← Blog

The Email Fraud That Skips Your Firewall

September 10, 2026 · 6 min read · Jim Johnson

A finance person gets an email from a vendor they've worked with for two years. It references a real invoice, uses the vendor's real name and logo, and asks for one thing: please send this month's payment to a new bank account, details attached. Nothing about the email looks wrong, because almost nothing about it is fake. The invoice is real. The relationship is real. The only lie is the last line.

There's no attachment carrying malware. No link to a fake login page. Nothing for antivirus to flag, nothing for a spam filter to catch. The entire attack is a sentence, sent at the right moment, to the right person.

The most expensive email attacks have no attachment at all.

What the numbers actually say

The FBI's Internet Crime Complaint Center tracks this every year, and the scale is worth sitting with. In its 2025 Annual Report, IC3 recorded 1,008,597 complaints totaling $20.877 billion in losses across every category of internet crime it tracks. Business email compromise — the category this scenario falls into — accounted for 24,768 of those complaints and $3,046,598,558 in losses on its own.

Look at the ratio, not just the total. BEC complaints were 2.5% of everything IC3 received. The losses from those complaints were 14.6% of the total dollar amount lost. Do the arithmetic and the average BEC complaint runs to roughly $123,000 — against an average of about $20,700 across all complaint types combined. Whatever a BEC email costs to send, it works far better than almost anything else criminals are trying.

This isn't a new problem finding new legs. The FBI's own September 2024 advisory on the subject, titled plainly Business Email Compromise: The $55 Billion Scam, put the cumulative exposed loss at $55,499,915,582 across just over a decade, October 2013 through December 2023. It has a title like that because the number has been climbing for that long, and nothing about 2025's figures suggests it stopped.

Why it skips your firewall

Most security spending is built to catch a payload — a malicious attachment, a link to a credential-harvesting page, code that runs when someone clicks the wrong thing. Business email compromise usually doesn't carry one. It's social engineering wearing a legitimate business conversation, and there's a version of it that's even harder to catch than a convincing fake.

In the more advanced version, the attacker isn't impersonating your vendor from the outside — they've actually gotten into your vendor's mailbox, or yours, through a caught credential or a phished login. From inside a real inbox, they read real invoice threads, learn the real cadence of the relationship, and then reply on an actual email chain at exactly the moment a payment is due. The email doesn't just look real. It is real, sent from a real compromised account, with one detail changed.

If there's nothing to click, there's nothing for your security software to catch.

The patterns that actually show up

Vendor payment redirect. An existing vendor relationship, a real or referenced invoice, and a "here's our new bank" email timed to land before the payment goes out.

Executive impersonation. An urgent request that appears to come from an owner or executive — a wire, a gift card purchase, a confidential favor — deliberately routed around the normal approval process and deliberately timed for when that person is traveling or unreachable to confirm.

Payroll diversion. A message to HR or payroll, appearing to come from an employee, asking to update direct-deposit details before the next pay run.

The compromised-mailbox version. Any of the above, except it starts from inside a real account the attacker already controls, which is why it can survive scrutiny that would catch an obvious fake.

The one control that actually stops it

The FBI's own advisory is specific about the fix, and it isn't a piece of software: "Use secondary channels and/or two-factor authentication to verify requests for changes in account information."

In plain terms: any request to change where money goes — a vendor's bank account, a wire destination, payroll direct deposit — gets a phone call before it gets a payment. Not a reply to the email. Not a call to a number the email itself provided. A call to a number you already had on file, from before this message ever arrived.

Verify to a number you already had. Not one the email just gave you.

This is the Email Security piece of the six-area framework we use in every assessment: the technical controls are a provider's job, but the finance-process rule — payment detail changes always require phone verification — is the one step that stops this specific fraud regardless of how good the email looks, and it costs nothing to put in place.

What to put in writing

  • A written rule that any payment or bank-detail change requires phone verification to a known number, with no exceptions for urgency, seniority, or how the request arrived.
  • A named backup approver for payment changes when the usual person is traveling or out — the same single-point-of-failure problem that shows up everywhere else in IT shows up here too.
  • Multi-factor authentication on every account that can send or read email, since the compromised-mailbox version of this attack starts with one caught password.
  • A check for mailbox forwarding rules quietly copying finance correspondence to an outside address — a common way attackers keep watching after the initial break-in, and something that sits invisible in settings almost nobody audits.
  • A named person responsible for email security, the same way backup and recovery needs one. If nobody owns it, nobody's checking it.

Why an IT company would tell you to do this yourself

Because the fix that actually works here is a phone call, not a product. The written verification rule above costs nothing, needs no vendor, and you can put it in place this week with your existing team. Several of the other items — multi-factor authentication, a mailbox-forwarding audit — are things your current provider, internal team, or Microsoft admin can check directly.

Everything above is yours to keep whether or not we ever speak again.

We're a veteran-owned team in the Denver metro, working with organizations in the 15-to-70 person range — nonprofits, professional services, and manufacturers. Senior engineers only, month-to-month, no multi-year lock-in. If you want the fuller picture of how email security fits into a managed IT relationship, we cover the structure in when co-managed IT makes sense.

So: if a vendor emailed your finance team new bank details tomorrow, is there a written rule that stops the payment until someone makes a call — or does it depend on someone happening to notice?

Book a free IT risk review or call us at 720-794-0400.


Sources, checked 10 September 2026

  • FBI Internet Crime Complaint Center (IC3), 2025 Internet Crime Report — 1,008,597 total complaints, $20.877 billion total losses; 24,768 BEC complaints, $3,046,598,558 in BEC losses. Per-complaint averages calculated from these figures.
  • FBI Internet Crime Complaint Center (IC3), Public Service Announcement I-091124-PSA, Business Email Compromise: The $55 Billion Scam, published 11 September 2024 — $55,499,915,582 cumulative exposed loss, October 2013 through December 2023; secondary-channel verification recommendation.

Sound like your situation?

Start with a free IT risk review or a platform discovery & alignment call — 30 minutes, no strings.

Assess your technology maturity Book my free IT risk review →

Sound like your situation?

Start with a free IT risk review or a platform discovery & alignment call — 30 minutes, no strings.