Most Malta business owners worry about ransomware, but statistically that’s not what is draining the most money from companies. The quiet champion of losses is business email compromise, and globally it has racked up more than 55 billion dollars in exposed losses over the past decade according to the FBI’s Internet Crime Complaint Center. Yet many SMEs here have never heard the term.
#What is business email compromise and why is it so expensive?
Business email compromise (BEC) is a targeted scam where criminals use real-looking emails to trick staff into sending money or sensitive data. There is usually no flashy malware, no locked screens, no dramatic ransom note. Just a believable email, a rushed finance team, and a wire transfer that never comes back.
Common BEC scenarios:
- An attacker spoofs or hacks your supplier’s email and sends a “new bank details” message just before a payment is due.
- Someone registers a domain one letter away from your own (e.g. limitbreaklt.com instead of limitbreakit.com) and emails your accounts team pretending to be your CEO, asking for an urgent transfer.
- HR receives a convincing email from “the CEO” asking for all employee payroll records for an upcoming audit.
According to recent FBI data, BEC generates around 2.7–3 billion dollars in reported losses per year and is consistently in the top two cybercrime categories by total cost, even though it is not the most commonly reported type of attack. Average loss per incident now sits well above 100,000 dollars. For many Malta SMEs, a single mistake of that size is the difference between a stressful month and a solvency problem.
BEC is expensive because it hijacks your existing business trust: invoices, suppliers, management approvals — the attacker plugs into processes that already move money.
Unlike many attacks, BEC often exploits your people and workflows more than your technology. That’s why traditional antivirus on its own barely moves the needle.
#How does business email compromise actually work in a Malta SME?
The mechanics are boringly simple, which is precisely why they are effective. A typical BEC chain for a local SME looks like this:
Initial access
The attacker gets into a mailbox through stolen credentials from a phishing email, password reuse on another breached service, or weak authentication on cloud email. Sometimes they don’t even hack anything — they just impersonate your domain.
Reconnaissance
They quietly read email threads. Who sends invoices? Who approves payments? Which clients pay regularly, and on what dates? For a few weeks, they learn your rhythm.
Impersonation
When a large payment is due, they slip in a message to accounts or finance that matches the real conversation history. The only change is a bank account number or payment destination.
Pressure and urgency
The email almost always includes urgency: “Must be paid today”, “Supplier is blocking shipment”, “Bank cutoff is in one hour”. This is engineered to bypass normal checks.
Transfer and exit
Funds are wired to a bank account controlled by the attacker or a money mule, often outside the EU. By the time anyone notices, the money has been moved through several accounts and is effectively gone.
In Malta, we see variations that exploit local habits: manual payments, heavy reliance on email for approvals, and small finance teams where one person may handle both invoices and bank transfers. If that person is on holiday and someone else covers without knowing all the usual checks, risk spikes.
#Business email compromise vs ransomware: which is worse for SMEs?
Business owners often ask whether they should worry more about ransomware or BEC. The honest answer is: both matter, but they hurt you in different ways. Here’s a simple comparison:
| Aspect | Business email compromise | Ransomware |
|---|---|---|
| Primary impact | Direct financial loss from fraudulent payments | Operational downtime, data loss and ransom demand |
| Average incident cost | Often 100k+ per incident globally; can be lower but still painful for SMEs | Highly variable; from a few thousand to millions depending on size and recovery |
| Visibility | Frequently discovered late, sometimes only after a supplier complains about missing payment | Usually obvious immediately (systems locked, ransom note) |
| Main attack vector | Email impersonation, account takeover, social engineering | Malware via phishing, vulnerable systems, remote access attacks |
| Recovery focus | Banking recalls, internal investigation, legal and insurance claims | Restoring systems, backups, forensics, regulatory reporting |
Many Malta SMEs have already implemented a proper backup system to deal with ransomware and downtime. Few have done the same level of work on payment workflows and email authentication. That imbalance is what makes BEC so profitable for attackers.
#The hidden business cost of a BEC incident
A BEC attack is not just “we lost a payment”. There are knock-on effects that often cost more than the initial transfer:
- Cash flow shock
Losing 50,000–100,000 euro can force you to delay supplier payments, salaries or projects. Small firms with thin margins feel this immediately.
- Relationship damage
If a client or supplier gets caught in a BEC involving your domain, they may quietly mark you as “risky”. That can affect contract renewals and terms.
- Operational overhead
Weeks of staff time go into reconciling payments, talking to banks, documenting the incident and updating controls. If your IT team is already stretched, this hits ongoing projects.
- Regulatory and legal exposure
If personal data was exposed in the emails that attackers accessed, you may have to consider GDPR notification to the IDPC and impacted individuals. If bank details were compromised, customers will expect clear communication.
- Insurance friction
As we discussed in our post on cyber insurance in Malta, insurers increasingly ask detailed questions about your email security and approval workflows. A messy BEC incident can affect future premiums or claims.
When you add those together, BEC is not an “IT problem”. It is a business risk that combines finance, legal, operations and reputation.
#Practical checklist: how Malta SMEs can reduce business email compromise risk
You won’t get BEC risk to zero, but you can make your company a much harder target. Focus on five areas: identity, email security, processes, people and response.
Lock down email identities
- Enforce multi-factor authentication on all business email accounts, especially finance, HR and management.
- Block legacy protocols (like insecure POP/IMAP) where possible.
- Use strong, unique passwords and a password manager — no shared accounts for “accounts@” if it can be avoided.
Harden your email infrastructure
- Enable and correctly configure SPF, DKIM and DMARC for your domains to reduce spoofing.
- Use advanced phishing and impersonation protection in Microsoft 365 or Google Workspace.
- Monitor for lookalike domains that closely resemble yours and might be used in scams.
Fix payment workflows, not just IT
- Require two-person approval for transfers above a clear threshold (e.g. 5,000 euro).
- Mandate out-of-band verification (phone call to a known number, not the one in the email) for any change in bank details.
- Maintain and regularly review a “trusted payee” list so changes stand out.
Train people on real BEC scenarios
- Show staff actual examples of BEC-style emails, not just generic phishing.
- Emphasise that urgency and secrecy in payment requests are red flags.
- Run short, regular refreshers rather than one long annual training.
Prepare a simple incident playbook
- Define the first five actions if BEC is suspected: pause payments, call the bank, inform IT, secure accounts, document what happened.
- Know who speaks to regulators, insurers and affected customers if personal data or large sums are involved.
- Test the playbook once a year so it’s muscle memory, not theory.
Use managed IT to keep controls consistent
- If you rely on a mix of freelancers and ad‑hoc support, email security and MFA policies tend to drift.
- A managed IT partner can standardise identity and email protection, keep policies aligned with frameworks like NIS2 where relevant, and handle monitoring and response.
If you want to stop worrying about business email compromise, get in touch — we work with Malta businesses to make IT one less thing on your list.



