TL;DR: Business email compromise remains a high-loss attack pattern, with nearly 20,000 attacks averaging $120,000 each, as attackers exploit urgency, fear, and hybrid work conditions to bypass existing controls, according to Abnormal AI. The governance problem is not awareness, but identity and process design that still leaves human decision-making too exposed.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Devastating Impact of Business Email Compromise”.
Key questions
Q: What should teams do when a compromised email account is detected?
A: Teams should move immediately from detection to containment.
Q: Why does hybrid work make business email compromise easier to pull off?
A: Hybrid work reduces the informal confirmation cues people rely on in an office, such as quick in-person checks and immediate peer validation.
Practitioner guidance
- Tighten payment verification paths Require out-of-band confirmation for wire changes, invoice updates, and urgent payment requests so a single email conversation cannot authorise funds movement.
- Separate approval and execution duties Split request approval, payment release, and beneficiary maintenance across different people or systems to reduce the chance that one compromised inbox can complete the full transaction.
- Harden executive impersonation checks Use callback procedures and known-contact validation for executive, finance, and vendor requests that arrive through email or chat, especially in hybrid work settings.
Bottom line: Business email compromise remains effective because it exploits human approvals inside normal business workflows, not because awareness has failed on its own.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Business email compromise is a human identity control problem disguised as an email problem. The article shows that attackers win by manipulating judgment inside ordinary approval flows, not by defeating every layer of technical security. That means the critical failure point is the trust boundary around human action, especially where finance, procurement, and executive communication intersect.
A question worth separating out:
Q: How should security teams balance awareness training and process controls for BEC?
A: Use awareness training to reduce mistakes, but rely on process controls to stop the loss path. The practical answer is layered verification, segregation of duties, and callback rules for high-risk requests, because trained users can still be bypassed when attackers exploit urgency and fear.
👉 Read our full editorial: Hybrid work is widening the business email compromise gap