On a Tuesday during month-end close, an accounts payable analyst at a logistics operator receives an email from the carrier that has served the company for four years. The sender is the same usual contact, the signature is the same, and the conversation follows the thread of a real invoice from the previous week. The request is simple: the carrier has switched banks, and the next invoices should be paid to the new account. The analyst updates the vendor record, the payment batch goes out on time, and no one notices anything until the real supplier calls, thirty days later, asking about three overdue invoices.
This scenario has a technical name, BEC (Business Email Compromise), and it rarely involves viruses, malicious attachments or anything an antivirus can block. It exploits a request that looks legitimate because, in large part, it is legitimate: it comes from a real mailbox, either hacked or precisely impersonated, and it arrives within a routine that rewards whoever resolves things quickly.
The analyst in the example completed the annual security training, knows how to spot phishing (a fraudulent message that tries to deceive the recipient) and got every question on the test right. The problem is that nothing in that email looked like phishing. It is precisely in this gap between knowing and being able to apply that knowledge, amid operational pressure, that your company may be more exposed than you think.
What is at stake when the scam slips through the process
The FBI (Federal Bureau of Investigation), through the IC3 (Internet Crime Complaint Center), recorded 21,442 BEC complaints in its Internet Crime Report 2024, with reported losses of approximately 2.77 billion dollars in a single year. For comparison, the same report tallies about 16.6 billion dollars in total losses from cybercrime, which places payment fraud among the costliest schemes out there. And these figures reflect only what was reported.
Verizon's Data Breach Investigations Report 2025 indicates that the human element is present in about 60% of the breaches analyzed, whether through error, deception or misuse of credentials. Meanwhile, the Microsoft Digital Defense Report 2025 describes how attackers favor identity theft and access to legitimate accounts, because logging in with someone's password is quieter than forcing the door. A hacked mailbox gives the criminal something no malware (malicious software) can deliver: context, including conversation history, usual amounts, the names of approvers and due dates.
With that context, the scam no longer looks like a scam. The criminal can spend weeks watching a supplier's mailbox, create forwarding rules (automatic instructions that divert or hide messages) to intercept replies and wait for the right moment, usually a month-end close, a change of manager or a spike in volume. When they strike, they reply within a genuine conversation, and the request to change bank accounts arrives as the most natural thing in the world.
In logistics, this scenario finds fertile ground. A typical operation works with dozens of third-party carriers, freight forwarders, customs brokers and partner warehouses, many of them small, with weak email security and bank details that change frequently. The volume of small and mid-sized invoices is high, and an “urgent” freight charge to release a held container raises no suspicion, because that really happens every week. The fraud hides in the noise of the operation.
The business impact goes beyond the amount diverted. There is the duplicate payment to the real supplier, who is still owed, the strained business relationship, executive time consumed by the investigation and, in some cases, the dispute over who bears the loss when the breach occurred in the partner's environment. For partners and boards, each incident is also a signal about the quality of internal controls, something that auditors, insurers and potential buyers watch closely.
The uncomfortable conclusion is that the human factor fails at the seams of the process, not for lack of information. The person knows what fraud is, but the system they work in offers no natural stopping point, nor explicit authority to use it.
Awareness as process design
The most effective approach is to build awareness into the workflow itself, rather than relying on an annual event on the HR calendar. This means deciding, in writing, which requests require verification and how it takes place, instead of expecting each employee to make the right decision alone and under pressure.
The first control is out-of-band verification: any change to bank details, new supplier registration or out-of-pattern payment request is confirmed through a phone number already on file, never through the number provided in the email itself. The second is dual approval by amount tier, in which payments above a defined threshold require a second person, and changes to vendor records always require one, regardless of the amount, because they are what redirect all subsequent payments.
The third control is teaching behavioral signals, in addition to technical ones. Unusual urgency, requests for secrecy, a change in tone, a request to “not involve” another department and an account change on the eve of an important due date are patterns anyone can learn to recognize. The decisive point is that the team has formal authority to hold a payment without having to ask permission, and that leadership recognizes those who stopped a legitimate request out of excessive caution.
Rounding out the design, technology underpins these controls. A layer of managed cybersecurity monitors signals the human eye can't see, such as logins from unlikely locations, forwarding rules created for no reason, and domains nearly identical to your suppliers' domains, and gives your in-house team the backup it needs to act before the money leaves.
5 questions every manager should ask
Before reviewing budgets or tools, it's worth bringing these five questions to your next meeting with the finance, operations, and IT teams.
Why do trained people keep approving fraudulent payments?
Because training teaches people to recognize the typical scam, and a well-executed BEC attack is atypical by definition. It comes from a real contact, with a real history, and asks for something the person has already done dozens of times. In that context, the brain runs on autopilot, and a routine that rewards speed speaks louder than the memory of a module watched months earlier.
This reveals the limit of training on its own: it transfers knowledge, but it doesn't change the decision-making environment. If the process doesn't create a mandatory verification step, security depends on individual attention on a bad day, and no awareness program can guarantee that attention consistently.
Where in our accounts payable is the risk really concentrated?
At three points: onboarding a new supplier, changing bank details, and approving invoices flagged as urgent. These are the moments when a single action changes where the money goes, which is why they deserve stricter controls than the routine payment of a recurring invoice.
In an operation with dozens of carriers and logistics partners, the practical exercise is to find out how many bank detail changes occurred in the last twelve months, who approved them, and how they were confirmed. If the answer is “by email,” you've found your business's biggest point of exposure, and it probably doesn't show up in any risk report.
How can we verify requests outside the original channel without slowing down operations?
The answer lies in calibrating controls to the risk of each transaction. Recurring payments to already validated accounts follow the normal flow. Account detail changes and payments above a set amount go through phone confirmation with the contact on file and a second approver. In practice, this affects a small fraction of transactions and adds only a few minutes to each verified case.
It's worth agreeing with partners in advance on how the check will be done, so it becomes part of the business relationship. Reputable suppliers tend to value this diligence, because it also protects their receivables against fraud that uses your company's name.
How far does technology protect us, and where does culture take over?
Technology covers what's detectable at scale: domain authentication to make it harder for third parties to send emails on your company's behalf, alerts on mailboxes behaving anomalously, blocking of suspicious forwarding rules, and identification of lookalike domains that mimic your suppliers'. A simple check, such as an email spoofing check, already shows whether your domain can be used by impostors.
Culture begins where technology can't reach: when the request comes from a legitimate account compromised in the partner's environment, outside your technical control. In that scenario, what protects your cash is the combination of a clear process, the authority to say no, and leadership that doesn't punish someone who delayed a payment to confirm its source.
How do we know whether awareness is truly changing behavior?
Completed training hours measure attendance, and attendance says little about behavior. The metrics that matter are the reporting rate for suspicious messages, the average time between receipt and report, the number of requests challenged or verified before payment, and the share of bank detail changes confirmed outside the original channel.
These numbers tell a business story the board understands. A team that reports within minutes and challenges out-of-pattern requests shrinks the criminal's window of opportunity and increases the chance of recovering funds, because fraudulent transfers reported quickly to the bank are far more likely to be blocked. If these metrics don't exist at your company, creating them is the first concrete action to take after reading this.
Frequently asked questions
What is BEC fraud in supplier payments?
BEC (Business Email Compromise) is fraud in which criminals use a hacked or spoofed email account to request payments or bank detail changes that appear legitimate. According to the FBI's 2024 Internet Crime Report, this type of scam accounted for about 2.77 billion dollars in reported losses in a single year. Because it rarely involves malware, it gets past technical filters and relies on process controls to be stopped.
Is annual security training enough to prevent payment fraud?
Annual training transfers knowledge, but it doesn't create mandatory verification points in the accounts payable workflow. Effective protection combines awareness with out-of-band verification, dual approval based on amount thresholds, and formal authority for the team to put suspicious payments on hold.
How can you safely confirm a supplier's bank account change?
Confirmation must be done using a phone number or contact already on file in the supplier's record, never using the details provided in the message requesting the change. Every bank detail change must also go through a second approver, regardless of the amount, because it redirects all subsequent payments.
If you want to find out where in your payment workflow the next fraud attempt would find an open door, schedule a no-obligation Strategic IT Assessment with Zamak.