Managed IT7 min read

The Invoice That Wasn't: How Business Email Compromise Hits Small Businesses

Business email compromise prevention starts with one phone call. How the fake-invoice scam works, what it cost in 2025, and what to do if a wire goes out.

Rodney Holum
Share
The Invoice That Wasn't: How Business Email Compromise Hits Small Businesses
In this article
  1. What business email compromise costs in Wisconsin and Florida
  2. The four business email compromise patterns to know
  3. Business email compromise prevention: call back on a number you already had
  4. What to do in the first hour after a wire goes out
  5. Frequently asked questions
  6. Train the people who approve payments

Business email compromise (BEC) is a scam where a criminal poses as someone your business already pays or trusts, usually by email, and talks your staff into sending money to an account the criminal controls. In 2025 the FBI's Internet Crime Complaint Center (IC3) logged 24,768 BEC complaints and $3.05 billion in reported losses (opens in a new tab), second only to investment fraud in dollars lost. Business email compromise prevention mostly comes down to one habit: before money goes to a new or changed account, call the person back on a phone number you already had.

Picture a bookkeeper at a 20-person company in Onalaska. An email arrives from a supplier she has paid for six years, inside the real thread about last month's order. The invoice is correct to the penny. One new line says the supplier switched banks. She updates the vendor record and pays. Three weeks later the real supplier calls to ask where the money is. That is the invoice that wasn't.

What business email compromise costs in Wisconsin and Florida#

The FBI's 2025 state reports bring it closer to home:

StateVictims reporting BECReported BEC lossesRank by loss among crime types
Wisconsin (opens in a new tab)346$38.2 million2nd, after investment fraud
Florida (opens in a new tab)2,025$187.3 million2nd, after investment fraud

These are only the losses people reported. For the rest of the state picture, see our breakdown of what cybercrime cost Wisconsin last year.

Most of the money leaves by bank transfer. In BEC complaints that said how the money moved, 86% named a wire transfer or ACH and 7% named prepaid or gift cards, according to the chart on page 10 of the 2025 IC3 annual report (opens in a new tab).

The four business email compromise patterns to know#

The IC3 says BEC is "frequently carried out when a subject compromises legitimate business e-mail accounts through social engineering or computer intrusion techniques." (opens in a new tab) In plain terms, the fake email may come from a lookalike address or from the real mailbox after a password was stolen. "It came from their real address" proves nothing.

A familiar voice is no longer proof either. The 2025 IC3 report (opens in a new tab) notes that voice cloning "can also be used to request wire payment," and that businesses reported more than $30 million in losses to BEC scams involving AI.

1. The vendor whose bank account changed#

This is the story above. The criminal imitates the vendor, or gets into the vendor's mailbox and waits for a real invoice to go out, then sends "new bank details" in the same thread. The IC3's first prevention tip: verify any change to account information through a second channel. Replying to the email is not a second channel.

2. The boss who needs gift cards#

An email or text that looks like it came from the owner asks an employee to buy gift cards for a company event or a client thank-you and send the card numbers. The FTC's warning about the fake boss gift card scam (opens in a new tab) is blunt: only scammers will ask for gift card numbers and the PIN. Check with your boss using a number or email you know is real.

3. The employee whose direct deposit changed#

In a 2018 alert, the FBI described criminals who phish an employee's login, change the direct deposit in their payroll account, and add rules so the employee never sees the change alert (opens in a new tab). A simpler version skips the hacking: an email that looks like it came from the employee asks HR to update the account. Either way, the employee finds out on payday.

4. The closing that wired to the wrong account#

If your business buys or sells a building through a title company, watch for this one. The CFPB describes scammers who compromise real estate professionals' email to watch for upcoming closings (opens in a new tab), then send spoofed emails with false wiring instructions. The amount is large and the deadline is real, which is the pressure the scam needs.

A Wisconsin warning: goods ordered and never paid for#

BEC does not always go after the money you send. Wisconsin's DATCP warned businesses in December 2022 (opens in a new tab) that criminals were using BEC to steal shipments of food products and ingredients valued at hundreds of thousands of dollars. They pose as real employees, using fake emails and domains, and order goods on a company's behalf without paying for them. If you sell on credit terms, a large order from an unfamiliar address, or a request to ship somewhere new, deserves the same callback as a request to change where you send money.

Business email compromise prevention: call back on a number you already had#

In every pattern above, someone acts on instructions that arrived through the same channel as the lie. So break the channel. The FTC's cybersecurity guidance for small businesses (opens in a new tab) puts it simply: require your employees to call and confirm wire transfer requests they receive through email.

Write it down as a rule your finance team can point to:

  1. Know the triggers. Any new payee, any change to bank details or a remit-to address, any payroll deposit change, any gift card request, and any wire above an amount you set.
  2. Call a number from your own records. Use the vendor file, the original contract, or a website you type in yourself. Never use the number in the email, the invoice, the signature block or a voicemail.
  3. Talk to someone you know. Read the old and new account details out loud. If they have not heard of the change, stop.
  4. Use two people for the first payment. One person enters the change. A second person approves the first payment to the new account.
  5. Allow no urgency exceptions, including for the owner. Owners, tell your team in writing that you will never be annoyed by a callback. The scam counts on staff not wanting to bother the boss.
  6. Log it. Record who called, which number they used, when, and who they spoke with.

That is the whole control. It costs a two-minute phone call.

Technical layers that back it up#

The callback is the last check. These layers put fewer fake emails in front of your team:

  • Multi-factor authentication on every mailbox, so a stolen password alone does not open the account.
  • Email authentication on your domain. The FTC recommends SPF, DKIM and DMARC so receiving servers can block imposters sending as your company.
  • Alerts on new forwarding and inbox rules, because hidden rules are how criminals keep the real replies away from you.
  • Regular training for the people who move money. Short, frequent sessions with realistic phishing tests build the reflex better than a yearly video. We laid out that approach in security awareness training that isn't a once-a-year lecture.

What to do in the first hour after a wire goes out#

If the money already left, speed matters most. The IC3 annual report (opens in a new tab) says it plainly: "If you discover a fraudulent transfer, time is of the essence."

  1. Call your bank's fraud line now. Ask the bank that sent the payment for a recall or reversal, and for a Hold Harmless Letter or Letter of Indemnity, as the IC3 advises for BEC incidents (opens in a new tab). Do this by phone.
  2. File a complaint at ic3.gov (opens in a new tab) the same day. Include the amount, date, both banks, the account numbers and the emails. The IC3 says it may be able to help banks and law enforcement freeze funds. In 2025 its Recovery Asset Team froze $679 million of the $1.16 billion in attempted theft across the 3,900 incidents it worked, a 58% success rate. Those figures cover all fraud types, not only BEC, and nothing is guaranteed.
  3. Keep everything. Do not delete the emails or reply to the scammer.
  4. Lock down the mailbox. Change the password, sign out every session, turn on multi-factor authentication, and look for forwarding or inbox rules nobody on your team created.
  5. Call the real vendor or customer on a number you know. If criminals were sending email as your business, the FTC advises telling your customers as soon as possible, and if you email them, sending a notice with no links in it.
  6. Report it to the FTC at ReportFraud.ftc.gov (opens in a new tab) and to local police, as the FTC advises. In Wisconsin, DATCP's Consumer Protection Hotline (opens in a new tab) takes scam reports at (800) 422-7128.
  7. Call your insurance agent, and your attorney for a large loss. Whether a loss is covered or recoverable depends on your policy, your bank agreement and the facts. This is general information, not legal advice.

Frequently asked questions#

Who do BEC scammers target?#

Anyone who can move money or change where it goes: owners, controllers, bookkeepers, and HR or payroll staff. The IC3 defines BEC as a scam aimed at businesses and people who work with suppliers or regularly send wire transfers.

Can you get your money back after a BEC wire transfer?#

Sometimes, if you act fast. Call the sending bank to request a recall, then file at ic3.gov with full transaction details. In 2025 the IC3's Recovery Asset Team froze 58% of the attempted theft in the incidents it worked, across all fraud types, but recovery is never guaranteed.

Does multi-factor authentication stop business email compromise?#

It closes one door: a stolen password alone no longer opens the mailbox. It does nothing against a lookalike domain, a fake boss texting from a new number, or a cloned voice. That is why the callback rule still matters after MFA is on.

What are the red flags of a fake invoice email?#

A change to bank details or the remit-to address, pressure to pay today, a request to keep it quiet, a sender address that is one character off, or a new contact you have never dealt with. Any one of these means you call before you pay.

Train the people who approve payments#

BEC works on capable people doing their jobs quickly. Ask us about security awareness training for your finance team. It pairs online training modules with realistic phishing simulations, so the people who approve payments practice spotting a fake before a real one lands. It is part of our cybersecurity services, from our La Crosse cybersecurity team serving the Coulee Region to our Fort Myers cybersecurity team serving Lee County. Contact us to get your team started.

business email compromise preventionbusiness email compromiseinvoice fraud small businesswire transfer email scamvendor payment fraudbusiness email compromise Wisconsinpayment callback verification
Back to Blog
Share this article

Ready to Strengthen Your IT?

Schedule a free discovery call to discuss your technology needs with our team.