What is business email compromise?
Business Email Compromise, or BEC, exploits trust in business communication. An attacker may imitate an address or gain access to a real account. Messages can therefore include familiar signatures and transaction details. The FBI describes changed payment instructions as one example.
This guide focuses on verifying payment requests, not just identifying suspicious links. A message can be dangerous without an attachment, malware or poor spelling.
Verify the request before paying
Call your known contact using a previously verified number. Do not use a new number supplied in the suspicious message. Confirm whether the change is genuine and check the beneficiary details through your company's established process.
- Hold the payment until the change is confirmed.
- Inspect the full sender and reply-to addresses; the display name is not enough.
- Watch for pressure to pay immediately or bypass the usual approver.
- Involve a second responsible person before changing supplier records.
For an internal exercise, imagine a supplier claiming their old account is temporarily blocked. The employee contacts the supplier through an existing number rather than continuing the same email conversation. This is an illustrative scenario, not a real NBG TEAM case study.
When IT should investigate the mailbox
Unexpected sent messages, missing conversations or unexplained forwarding warrant an administrator's attention. Microsoft's compromised-account guidance covers containing unauthorised access, active sessions, authentication methods and forwarding rules.
Changing a password alone is not a complete incident review. The administrator determines how to restrict access and preserve evidence. Employees should report what happened rather than deleting suspicious messages or rules themselves.
If the payment has already been made
Contact your bank immediately through an established official channel and report suspected fraud. Ask what action is available; recovery is not guaranteed. Notify the responsible person in your company and the real supplier through an independent channel.
Preserve the message, attachments, event times and transaction details for the bank, IT investigation and reporting to the relevant authorities. Do not publish business correspondence. Technical support can help secure accounts but cannot promise recovery of funds.
Create a repeatable payment-change process
Every supplier bank-detail change should receive independent confirmation and a recorded approval. Arrange cover for absent colleagues so urgency does not mean skipping checks. New employees should know who receives suspicious-message reports.
Complement that process with MFA for business accounts. Domain authentication also helps, but does not prove that a request from a compromised legitimate mailbox is authorised.
NBG TEAM support for business email security
NBG TEAM can review business accounts, sign-in methods and forwarding rules, and help organise employee access. Explore our business IT support in Belgrade.
If you suspect misuse of business correspondence, contact NBG TEAM. Tell us when you noticed the issue and which system you use. Do not include passwords or sensitive documents in the initial enquiry; we will agree how to investigate.
Related guide: First steps after a phishing link.
