Start smart. Scale strong. Stay protected.​

  1300 475 092   hello@withpocket.com.au

Business Email Compromise: What it is, how it works, and how to protect your business


Estimated reading time: 12 minutes

 

Key facts

  • Business email compromise resulting in financial loss made up 15% of all business cybercrime reports, and email compromise without direct loss a further 19% — so email compromise sits behind roughly one in three cybercrime incidents affecting Australian businesses (Source: ASD Annual Cyber Threat Report 2024–25)
  • The average self-reported cost of cybercrime rose to $56,600 for small businesses and $97,200 for medium businesses, up 14% and 55% respectively (Source: ASD Annual Cyber Threat Report 2024–25 — figures are all-cybercrime averages; ASD does not publish a standalone BEC average for this year)
  • In the prior year, businesses self-reported almost $84 million in BEC losses, averaging about $55,000 per incident (up from $39,000 the year before), the most recent BEC-specific dollar figure the ASD has published (Source: ASD Annual Cyber Threat Report 2023–24)
  • One cybercrime report was made to the ACSC roughly every six minutes, that’s over 84,700 in the year (Source: ASD Annual Cyber Threat Report 2024–25)
  • By mid-2024, an estimated 40% of BEC phishing emails were AI-generated — more convincing, more personalised, and harder to detect — with research showing roughly a 30% increase in BEC attacks by early 2025 (Source: Hoxhunt)
  • In Australia specifically, BEC attacks rose about 7% year-on-year, slightly above the global average (Source: Hoxhunt, 2026)

TL;DR

Email compromise is one of Australia’s most commonly reported cybercrimes. It sits behind roughly one in three cybercrime incidents affecting Australian businesses. It works because it exploits trust and urgency, not just technical vulnerabilities. The defences that matter most are verification processes, multi-factor authentication, and staff training. And if it does happen, Cyber Insurance with a Social Engineering Fraud (SEF) or BEC extension is the financial backstop.

Table of Contents

What is Business Email Compromise?


Business Email Compromise (BEC) is a form of fraud where attackers use email — either by impersonating someone trusted or by actually compromising a real email account — to trick your business into transferring money or handing over sensitive information. It’s one of the most common forms of what’s known as Social Engineering Fraud (SEF) — the term you’ll often see on Australian cyber insurance policies, where it appears as a specific extension.

It’s not a generic spam campaign. BEC is targeted, researched, and timed. Attackers know who your suppliers are, what your payment processes look like, and when your finance team is most likely to act quickly. That’s what makes it so effective and so damaging.

How BEC actually works

The basic pattern

BEC attacks follow a consistent structure:

1. Reconnaissance. The attacker researches your business, your suppliers, your payment processes, your key contacts, often through LinkedIn, your website, or social media

2. Impersonation or compromise. They either create a convincing fake email address (or display name) to impersonate someone you trust, or they actually compromise a legitimate email account

3. The ask. A seemingly normal request arrives: update the bank account for a payment, transfer funds urgently, approve an invoice, or share sensitive data

4. Execution. Under time pressure and trusting the sender, someone executes the money transfers, the data is shared, and the credentials are entered

The transfer often happens before anyone realises something is wrong. Once funds leave your account to a criminal’s controlled account, recovery is rare.

Why it works today

BEC has become significantly more sophisticated:

  • AI-generated emails are now grammatically perfect, contextually accurate, and personalised with real invoice numbers, project names, and relationship details

  • Session hijacking can allow attackers to bypass MFA by stealing authentication tokens. They don’t need your password if they can steal your active session.

  • Supply chain impersonation where attackers compromise one of your suppliers and send fraudulent invoices from a legitimate, trusted email address

The era of obviously fake emails with bad grammar is largely over. Modern BEC can be difficult to distinguish from legitimate communication without deliberate verification.

The most common attack types

Attack type How it works Common target
CEO fraud / executive impersonation

Attacker impersonates a director or CEO, urgently requesting a fund transfer or sensitive data

Finance team, accounts payable

Invoice fraud / supplier impersonation

Fraudulent invoice or payment detail update from what appears to be a known supplier

Anyone who processes supplier payments

Account takeover

Attacker compromises a real email account, monitors communications, then intercepts or initiates payment requests

Any staff with financial authority

Payroll diversion

Attacker impersonates an employee, requesting a change to bank account details before payday

HR or payroll staff

Property settlement fraud

Attacker impersonates a conveyancer or solicitor, redirecting settlement funds

Property buyers, legal and real estate clients

Credential harvesting

Fake login page captures email credentials, enabling account takeover

Anyone with email access

Who is targeted?

Small businesses are heavily represented

BEC isn’t reserved for large corporates. Small businesses are frequently targeted because:

  • They typically have less rigorous payment verification processes
  • Finance and payment functions are often handled by one or two people who have authority to act quickly
  • Relationships with suppliers and clients are informal enough that unusual requests can seem plausible

The ASD notes that small and medium businesses continue to bear a heavy share of cybercrime cost, with the average self-reported cost to a small business rising to $56,600. (Source: ASD Annual Cyber Threat Report 2024–25)

High-risk business types

Business type Why they’re targeted
Trades, construction, and contractors

Regular supplier payments and subcontractor invoices making them easy to intercept or impersonate

Professional services (legal, accounting, consulting)

Handle client funds, have access to financial data, trusted as payment intermediaries

Property and real estate

Settlement amounts are large, timing is pressured, and account changes happen legitimately

Hospitality and retail

Regular stock orders and supplier relationships which have predictable payment patterns

Any business using cloud accounting

Compromised Xero or MYOB credentials can expose all supplier payment details

What you can do to prevent it

The controls that actually work

Control What it does Difficulty to implement
Verbal verification of account changes

Call the supplier or staff member on a known number before processing any bank account change

Low – process change only

Multi-factor authentication on email

Prevents attackers from accessing your email even with a stolen password

Low – enable in your email platform (like Microsoft 365 or Google Workspace)

Dual approval for payments above a threshold

Requires two people to approve transfers above a set amount

Low – process change

Staff training on BEC recognition

Reduces the likelihood that suspicious requests slip through

Medium – ongoing, not one-off

Email sender verification (DMARC/DKIM/SPF)

Technical controls that help prevent your domain from being spoofed by attackers

Medium – requires IT configuration

Session token protection

Advanced controls to help prevent session hijacking, particularly for Microsoft 365

Medium to high – requires IT support

The one rule that stops most BEC attacks

Any request to change bank account or payment details should be verified via a phone call to a known number — not by replying to the email that made the request.

Verbal verification of account changes stops the majority of BEC attempts on its own, which makes it one of the highest-value controls on this list. Any request to change bank account or payment details should get a phone call to a known number before it’s actioned — not a reply to the email that made the request. It’s not a substitute for the other controls above, but it closes off the single most common way these attacks succeed.

What happens if it succeeds

Immediate steps

If you suspect a BEC attack has resulted in a fraudulent transfer:

  • Contact your bank immediately – request a recall of the transfer. Speed matters; funds may not have cleared the receiving account yet
  • Report to ReportCyber – the ASD’s national cybercrime reporting platform at cyber.gov.au/report
  • Notify your cyber insurer – if you have Cyber Insurance with a Social Engineering Fraud (SEF) or BEC extension, notify immediately. There are often strict timeframes for reporting
  • Preserve evidence – keep a record of what happened before making changes
  • Engage an incident response specialist they can determine whether your email account was actually compromised and help contain the damage

 

BEC and Cyber Insurance

Does Cyber Insurance cover BEC losses?

Many Cyber Insurance policies include a Business Email Compromise or Social Engineering Fraud extension but this is one of the most important things to check, because:

  • BEC cover is often a sublimit significantly lower than the main policy limit (for example, a $500,000 policy may carry only a $50,000 SEF/BEC sublimit)

  • Some policies require specific preconditions to be met such as having MFA enabled on email for SEF/BEC cover to apply

  • Coverage terms vary significantly between insurers — what one policy covers, another may exclude

What to check in your Cyber policy Why it matters

Is BEC / Social Engineering Fraud included?

Not all policies include it — confirm explicitly

What is the sublimit?

Often lower than the main policy limit

Are there preconditions?

Some policies require MFA or specific controls

What is the timeframe for notification?

Late notification can affect a claim

Does it cover employee-initiated fraud?

Some policies treat staff-manipulated losses differently

Not sure whether your current Cyber policy covers SEF/BEC, or what the sublimit is? The Pocket team can review it with you.
Book a call with the team →

Frequently asked questions

  1. What is Business Email Compromise (BEC)?
    BEC is a form of targeted cyber fraud where attackers use email — either by impersonating a trusted contact or by actually compromising a legitimate email account — to trick a business into transferring money or sharing sensitive information. Email compromise sits behind roughly one in three cybercrime incidents affecting Australian businesses. (Source: ASD Annual Cyber Threat Report 2024–25)

  2. How much does BEC cost Australian businesses?

    In FY2023–24 — the most recent year the ASD published a BEC-specific figure — Australian businesses self-reported almost $84 million in BEC losses, averaging about $55,000 per incident. More broadly, the ASD’s 2024–25 report puts the average self-reported cost of cybercrime at $56,600 for small businesses and $97,200 for medium businesses (these are all-cybercrime averages, not BEC-specific). (Source: ASD Annual Cyber Threat Reports 2023–24 and 2024–25)

  3.  

     

     

     

     

     

    Can BEC bypass multi-factor authentication?
    Standard MFA methods can be bypassed by session hijacking which is a technique that steals your authentication token after you’ve already logged in. Research indicates this is now a common feature of modern BEC attacks. MFA is still essential but is strongest when combined with conditional access policies and session monitoring.

     

     

     

     

     

  4. What is the single most effective defence against BEC?
    A verification process: any request to change bank account or payment details should be verbally confirmed via a phone call to a known number — not by responding to the email that made the request. This one process change stops the majority of supplier impersonation attacks.

     

  5. Does Cyber Insurance cover BEC losses?
    Many Cyber Insurance policies include a BEC or Social Engineering Fraud extension, but coverage terms vary significantly. SEF/BEC cover is often subject to a sublimit lower than the main policy limit, and some policies require preconditions like MFA to be in place. Always confirm SEF/BEC coverage explicitly with your broker.

     

  6. What should I do if I think I’ve been targeted by BEC?
    If you’ve transferred funds: contact your bank immediately, report to ReportCyber (cyber.gov.au/report), and notify your cyber insurer without delay. If you’ve received a suspicious request but haven’t acted: do not respond, call the apparent sender on a known number to verify, and report internally.

  7. What is session hijacking?
    Session hijacking is a technique where an attacker steals your session authentication token, which is the credential your browser uses to stay logged in after you’ve already authenticated. This can bypass MFA because the attacker doesn’t need your password or second factor; they use the session after you’ve logged in. It’s typically delivered via phishing links or malicious websites.

    Separately, we also offer a direct online platform where you can quote and buy a specific set of products — cyber, trades liability, tax audit, vacant land, and drone cover — without a broker, for when advice isn’t needed.

  8. Is BEC different from phishing?
    Phishing is a broad category of email-based attacks designed to harvest credentials or install malware, typically through bulk campaigns. BEC is a more targeted subset, it involves specific research into your business, personalised content, and a direct financial goal. All BEC involves some form of phishing, but not all phishing is BEC.

  9. What businesses are most at risk from BEC?
    Any business that processes supplier payments, handles client funds, or has staff with payment authority is at risk. Particularly targeted: trades and construction (regular supplier invoices), professional services (legal, accounting), property and real estate (large settlement amounts), and any business using cloud accounting software.

Related guides

BEC can happen to any business. Cyber Insurance is the financial backstop when it does.

Prevention processes reduce the risk. Cyber Insurance helps cover the loss when — despite everything — an attack succeeds. The Pocket team can review your current cyber cover and talk through whether your BEC sublimit is adequate for your business.

If you’d like advicebook a call with the Pocket team →

If you want to move quicklyget a cyber insurance quote online →

With Pocket is a business name of Insurance Services Holdings Pty Ltd (ABN 36 612 629 295, AFSL 491165), a member of NIBA and part of the Steadfast Group. This article contains general information only and does not take into account your objectives, financial situation or needs. It is not personal or IT security advice. Before acting on any information here, consider whether it is appropriate for your circumstances and read the relevant Product Disclosure Statement. Sources: ASD Annual Cyber Threat Reports 2023–24 and 2024–25 (cyber.gov.au), Hoxhunt (2026).