Knowledge Centre

Business Email Compromise, or BEC, is one of the most costly and persistent forms of fraud facing organizations because it targets something every business depends on: trust. Rather than relying only on technical vulnerabilities, fraudsters impersonate executives, vendors, employees or trusted partners to influence payment decisions, redirect funds or obtain sensitive information.

One common tactic is spear phishing, a targeted form of phishing where fraudsters tailor messages to a specific person, role, or organization so the request appears credible, urgent, and difficult to question. That kind of targeted deception was central to a July 2025 case reported by the Canadian Anti-Fraud Centre, where fraudsters used a spear phishing attack to trick a Canadian law firm in the Vancouver area into wiring CAD $2.3 million to a fraudulent account in Hong Kong before international coordination helped intercept and return the funds.1

The 2026 AFP Payments Fraud and Control Survey reported that 76% of organizations experienced attempted or actual payments fraud in 2025, while roughly three in four organizations were affected by BEC.2 BEC does not need to break through a company’s strongest technical defences if it can convince one person to bypass a process, approve a payment, or trust a message that appears legitimate.

 

BEC Is a Business Risk, Not Just a Cybersecurity Risk

Fraud prevention often starts with technology: stronger passwords, email filters, multi-factor authentication, and security tools. These controls matter, but they are only part of the solution. BEC is ultimately a business process risk. It targets the moments where decisions are made quickly, where authority is assumed, and where routine transactions are approved without independent verification.

Finance teams, accounts payable, payroll, procurement, executive assistants, relationship managers, and client-facing employees can all become points of exposure. For senior leaders, that means BEC prevention should be viewed as part of operational resilience, payment governance and third-party risk management - not only as an IT or cybersecurity issue.

 

Why the Risk Looks Different by Business Size

For small businesses, the impact can be immediate. Fraudsters know that smaller organizations may have leaner teams, fewer layered approvals, and closer working relationships that make informal requests feel normal. A payment change from a vendor, a rushed invoice from a supplier, or an urgent message appearing to come from an owner or senior leader may not trigger the same scrutiny it would in a larger organization. A five-figure loss may affect hiring plans, inventory purchases, supplier payments, or the ability to operate confidently. Beyond financial loss, there is also the time required to investigate, recover, communicate with partners, and rebuild trust. In many cases, the operational disruption can be as damaging as the fraud itself.

For large organizations, scale creates a different exposure. Multiple business units, global suppliers, distributed teams, hybrid work models, and complex approval workflows can make it harder to detect when a legitimate process has been manipulated. BEC can expose weaknesses in governance, third-party risk management, payment controls, and employee awareness. In a highly connected business environment, one compromised inbox can become a gateway to broader financial and operational exposure.

 

BEC Is Becoming Harder to Detect

Business Email Compromise has become more convincing because fraudsters are becoming better at imitating how real businesses communicate. Messages may be well-written, correctly formatted, and timed around real business events. In some cases, attackers may use information from public websites, social media, supplier relationships, or previous data breaches to make a fraudulent request appear routine.

Artificial intelligence is adding another layer of risk. Poor grammar and obvious mistakes were once warning signs, but modern fraud attempts may now appear polished, personalized, and context-aware. Association for Financial Professionals’ (AFP)  2026 survey found that only 17% of organizations are using AI to combat payments fraud, even as AI-enabled voice, video, and deepfake impersonation are emerging as new detection challenges.2 Recent AFP commentary also reinforces that procedure, not perception, has become the stronger defense: businesses can no longer rely on employees simply “spotting a suspicious email.” They need processes that assume a message can look authentic and still be fraudulent.

AI and analytics are becoming important detection layers for BEC, helping organizations identify unusual email behaviour, payment anomalies, vendor changes, and impersonation attempts. However, technology should complement, not replace, strong verification procedures. The most effective defense combines detection tools with clear controls that require employees to confirm high-risk requests through trusted channels.

 

Make Verification Part of the Process

The strongest defense against BEC is a culture where verification is expected, supported, and never treated as a lack of trust. Employees should feel empowered to pause, question, and confirm unusual requests, especially those involving payment changes, urgent transfers, sensitive data, or requests to bypass normal procedures.

Recent guidance from the RCMP shows why that pause matters. In reported cases, fraudsters gained access to legitimate business email accounts, used accurate invoice details to redirect client payments, and intercepted replies to delay detection. Because the emails appeared to come from trusted addresses, recipients had little reason to suspect fraud, reinforcing the need to independently verify any request to change payment instructions.3

For business leaders, the practical question is whether controls are clear enough to work under pressure. Organizations should consider whether they have consistent procedures for the moments when BEC is most likely to succeed:

  • Payment changes: Require independent confirmation before updating vendor banking details.
  • Urgent transfers: Escalate rushed or unusual payment requests through a second approval path.
  • Vendor records: Keep verified contact information separate from email threads.
  • System access: Limit access to payment and financial systems to employees who need it.
  • Incident response: Rehearse what teams should do if a fraudulent request is suspected or a payment has already been sent.

Leaders also play a critical role by reinforcing that speed should never override control. A well-designed verification process does not slow the business down; it protects the business from decisions made too quickly.

 

A Leadership Imperative

BEC is important because it sits at the intersection of people, process, technology, and trust. It reminds us that fraud prevention is not only the responsibility of security teams. It belongs to every leader who designs processes, approves payments, manages vendor relationships, or sets expectations for how work gets done.

Whether a business has ten employees or ten thousand, the lesson is the same: trust is valuable, but it must be protected. Organizations that build verification into everyday workflows will be better positioned to prevent losses, protect relationships, and maintain confidence in an increasingly complex fraud environment.

If you think your business has been targeted or compromised, act quickly. Contact your financial institution immediately. Scotiabank clients should reach out to their Relationship Manager to report the incident and get guidance on next steps.

To try our business email compromise simulation activity, visit us at: https://www.scotiabank.com/ca/en/security/fraud-simulation-activities/business-email-fraud.html

 

 

Disclaimer 

This article is provided for information purposes only. It is not to be relied upon as financial, tax or investment advice or guarantees about the future, nor should it be considered a recommendation to buy or sell. Information contained in this article, including information relating to interest rates, market conditions, tax rules, and other investment factors are subject to change without notice and The Bank of Nova Scotia is not responsible to update this information. All third-party sources are believed to be accurate and reliable as of the date of publication and The Bank of Nova Scotia does not guarantee its accuracy or reliability. Readers should consult their own professional advisor for specific financial, investment and/or tax advice tailored to their needs to ensure that individual circumstances are considered properly, and action is taken based on the latest available information. 

 

 

Sources

1 Canadian Anti-Fraud Centre. (July 24, 2025). International collaboration successfully intercepts and returns $2.3 million fraudulent transfer. https://antifraudcentre-centreantifraude.ca/news-nouvelles/2025/2025-07-24-eng.htm

2 Association for Financial Professionals. (2026). 2026 AFP Payments Fraud and Control Survey Report. https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud

3 Royal Canadian Mounted Police. (May 7, 2026). Cranbrook RCMP warns businesses and public of email payment fraud. https://rcmp.ca/en/bc/cranbrook/news/2026/05/4352889