

Attackers also adapt quickly to the weakest human and process junctions. They do not need every recipient to comply, only the one person whose mailbox, approval authority, or reset process can unlock value. That is why the most damaging cases often involve vendor onboarding, urgent payment requests, payroll change requests, or account recovery flows that were built for efficiency rather than adversarial pressure.

Risk and Threat Considerations

Phishing and BEC are high-risk precisely because they combine social engineering with business process abuse. The loss driver is not just credential theft, but the attacker’s ability to exploit trust relationships inside payment, vendor, and approval workflows, where a single successful action can create direct financial loss or a second-stage compromise.

Failure mechanism: An attacker gains enough credibility to bypass normal scrutiny, then uses that access to alter payment instructions, capture login tokens, or pivot into higher-value systems through trusted channels.

Impact: Organisations can suffer unauthorized transfers, invoice fraud, data exposure, account takeover, and operational disruption even when complaint metrics appear stable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Phishing is the core delivery mechanism behind this loss pattern.
T1589 — Gather Victim Identity Information Attackers exploit trusted roles and business context to improve BEC success.
T1078 — Valid Accounts BEC often turns stolen credentials into authorized-looking access and action.
Recommendation — Map observed lures to T1566 and harden controls around user-targeted delivery paths. Hunt for pretexting activity that collects role, vendor, or approval details. Prioritise detection for compromised accounts used to authorise payments or inbox changes.
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Limiting approval authority reduces the blast radius of one compromised mailbox or user.
IA-5 — Authenticator Management Credential theft and token abuse are common enabling mechanisms in BEC chains.
Recommendation — Restrict payment and vendor-change permissions to the minimum required set. Rotate and protect authenticators that can access mail, finance, or recovery workflows.

Practitioner Guidance

What to verify: Treat complaint counts as a hygiene metric, not a loss predictor. The more useful question is whether suspicious messages are reaching people who can approve money, reset access, or change vendor details, because that is where losses are created.

Decision rule: If an email path can change payment instructions, approve exceptions, or reset credentials without a second, independent check, treat it as a fraud-control gap rather than a user-awareness issue. The control objective is to break the attacker’s ability to turn one convincing message into an irreversible business action.

Practitioner takeaway: The right measure is not how many phishing messages were seen, but how many of them could still reach a high-trust workflow with enough authority to move money or unlock access.