The email arrives at 3:42 p.m. on a busy Thursday. A familiar supplier says its banking information has changed and asks that tomorrow’s payment go to a new account. The signature looks right. The thread includes a real invoice. The tone sounds like the person your bookkeeper knows. Nothing in the message asks anyone to click a strange attachment.
That is why business email compromise is so effective. The attacker may spoof a trusted address, compromise a real mailbox, study an existing conversation, register a lookalike domain, or impersonate an executive. The objective is often not malware. It is persuading a legitimate employee to send money or sensitive information to the wrong place.
The risk is current in Canada. On May 13, 2026, the Canadian Anti-Fraud Centre reported helping recover approximately CAD $3.5 million connected to payment-redirection fraud targeting a Quebec business. Criminals impersonated legitimate contacts and manipulated email communications to provide fraudulent instructions for two wire transfers. Fast reporting helped financial institutions and investigators coordinate the recovery.
Toronto and Ontario small businesses do not need an enterprise security operations centre to reduce this risk. They need secure identities and email, a payment process that an email alone cannot change, employees who know what to verify, and a response plan that begins in minutes rather than days.
What is business email compromise?
Business email compromise, commonly shortened to BEC, is fraud that uses a trusted business identity or relationship to persuade someone to transfer funds, change payment instructions, disclose data, or grant access. Microsoft describes BEC as using forged trusted senders—such as financial officers, customers, or partners—to trick recipients into approving payments, moving funds, or revealing customer data.
The sender may not be forged at all. If an attacker signs in to a supplier’s or employee’s real mailbox, they can read conversations, wait for a payment opportunity, create hidden forwarding or inbox rules, and reply from the legitimate account. A correct display name, address, signature, or thread history is therefore not proof that a request is safe.
| BEC pattern | What the message may say | What the attacker wants |
|---|---|---|
| Supplier payment change | “Our bank details have changed. Use this account for the outstanding invoice.” | Redirect a legitimate payment |
| Executive impersonation | “I am in a confidential meeting. Send this wire or buy gift cards now.” | Exploit authority and urgency |
| Payroll diversion | “Please update my direct-deposit account before payroll closes.” | Redirect an employee’s pay |
| Customer or lawyer impersonation | “Use the attached instructions to complete the transaction today.” | Intercept a high-value transaction |
| Sensitive-data request | “Send the employee tax files or customer list for review.” | Steal personal or business information |
| Account recovery or MFA request | “I lost my phone. Reset my password and add this new authentication method.” | Take control of an identity |
Why business email compromise gets past normal caution
BEC attacks are designed around business context. Criminals collect names, roles, suppliers, travel plans, project announcements, and reporting relationships from company websites, social media, data breaches, and compromised mailboxes. They time the request around a real invoice, closing date, executive absence, or busy accounting period.
The Canadian Centre for Cyber Security’s July 2026 social-engineering guidance says threat actors impersonate trusted people and use publicly available information to make messages credible. The request may arrive by email, phone, text, collaboration tool, social media, or a QR code. A process that verifies only through a reply to the same conversation can therefore be defeated.
1. Map the workflows that can move money, data, or access
Start with business operations. List every workflow where one message can lead to a financial transfer, banking-detail change, payroll update, customer refund, gift-card purchase, tax-document release, password reset, new MFA method, or administrator access.
- Who can request the action?
- Who enters or changes the information?
- Who approves it, and at what amount or risk threshold?
- Which system records the request and approval?
- What independent evidence confirms the requester’s identity?
- What happens if the normal approver is unavailable?
This exercise often exposes a larger problem: the company has a payment policy in someone’s memory rather than in a documented workflow. Fixing that process can prevent more fraud than another warning banner alone.
2. Require independent verification for financial changes
A request to change payment instructions must be verified outside the message that requested the change. Call the supplier or employee using a phone number already stored in the approved vendor, payroll, or customer record—not a number in the email, attachment, new website, or signature.
For higher-risk changes, require a second authorized employee to review the original record, verification result, beneficiary name, institution, account details, amount, and effective date. Make the same rule apply to executives so employees are never punished for slowing down an urgent request.
3. Use two-person approval and meaningful limits
Separate the ability to create or change a payee from the ability to approve payment. Use banking controls, accounting-system roles, payment limits, callback services, and dual authorization where available. A second approval is useful only if the reviewer sees the relevant evidence and is expected to challenge the request.
- New payees and changed bank details require independent verification.
- High-value or unusual payments require two authorized people.
- The requester, data-entry user, and final approver are separated where staffing allows.
- Daily and per-transaction limits reflect normal business activity.
- Bank alerts go to more than one trusted person.
- Exceptions are documented rather than approved through an informal chat.
4. Protect email identities with strong authentication
Require multifactor authentication for every email account, with priority for administrators, executives, finance, payroll, human resources, customer service, and anyone who can reset another user. Where supported, prefer phishing-resistant methods such as passkeys or hardware security keys for high-risk users.
Traditional push or one-time-code MFA is much better than a password alone, but adversary-in-the-middle phishing can capture a live session. The Canadian Centre for Cyber Security continues to observe these campaigns connected to BEC and recommends phishing-resistant MFA to reduce that exposure.
- Disable legacy authentication and unused email protocols where business applications allow.
- Use separate administrator accounts and least-privilege roles.
- Review registered authentication methods and remove old phones, app passwords, and unknown devices.
- Protect password-reset and help-desk procedures against executive impersonation.
- Revoke sessions promptly when employment ends or compromise is suspected.
- Do not share mailboxes through shared passwords; use delegated access with individual identities.
5. Configure SPF, DKIM, and DMARC for every business domain
Email authentication makes it harder for attackers to send messages that directly spoof a company’s domain. SPF identifies permitted sending sources. DKIM adds a cryptographic signature. DMARC checks alignment with the visible From domain, tells receiving systems how to handle failures, and can provide reports.
Microsoft’s July 2026 guidance is explicit that SPF alone is not sufficient; SPF, DKIM, and DMARC must work together for effective authentication. Inventory every legitimate sender first—including Microsoft 365, website forms, CRM, accounting, marketing, ticketing, payroll, scanners, and third-party platforms. Start DMARC with reporting and controlled monitoring, remediate legitimate failures, then move toward quarantine or reject based on evidence.
6. Tune anti-phishing and impersonation protection
Microsoft 365 cloud mailboxes include baseline protections, while Microsoft Defender for Office 365 adds capabilities according to plan. Defender for Office 365 Plan 1 is designed to protect email and collaboration from zero-day malware, phishing, and BEC; Plan 2 adds investigation, hunting, automation, and simulation capabilities.
Protect high-value users and trusted domains with impersonation settings where licensing supports them. Review anti-phishing, anti-spam, Safe Links, Safe Attachments, quarantine, user reporting, and external-sender behaviour. Avoid broad allow lists and mail-flow rules that bypass filtering; a convenient exception can create a permanent blind spot.
7. Detect mailbox persistence and suspicious changes
Attackers who gain mailbox access may create forwarding, inbox rules, app consent, new authentication methods, or delegated access so they can continue reading messages or hide replies. They may move messages to RSS, Notes, Junk, or Deleted Items to keep the legitimate user unaware.
- Alert on new external forwarding and suspicious inbox rules.
- Review risky or unusual sign-ins and impossible or unexpected travel patterns in context.
- Monitor added MFA methods, app consent, role assignment, connector, transport-rule, and delegate changes.
- Investigate unexpected deletion, missing replies, unfamiliar sent messages, or unexplained account lockouts.
- Send security alerts to a monitored path that does not depend only on the affected mailbox.
- Retain audit evidence for the period required by the business, contracts, and incident plan.
8. Maintain trusted vendor and employee records
Keep approved contact and payment information in a controlled accounting, vendor-management, or payroll record. Limit who can change it, record previous values, and require evidence and approval. An employee should not build the verification channel from information supplied in the suspicious request.
Tell suppliers and employees how changes are accepted. If a supplier knows your organization always confirms bank changes through a known contact and dual approval, an attacker has less room to create urgency or shame an employee into bypassing the process.
9. Reduce public information that helps impersonation
Marketing and recruitment require some public information, but not every reporting relationship, travel date, finance contact, direct email address, supplier, contract award, or employee birthday needs to be published. Review the company website and social profiles through an attacker’s eyes.
Do not rely on secrecy as the main control; much of this information can still be discovered. Use the review to remove unnecessary detail and to create additional verification around roles that are easy to identify and impersonate.
10. Train employees around real business decisions
Generic advice to “look for bad grammar” is outdated and unfair to employees. Modern messages can be polished, timely, and sent from a genuine account. Training should focus on risky requests, approved verification channels, and the authority to pause.
- New or changed banking and payroll details
- Urgent secrecy or pressure from an executive
- Unexpected gift cards, wires, refunds, or cryptocurrency
- Requests for tax, payroll, customer, credential, or MFA information
- Login pages reached through email, QR codes, shared documents, or unfamiliar collaboration invites
- A familiar person using a different number, domain, tone, or process
Run short exercises with finance, payroll, reception, executives, and IT support. Measure whether employees report suspicious requests and follow the verification procedure—not simply whether they click a simulated link.
11. Protect devices and business applications
Email security cannot compensate for an infected or unmanaged endpoint. Keep operating systems, browsers, Office applications, password managers, accounting software, and security tools supported and updated. Use endpoint protection, disk encryption, screen locking, secure mobile access, and device-management policies appropriate to the organization.
Finance and administrative users should not have local administrator privileges for daily work. Restrict browser extensions and unapproved remote-access tools, and review whether sensitive payments can be initiated from unmanaged or personally owned devices.
12. Prepare a BEC response plan before money moves
Speed matters. The organization should know whom to call at its bank, insurer, managed IT provider, Microsoft 365 administrator, legal or privacy advisor, and local police. Store the contacts somewhere available even if email is unavailable or untrusted.
| Priority | Immediate action | Why it matters |
|---|---|---|
| Financial | Call the financial institution through a known number and request recall, hold, or fraud escalation | Funds can move rapidly through other accounts |
| Identity | Block or contain affected accounts, reset credentials, revoke sessions, and inspect MFA methods and app consent | A password change alone may not end active access |
| Mailbox | Review forwarding, inbox rules, delegates, connectors, sent/deleted items, and message trace | Attackers often hide communication and maintain access |
| Evidence | Preserve emails, headers, screenshots, transaction records, audit logs, phone numbers, and timelines | Investigation and recovery depend on accurate evidence |
| Reporting | Notify local police and report through Canada’s Report Cybercrime and Fraud system | Fast reporting can support coordinated recovery and disruption |
| Business | Warn affected partners through a trusted channel and review related payments or data exposure | The compromise may span multiple organizations |
Microsoft’s current compromised-account guidance includes resetting credentials, revoking active sessions, reviewing registered MFA devices, checking application consent and roles, and inspecting mailbox settings. Adapt the technical procedure to your identity environment and preserve evidence before making changes when it is safe to do so.
A five-minute payment-change checklist
- Stop: do not use the reply button, link, attachment, or phone number in the request to verify it.
- Compare: review the approved vendor or employee record and previous payment history.
- Call: contact the known person using a trusted number already on file.
- Confirm: verify the reason, beneficiary, institution, account change, amount, and effective date without reading all new details first.
- Approve: obtain the required second-person authorization and record who verified what, when, and through which channel.
- Notify: alert the supplier through the established process and monitor the first payment to the changed account.
A practical 30-day BEC prevention plan
| Week | Focus | Deliverable |
|---|---|---|
| Week 1 | Map payment, payroll, data-release, and account-recovery workflows | Risky actions, owners, verification paths, and approval thresholds |
| Week 2 | Review Microsoft 365 identity, forwarding, authentication, and email policies | Prioritized technical remediation list |
| Week 3 | Inventory sending services and deploy or improve SPF, DKIM, and DMARC monitoring | Documented email sources and authentication plan |
| Week 4 | Test one realistic supplier-change scenario and one compromised-account response | Corrected procedure, contact list, and evidence checklist |
When to involve a cybersecurity or managed IT provider
Professional help is useful when Microsoft 365 settings have grown without ownership, the organization lacks phishing-resistant MFA, email authentication is incomplete, multiple third parties send as the domain, external forwarding is unmanaged, audit alerts are not monitored, or no one can lead a compromised-account response.
A practical cybersecurity assessment should review both technology and the business process. The deliverable should include identity and email findings, SPF/DKIM/DMARC status, high-risk users, forwarding and app-consent controls, financial verification steps, incident contacts, prioritized fixes, and evidence that critical controls were tested.
The bottom line
Business email compromise is not only an email-filter problem. A perfect-looking message can arrive from a real account. The decisive control is a business process that requires trusted, independent verification before money, data, or access changes hands.
For Toronto and Ontario businesses, the right starting point is simple: document who can change payment details, secure the accounts involved, authenticate the company domain, monitor for attacker persistence, and rehearse the first hour of response. Those steps make an urgent message much less likely to become an irreversible loss.