Join our Newsletter — 33% off our NHI Course

Why does hybrid work make business email compromise easier to pull off?

Hybrid work reduces the informal confirmation cues people rely on in an office, such as quick in-person checks and immediate peer validation. Attackers use that gap to create urgency, impersonate trusted senders, and push decisions through before the target has a second way to verify the request.

Why hybrid work gives attackers more room to impersonate trusted senders

Hybrid work weakens the fast, informal checks that used to interrupt a fraudulent request. In person, people can swivel a chair, confirm a payment request, or overhear hesitation. Remotely, email becomes the default coordination layer, and that gives business email compromise more time to work before anyone pauses to validate the request.

That shift matters because BEC is usually not a technical exploit first, it is a trust exploit. The attacker is trying to borrow the credibility of a known executive, supplier, or colleague, then exploit the fact that the request arrives in a channel where urgency feels normal and verification feels slower.

In practice, the hybrid model increases the chance that a message reaches a decision-maker without friction. If the target is already moving between home, office, and mobile devices, the attacker can count on weaker context, fewer nearby validators, and more delayed challenge from the real person being impersonated.

Why urgency works better when people are not co-located

Hybrid work changes the rhythm of decision-making. A fake invoice, wire instruction, or account-change request can arrive when the target is isolated, distracted, or relying on asynchronous messages rather than live conversation. That creates the opening for pressure tactics such as “do this before the meeting” or “I am on the move and need this now.”

Because the target cannot easily verify the request face to face, the attacker can compress the response window. The shorter the window, the more likely a person is to rely on recognition of names, tone, and branding instead of checking whether the request really came from the claimed sender.

Hybrid work also increases dependence on digital context. When collaboration is spread across chat, email, calendar invites, and cloud documents, an attacker only needs one believable thread to look legitimate. That makes the first message, or the first reply in an existing thread, disproportionately valuable.

What hybrid work changes about verification and control

The core weakness is not remote work itself, it is the loss of shared verification habits. Organisations that rely on ad hoc approval, reply-chain confirmation, or “we would have heard about it if it was wrong” are especially exposed. A stronger control posture uses a second channel for verification, separates payment approval from request receipt, and makes exception handling explicit.

Technical controls still matter, but they work best when they reinforce process. Email authentication, sender reputation, mailbox protection, and payment verification reduce the attacker’s options, yet none of them remove the need for a deliberate out-of-band check when money, credentials, or sensitive changes are involved.

For a useful primer on stopping impersonation and mailbox abuse, the Email Identity and BEC Guide is the clearest fit because it ties the request path to the controls that actually break the scam. For a threat-and-impact view of real-world compromise patterns, see The State of NHI & AI Agent Breach Report 2026, which shows how stolen access and impersonation often move together once trust is established.

Risk and Threat Considerations

Hybrid work does not create BEC by itself, but it increases the odds that a fraudulent request is accepted before it is challenged. The risk is highest where approvals are rushed, executives travel often, and staff have no reliable habit for confirming unusual payment or account-change requests.

Failure mechanism: The attacker exploits reduced co-location, delayed peer validation, and normalised async communication to make a forged request feel routine, then uses urgency to prevent a second verification step.

Impact: Losses can include fraudulent transfers, mailbox compromise, vendor payment diversion, credential theft, and follow-on fraud that spreads through the same trust relationship the first message abused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP API Security Top 10 API2 — Broken Authentication Email compromise often starts with stolen or abused mailbox access.
Recommendation — Require stronger mailbox authentication and detection for account takeover attempts.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management BEC often succeeds after credential or token abuse of email accounts.
AC-6 — Least Privilege Limiting mailbox and finance-system permissions reduces BEC blast radius.
AU-6 — Audit Review, Analysis, and Reporting BEC detection improves when mailbox and payment anomalies are reviewed quickly.
Recommendation — Enforce strong credential lifecycle controls and rapid revocation for exposed accounts. Restrict account capabilities so compromised inboxes cannot approve or move funds freely. Monitor for unusual forwarding, login, and payment-approval patterns tied to BEC.
NIST SP 800-63 Digital Identity Guidelines Hybrid-work BEC is reduced by phishing-resistant verification of users and staff accounts.
Recommendation — Use phishing-resistant authentication for accounts that approve sensitive requests.

Practitioner Guidance

What to prioritise: Focus first on the approval paths that can move money, reset credentials, or change supplier bank details. Those are the requests where reduced social friction in hybrid work most directly increases loss potential.

Decision rule: If a request is unusual, time-sensitive, or comes from a relationship that could be impersonated, treat email as insufficient proof and require a second-channel check with a known contact method.

What to verify: Confirm that teams can still authenticate the requestor, not just the message, and that the verifier has an independent way to reach the real person or vendor. If that cannot be done quickly, the process is too dependent on email trust.

Practitioner takeaway: Hybrid work makes BEC easier when organisations confuse communication convenience with identity assurance; the control objective is to preserve fast business execution without letting speed replace verification.