Free cybersecurity training for organizations of any size. Schedule yours today ›

The Fake Vendor Email That’s Draining Business Bank Accounts

The Security BriefJune 10, 2026

One routine-looking email can cost your business tens of thousands. Here's how the BEC scam works, and the simple policy that stops it cold.

Scammers have figured out something uncomfortable about how most businesses handle money: in a lot of offices, it only takes one person to approve a wire transfer or change a vendor’s banking details. And they’re actively targeting that gap right now.

The scam is called Business Email Compromise, or BEC, and it’s one of the most expensive cyber threats facing businesses today. BEC accounted for 73% of all reported cyber incidents in 2024, a sharp jump from 44% in 2023. And from 2013 to 2023, U.S. businesses reported $20 billion in losses from fraudulent wire transfers started by scams just like this one.

The good news: there’s a simple, free policy change that stops it cold. Let’s walk through how the scam works first, because once you see it, you can’t unsee it.

How the scam works

Your accounts payable person gets an email that appears to come from one of your long-term vendors. The message says the vendor has updated their banking information and asks that all future payments be sent to a new account.

The email looks legitimate. The sender name matches. The request feels routine. So your employee updates the vendor profile and processes the next payment, sometimes tens of thousands of dollars, to the new account.

Two weeks later, your real vendor calls asking why they haven’t been paid.

Notice what’s missing from that story: no malware, no suspicious attachment, nothing for your security tools to catch. BEC works because it exploits trust and speed instead of technology. Someone on your team gets a request that looks normal, feels a little urgent, and comes from a name they recognize. It’s entirely social engineering, and it succeeds because most businesses have no requirement for a second set of eyes before money moves.

That single gap is all it takes.

How to protect your business

The fix is refreshingly straightforward: require at least two people to approve any significant fund transfer or change to vendor banking details. That one policy turns a devastating scam into a non-event.

Here’s what that looks like in practice:

  • Require two-person approval for every wire transfer and every change to vendor payment details. No exceptions, no matter how routine the request seems.
  • Verify banking changes by phone, using a number already on file for the vendor. Never call a number listed in the email itself. If the email is fake, so is the phone number.
  • Treat urgency as a red flag. Real vendors can wait a day for a verification call. Scammers push for speed because pressure short-circuits careful thinking.
  • Write the policy down and share it with everyone who touches payments or vendor accounts, so the process holds up even when someone is out of office or covering a new role.

With the policy in place, the story ends differently: one person gets the email, flags it for a second approver, and that approver makes a quick phone call to the vendor using the number on file. The fraud stops before it starts.

Worth addressing this week

If your business doesn’t currently have a multi-person approval process for wire transfers and vendor payment changes, this is worth fixing this week, not someday. Share this article with whoever handles your payments and vendor accounts, and put the two-approval rule in place before the next “updated banking information” email lands.

And if you’d like a second set of eyes on your internal controls, that’s exactly what we do. Start with our free 60-second Security Score to see where you stand, or talk to our team about setting up the right safeguards for your business. Keeping clients ahead of threats like this one is at the heart of how we approach Cybersecurity-Driven IT.

Ready to get started?

Get a free quote, or talk to our team about your IT needs.