CtrlShiftIT
Identity security guide

Business Email Compromise

Business email compromise, or BEC, is a practical fraud problem more than a technical spectacle. Attackers gain access to a mailbox or impersonate a trusted sender, then use normal business conversations to redirect payments, request gift cards, change banking details, or harvest confidential information.

Small businesses are attractive because payment approval is often relationship-based. A law clerk, clinic administrator, bookkeeper, or consultant may know the requester personally and want to keep work moving. The best defence combines Microsoft 365 controls with simple finance procedures that make unusual requests easier to verify.

The explanation

What it means

BEC can involve full mailbox compromise, lookalike domains, display-name spoofing, or a changed reply-to address. In many cases, the message does not contain malware. It works because it fits into a real business process.

After mailbox access, attackers often search for words like invoice, payment, wire, closing, retainer, payroll, or tax. They may create forwarding rules, hide replies, and wait until the right conversation appears.

How it affects small businesses

A professional office may have a small finance team, a managing partner who approves payments by email, and vendors that send invoices as PDFs. That is normal, but it creates predictable workflows attackers can study.

The impact can include misdirected funds, delayed closings, vendor disputes, client notification work, mailbox cleanup, and staff confidence issues. Even when money is recovered, the business loses time proving what happened and tightening the process.

Invoice redirection

Attackers change banking details during an active vendor or client conversation.

Hidden mailbox rules

Rules can forward messages externally or move replies to folders users rarely check.

Trusted account abuse

Messages from a real staff mailbox can bypass the healthy skepticism people apply to unknown senders.

Warning signs

Signals to watch for

New inbox or forwarding rules

Rules that delete, archive, forward, or hide messages are a common compromise indicator.

Changed reply-to or unusual sender domain

A message may look familiar while replies go somewhere else.

Strange sent mail or missing sent items

Attackers may send messages then delete traces or use rules to hide responses.

Urgent vendor payment changes

Banking detail changes should be verified through a known phone number or established out-of-band process.

Reduce risk

First controls to put in place

Require MFA and monitor MFA changes

MFA reduces password-only compromise, while alerts for new MFA methods help catch account takeover attempts.

Enable mailbox auditing and alerting

Audit logs, inbox rule alerts, forwarding alerts, and suspicious sending alerts make response faster.

Use payment verification procedures

Verify new banking details or urgent payment changes through a known phone number, not by replying to the email thread.

Train staff on workflow checks

Training should focus on practical moments: invoice changes, executive requests, new vendors, and unexpected secrecy.

Review external forwarding

Disable or tightly control automatic forwarding to external addresses unless there is a documented business need.

CtrlShift assessment

What we look at during a review

When we assess identity security, these are the specific areas we check against your actual Microsoft 365 tenant.

Mailbox rule and forwarding review

We check for suspicious rules, external forwarding, hidden folders, and unusual mailbox permissions.

Audit and alert readiness

We confirm that Microsoft 365 logging captures the events needed to investigate mailbox compromise.

Finance workflow exposure

We identify payment approval paths that rely only on email and recommend lightweight verification steps.

Account recovery hygiene

We review MFA methods, password resets, session revocation, and risky sign-in history for affected users.

ops@ctrlshiftit: ~/identity-security

Need this mapped to your own tenant?

We can review your Microsoft 365 sign-in posture, MFA coverage, Conditional Access policies, legacy auth exposure, admin roles, and mailbox permissions — practical and scoped to a small team.

no obligation~30 minutesGTA-based engineers

FAQ

Identity attack questions answered

4 results
CoverageAre identity attacks mostly a Microsoft 365 problem?

Microsoft 365 is a common target because email, files, Teams, and identity all meet there. The same principles apply to Google Workspace, accounting portals, CRM systems, and remote access tools.

SecurityCan MFA be bypassed?

MFA greatly reduces risk, but active session theft, phishing proxies, OAuth consent abuse, and compromised devices can still create access. That is why Conditional Access, endpoint protection, and logging matter.

SecurityWhat should we check first after a suspected mailbox compromise?

Revoke sessions, reset the password and MFA methods, review inbox and forwarding rules, check sign-in logs, inspect sent mail, and preserve audit logs before cleanup.

CoverageDo small businesses need separate admin accounts?

Yes. Admin accounts should be separate from daily email accounts, protected with strong MFA, and used only for administration.