Estimated reading time: 12 minutes
Key facts
- Business email compromise resulting in financial loss made up 15% of all business cybercrime reports, and email compromise without direct loss a further 19% — so email compromise sits behind roughly one in three cybercrime incidents affecting Australian businesses (Source: ASD Annual Cyber Threat Report 2024–25)
- The average self-reported cost of cybercrime rose to $56,600 for small businesses and $97,200 for medium businesses, up 14% and 55% respectively (Source: ASD Annual Cyber Threat Report 2024–25 — figures are all-cybercrime averages; ASD does not publish a standalone BEC average for this year)
- In the prior year, businesses self-reported almost $84 million in BEC losses, averaging about $55,000 per incident (up from $39,000 the year before), the most recent BEC-specific dollar figure the ASD has published (Source: ASD Annual Cyber Threat Report 2023–24)
- One cybercrime report was made to the ACSC roughly every six minutes, that’s over 84,700 in the year (Source: ASD Annual Cyber Threat Report 2024–25)
- By mid-2024, an estimated 40% of BEC phishing emails were AI-generated — more convincing, more personalised, and harder to detect — with research showing roughly a 30% increase in BEC attacks by early 2025 (Source: Hoxhunt)
- In Australia specifically, BEC attacks rose about 7% year-on-year, slightly above the global average (Source: Hoxhunt, 2026)
TL;DR
Email compromise is one of Australia’s most commonly reported cybercrimes. It sits behind roughly one in three cybercrime incidents affecting Australian businesses. It works because it exploits trust and urgency, not just technical vulnerabilities. The defences that matter most are verification processes, multi-factor authentication, and staff training. And if it does happen, Cyber Insurance with a Social Engineering Fraud (SEF) or BEC extension is the financial backstop.
Table of Contents
What is Business Email Compromise?
Business Email Compromise (BEC) is a form of fraud where attackers use email — either by impersonating someone trusted or by actually compromising a real email account — to trick your business into transferring money or handing over sensitive information. It’s one of the most common forms of what’s known as Social Engineering Fraud (SEF) — the term you’ll often see on Australian cyber insurance policies, where it appears as a specific extension.
It’s not a generic spam campaign. BEC is targeted, researched, and timed. Attackers know who your suppliers are, what your payment processes look like, and when your finance team is most likely to act quickly. That’s what makes it so effective and so damaging.
How BEC actually works
The basic pattern
BEC attacks follow a consistent structure:
1. Reconnaissance. The attacker researches your business, your suppliers, your payment processes, your key contacts, often through LinkedIn, your website, or social media
2. Impersonation or compromise. They either create a convincing fake email address (or display name) to impersonate someone you trust, or they actually compromise a legitimate email account
3. The ask. A seemingly normal request arrives: update the bank account for a payment, transfer funds urgently, approve an invoice, or share sensitive data
4. Execution. Under time pressure and trusting the sender, someone executes the money transfers, the data is shared, and the credentials are entered
The transfer often happens before anyone realises something is wrong. Once funds leave your account to a criminal’s controlled account, recovery is rare.
Why it works today
BEC has become significantly more sophisticated:
-
AI-generated emails are now grammatically perfect, contextually accurate, and personalised with real invoice numbers, project names, and relationship details
-
Session hijacking can allow attackers to bypass MFA by stealing authentication tokens. They don’t need your password if they can steal your active session.
-
Supply chain impersonation where attackers compromise one of your suppliers and send fraudulent invoices from a legitimate, trusted email address
The era of obviously fake emails with bad grammar is largely over. Modern BEC can be difficult to distinguish from legitimate communication without deliberate verification.
The most common attack types
| Attack type | How it works | Common target |
|---|---|---|
| CEO fraud / executive impersonation |
Attacker impersonates a director or CEO, urgently requesting a fund transfer or sensitive data |
Finance team, accounts payable |
| Invoice fraud / supplier impersonation |
Fraudulent invoice or payment detail update from what appears to be a known supplier |
Anyone who processes supplier payments |
| Account takeover |
Attacker compromises a real email account, monitors communications, then intercepts or initiates payment requests |
Any staff with financial authority |
| Payroll diversion |
Attacker impersonates an employee, requesting a change to bank account details before payday |
HR or payroll staff |
| Property settlement fraud |
Attacker impersonates a conveyancer or solicitor, redirecting settlement funds |
Property buyers, legal and real estate clients |
| Credential harvesting |
Fake login page captures email credentials, enabling account takeover |
Anyone with email access |
Who is targeted?
Small businesses are heavily represented
BEC isn’t reserved for large corporates. Small businesses are frequently targeted because:
- They typically have less rigorous payment verification processes
- Finance and payment functions are often handled by one or two people who have authority to act quickly
- Relationships with suppliers and clients are informal enough that unusual requests can seem plausible
The ASD notes that small and medium businesses continue to bear a heavy share of cybercrime cost, with the average self-reported cost to a small business rising to $56,600. (Source: ASD Annual Cyber Threat Report 2024–25)
High-risk business types
| Business type | Why they’re targeted |
|---|---|
| Trades, construction, and contractors |
Regular supplier payments and subcontractor invoices making them easy to intercept or impersonate |
| Professional services (legal, accounting, consulting) |
Handle client funds, have access to financial data, trusted as payment intermediaries |
| Property and real estate |
Settlement amounts are large, timing is pressured, and account changes happen legitimately |
| Hospitality and retail |
Regular stock orders and supplier relationships which have predictable payment patterns |
| Any business using cloud accounting |
Compromised Xero or MYOB credentials can expose all supplier payment details |
What you can do to prevent it
The controls that actually work
| Control | What it does | Difficulty to implement |
|---|---|---|
| Verbal verification of account changes |
Call the supplier or staff member on a known number before processing any bank account change |
Low – process change only |
| Multi-factor authentication on email |
Prevents attackers from accessing your email even with a stolen password |
Low – enable in your email platform (like Microsoft 365 or Google Workspace) |
| Dual approval for payments above a threshold |
Requires two people to approve transfers above a set amount |
Low – process change |
| Staff training on BEC recognition |
Reduces the likelihood that suspicious requests slip through |
Medium – ongoing, not one-off |
| Email sender verification (DMARC/DKIM/SPF) |
Technical controls that help prevent your domain from being spoofed by attackers |
Medium – requires IT configuration |
| Session token protection |
Advanced controls to help prevent session hijacking, particularly for Microsoft 365 |
Medium to high – requires IT support |
The one rule that stops most BEC attacks
Any request to change bank account or payment details should be verified via a phone call to a known number — not by replying to the email that made the request.
Verbal verification of account changes stops the majority of BEC attempts on its own, which makes it one of the highest-value controls on this list. Any request to change bank account or payment details should get a phone call to a known number before it’s actioned — not a reply to the email that made the request. It’s not a substitute for the other controls above, but it closes off the single most common way these attacks succeed.
What happens if it succeeds
Immediate steps
If you suspect a BEC attack has resulted in a fraudulent transfer:
- Contact your bank immediately – request a recall of the transfer. Speed matters; funds may not have cleared the receiving account yet
- Report to ReportCyber – the ASD’s national cybercrime reporting platform at cyber.gov.au/report
- Notify your cyber insurer – if you have Cyber Insurance with a Social Engineering Fraud (SEF) or BEC extension, notify immediately. There are often strict timeframes for reporting
- Preserve evidence – keep a record of what happened before making changes
- Engage an incident response specialist – they can determine whether your email account was actually compromised and help contain the damage
BEC and Cyber Insurance
Does Cyber Insurance cover BEC losses?
Many Cyber Insurance policies include a Business Email Compromise or Social Engineering Fraud extension but this is one of the most important things to check, because:
-
BEC cover is often a sublimit significantly lower than the main policy limit (for example, a $500,000 policy may carry only a $50,000 SEF/BEC sublimit)
-
Some policies require specific preconditions to be met such as having MFA enabled on email for SEF/BEC cover to apply
-
Coverage terms vary significantly between insurers — what one policy covers, another may exclude
| What to check in your Cyber policy | Why it matters |
|---|---|
|
Is BEC / Social Engineering Fraud included? |
Not all policies include it — confirm explicitly |
|
What is the sublimit? |
Often lower than the main policy limit |
|
Are there preconditions? |
Some policies require MFA or specific controls |
|
What is the timeframe for notification? |
Late notification can affect a claim |
|
Does it cover employee-initiated fraud? |
Some policies treat staff-manipulated losses differently |
Not sure whether your current Cyber policy covers SEF/BEC, or what the sublimit is? The Pocket team can review it with you.
Book a call with the team →
Frequently asked questions
-
What is Business Email Compromise (BEC)?
BEC is a form of targeted cyber fraud where attackers use email — either by impersonating a trusted contact or by actually compromising a legitimate email account — to trick a business into transferring money or sharing sensitive information. Email compromise sits behind roughly one in three cybercrime incidents affecting Australian businesses. (Source: ASD Annual Cyber Threat Report 2024–25) -
How much does BEC cost Australian businesses?
In FY2023–24 — the most recent year the ASD published a BEC-specific figure — Australian businesses self-reported almost $84 million in BEC losses, averaging about $55,000 per incident. More broadly, the ASD’s 2024–25 report puts the average self-reported cost of cybercrime at $56,600 for small businesses and $97,200 for medium businesses (these are all-cybercrime averages, not BEC-specific). (Source: ASD Annual Cyber Threat Reports 2023–24 and 2024–25)
-
Can BEC bypass multi-factor authentication?
Standard MFA methods can be bypassed by session hijacking which is a technique that steals your authentication token after you’ve already logged in. Research indicates this is now a common feature of modern BEC attacks. MFA is still essential but is strongest when combined with conditional access policies and session monitoring. -
What is the single most effective defence against BEC?
A verification process: any request to change bank account or payment details should be verbally confirmed via a phone call to a known number — not by responding to the email that made the request. This one process change stops the majority of supplier impersonation attacks. -
Does Cyber Insurance cover BEC losses?
Many Cyber Insurance policies include a BEC or Social Engineering Fraud extension, but coverage terms vary significantly. SEF/BEC cover is often subject to a sublimit lower than the main policy limit, and some policies require preconditions like MFA to be in place. Always confirm SEF/BEC coverage explicitly with your broker. -
What should I do if I think I’ve been targeted by BEC?
If you’ve transferred funds: contact your bank immediately, report to ReportCyber (cyber.gov.au/report), and notify your cyber insurer without delay. If you’ve received a suspicious request but haven’t acted: do not respond, call the apparent sender on a known number to verify, and report internally. -
What is session hijacking?
Session hijacking is a technique where an attacker steals your session authentication token, which is the credential your browser uses to stay logged in after you’ve already authenticated. This can bypass MFA because the attacker doesn’t need your password or second factor; they use the session after you’ve logged in. It’s typically delivered via phishing links or malicious websites.Separately, we also offer a direct online platform where you can quote and buy a specific set of products — cyber, trades liability, tax audit, vacant land, and drone cover — without a broker, for when advice isn’t needed.
-
Is BEC different from phishing?
Phishing is a broad category of email-based attacks designed to harvest credentials or install malware, typically through bulk campaigns. BEC is a more targeted subset, it involves specific research into your business, personalised content, and a direct financial goal. All BEC involves some form of phishing, but not all phishing is BEC. -
What businesses are most at risk from BEC?
Any business that processes supplier payments, handles client funds, or has staff with payment authority is at risk. Particularly targeted: trades and construction (regular supplier invoices), professional services (legal, accounting), property and real estate (large settlement amounts), and any business using cloud accounting software.
Related guides
BEC can happen to any business. Cyber Insurance is the financial backstop when it does.
Prevention processes reduce the risk. Cyber Insurance helps cover the loss when — despite everything — an attack succeeds. The Pocket team can review your current cyber cover and talk through whether your BEC sublimit is adequate for your business.
If you’d like advice — book a call with the Pocket team →
If you want to move quickly — get a cyber insurance quote online →
With Pocket is a business name of Insurance Services Holdings Pty Ltd (ABN 36 612 629 295, AFSL 491165), a member of NIBA and part of the Steadfast Group. This article contains general information only and does not take into account your objectives, financial situation or needs. It is not personal or IT security advice. Before acting on any information here, consider whether it is appropriate for your circumstances and read the relevant Product Disclosure Statement. Sources: ASD Annual Cyber Threat Reports 2023–24 and 2024–25 (cyber.gov.au), Hoxhunt (2026).
Pocket is a licensed Australian insurance broker (AFSL 491165) and member of NIBA. Part of the Steadfast Group — Australia’s largest broker network. We help small and growing businesses get the right cover without the jargon. Start smart. Scale strong. Stay protected.