Insights · July 2026

Anatomy of a BEC: How the Quiet Mailbox Steals Your Invoices

Business email compromise is patient crime. The intrusion happens weeks before any money moves, and the fraud works precisely because nothing looks wrong until the day it is far too late.

Act one: the way in

A phished password, a reused credential from someone else's breach, a session token lifted by malware. The attacker signs in from infrastructure chosen to look plausible and does nothing dramatic at all. In the audit logs, this is a single anomalous sign-in among thousands, unmistakable in hindsight and invisible without it.

Act two: the watching

Then comes the quiet fortnight. The attacker reads. Who invoices whom, for how much, in what format, with what tone. A forwarding or inbox rule is created so correspondence flows out continuously, often filed to a folder no one opens. The rule is the tell: in nearly every BEC we examine, a mailbox rule marks the occupation like a flag planted in the sand.

Act three: the strike

A real invoice is intercepted or a familiar one is counterfeited, the bank details changed, the language borrowed from genuine threads. Finance pays, because everything about the request is authentic except the account number. The discovery usually comes from the supplier chasing payment that never arrived.

What the evidence settles

The logs answer the questions that follow: when the intrusion began, what was read, which other mailboxes were touched, whether data beyond the fraud was taken, and what insurers and regulators need scoped. Speed matters, because parts of that trail expire on schedule. And the single cheapest defence remains unglamorous: mail rules audited regularly, and multi-factor authentication that is actually enforced.

Facing something like this?

The first discussion is confidential and free, and usually changes what you decide to do next. Call +852 5808 1071 or use the case review form.