Business owner reviewing suspicious emails on laptop in office
← All articles
Cybersecurity·7 min read·

Business email compromise: the most expensive attack you have never heard of

Most Malta business owners worry about ransomware, but statistically that’s not what is draining the most money from companies. The quiet champion of losses is business email compromise, and globally it has racked up more than 55 billion dollars in exposed losses over the past decade according to the FBI’s Internet Crime Complaint Center. Yet many SMEs here have never heard the term.

#What is business email compromise and why is it so expensive?

Business email compromise (BEC) is a targeted scam where criminals use real-looking emails to trick staff into sending money or sensitive data. There is usually no flashy malware, no locked screens, no dramatic ransom note. Just a believable email, a rushed finance team, and a wire transfer that never comes back.

Common BEC scenarios:

  • An attacker spoofs or hacks your supplier’s email and sends a “new bank details” message just before a payment is due.
  • Someone registers a domain one letter away from your own (e.g. limitbreaklt.com instead of limitbreakit.com) and emails your accounts team pretending to be your CEO, asking for an urgent transfer.
  • HR receives a convincing email from “the CEO” asking for all employee payroll records for an upcoming audit.

According to recent FBI data, BEC generates around 2.7–3 billion dollars in reported losses per year and is consistently in the top two cybercrime categories by total cost, even though it is not the most commonly reported type of attack. Average loss per incident now sits well above 100,000 dollars. For many Malta SMEs, a single mistake of that size is the difference between a stressful month and a solvency problem.

BEC is expensive because it hijacks your existing business trust: invoices, suppliers, management approvals — the attacker plugs into processes that already move money.

Unlike many attacks, BEC often exploits your people and workflows more than your technology. That’s why traditional antivirus on its own barely moves the needle.

#How does business email compromise actually work in a Malta SME?

The mechanics are boringly simple, which is precisely why they are effective. A typical BEC chain for a local SME looks like this:

Initial access

The attacker gets into a mailbox through stolen credentials from a phishing email, password reuse on another breached service, or weak authentication on cloud email. Sometimes they don’t even hack anything — they just impersonate your domain.

Reconnaissance

They quietly read email threads. Who sends invoices? Who approves payments? Which clients pay regularly, and on what dates? For a few weeks, they learn your rhythm.

Impersonation

When a large payment is due, they slip in a message to accounts or finance that matches the real conversation history. The only change is a bank account number or payment destination.

Pressure and urgency

The email almost always includes urgency: “Must be paid today”, “Supplier is blocking shipment”, “Bank cutoff is in one hour”. This is engineered to bypass normal checks.

Transfer and exit

Funds are wired to a bank account controlled by the attacker or a money mule, often outside the EU. By the time anyone notices, the money has been moved through several accounts and is effectively gone.

In Malta, we see variations that exploit local habits: manual payments, heavy reliance on email for approvals, and small finance teams where one person may handle both invoices and bank transfers. If that person is on holiday and someone else covers without knowing all the usual checks, risk spikes.

#Business email compromise vs ransomware: which is worse for SMEs?

Business owners often ask whether they should worry more about ransomware or BEC. The honest answer is: both matter, but they hurt you in different ways. Here’s a simple comparison:

Aspect Business email compromise Ransomware
Primary impact Direct financial loss from fraudulent payments Operational downtime, data loss and ransom demand
Average incident cost Often 100k+ per incident globally; can be lower but still painful for SMEs Highly variable; from a few thousand to millions depending on size and recovery
Visibility Frequently discovered late, sometimes only after a supplier complains about missing payment Usually obvious immediately (systems locked, ransom note)
Main attack vector Email impersonation, account takeover, social engineering Malware via phishing, vulnerable systems, remote access attacks
Recovery focus Banking recalls, internal investigation, legal and insurance claims Restoring systems, backups, forensics, regulatory reporting

Many Malta SMEs have already implemented a proper backup system to deal with ransomware and downtime. Few have done the same level of work on payment workflows and email authentication. That imbalance is what makes BEC so profitable for attackers.

#The hidden business cost of a BEC incident

A BEC attack is not just “we lost a payment”. There are knock-on effects that often cost more than the initial transfer:

  • Cash flow shock

Losing 50,000–100,000 euro can force you to delay supplier payments, salaries or projects. Small firms with thin margins feel this immediately.

  • Relationship damage

If a client or supplier gets caught in a BEC involving your domain, they may quietly mark you as “risky”. That can affect contract renewals and terms.

  • Operational overhead

Weeks of staff time go into reconciling payments, talking to banks, documenting the incident and updating controls. If your IT team is already stretched, this hits ongoing projects.

  • Regulatory and legal exposure

If personal data was exposed in the emails that attackers accessed, you may have to consider GDPR notification to the IDPC and impacted individuals. If bank details were compromised, customers will expect clear communication.

  • Insurance friction

As we discussed in our post on cyber insurance in Malta, insurers increasingly ask detailed questions about your email security and approval workflows. A messy BEC incident can affect future premiums or claims.

When you add those together, BEC is not an “IT problem”. It is a business risk that combines finance, legal, operations and reputation.

#Practical checklist: how Malta SMEs can reduce business email compromise risk

You won’t get BEC risk to zero, but you can make your company a much harder target. Focus on five areas: identity, email security, processes, people and response.

Lock down email identities

  • Enforce multi-factor authentication on all business email accounts, especially finance, HR and management.
  • Block legacy protocols (like insecure POP/IMAP) where possible.
  • Use strong, unique passwords and a password manager — no shared accounts for “accounts@” if it can be avoided.

Harden your email infrastructure

  • Enable and correctly configure SPF, DKIM and DMARC for your domains to reduce spoofing.
  • Use advanced phishing and impersonation protection in Microsoft 365 or Google Workspace.
  • Monitor for lookalike domains that closely resemble yours and might be used in scams.

Fix payment workflows, not just IT

  • Require two-person approval for transfers above a clear threshold (e.g. 5,000 euro).
  • Mandate out-of-band verification (phone call to a known number, not the one in the email) for any change in bank details.
  • Maintain and regularly review a “trusted payee” list so changes stand out.

Train people on real BEC scenarios

  • Show staff actual examples of BEC-style emails, not just generic phishing.
  • Emphasise that urgency and secrecy in payment requests are red flags.
  • Run short, regular refreshers rather than one long annual training.

Prepare a simple incident playbook

  • Define the first five actions if BEC is suspected: pause payments, call the bank, inform IT, secure accounts, document what happened.
  • Know who speaks to regulators, insurers and affected customers if personal data or large sums are involved.
  • Test the playbook once a year so it’s muscle memory, not theory.

Use managed IT to keep controls consistent

  • If you rely on a mix of freelancers and ad‑hoc support, email security and MFA policies tend to drift.
  • A managed IT partner can standardise identity and email protection, keep policies aligned with frameworks like NIS2 where relevant, and handle monitoring and response.

If you want to stop worrying about business email compromise, get in touch — we work with Malta businesses to make IT one less thing on your list.

Frequently asked questions

What is business email compromise in simple terms?

Business email compromise is a type of fraud where attackers use real-looking emails, often from hacked or spoofed accounts, to trick staff into sending money or sensitive data. It usually targets finance, HR or management and relies on social engineering rather than malware.

How can a small business prevent business email compromise?

A small business can reduce BEC risk by using strong email security, enforcing payment approval workflows, training staff to spot suspicious requests, and enabling multi-factor authentication on all email accounts. Regular testing and clear incident procedures also make attacks easier to catch before money leaves the bank.

Is business email compromise covered by cyber insurance?

Many cyber insurance policies include some cover for business email compromise, but the details vary and often depend on how the fraud happened. You need to check whether your policy covers social engineering, financial loss, legal costs and incident response, and what security controls are required for claims to be paid.

What should I do if I suspect a business email compromise attack?

Immediately stop any pending payments linked to the suspicious email and call the bank, then contact IT or your managed service provider to secure accounts and check logs. Preserve all evidence, inform management, and consider reporting the incident to law enforcement and relevant regulators if data may be involved.