⏰ Support Available: Mon-Fri 4:00pm-6:00am | Weekends 24/7

Back to all articles
Email Security7 min read

Business Email Compromise, How Attackers Get In and How M365 Can Stop Them

By Jamie Hamilton · Published

Business email compromise is consistently one of the highest value cybercrime categories reported in Australia, and it is unusual among them in that it often involves no technical exploit at all. No malware, no stolen credentials, no vulnerability. A convincing email and somebody having a busy morning.

That is what makes it hard to defend with products alone, and it is why the section near the end of this article matters more than the ones before it.

The four shapes it takes

Nearly every case is a variation on one of four:

  • •Executive impersonation. An email that appears to come from the managing director, usually short, usually urgent, usually while they are known to be travelling, asking for a payment to be made quickly and quietly.
  • •Invoice and supplier fraud. A message from a supplier you genuinely use, advising that their bank details have changed. This is the most expensive variety because the amounts are already expected and the payment is already scheduled.
  • •Payroll diversion. A staff member emails asking to update the account their pay goes into. Small individually, and it works because the request is routine.
  • •Compromise and lateral movement. The attacker is inside a real mailbox, reading the actual conversation, and joins it at the right moment with the right context. This is the hardest to spot because every signal is genuine except the intent.

Why it works when better-defended things fail

Three reasons, and none of them is a software problem.

It contains nothing to detect. No malware, no attachment, often not even a link. A filter looking for malicious content finds none, because there is none. The payload is the sentence.

It arrives inside a real context. Invoice fraud works because you were expecting an invoice. Payroll diversion works because people do change banks. The message is plausible precisely because the business process it targets is genuine and routine.

And the money moves in one direction. A transfer made on a Friday afternoon to an account that closes on Monday is not a technical incident you can roll back. That asymmetry is why prevention gets so much more attention here than detection does.

What Microsoft 365 can actually do

The technical controls do real work, mostly by making the compromise half harder:

  • •Multi-factor authentication, enforced for everybody with no undocumented exceptions. This is the single largest reduction in automated account compromise available, and it is the precondition for the fourth attack shape above being difficult rather than trivial.
  • •Conditional Access, so a sign-in from a country the business has no presence in is treated differently from one in the office.
  • •Anti-phishing with impersonation protection in Defender for Office 365, which is specifically built for the display name and look-alike domain cases that content filtering cannot catch.
  • •External sender tagging, which puts a visible marker on mail from outside the organisation. Cheap, unglamorous, and it directly undermines executive impersonation because the message claiming to be from your own director arrives labelled as external.
  • •SPF, DKIM and DMARC at enforcement, which stops your exact domain being forged. Note the limit: this protects your domain from being used against your customers and does nothing about a look-alike domain, which belongs to the attacker.
  • •Alert policies for the behaviour that follows a compromise, particularly new forwarding rules and unusual sign-in locations.

Mailbox forwarding rules deserve their own mention. Setting one is the first thing an attacker does after getting into a mailbox, because it gives them a copy of the conversation without needing to sign in again. An alert on rule creation is one of the highest value things you can switch on and one of the least often configured.

The control that does most of the work is not technical

One rule, written down and applied without exceptions: any request to change bank details, or to make a payment outside the normal process, is verified by voice on a number you already had. Not a number in the email. Not a number in the signature block. The number you had before the request arrived.

That single rule defeats the first three attack shapes entirely and most of the fourth, because it does not depend on anybody spotting that a message is fake. It removes the need to spot anything.

It only works if it applies to everybody. A rule with an exception for the managing director is a rule that specifically permits the most common version of the attack, and the whole point of executive impersonation is that people do not challenge the executive. Saying so in advance, in writing, is what gives the accounts clerk permission to ring and check.

Testing whether it holds

Attack simulation training in Microsoft 365 Business Premium lets you run a simulated phishing campaign against your own staff and see what happens. It is worth doing, with one caveat about how you use the result.

The number of people who clicked is the least useful output. The useful one is how many reported it, and how quickly. A business where nobody clicked but nobody reported either is not safe, it is lucky, because it has no signal when a real one arrives. Measure and reward the reporting.

Frequently asked questions

What is business email compromise?

A fraud where somebody uses email to impersonate a person or a business you trust and redirect a payment. It usually involves no malware and no technical exploit, which is what separates it from most cybercrime: the message contains nothing for a filter to detect because the payload is the sentence rather than an attachment. The four common shapes are executive impersonation, supplier invoice fraud, payroll diversion, and an attacker operating from inside a real mailbox.

How can I protect my business from BEC?

The technical half is multi-factor authentication enforced for everybody, Conditional Access, impersonation protection in Defender, external sender tagging, DMARC at enforcement, and an alert when a mailbox forwarding rule is created. The half that does more work is a written rule that any change of bank details or unusual payment is verified by voice on a number you already had, applied to everybody including the directors.

Will DMARC stop business email compromise?

It stops one version of it. Enforcing DMARC prevents your exact domain being forged, which protects your customers from invoices that appear to come from you. It does nothing about a look-alike domain, because that domain belongs to the attacker and your policy has no authority over it, and nothing about a compromised mailbox, because that mail is genuinely yours and authenticates perfectly. It is necessary and it is not sufficient.

What is the first sign of a compromised mailbox?

Usually a forwarding rule the owner did not create, because that is the first thing an attacker sets up: it gives them a running copy of the conversation without needing to sign in again and risk an alert. Others are sign-ins from unfamiliar locations, mail disappearing from the sent items, and colleagues mentioning replies to messages the owner never wrote. An alert on rule creation is one of the highest value settings to enable and one of the least often configured.

Does multi-factor authentication stop BEC?

It stops the account compromise route, which is a large part of it, and it is the highest value control available for that. It does not stop the versions that never touch your systems at all: an executive impersonation email sent from an unrelated address, or a supplier fraud from a look-alike domain, does not require access to anything of yours. Those are defeated by the verification rule rather than by authentication.

Is phishing simulation training worth doing?

Yes, provided you read the result correctly. Attack simulation training is included with Microsoft 365 Business Premium. The click rate is the least useful number it produces. What matters is how many people reported the message and how fast, because a business where nobody clicked and nobody reported has no early warning when a real one lands. Measure the reporting and make it easy.

Not confident your Microsoft 365 is configured to resist this?

Health Check, $599

or call 0403 401 250