5 Real Business Email Compromise Examples (and What They Cost)

Business email compromise is a scam in which criminals impersonate an executive, employee or vendor by email. The goal is to trick your staff into sending money or sensitive data. The best-known business email compromise examples include Facebook and Google, which lost over $120 million to fake invoices. Ubiquiti lost $46.7 million, and Toyota Boshoku lost about $37 million.

These are not rare events. The FBI’s Internet Crime Complaint Center (IC3) logged $3,046,598,558 in reported BEC losses in 2025, from 24,768 complaints. The famous names also skew the picture. Verizon’s research puts the median BEC theft at around $50,000. That won’t make headlines. For many SMBs and nonprofits, though, it’s a large vendor payment or a month of operating costs. Big enough to hurt, and small enough to slip through a busy finance inbox.

BEC Is Impersonation Fraud, and It Ranks Second in Reported Losses

Business email compromise ranked second by dollar losses in the FBI’s 2025 data, behind only investment fraud at about $8.6 billion. The attacker doesn’t need to break into your systems. They borrow someone’s identity instead. It might be your CEO, a supplier, a colleague or a lawyer. Then they ask for money or data in a way that feels routine.

Reported BEC losses rose from about $2.77 billion and 21,442 complaints in 2024 to $3,046,598,558 and 24,768 complaints in 2025

These totals count only incidents victims chose to report to the FBI, so the real cost to businesses is larger.

The trend is moving the wrong way. IC3 recorded about $2.77 billion in BEC losses from 21,442 complaints in 2024. Both the dollar total and the complaint count rose in 2025.

Those figures only count losses that victims reported. Many never report, so the true total is higher. The data is also American. But the cases below hit offices in Hong Kong, Europe and the US. The playbook works the same way in Calgary or Halifax.

BEC Often Has No Link, Which Is Why Spam Filters Miss It

Most BEC emails carry no malicious link or attachment, so the tools built to catch phishing often wave them through. Phishing is a numbers game. BEC is a researched, targeted request that looks like ordinary business. The table below shows how the two differ.

FactorPhishingBusiness email compromise
Who gets itThousands of people at onceA few named people
Research beforehandLittle or noneOrg charts, vendors, payment habits
PayloadMalicious link or attachmentOften none, just a request
Who it pretends to beA well-known brandA colleague, boss or supplier
GoalSteal logins or install malwareMove money or sensitive data
What catches itFilters and link scanningProcess and verification

That last row matters most. If your staff training stops at real phishing examples with dodgy links, your team learns to hunt for the wrong thing. A BEC email can be perfectly written, sent from a real account and contain nothing a filter would flag.

How a BEC Attack Unfolds in Five Steps

A BEC attack usually follows the same five stages, and each one leaves a chance to catch it. Here is the sequence, with the tactics attackers use at each step.

Five BEC attack stages: reconnaissance, spoofing or compromise, social engineering, execution and exfiltration

Each stage is a checkpoint: the earlier your team spots the pattern, the less verification has to catch at the payment step.

  1. Reconnaissance. Attackers study your website, staff profiles, press releases and public filings. They want to know who approves payments, who your suppliers are and when your leaders travel.
  2. Spoofing or compromise. They register a lookalike domain, such as “yourcompany.co” in place of “yourcompany.com.” Or they steal a password and take over a real mailbox.
  3. Social engineering. Inside a compromised mailbox, they read quietly and set hidden inbox rules that file away or forward replies. Then they hijack a real email thread, so their request sits under genuine history.
  4. Execution. The request lands. Pay this invoice to our new bank account. Wire funds for a confidential deal. Update my direct deposit.
  5. Exfiltration. The money moves fast, often split across several accounts and sent overseas, before anyone notices.

Lookalike domains, hijacked threads, hidden inbox rules, changed bank details. Not one of them needs malware.

Seven Types of BEC Scams, Each Aimed at a Different Role

BEC scams come in several forms, and each one targets the person in your organization who can approve what the attacker wants. Knowing which role gets which scam tells you where to focus training. The table maps each type to its usual target.

TypeWho it impersonatesWho it targetsWhat it asks for
CEO fraudA senior leaderFinance staffAn urgent wire transfer
Vendor or invoice fraudA real supplierAccounts payablePayment to a new account
Account compromiseA real employee’s mailboxColleagues and customersPayments to the attacker
Attorney impersonationA lawyer or legal advisorExecutivesA fast, confidential transfer
Data theftAn executive or HR leadHR and payrollEmployee records
Payroll diversionAn employeePayroll staffNew direct deposit details
Gift card scamsA managerAny staff memberGift card codes

Every type works on the same levers of authority, urgency and helpfulness. That’s why BEC belongs under social engineering attacks and how to prevent them, not just email security. The five cases below cover vendor fraud, employee impersonation and a deepfake twist on the classic urgent request.

1. Facebook and Google Lost Over $120 Million to Fake Invoices

Two of the biggest tech companies in the world paid invoices from a supplier that wasn’t who it claimed to be. Lithuanian Evaldas Rimasauskas posed as Quanta Computer, a Taiwan-based hardware maker that was a real vendor to both companies. The victims were Facebook and Google.

The tactic. Vendor impersonation, backed by convincing paperwork. Rimasauskas supported his payment requests with forged invoices, contracts and corporate stamps. To accounts payable, it looked like a normal supplier bill.

The cost. In December 2019, a US court sentenced him to five years in prison. He was also ordered to forfeit $49,738,559.41, his personal take from the scheme.

The control that stops it. A phone call to Quanta, using a number already on file, would have exposed the fake invoices. Better paperwork never proves a payment is real. Only the real vendor can confirm that.

2. Ubiquiti Lost $46.7 Million and Got Back Only $16.7 Million

Ubiquiti’s case shows how little money comes back once a wire clears. The company reported that employee impersonation and fraudulent requests aimed at its finance department moved $46.7 million out of a Hong Kong subsidiary to overseas accounts.

Ubiquiti recovered $16.7 million by March 31, 2017, of the $46.7 million it lost to a BEC scam

Recovery took nearly two years even with legal and banking support, which is why stopping the wire beats chasing it.

The tactic. Impersonation aimed squarely at the people who move money. Finance staff approve large transfers as part of their job. That’s exactly why attackers pick them.

The cost. Ubiquiti discovered the fraud on June 5, 2015 and disclosed it that August. By the quarter ended March 31, 2017, it had recovered $16.7 million. About $30 million was still gone.

The control that stops it. Verify any unusual payment request through a separate channel you already trust. A plan for recovering from the financial damage of a cyber attack still matters. But Ubiquiti had lawyers, banks and time on its side, and most of the money never came back.

3. Toyota Boshoku Lost About $37 Million in One Transfer

Toyota Boshoku’s loss shows how much damage a single payment can do. On September 6, 2019, the company said a European subsidiary had lost up to about 4 billion yen (roughly $37 million) to fraudulent payment directions. The transfer went out on August 14, 2019.

The tactic. False instructions about where to send money. Payment redirection is the heart of vendor and invoice fraud. The amount is right and the reason is right. Only the destination is wrong.

The control that stops it. Treat every change to payment details as unverified until you confirm it by phone. Use contact details you held before the request arrived. Routine-looking requests deserve the same check, because routine is what attackers copy.

4. Orion S.A. Lost $55.7 Million Through One Targeted Employee

Orion’s loss started with one person. On August 10, 2024, Orion S.A. found that an employee had been targeted by a criminal scheme that led to multiple fraudulent wire transfers. The company first expected a one-time charge of about $60 million.

The cost. Final figures came in at $55.7 million in fraudulent transfers net of recoveries, plus $3.6 million in investigation fees. Even the cleanup carried a seven-figure bill.

The tactic. Press coverage labeled it a business email compromise scam, though Orion’s own filings don’t use that term. Either way, the shape is familiar. One targeted employee, and several wires went out before anyone caught it.

The control that stops it. Dual approval. If a second person must sign off on every large wire, one deceived employee can’t move the money alone.

5. Arup Paid About $25 Million After a Deepfake Video Call

Seeing someone on video no longer confirms who they are. A Hong Kong employee at Arup paid about $25 million (HK$200 million) to fraudsters after a video call that used fake voices and images. The scheme began with a suspicious email asking for a “secret transaction.”

Deepfake tools now let attackers fake a face and voice cheaply, so hanging up and calling back is the only check that holds.

The tactic. Email fraud, reinforced with deepfakes. The email set up the request. The video call made it feel confirmed. The employee then made 15 transfers to five Hong Kong bank accounts.

The control that stops it. Out-of-band verification, done properly. A second channel only helps if the attacker can’t control it. A video call the requester set up is part of the scam. End it, and call the person back on a number from your own records.

What These Business Email Compromise Examples Have in Common

All five losses came down to trusting a payment instruction because of how it arrived, not because anyone confirmed it. The emails, invoices and video calls all came through channels the attacker controlled. The table lines up each case with the gap and the fix.

CaseHow the request arrivedGap exploitedControl that stops it
Facebook and GoogleForged vendor invoicesPaperwork trustedCallback to known vendor
UbiquitiImpersonation of employeesRequests trusted on sightSeparate-channel check
Toyota BoshokuFraudulent payment directionsDestination not verifiedVerify bank-detail changes
Orion S.A.Scheme aimed at one employeeSingle approverDual approval
ArupEmail, then deepfake callAttacker-run “verification”Callback you initiate

Three gaps repeat. A payment request or change was accepted through the attacker’s own channel. One person could act alone. And urgency or secrecy pushed process aside. If you remember one line, make it this one. A callback only counts if you placed it, to a number you already had.

These five made the news because the sums were huge. Most victims never make headlines, and their losses look far more like that $50,000 median. The fixes are the same at every size, and none of them costs much.

Red Flags That Should Stop Any Payment

Several of these cases leaned on the same warning signs, and your finance team can learn them in an afternoon. If a request shows any of these, pause and verify before money moves.

  • Urgency. A same-day deadline, a deal closing in an hour, or “can you handle this before end of day?”
  • Secrecy. “Keep this between us,” like the “secret transaction” email that opened the Arup scheme.
  • New or changed bank details, especially by email and especially right before a payment is due.
  • An executive request that skips your normal process or asks you to bypass approval “just this once.”
  • A sender address that’s almost right, with a swapped letter, an extra word or a different domain ending.
  • Replies that route to a different address than the one shown in the “From” line.
  • Pressure to move to a call or video meeting that the requester arranges.
  • Unusual asks from familiar names, such as gift cards, employee records or payroll changes.

A Payment Verification Policy You Can Adopt This Week

The controls that would have stopped these losses are policies, not products, and you can put them in place within days. They form the core of business email compromise prevention, and they help with compliance conversations with your auditors, board and insurer too.

Six payment controls: callback rule, dual approval, training brief, MFA, email authentication records and permission to pause

Written policies also give auditors, boards and cyber insurers concrete evidence that payment fraud risk is being managed.

  1. Callback rule. Every new or changed bank detail gets a phone call to a number already on file. Never use a number from the email itself.
  2. Dual approval. Set a dollar threshold that fits your business. Any wire above it needs two people. Any bank-detail change needs two people at any amount.
  3. One-page training brief. Put these five cases and the red flags on a single page. Walk your finance, HR and admin staff through it, and add it to your security awareness training topics for the year.
  4. Multi-factor authentication on every mailbox. Account compromise usually starts with a stolen password. A second login factor makes that password far less useful.
  5. Email authentication records. SPF, DKIM and DMARC tell receiving servers which senders may use your domain. They make spoofing your exact address harder, though they don’t stop lookalike domains.
  6. Permission to pause. Tell staff in writing that no one gets in trouble for delaying a payment to verify it.

Give whoever handles payment changes a script they can read word for word. “Hi, this is [name] from [your organization]. We received a request to change your payment details. I’m calling the number we have on file to confirm. Can you tell me whether you sent it, and who on your side requested it?” If the answer is no, you’ve just saved the payment.

Quick Answers About Business Email Compromise

What Are Some Examples of Business Email Compromise?

Well-documented cases include Facebook and Google (over $120 million in fake invoices), Ubiquiti ($46.7 million) and Toyota Boshoku (up to about 4 billion yen). Orion S.A. ($55.7 million net of recoveries) and Arup (about $25 million after a deepfake video call) round out the list.

What Does Business Email Compromise Mean?

Someone poses as a person your staff trust, usually by email, to get money or sensitive data sent their way. The disguise is typically an executive, employee or vendor.

How Common Is Business Email Compromise?

Very common. The FBI’s IC3 received 24,768 BEC complaints in 2025, and BEC ranked second among cybercrimes by reported losses. Those are only the reported cases.

What Tactics Do BEC Attackers Use?

Lookalike domains, hijacked email threads, hidden inbox rules and requests to change bank details. Some attackers now add deepfake audio or video to make the request seem confirmed.

Start With the Person Who Approves Your Next Payment Change

You don’t need a big budget to block what cost these companies tens of millions. Pick the person who approves your next wire or bank-detail change. Hand them the callback script today, and agree that no payment change goes through without it.

Then see where the rest of your payment process stands. RiskAware has helped hundreds of SMBs and nonprofits reduce cyber risks. Get your free cybersecurity score, or book a discovery call with our team.

Share the Post: