Cybersecurity

Business Email Compromise Prevention: Payment Verification, Mailbox Rules and Account Recovery

Prevent business email compromise with practical controls for invoice verification, vendor bank-detail changes, mailbox forwarding rules, OAuth access, phishing-resistant MFA and rapid account recovery.

Published 4 Oct 2026 · Digital Reality Studio
Business Email Compromise Prevention: Payment Verification, Mailbox Rules and Account Recovery

What business email compromise looks like

Business email compromise (BEC) is a fraud pattern in which criminals use social engineering, stolen credentials, mailbox access or impersonation to influence a legitimate business transaction. The goal may be to redirect a vendor payment, obtain payroll information, approve a fake invoice, purchase goods on credit or gain access to another account.

BEC does not always require a technically sophisticated malware infection. A criminal may impersonate an executive from a lookalike domain, compromise an employee's mailbox, register an OAuth application, or use a real account to make a request appear trustworthy. The FBI's Internet Crime Complaint Center (IC3) recorded more than $2.77 billion in reported BEC losses in 2024, illustrating why payment processes and email security need to work together. See the FBI IC3 2024 Annual Report and its BEC prevention guidance.

The most effective defense is not asking employees to spot every convincing message. It is creating a process in which an email alone cannot authorize a high-risk payment or account change.

Build a payment verification procedure before an incident

A payment verification procedure should apply to wire transfers, ACH payments, international payments, large purchases, refunds, payroll changes and any request to alter a vendor's bank details. Document the procedure, train the people who approve payments and test it with realistic scenarios.

1. Require an independent verification channel

When a supplier, customer, executive or employee requests a new payment destination or a change to existing bank details, do not verify the request by replying to the same email thread. Instead, contact the person or organization through a previously known telephone number, a trusted vendor portal or another communication channel already recorded in your business systems.

Do not use a phone number, QR code or contact link supplied only in the suspicious message. A compromised mailbox may contain accurate-looking signatures, invoices and telephone numbers controlled by the attacker.

2. Use dual approval for high-risk transactions

Separate the person who enters a payment from the person who approves it. The second reviewer should confirm the recipient, amount, purpose, invoice, account details and verification record. For small organizations, this may involve an owner, finance lead or department manager. The control is valuable because it creates a deliberate pause and prevents one compromised account from controlling the entire transaction.

3. Define risk triggers

Require additional verification when a request includes one or more of these conditions:

  • A new vendor or unfamiliar bank account.
  • A change to a vendor's routing number, account number or payment address.
  • An urgent request that bypasses the normal approval process.
  • A request from an executive to keep the transaction confidential.
  • A last-minute change to an invoice, purchase order or closing instruction.
  • A payment involving an international account, cryptocurrency, gift cards or an unusual payment method.
  • A request that conflicts with prior instructions or established contract terms.

The Federal Trade Commission recommends clear procedures for approving purchases and invoices and advises businesses to scrutinize how a payment is requested. Its small-business scam guidance is available at FTC.gov.

4. Record the verification

Keep a short audit record showing who requested the change, who verified it, which channel was used, when the verification occurred and what information was confirmed. Store this with the invoice or vendor record. A written trail helps reviewers detect repeated attempts and gives investigators useful evidence if fraud occurs.

Prevent vendor bank-detail change fraud

Vendor bank-detail change fraud is one of the most damaging BEC scenarios because the underlying invoice may be genuine. The attacker only changes where the money should go.

Use these controls:

  • Maintain vendor master data in a system with restricted write access.
  • Do not allow a payment request email to update bank details automatically.
  • Require independent verification for every bank-detail change, even when the request appears to come from a familiar contact.
  • Send a confirmation to the old, trusted contact method and the newly supplied contact method, but do not treat email confirmation alone as sufficient.
  • Consider a short cooling-off period before the first payment to a changed account, where business operations allow it.
  • Review changes to supplier records periodically and alert on unusual edits.
  • Match invoices against purchase orders, contracts, receiving records and known payment patterns.

Be especially cautious when an attacker uses a real conversation. A compromised supplier or employee account can produce messages that contain accurate historical details. Familiarity is not proof of authenticity.

Protect email accounts against takeover

Email is a high-value identity system because it can expose invoices, contracts, password-reset messages, customer data and internal conversations. An attacker who controls an employee's mailbox may silently monitor a transaction before sending a fraudulent instruction.

Use strong authentication

Require multifactor authentication for email, identity providers, finance platforms, remote access, password managers and administrative accounts. Prefer phishing-resistant methods such as passkeys or FIDO2 security keys for administrators, finance staff, executives and other users who can authorize payments. NIST explains that passwords and manually entered one-time codes are not phishing-resistant because an attacker may relay them to an impostor website; its guidance on authenticators is available at NIST SP 800-63B.

MFA does not replace payment controls. A criminal may still use a compromised session, a stolen browser token, a delegated application or a trusted mailbox to manipulate a transaction. Treat authentication, email monitoring and financial approval as separate layers.

Reduce password and session risk

  • Use a unique, long password for each account and store it in an approved password manager.
  • Disable legacy authentication protocols when your email platform supports that control.
  • Review sign-in alerts, unfamiliar devices, impossible-travel events and unusual locations.
  • Restrict administrative roles and use separate administrator accounts.
  • Remove former employees and dormant accounts promptly.
  • Review delegated mailbox access and shared-mailbox permissions.

Phishing-resistant MFA is covered in more detail in the DRS Guides article Phishing-Resistant MFA for Small Businesses.

Inspect mailbox rules, forwarding and OAuth grants

Attackers frequently create mailbox rules to hide evidence or maintain visibility into business conversations. Examples include forwarding messages to an external address, moving messages containing terms such as “invoice” or “wire” into a hidden folder, marking messages as read, deleting security notifications or redirecting replies.

Mailbox rules are not automatically malicious. Employees may use legitimate rules for newsletters, ticket routing or shared workflows. The security issue is an unapproved rule that changes the visibility or delivery of sensitive messages.

Review these settings after any suspected compromise

  • Inbox rules and server-side filters.
  • External forwarding addresses.
  • Hidden, archive or unusual folders.
  • Delegates, shared-mailbox permissions and send-as permissions.
  • Automatic replies and signature changes.
  • Recently registered OAuth applications and consent grants.
  • Active sessions, refresh tokens and connected devices.
  • Mail transport rules and administrator-created routing policies.

Prioritize alerts for newly created external forwarding rules, rules that delete or hide messages, and OAuth grants that request broad access to mail, contacts or files. Where possible, block automatic external forwarding by default and permit documented exceptions only for approved business workflows.

Review your email provider's audit logs for rule creation, suspicious sign-ins, mailbox access, consent grants and changes to authentication methods. If you use Microsoft 365, Google Workspace or another hosted platform, the exact menu names and log retention periods vary, so use the provider's current administrator documentation rather than relying on an old checklist.

Recognize high-risk BEC requests

Training should focus on decisions, not only on visual clues. A message may contain correct branding, a real signature and a familiar email thread. Teach employees to pause when a request changes money, authority or sensitive information.

Warning signs include urgency, secrecy, pressure to bypass normal approvals, a changed reply-to address, a lookalike domain, a request to use a new payment method, unusual writing for the sender, or an executive request made outside normal working patterns. These signs are prompts for verification, not proof that a message is fraudulent.

Employees should never send passwords, MFA codes or recovery codes by email. They should not approve a payment solely because the sender's display name is familiar. On mobile devices, staff should expand the sender details and inspect the complete address before taking action.

Account takeover response: the first hour

If you suspect that an email account has been compromised, treat it as an incident. Do not wait for confirmation if the account can influence payments or access sensitive information.

  1. Contain the account. Disable the account or block risky access according to your identity provider's incident procedure. Preserve the account and mailbox data rather than deleting it.
  2. Revoke access. Reset the password from a known-clean device, revoke active sessions and refresh tokens, remove unfamiliar MFA methods, and revoke suspicious OAuth applications or delegated access.
  3. Remove persistence. Delete unauthorized forwarding rules, inbox rules, transport rules, delegates and automatic replies after documenting them.
  4. Protect connected accounts. Change credentials for finance, payroll, cloud storage, customer portals and other services that use the compromised mailbox for recovery or authentication.
  5. Check for payment activity. Review recent invoices, vendor changes, payroll updates, payment approvals and messages involving funds or sensitive data.
  6. Notify affected parties. Inform finance staff, executives, vendors and customers through trusted channels if they may have received fraudulent instructions.
  7. Preserve evidence. Save message headers, suspicious emails, login records, rule details, OAuth consent records, transaction information and a timeline of actions taken.

Do not assume that changing the password alone completes recovery. A threat actor may retain access through a session token, app consent, forwarding rule, delegate permission or alternate authentication method.

If money was sent, act immediately

Contact the financial institution immediately and request a recall or other recovery action. Provide the transaction details, recipient information, timestamps and evidence of the fraudulent instruction. The FBI advises victims to contact their financial institution as soon as possible and file a complaint with IC3.gov, regardless of the amount involved. Recovery is not guaranteed, but delay can reduce the opportunity for a financial institution or law enforcement agency to intervene.

Also consider legal, insurance, contractual and regulatory obligations. A qualified attorney, insurer, incident-response provider or law-enforcement contact can help determine what must be reported and how communications should be handled. Use your documented small-business incident response plan to coordinate decisions.

Post-incident investigation and prevention

After containment, determine how the attacker obtained access and what they could see or change. Review authentication logs, mailbox audit events, endpoint alerts, phishing reports, browser sessions, OAuth applications, rule changes and financial-system records. Establish the earliest known suspicious activity and identify every account, vendor, customer and transaction affected.

Then improve the process that failed. Possible changes include phishing-resistant MFA, tighter mailbox forwarding policies, stronger vendor-master controls, dual payment approval, better alerting, shorter session lifetimes, improved log retention and a defined escalation path for suspicious invoices.

Run a tabletop exercise at least once a year and after major process changes. Give participants a realistic scenario: a supplier requests a new bank account, an executive asks for a confidential wire transfer, or finance discovers an unfamiliar forwarding rule. Measure whether staff know who verifies the request, who freezes a payment, who contacts the bank and who preserves evidence.

A practical BEC prevention checklist

  • Document independent verification for payment and bank-detail changes.
  • Use dual approval for high-risk payments and vendor-record edits.
  • Require MFA across email and financial systems, with phishing-resistant methods for high-risk users.
  • Block or tightly control external mailbox forwarding.
  • Review inbox rules, delegates, OAuth grants and active sessions during account recovery.
  • Monitor sign-ins, rule changes, authentication changes and suspicious application consent.
  • Train employees to pause on urgency, secrecy and process-bypass requests.
  • Maintain current finance, vendor and incident-response contacts outside email.
  • Know how to request a payment recall and report fraud to the relevant authorities.
  • Test the procedure with a tabletop exercise and update it after each lesson learned.

BEC prevention is strongest when technology and business process reinforce each other. Email authentication, MFA and monitoring reduce the chance of account compromise, while independent verification and dual approval limit the damage when a convincing message reaches the inbox.