Join our Newsletter — 33% off our NHI Course

Why do pandemic-driven disruptions increase the risk of business email compromise in financial services?

When employees are dispersed, overloaded, and relying on unfamiliar channels, attackers can exploit confusion, urgency, and weaker verification habits. Business email compromise works better when normal communication patterns break down and staff are less able to confirm requests through trusted internal routes. In financial services, that risk is amplified because payment, trading, and confidential information flows depend on fast decisions.

Why disruptions make BEC easier to execute

Pandemic-style disruption breaks the routines that BEC defences depend on. When teams are dispersed, working through ad hoc channels, or under operational pressure, the usual human checks, “walk over to the colleague’s desk” verification, and predictable approval paths weaken. Attackers benefit because urgency, ambiguity, and reduced social friction make fraudulent instructions look routine.

In financial services, that effect is amplified by the speed of settlement, trading, treasury, and client payment workflows. A request that arrives during a period of change can be processed quickly because delay itself is costly, which gives attackers a narrower but more valuable window to blend in with legitimate business activity. Email identity controls and payment verification discipline matter because the compromise often starts with a believable message, not a technical exploit. Email Identity and BEC Guide

Disruption also increases dependence on remote collaboration tooling, forwarded messages, and alternative approval paths. Those conditions make it easier for an attacker to intercept a conversation, imitate a senior executive, or redirect a payment request before anyone notices that the communication chain has changed. The problem is not just mail delivery, it is the loss of a stable verification path across the business process itself.

Why financial services are a high-value target during disruption

Financial firms have dense payment flows, confidential customer data, treasury activity, and time-sensitive operational decisions. That concentration creates strong incentives for fraudsters because one successful compromise can produce immediate monetary gain or access to sensitive information that supports follow-on fraud. A small weakness in verification can become a material loss when the organisation moves money at scale.

This is why the sector needs to treat email compromise as part of broader financial-services identity and payment risk, not just as a mail hygiene issue. Controls around privileged workflow approval, third-party communications, and customer-facing instructions need to assume that the sender may be credible but not genuine. Financial Services Identity Security Guide

Attackers also exploit the fact that disruption changes who can validate a request. In normal conditions, a controller, finance manager, or operations lead may confirm an instruction through a trusted internal route. During a disruption, that confirmation may be slower, less formal, or handled by whoever is available, which lowers the quality of the trust decision and raises the success rate of impersonation.

What BEC campaigns exploit when normal work patterns break down

business email compromise succeeds when defenders lose certainty about the source, context, or urgency of a request. Disruption creates exactly that environment: people are overloaded, approvals are compressed, and exceptions become common. Attackers use those conditions to push for gift-card style fraud, invoice redirection, payroll diversion, or changes to banking details before scrutiny catches up.

The strongest examples are not always simple spoofing. They can involve account takeover, mailbox rule abuse, stolen credentials, or impersonation through another channel once trust has already been established. Financial firms should treat compromised email identity as a route into payment fraud, not as a standalone messaging problem. Real-world breach patterns show that stolen credentials and account abuse frequently support broader fraud and lateral movement. The 52 NHI Breaches Report and TruffleNet BEC Attack, Stolen AWS Credentials

Risk and Threat Considerations

Disruption increases both exposure and trust abuse. When a business is operating under changed routines, attackers can hide inside legitimate urgency, exploit weaker callback habits, and redirect payments before staff have time to validate the request through a trusted route. In financial services, that can turn a single convincing email into direct monetary loss or a broader compromise of sensitive business flows.

Failure mechanism: The attacker exploits degraded verification discipline, then uses urgency, impersonation, or compromised mail access to push a payment or instruction through before the inconsistency is challenged.

Impact: The result can be fraudulent transfers, account manipulation, exposure of confidential data, and follow-on social engineering against other business units or clients.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-2 — Identification and Authentication (Organizational Users) BEC often starts by abusing user access and trusted email accounts.
AC-6 — Least Privilege Limits damage if a mailbox or workflow account is abused during disruption.
AU-6 — Audit Review, Analysis, and Reporting BEC detection depends on reviewing anomalous mailbox and payment activity.
Recommendation — Enforce strong user authentication and conditional verification for sensitive financial actions. Restrict mail and payment workflow permissions to the minimum needed. Review email forwarding, login, and payment anomalies for suspicious changes.
NIST Zero Trust (SP 800-207) Zero Trust Architecture Trusted internal routes can fail under disruption, so every request needs fresh verification.
Recommendation — Apply continuous verification to urgent requests regardless of channel or location.
CIS Controls v8 5 — Account Management Compromised or misused accounts often enable BEC and related fraud.
Recommendation — Remove stale accounts and tightly govern privileged email and finance access.

Practitioner Guidance

What to prioritise: Focus first on the payment and instruction paths that can move money or sensitive information without a second, independent validation step. If a request can be actioned from email alone, it should be treated as a high-risk path during periods of disruption.

What to verify: Confirm that staff still have a reliable out-of-band method to validate urgent payment, banking-detail, and executive requests when normal office contact patterns are unavailable. The control is only real if people can actually use it under pressure.

Common mistake: Treating BEC as an awareness problem alone. The better indicator is whether the organisation has preserved a trusted verification route that survives remote work, overload, and channel changes.

Practitioner takeaway: Pandemic-driven disruption does not create BEC from nothing, it removes the friction that usually exposes it, so the decisive control is resilient verification, not just better phishing awareness.