Business Email Compromise (BEC) UK: How It Works and How to Stop It
Business Email Compromise (BEC) UK: How It Works and How to Stop It
BEC is one of the most financially damaging cyber crimes targeting UK businesses. Unlike ransomware, it often leaves no trace — by the time you realise money has gone, it's typically unrecoverable.
The Scale of the Problem
- BEC attacks cost UK businesses £190M+ in 2023 (Action Fraud)
- Average loss per UK BEC incident: £35,000–£50,000
- Many incidents go unreported due to reputational concerns
- BEC exploits trust, not technology — bypasses most technical controls
Main BEC Tactics
CEO Fraud / Executive Impersonation
Attacker poses as CEO via:
- Similar-looking domain (gridisys.co vs gridisys.com)
- Spoofed display name ('John Smith CEO' from a Gmail address)
- Genuinely compromised executive account
'Hi Sarah, I'm in a confidential meeting. Can you urgently transfer £25,000? Don't tell anyone — this is sensitive.'
Supplier Invoice Fraud
Attacker intercepts supplier communication and changes bank account details on an invoice. You pay what looks like a legitimate invoice — funds go to attacker.
Payroll Fraud
Attacker contacts HR/payroll to change employee bank details. Next payroll run pays the attacker.
Conveyancing Fraud
Attacker monitors solicitor–client communication during property purchase and redirects the purchase funds. Has cost UK homebuyers hundreds of thousands in individual cases.
Process Controls (Most Effective)
- Verify all bank account changes by phone — call on a known number, not one from the email
- Two-person authorisation for large transfers — above £5,000 (or your threshold)
- Never act on email alone for payment detail changes
- Verify 'urgent CEO requests' by phone — train employees to do this without embarrassment
- Train employees: urgency + secrecy + pressure = BEC red flag
Technical Controls
- Configure DMARC, DKIM, SPF — prevent domain spoofing
- Enable impersonation protection in Microsoft Defender / Google
- Block external email forwarding
- Monitor for suspicious inbox rules (used to hide BEC activity)
- Enable login alerts for unusual account access
How Gridisys Helps Prevent BEC
BEC often starts with a compromised account. Gridisys detects: unusual logins, new inbox forwarding rules, new inbox rules that delete replies, impossible travel — alerting your team within minutes of compromise.