Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do business email compromise attacks peak during…
Threats, Abuse & Incident Response

Why do business email compromise attacks peak during finance-heavy periods?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Threats, Abuse & Incident Response

BEC works best when payment decisions, vendor changes, and budget activity are already moving quickly. That creates ambiguity, which attackers exploit by impersonating trusted counterparties and pushing recipients to bypass normal verification. The risk is highest when process pressure is stronger than identity confirmation.

Why finance-heavy periods create the best cover for BEC

When finance teams are busy, the normal friction that protects payments gets weaker. Approvals move faster, exceptions become common, and staff are more willing to treat an urgent message as part of the process rather than as a challenge to it. That is why attackers time BEC for periods where urgency, volume, and routine change are already expected.

In those windows, the attacker does not need to invent confusion, only to ride along with it. A fake invoice, altered bank details, or a “new contact” request is more believable when the recipient already expects unusual requests, tight deadlines, and incomplete context. The more the organisation normalises speed, the less attention individual messages receive.

Finance-heavy periods also compress verification into the least convenient moment. If the person who must confirm a payment is in meetings, travelling, closing books, or handling exceptions, the attacker benefits from delayed callback checks, skipped secondary approval, and reliance on familiar names in email threads. That is why process load becomes a security factor, not just an operations issue.

Where the attack path becomes easier for criminals

BEC succeeds when the social engineering fits the business rhythm. Attackers watch for payroll runs, quarter-end activity, vendor onboarding, tax deadlines, and budget resets because those events create predictable pressure points. They then imitate the people most likely to be trusted during those periods, including executives, suppliers, and internal finance approvers.

The technique is attractive because it exploits the normal trust chain rather than breaking technical controls first. If an inbox, supplier account, or executive identity is already trusted, a well-timed request can appear routine enough to bypass suspicion. For a practitioner view of how impersonation, mailbox abuse, and payment fraud combine, see Email Identity and BEC Guide.

That same trust chain is what makes finance periods dangerous at scale. The more invoices, corrections, and approvals move through email, the more opportunities attackers have to insert a small change that looks operationally normal. A single altered bank account number can be enough if the recipient assumes the request is part of an already-pressured workflow.

What defenders should treat as the real control problem

The core issue is not simply phishing resistance, it is whether payment decisions remain independently verified when the organisation is under pressure. Controls matter most when they are inconvenient: callback verification, dual approval, vendor master data checks, and segregation between request, approval, and release. If those steps disappear during busy periods, the attacker has already won part of the process.

business email compromise also overlaps with mailbox impersonation, OAuth abuse, and stolen credentials that make fraudulent requests look more convincing. In practice, a finance team needs to assume that a message may come from a real-looking but compromised account, not just a spoofed sender. NHIMG’s Microsoft verified publisher OAuth phishing 2022 shows how mailbox access can be obtained through trusted-looking application abuse, which turns email into a stronger fraud channel.

That is why finance-heavy periods deserve more than awareness training. They require explicit operational checks on who can change payment details, who can approve an exception, and what evidence is required before money moves. If those decisions are left to message tone and urgency, the attack surface expands exactly when the business is least able to absorb a mistake.

Risk and Threat Considerations

Finance-heavy periods raise exposure because the organisation is simultaneously processing more exceptions, more payments, and more message-driven decisions. That combination creates a favourable environment for impersonation, rushed approvals, and payment redirection, especially when staff assume urgency is normal.

Failure mechanism: Attackers exploit workload pressure to push recipients past independent verification, then use trusted-looking correspondence to redirect funds or alter vendor details before inconsistencies are checked.

Impact: The result can be fraudulent payment, delayed recovery, vendor disruption, and a wider loss of confidence in payment and email workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementFinance-heavy BEC often abuses account and vendor-change workflows, so account governance matters.
Recommendation — Review and restrict payment-related account changes and approvals.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeBusy finance periods become safer when payment change authority is tightly limited.
IA-2 — Identification and Authentication (Organizational Users)BEC relies on trusted-looking internal senders, making user authentication and verification central.
AU-6 — Audit Record Review, Analysis, and ReportingBEC investigations depend on tracing approval, mailbox, and payment-change activity.
Recommendation — Limit who can initiate, approve, and release payment changes. Strengthen identity verification for users who can approve finance actions. Review alerts and audit trails for anomalous payment and mailbox activity.
ISO/IEC 27001:2022A.5.15 — Access controlPayment and vendor workflows need controlled access during high-pressure periods.
Recommendation — Enforce access restrictions on payment and vendor-master processes.

Practitioner Guidance

What to prioritise: Put the strongest verification steps on the exact transactions that are most likely to be rushed, especially vendor bank changes, first-time payments, and exceptions near close or payroll. Those are the points where urgency most often defeats caution.

What to verify: Require an out-of-band confirmation path for any request that changes payment destination, approver chain, or urgency level. If the request cannot survive a callback or known-good contact check, it should not be paid.

Practitioner takeaway: BEC peaks when finance activity is noisy enough to make fraud look ordinary, so the safest control is to make payment validation harder to skip precisely when the business feels it has the least time.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org