Your outsourced IT department, serving NJ & NYC small businesses
NYC IT Insights

Business Email Compromise Is Robbing NYC Businesses. Here's How It Works.

No malware, no ransom note, just a polite email asking finance to update wire instructions. Here's the whole play, stage by stage.

On a Thursday afternoon, the office manager of a 20-person professional firm in Midtown wires $86,000 to settle a vendor invoice. The invoice is real. The email thread is real, it goes back four months and includes her own replies. The only thing that changed is the bank account number, updated "due to an audit at our bank" two emails earlier.

The vendor calls three weeks later asking when they'll be paid. The money is gone, moved out of the receiving account within 48 hours, usually beyond recovery.

That's a composite of incidents we've been called into after the fact, but every detail in it is typical. Business email compromise doesn't look like hacking. There's no ransom screen, no locked files, no drama. The FBI's IC3 has logged billions of dollars in BEC losses every year, consistently more than ransomware, precisely because it exploits trust and process, not software. Here's how the play actually runs.

Stage 1: The way in

It usually starts with one phished password. Modern phishing kits don't just steal credentials, adversary-in-the-middle pages proxy the real Microsoft login, capturing the session token after the user completes MFA. Push-notification fatigue attacks ("just approve it so it stops buzzing") work too. The attacker isn't targeting the CEO; they're targeting whoever pays the bills, accounts payable, the office manager, the bookkeeper.

One detail that surprises owners: the way in is often not your company at all. Compromising your vendor's, attorney's, or title company's mailbox works just as well, because the fraudulent email then arrives from a genuinely legitimate address.

Stage 2: The quiet weeks

A good BEC operator does nothing loud. They set up an inbox rule, usually moving any reply containing words like "wire," "payment," or "invoice" to an obscure folder so the real owner never sees the conversation happening in their own mailbox. Then they read. For two to six weeks they learn the payment rhythms: who approves what, which vendors invoice monthly, what the email sign-offs look like, when the controller goes on vacation.

This is the stage where good monitoring wins. A new inbox rule created at 3 a.m. from an IP in another country is exactly the kind of signal our cybersecurity monitoring alerts on, and the kind of thing nobody notices without it.

Stage 3: The swap

When a real payment is due, the attacker strikes from inside the real thread, that's thread hijacking, and it's why "check the email history" fails as a defense. If they've lost mailbox access, they fall back to a lookalike domain registered days earlier: acmehold1ngs.com for acmeholdings.com, or the classic rn standing in for m. At 11 p.m. in a 14px font, nobody catches it.

The message itself is mundane by design: "Please note our remittance details have changed ahead of this payment." Often there's a plausible reason and gentle urgency, end of quarter, an audit, a closing date. Urgency plus routine is the whole psychology.

Stage 4: The cash-out, and its uglier siblings

The wire swap is the headline version, but the same access funds smaller plays that fly under the radar:

  • Payroll redirects: "HR" receives a casual note from an employee asking to update direct deposit. The change costs one paycheck at a time and often runs for months.
  • Gift card asks: a spoofed partner or principal asks an assistant to grab "$500 in gift cards for client thank-yous, in a meeting, just text me the codes." Small, fast, unrecoverable.
  • Aging report theft: the attacker exports your receivables list, then invoices your customers with new bank details, in your name. Now it's your reputation paying the price.

Why NYC firms are prime targets

This isn't random. New York businesses concentrate everything the play needs: wires are routine here, real estate closings, escrow and trust transfers, fund distributions, vendor retainers, so a six-figure transfer raises no eyebrows. Deal information is often public or semi-public, which hands attackers their timing. And small professional firms move big-company money with small-company controls: one bookkeeper, no second approver, everything by email. We see the same exposure pattern in financial firms, law practices, and title and real estate offices across the city.

The control stack: what actually stops it

No single control stops BEC, because the attack spans both technology and process. The stack we deploy has both halves.

Technical controls

  • Phishing-resistant MFA and conditional access, number matching at minimum, hardware keys or passkeys for finance roles; sign-ins blocked from non-compliant devices. This kills most of Stage 1.
  • Email authentication enforced: SPF, DKIM, and DMARC at reject, most small businesses have DMARC missing or stuck in monitor-only, which lets others spoof your domain freely.
  • Mailbox rule and sign-in alerting, so the quiet weeks aren't quiet. This is bread-and-butter Microsoft 365 security configuration.
  • Lookalike-domain flagging: external-sender banners and first-time-sender warnings that make rn look like what it is.

Process controls, the half technology can't replace

  • Callback verification, no exceptions: any change to payment instructions, payroll, or banking details is confirmed by phone to a number you already had on file, never one from the email requesting the change. This single rule defeats the swap outright.
  • Dual approval for transfers above a threshold you set ($10,000 is common for firms this size).
  • A culture where verification isn't rude. The targets aren't careless people, they're polite people. Training has to give them permission to slow down, which is the entire point of ongoing phishing training.
Defense in depth

The Anti-BEC Control Stack

  • Phishing-resistant MFA Number matching for everyone; hardware keys or passkeys for anyone who can move money.
  • SPF + DKIM + DMARC at reject Your domain stops being spoofable; lookalikes get easier to spot.
  • Mailbox rule & sign-in alerts The "quiet weeks" trigger alarms instead of going unnoticed.
  • Callback verification Banking changes confirmed by phone to a known number, never a number from the email.
  • Dual approval over a set threshold One compromised mailbox can no longer move five figures alone.
  • Trained, unhurried people Staff with standing permission to slow down and verify, politeness is the vulnerability.

If you only do two things this month

Make them these: get DMARC to enforcement, and write the callback rule into your payment process today, it costs nothing and beats the most expensive version of the attack. If a wire has already gone out, call your bank's fraud department and file with IC3 immediately; recalls occasionally succeed inside the first 24-72 hours, and almost never after.

We build and monitor this full stack for firms across the five boroughs, working remote-first at New Jersey pricing, details on our NYC IT services page, with the broader program under managed IT services. Want us to check your mailbox rules, DMARC status, and sign-in logs for signs someone's already reading? Book a free IT assessment, and find more security guides on the blog.

Get started

Could a fake invoice email beat your payment process today?

Book a free IT assessment. We'll check your MFA, DMARC, mailbox rules, and finance workflow against the exact attack described above, and show you where the gaps are.

Book Your Free IT Assessment

Tell us a little about your business and we'll be in touch within one business day.

No spam. No sales pressure. Just straight answers about your IT.

Call Now Get My Risk Score