Business Email Compromise and Wire Fraud Countermeasures for Trade Businesses

Why this matters

Business Email Compromise (BEC) is the single most expensive cybercrime category for small business according to the FBI Internet Crime Complaint Center (IC3). The 2023 IC3 report showed BEC-related losses exceeded $2.9 billion in the prior reporting year, with average loss per incident in the high five figures to low six figures. Trade businesses are a soft target: they wire material deposits to suppliers, send ACH payments to subcontractors, and frequently get changes-of-banking-instructions through email. A successful BEC attack diverts a $50,000 deposit to the attacker's account, the funds clear in 24-48 hours, and most are unrecoverable within 72 hours. The contractor's insurance often denies the claim because most general business insurance policies have a "social engineering" exclusion or low sublimit. The countermeasures are technical, procedural, and cultural. Each is cheap. Skipping any of them is the difference between an annoying phishing attempt and a catastrophic loss. This article gives you the playbook to implement before, not after, the attack lands.

How BEC attacks actually work

The four patterns that account for the majority of losses:

Pattern 1 - Vendor invoice diversion. The attacker compromises a supplier's email account (often by phishing a single user at the supplier), monitors traffic for outgoing invoices, then either alters the bank account info on an outgoing invoice or sends a follow-up "we changed banks - please update our wire instructions" email to all of the supplier's customers. The contractor wires the deposit to the attacker's account, thinking they're paying their supplier. The supplier discovers the breach weeks later when their unpaid invoice goes to collections. By then your money is gone.

Pattern 2 - Owner/executive impersonation. The attacker registers a domain that looks like the owner's email (e.g., owner@aacme-plumbing.com vs the real owner@acme-plumbing.com - extra "a"), or uses a free Gmail/Yahoo address with the owner's name as the display. Sends an urgent message to the bookkeeper or office manager: "I'm in a meeting and can't talk - please wire $35,000 to this vendor for a deposit, here's the wire info, send confirmation when done." The bookkeeper wires the money, finds out hours or days later when the owner returns.

Pattern 3 - Compromised contractor email itself. The attacker phishes one of YOUR users (often a field tech who clicked a link about "package delivery"), gains access to the email, then watches outgoing invoices to YOUR customers. Modifies banking instructions on YOUR invoices going out. Your customers pay the attacker thinking they're paying you. You don't find out until you start chasing unpaid invoices and customers say "we paid that weeks ago."

Pattern 4 - Payroll diversion. Attacker, posing as an employee (using compromised credentials or social engineering), submits a "direct deposit change" request to payroll changing the employee's banking info to the attacker's account. One pay period of an employee's pay goes to the attacker, then the employee complains they didn't get paid. By then attacker has withdrawn and disappeared.

A fifth, rarer pattern is "M&A diversion" - high-dollar transaction (acquisition, partner buyout, refinancing) gets a "last-minute change of wire instructions" the day of closing. Disproportionately damaging because of the dollar amount but the same mechanic.

Layer 1 - Technical controls (block the attack)

Multi-factor authentication (MFA) on every email account, every cloud account, every accounting system. Microsoft 365 Business, Google Workspace, QuickBooks Online, Bill.com, your bank, your payroll service - everything. The cheapest, highest-impact control. Push notification or authenticator app (Microsoft Authenticator, Google Authenticator, Authy, Duo) is more secure than SMS, but SMS is dramatically better than nothing. Hardware security keys (YubiKey, Titan Security Key) are the gold standard for owner / finance team accounts.

Email authentication: SPF, DKIM, DMARC. These are DNS records that prevent attackers from impersonating YOUR domain in emails to your customers. SPF (Sender Policy Framework) lists which mail servers can send as your domain. DKIM (DomainKeys Identified Mail) cryptographically signs outgoing email. DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells receiving mail servers what to do with email that fails SPF/DKIM checks (reject, quarantine, allow). With DMARC set to "p=reject" your customers' email servers reject impersonation attempts before they reach the inbox. Implementation is free (DNS configuration); takes an IT person 2-4 hours to do correctly.

Domain monitoring. Register every plausible look-alike domain of your own (your-business.net, your-business.co, your-buisness.com with the misspelling) and route them to your real domain or null-route. Set up an alert for newly-registered domains that resemble yours (services like DomainTools, Cyveillance, several free alternatives). Most BEC attacks use a look-alike domain registered 24-72 hours before the attack.

Email gateway with phishing/BEC detection. Microsoft Defender for Office 365, Google Workspace Security, Proofpoint, Mimecast, Abnormal Security. These scan inbound email for impersonation patterns, suspicious links, attachment threats. The Microsoft and Google native offerings at the Business Standard and above tier are sufficient for most small contractors.

References

  • FBI Internet Crime Complaint Center (IC3) annual report (https://www.ic3.gov) - quantitative loss data for Business Email Compromise and related fraud categories.
  • CISA (Cybersecurity and Infrastructure Security Agency) "Stop Ransomware" and BEC guidance (https://www.cisa.gov/stopransomware).
  • NIST Cybersecurity Framework 2.0 (NIST CSWP 29, released February 2024) - foundational framework for small-business cybersecurity programs.
  • NIST Special Publication 800-63B (Digital Identity Guidelines - Authentication and Lifecycle Management) - authoritative guidance on MFA implementation.
  • 15 USC Section 6801 (Gramm-Leach-Bliley Act - Privacy and Safeguards Rule for financial information) - relevant where trade businesses store customer financial information.
  • State breach-notification statutes - all 50 states have data breach notification laws (e.g., California Civil Code Section 1798.82, New York General Business Law Section 899-aa, Texas Business & Commerce Code Section 521.053). Reporting timeframes range from 30 to 90 days.
  • DMARC.org (https://dmarc.org) - implementation guidance for SPF, DKIM, DMARC email authentication.
  • FTC Business Center "Cybersecurity for Small Business" (https://www.ftc.gov/business-guidance/small-businesses/cybersecurity) - actionable guidance and posters for small-business security awareness.
  • Federal Reserve "Recall a Wire" procedures via Fedwire Funds Service - the operational pathway for time-sensitive wire recall requests.