Business email compromise (BEC) has quietly become one of the most financially damaging categories of cybercrime, ahead of ransomware in total reported losses in several recent years. It doesn't rely on malware at all — it relies on convincing a real employee to send money or data somewhere it shouldn't go. Generative AI has made that con dramatically easier to pull off convincingly.

What changed: AI removed the old warning signs

For years, the advice was 'watch for spelling mistakes and awkward phrasing.' That advice is now dangerously outdated. AI language tools let attackers generate fluent, well-punctuated, contextually appropriate emails in seconds — in your CEO's typical tone, referencing real vendors, real project names, and real recent events pulled from LinkedIn or your company website. The grammar tell is gone.

What today's BEC attempts actually look like

The invoice redirect

An email arrives, apparently from a known vendor, saying their banking details have changed. It references a real, recent invoice number. The request is small enough not to trigger obvious suspicion, and urgent enough to discourage double-checking.

The executive impersonation

An email or text appears to come from a senior executive, often timed for when that person is known to be travelling or in meetings (frequently visible from an out-of-office reply or a public calendar). It asks someone in finance to process an urgent wire transfer or purchase gift cards, framed as confidential.

The AI voice clone follow-up

Increasingly, these attacks are backed by a follow-up phone call using AI voice cloning, generated from a few seconds of publicly available audio — a podcast appearance, a conference talk, a voicemail greeting — to add a second layer of false confidence to the email.

Controls that work regardless of how convincing the email is

Out-of-band verification for any payment or banking change. Any request to change payment details or send funds should require a phone call to a known, previously verified number — not a number provided in the email itself. This single habit defeats the vast majority of BEC attempts, no matter how well written they are.

Dual approval on wire transfers and vendor changes above a set threshold. Requiring a second person to independently approve removes the single point of failure that BEC relies on.

Email authentication (DMARC, SPF, DKIM) configured correctly. These don't stop every attack, but they stop domain spoofing — a common technique where an attacker sends from a domain that looks nearly identical to a real vendor's.

Security awareness training that reflects 2026 tactics, not 2015 tactics. Training that only teaches 'look for typos' leaves your team unprepared for what they'll actually receive. Training should cover urgency framing, executive impersonation, and voice-based follow-ups.

The habit that matters most

If a request is urgent, unusual, or involves money or data, and it arrived by email or a call you didn't initiate — pause, and verify through a separate, known channel. That one habit, practiced consistently, is more effective than almost any technology control against BEC.

Want help putting email authentication and awareness training in place? Find your plan or book a free 15-minute call.