Common warning signs include urgent or unusual payment requests, changes in bank details, grammar errors, mismatched sender information, and pressure to bypass normal approval steps. Teams should also treat account takeover indicators seriously, especially when a legitimate mailbox suddenly sends unexpected instructions. These cues are not proof on their own, but they should trigger independent verification before action is taken.
Recognising Fraud Patterns in Business Email Compromise
business email compromise fraud often looks convincing because it borrows the tone, timing, and authority of a real internal or external business process. The most useful clue is not a single error, but a cluster of anomalies that appear when a request is urgent, financially sensitive, and slightly out of character for the sender or the process being used.
Changes to payment destination, last-minute bank-detail updates, and pressure to skip normal review are especially important because they target the moment when teams are most likely to rely on trust instead of verification. Grammar mistakes and mismatched sender information still matter, but modern impersonation can be polished, so process deviation is often a stronger signal than obvious spelling errors.
Mailbox compromise changes the picture further. If a legitimate account suddenly issues unexpected instructions, that can indicate an attacker is operating from within a trusted channel rather than simply spoofing a display name. In that case, the warning is not just about the message content, but about the possibility that the account itself, or the communication path behind it, has been abused.
How to Separate Suspicious Messages from Normal Exceptions
The practical test is whether the request survives independent verification outside the email thread. A legitimate exception may still be urgent, but it should remain consistent with known contacts, approved payment workflows, and established escalation paths. Fraud attempts often fail when a second channel confirms that the change was never authorised.
Look for inconsistencies across sender identity, reply path, domain details, signature blocks, and the commercial context of the request. A message can appear locally familiar while still being fraudulent if the request is unusual for that counterparty, arrives at an odd time, or asks for a one-off deviation that would normally trigger extra scrutiny. For context on the downstream impact of credential abuse and account takeover in real incidents, see The 52 NHI breaches Report, which includes cases where stolen credentials enabled broader compromise, and TruffleNet BEC Attack, Stolen AWS Credentials, which shows how credential abuse can support business email compromise at scale.
One useful operational signal is whether the request is trying to collapse normal controls into a single email exchange. Fraudsters often want the approver, finance team, or supplier relationship owner to act quickly before a control check can happen. That is why a message can be highly suspect even when it does not contain a clear typo or an obviously fake address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 5 — Account Management | BEC often exploits account takeover and unauthorized account use. |
| CIS Control 6 — Access Control Management | Fraudulent payment requests try to bypass approval and access restrictions. | |
| Recommendation — Harden account lifecycle controls and review unexpected account activity quickly. Enforce approval paths and least privilege for payment and banking changes. | ||
| MITRE ATT&CK | T1566 — Phishing | BEC commonly begins with deceptive email messages that impersonate trusted senders. |
| T1114 — Email Collection | Compromised mailboxes let attackers observe and abuse trusted communication threads. | |
| T1078 — Valid Accounts | A legitimate mailbox sending fraudulent instructions implies abuse of real credentials. | |
| Recommendation — Hunt for impersonation and social-engineering indicators in inbound email traffic. Monitor for mailbox compromise and unusual message sent patterns. Investigate unexpected actions from valid accounts as potential compromise. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Verification and approval controls reduce the chance of fraudulent action on trusted channels. |
| DE.CM — Continuous Monitoring | Anomalous sender behaviour and mailbox takeover need detection and alerting. | |
| Recommendation — Require stronger verification before acting on payment or bank-detail changes. Monitor for unusual sender behaviour and suspicious mailbox activity. | ||
Practitioner Guidance
What to verify: Require an out-of-band callback or approved workflow confirmation before any payment, bank-detail change, or account reset is accepted. If the request came from a real mailbox but the instruction is unexpected, treat it as potentially compromised until the sender independently confirms it.
Decision rule: If the request changes money movement, beneficiary data, or approval routing, do not let urgency lower the verification bar. If the message pressures staff to bypass segregation of duties, that pressure itself is a fraud signal and should escalate the review rather than accelerate it.
What practitioners underestimate: A polished message with correct branding can still be fraudulent when the fraud lives in the process, not the prose. The most reliable safeguard is to verify the business event separately from the email that announces it.
Practitioner takeaway: Treat BEC as a trust-and-process problem first, a messaging-quality problem second. The more a request depends on speed, secrecy, or a one-time deviation, the more it should be challenged before any action is taken.
Related resources from NHI Mgmt Group
- How should organizations reduce the risk of business email compromise before attackers can trigger a fraudulent payment or data transfer?
- What are the signs that supplier account compromise is being used to drive business email compromise?
- How do attackers turn a supply-chain incident into wider NHI compromise?
- What did Shai Hulud 2.0 actually compromise?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org