Finance & Risk

The Fraud Tax: How BEC Attacks Are Draining Cash and What Controls Actually Stop Them

Seventy-nine percent of businesses experienced payment fraud in 2024, with Business Email Compromise accounting for 63% of attacks. Most $1M-$50M+ businesses lack dual authorization, verbal verification, and segregation of duties, leaving them one spoofed email away from six-figure losses.

Published: 20260122 ‖ Read Time: Read Time: 12 minutes

Field Fit

Confirm the fit before you read further

This briefing is written for a specific operator. Match yourself against the two columns below before you invest the next ten minutes.

This Is Written For You If

  • You run a business doing $1M to $50M in annual revenue.
  • You make the final call on strategy and how capital gets spent.
  • Growth has stalled, or revenue moves without a clear reason.
  • You want operating systems, not one more tactic to try.

Save Your Time If

  • You are pre-revenue or under $1M. Build the base first.
  • You already run a full strategy function in house.
  • Someone else owns the numbers and the decisions.
  • You are not ready to change how the business runs.

Why This Briefing Matters Now

This briefing exists because 79% of businesses were hit by payment fraud in 2024, and most $1M-$50M+ operators lack the financial controls needed to stop BEC attacks before cash leaves their accounts.

The Cash Drain

Your Profit

The average BEC wire transfer is $24,586, enough to wipe out an entire month of profit for a $5M business operating on 8-10% margin. One in five organizations working with MSPs lost actual money to BEC in the past year. Without layered controls, you are exposed to fraud attempts that drain cash faster than you can detect them, and recovery is nearly impossible once money clears.

The Recovery Burden

Your Capacity

When fraud succeeds, you spend weeks filing reports, working with banks, explaining to vendors, and rebuilding trust with your team. Owners report 60-80 hours of recovery time per incident, all while the actual work of running the business stalls. The capacity cost is not just the fraud itself but the distraction and demoralization that follows when your systems fail to protect you.

The Trust Erosion

Your Team

BEC attacks exploit your team’s trust in email, urgency, and authority. When fraud happens, finance teams feel violated and second-guess every payment request. The emotional toll is real: frustration, fear, and the knowledge that normal business processes left you completely exposed. Controls rebuild confidence by making fraud attempts visible before they succeed.


Operational Context

One question, one number, one action

One Question

Can one person in your organization initiate, approve, and execute a wire transfer or change vendor banking details without independent verification?

One Number

$55 billion in total BEC losses over the past decade, making it one of the most financially damaging cybercrimes targeting businesses.

One Action

Set a dual authorization threshold for payments over $5,000-$10,000 and implement verbal verification for any banking change or new vendor, with zero exceptions.

Situation Snapshot

Where a typical operation sits on this issue

Stable Operations

Payment controls are clear, enforced, and visible. Dual authorization is automatic for high-value payments, verbal verification happens without exception for banking changes, and real-time alerts surface anomalies before money clears. Finance teams trust the process because it works, fraud attempts are caught early, and owners sleep knowing their cash is protected by systems, not hope.

Under Friction

Anyone in finance can initiate and approve payments, verification relies on email alone, and urgent requests bypass normal process. Banking changes happen without confirmation, reconciliations lag weeks behind, and nobody notices fraud until vendors call asking where their money went. The team works under constant pressure with no checkpoints to catch mistakes or attacks.

At Risk

A single compromised email or spoofed request can move five or six figures out of your account before anyone realizes. No segregation of duties means one person controls the entire payment cycle, no real-time monitoring means fraud clears before it surfaces, and no verification protocol means attackers exploit urgency to bypass weak controls. Recovery is nearly impossible and the reputational damage compounds.


The Brief

Opening Hook

Seventy-nine percent of businesses experienced payment fraud in 2024, and Business Email Compromise now accounts for 63% of all fraud attempts targeting companies. For $1M-$50M+ businesses, this is not a theoretical risk. It is a daily exposure. The average BEC wire transfer request in early 2025 was $24,586, and one in five organizations working with managed service providers lost actual money to BEC attacks in the past year. Your finance team processes wire transfers, ACH payments, and vendor invoices every week. Without layered controls, you are one compromised email away from a six-figure loss.

The NFIB Small Business Optimism Index stands at 99.5, above its 52-year average, yet 12% of owners still cite inflation as their top challenge, 17% struggle with recruiting and retention, and capital investment remains weak at just 19% planning outlays. In this environment, the average $24,586 BEC loss can wipe out an entire month of profit for a $5M business operating on 8-10% margins. Fraud does not just drain cash. It diverts capacity from revenue growth, burns leadership time on recovery instead of execution, and increases when finance team turnover strips institutional knowledge of vendors and payment patterns.

BEC attacks have become more sophisticated and harder to detect. Forty percent of BEC emails are now AI-generated, matching the tone and formatting of legitimate business correspondence. Attackers infiltrate real email threads, impersonate executives and vendors, and request payment changes or urgent wire transfers that appear completely normal until the money is gone. The FBI reports BEC has become a $55 billion scam over the past decade, and 2024 saw a 66% increase in BEC incidents compared to 2023, jumping from 44% to 73% of all reported cyber incidents. The exposure is structural. Most $1M-$50M+ businesses lack segregation of duties in payment approvals, run verification processes that can be bypassed under time pressure, and have no real-time monitoring to flag unusual payment patterns. This briefing shows you how to install financial controls that make fraud attempts visible before money moves.

What the Research Really Says

The 2025 AFP Payments Fraud and Control Survey, published January 2026, found that 79% of businesses experienced payment fraud in 2024. Among those hit, 63% identified Business Email Compromise as the primary attack method. For the first time, BEC attacks targeting ACH credits surpassed wire transfers, signaling that attackers are adapting to where businesses have weaker controls. The Federal Reserve reports that BEC accounted for 73% of all cyber incidents in 2024, a sharp increase from 44% in 2023. This is not a marginal shift. It is a structural acceleration in fraud volume and effectiveness.

The average financial impact is significant. At the start of 2025, the average BEC wire transfer request was $24,586. For a $5M business operating on 8-10% net margin, a single successful BEC attack can wipe out an entire month of profit. The FBI reports that BEC has generated $55 billion in losses over the past 10 years, making it one of the most financially damaging cybercrimes targeting businesses. Email security research from 2025 found that 12.9% of organizations lost money through BEC attacks in the previous 12 months, and among businesses working with managed service providers, that number jumped to 21.6%, meaning one in five MSP clients took an actual financial loss.

AI is accelerating BEC sophistication. Forty percent of BEC emails identified in 2024 were AI-generated, allowing attackers to craft messages that are nearly indistinguishable from genuine business correspondence in language, tone, and formatting. Attackers now hijack real email conversations, inserting themselves into ongoing vendor or customer threads to request payment changes. Seventy percent more conversation hijacking attacks were detected in 2024 compared to prior years. Sixty-seven percent of BEC attacks originated from free webmail services like Gmail, where attackers spoof executive or vendor identities with slightly altered addresses that busy employees miss under deadline pressure.

Internal control gaps leave businesses exposed. Research on SME fraud prevention found that most small and midsize businesses lack adequate segregation of duties, meaning the same person who initiates a payment can also approve and execute it. Authorization processes are weak or inconsistent, allowing urgent requests to bypass verification. Reconciliations happen too infrequently to catch fraud before it compounds, and access controls do not limit who can change vendor banking details or initiate wire transfers. When attackers exploit these gaps, the fraud is not discovered until days or weeks later, after the money has been moved through multiple accounts and recovery becomes nearly impossible.

Phishing remains the entry point. Sixty-four percent of security professionals expect phishing threat levels to increase in 2025, and 94% of organizations experienced phishing attacks in 2024. Credentials compromised through phishing give attackers access to email accounts, financial systems, and internal communications, enabling them to study payment patterns, identify high-value targets, and time their BEC requests for maximum success. The 2025 State of Email Security report found that 79% of Microsoft 365 users faced cyber incidents in the past year, and 45% experienced employee data breaches, often used to further refine social engineering attacks.

What Owners on the Ground Are Saying

Owners describe fraud attempts that feel disturbingly real. A CEO of a $12M distribution company said, “I got an email from our CFO asking me to approve a wire transfer for a vendor payment while she was traveling. The tone, the signature, everything looked right. I almost approved it before I called her directly and found out her email had been spoofed.” A founder running a $7M professional services firm said, “We received an invoice from a longtime vendor with updated banking information. It looked identical to their usual invoices. We paid it. Two weeks later, the real vendor called asking where their payment was. We lost $38,000.”

The fraud methods are evolving faster than internal controls. Owners say things like, “Our process is to verify wire transfers over $10K with a phone call, but the attacker emailed late Friday afternoon when everyone was rushing to close the week,” and “The email came from an address one letter off from our actual vendor. Nobody caught it until the money was gone.” A manufacturing owner at $18M said, “They hacked into a real email thread we had with a supplier about a pending invoice. The request to change the bank account came from within that thread, so it looked completely legitimate.”

The emotional and operational cost is severe. Owners report feelings of violation, distrust, and frustration with their own systems. A services CEO at $9M said, “I realized we had no real controls. Anyone in finance could initiate and approve a payment. We were relying on trust and busy people not making mistakes.” Another owner said, “After the fraud, I spent two weeks trying to recover the money, filing reports, dealing with the bank, and explaining to the team how it happened. It was not just the cash. It was the time, the morale hit, and the realization that we were completely exposed.”

The shared experience is this: fraud attempts are constant, sophisticated, and designed to exploit exactly the process gaps that exist in most $1M-$50M+ businesses. Owners who have been hit describe the fraud as a systems failure, not a people failure. The controls that prevent fraud either do not exist, are too slow to use under pressure, or are easy to bypass when someone believes the request is urgent and legitimate.

How This Plays Out in the Field

A $15M manufacturing company processed 50-80 vendor payments monthly. Wire transfers and ACH payments were initiated by the AP manager and approved by the CFO via email. The process worked until a BEC attack targeted the CFO through a phishing link. The attacker monitored email for three days, identified a pending $47,000 wire to a supplier, and sent a spoofed email requesting the wire be sent immediately to an updated account due to a merger. The email used the CFO’s real signature and referenced the actual invoice number. Under deadline pressure to close the month, the AP manager initiated the wire without calling to verify.

The fraud surfaced four days later when the supplier called about late payment. The money had moved through three intermediary accounts and was unrecoverable. The company lost $47,000 in cash plus 60 hours of owner time dealing with the FBI, their bank, and a damaged supplier relationship. After the loss, they rebuilt controls with three layers. First, mandatory dual authorization for payments over $5,000. Second, verbal verification via phone to a known number for any payment over $10,000 or banking change, with zero exceptions. Third, real-time alerts through their banking platform for new accounts or amounts significantly above historical patterns. Within 90 days, the controls blocked three BEC attempts. In one case, an attacker spoofed the CEO requesting $22,000 for a conference sponsorship. The finance manager followed dual authorization, called the CEO directly, and confirmed fraud. The CFO said, “The controls add five minutes per high-value payment but have already saved six figures in blocked fraud.”

A $9M professional services firm had no segregation of duties. One person handled AP, initiated payments, reconciled accounts, and had full access to change vendor details. When they received a spoofed email from the landlord requesting ACH redirection for a property management change, they updated the vendor record and processed the next rent payment of $18,500 to the fraudulent account. The fraud was caught during quarterly review when the landlord asked about missing rent. The firm lost $37,000 total and faced eviction proceedings until they proved fraud and settled actual owed rent. The owner said, “I trusted our finance person completely. They did nothing wrong. The system was the problem.”

The firm restructured with segregation: one person enters vendor details, a second approves changes, a third initiates payments. Any banking change requires written confirmation sent to the vendor’s address on file, not the email requesting the change. Monthly reconciliations compare payments to approved vendor lists. Six months later, they caught a fraudulent IT invoice because the approval process surfaced the discrepancy before money moved. The owner said, “Fraud does not succeed when your systems make it visible.”

The Operator’s Battle Plan

Protocol 1: Install Mandatory Dual Authorization for High-Value Payments

What: Define a payment threshold, typically $5,000-$10,000, above which two independent people must approve. Person A initiates the payment and provides documentation. Person B reviews, verifies the vendor and invoice independently, and approves. Neither person can perform both roles for the same transaction. Build this into your accounting software or banking platform as a hard control, not a policy that can be skipped. If you lack staff for true separation, use your bank’s dual control features or external bookkeeper as the second approver.

Measure: Track the percentage of payments over threshold that completed dual authorization without exception. Anything below 100% means your control can be bypassed.

Why: BEC attacks succeed when one person can initiate and complete a payment under time pressure. Dual authorization forces a second set of eyes and creates a decision point where fraud becomes visible before money moves.

Protocol 2: Require Verbal Verification for Payment Changes and New Accounts

What: Establish a rule: any change to vendor banking details, any payment to a new vendor, or any request that deviates from normal patterns requires verbal verification via phone to a known number. Do not use phone numbers in the email requesting the change. Call the vendor contact on file in your accounting system or their official website. Confirm the change verbally before updating records or initiating payment. Train your team that email alone is never sufficient verification for banking changes, regardless of urgency.

Measure: Track payment change requests received and the number verified verbally. If any update happens without a call, your control failed.

Why: BEC attackers rely on email-only verification. A phone call to a known number breaks the attack because the real vendor or executive will have no knowledge of the request. This simple step blocks most BEC fraud.

Protocol 3: Segregate Duties in Financial Processes

What: Separate these four functions across different people: initiating payments, approving payments, reconciling accounts, and changing vendor master data. No single person should control more than one function for the same vendor or payment. If you have a small team, assign reconciliation to the owner or external bookkeeper, and use banking platform controls to enforce approval workflows. Document who is responsible for each function and review the segregation quarterly.

Measure: Audit your payment process monthly. Identify any payments where the same person initiated, approved, and reconciled. Anything above zero is a control failure.

Why: Fraud, whether external or internal, succeeds when one person controls the entire payment cycle. Segregation creates natural checkpoints where discrepancies surface before they compound.

Protocol 4: Enable Real-Time Payment Monitoring and Alerts

What: Work with your bank or accounting platform to set up alerts for payments over a defined threshold, payments to new accounts, or payments that deviate from historical patterns. Configure alerts to notify at least two people: the payment initiator and an independent reviewer or owner. Set alerts to trigger before funds are released, not after they clear. Review flagged transactions within one business hour.

Measure: Track alerts triggered and response time to review each alert. Alerts ignored or reviewed too late provide no protection.

Why: Real-time monitoring catches anomalies manual processes miss. BEC attackers count on payments clearing before anyone notices. Alerts compress the decision window and give you time to verify before money leaves your account.

Protocol 5: Conduct Quarterly Fraud Drills and Control Audits

What: Every 90 days, run a simulated BEC attack: send a fake urgent payment request from a spoofed email to your finance team and see if they follow verification protocols. Document whether the team caught the fraud or would have processed payment. Use results to identify control gaps, retrain staff, and tighten processes. Quarterly, audit a random sample of 10-15 payments to verify dual authorization, verbal verification, and segregation of duties were maintained.

Measure: Track pass/fail rates on fraud drills and control violations found in audits. A passing score is 100% compliance. Anything less means your controls are not operational.

Why: Controls degrade over time as urgency, turnover, and process drift erode discipline. Regular drills keep fraud top of mind and surface weaknesses before real attackers exploit them. Audits ensure your designed controls match actual practice.

Your Next 30-60 Days

Phase 1: Week 1

Map your current payment process end-to-end. Identify who can initiate payments, who approves them, who can change vendor details, and who reconciles. Document every gap where one person controls multiple steps or verification relies on email alone. Calculate your monthly exposure: total dollar value of payments over $5,000, number of wire transfers, number of vendor banking changes. Set your dual authorization threshold based on exposure and team capacity. Schedule a kickoff meeting with your finance team to explain the new controls and the fraud risk driving them.

Phase 2: Weeks 2-4

Implement dual authorization for all payments above your threshold. Work with your bank or accounting software to configure workflow approvals that enforce the control automatically. Build the verbal verification protocol into your process: create a checklist for payment approvers that requires a phone call for any banking change or new vendor. Train your team on BEC red flags: urgent language, after-hours requests, slight email address changes, requests to bypass normal process. Run your first fraud drill by sending a fake spoofed payment request and measuring response. Use the results to refine your protocol.

Phase 3: Weeks 5-8

Install real-time payment alerts through your banking platform. Configure alerts for payments over $10,000, payments to new accounts, and any amount 50% higher than vendor historical average. Assign two people to receive alerts and define a one-hour response window. Conduct your first quarterly control audit: pull 10 payments at random and verify dual authorization, verbal verification, and segregation of duties were followed. Identify any violations and address them immediately. Lock in the new controls as permanent operating standard. Schedule the next fraud drill and audit for 90 days out.

Why This Matters Now

Payment fraud is not slowing down. Seventy-nine percent of businesses were hit in 2024, BEC incidents jumped 66% year over year, and AI-generated attacks are making fraud harder to detect. For $1M-$50M+ businesses, the financial and operational cost of a successful BEC attack is measured in tens of thousands of dollars, weeks of recovery time, damaged vendor relationships, and the corrosive realization that your systems failed to protect you.

The fraud risk is structural, not behavioral. Your team is not careless. Your vendors are not untrustworthy. But your payment processes lack the layered controls that make fraud attempts visible before money moves. Attackers exploit exactly the gaps that exist in most SMBs: single-person payment authority, email-only verification, weak segregation of duties, and no real-time monitoring. These are not technology problems. They are discipline problems.

The protocols in this briefing work because they create friction at the right points. Dual authorization forces a second decision. Verbal verification breaks email-based attacks. Segregation of duties prevents any one person from controlling the entire payment cycle. Real-time alerts compress reaction time. Fraud drills and audits ensure controls stay operational under pressure. None of these are complex. All of them are effective.

This matters now because the next BEC attempt is already in motion. Attackers are studying your email traffic, mapping your vendor relationships, and waiting for the right moment to strike. The question is not whether you will be targeted. It is whether your controls will catch the fraud before your money is gone.

Set your threshold. Install dual authorization. Require verbal verification. Run your first drill within seven days. That is how you build a company worth owning, not a target that bleeds profit to criminals who count on you having no defenses.


Operational Picture

The signal, the breakdown, and the move

The Signal

Anyone in your organization can initiate and approve a payment without independent review. Vendor banking changes happen via email with no phone verification. You have no real-time alerts for unusual payment patterns or amounts. Reconciliations happen monthly or quarterly, not weekly. The same person who processes payments also reconciles accounts. Urgent payment requests bypass normal process without documentation. You have never run a fraud drill or audited payment controls.

The Breakdown

Fraud starts with a phishing email that compromises credentials or a spoofed request that looks legitimate. The attacker studies your payment patterns, identifies high-value targets, and times the request for maximum urgency. Your team, under deadline pressure, initiates payment without verbal verification because the email looks real. No dual authorization catches it, no alert triggers, and the payment clears. Days later, the real vendor calls asking about late payment, and you discover the money is gone.

The Move

The move is to install layered controls that create decision points before money leaves your account. Set dual authorization thresholds, enforce verbal verification for banking changes, segregate duties so no one person controls the payment cycle, and configure real-time alerts that surface anomalies within minutes. Run quarterly fraud drills to test whether your team follows protocol under pressure, and audit payments monthly to ensure controls remain operational as urgency and turnover test discipline.


Area of Operations

Four domains this gap touches at once

Financial

The average BEC wire transfer is $24,586, enough to eliminate a month of profit for most $1M-$10M businesses. One successful fraud can cost $30K-$50K in lost cash, plus bank fees, legal costs, and zero recovery. Weak controls drain profit through undetected fraud, and each incident burns capacity on recovery efforts that produce no revenue.

Operational

When fraud succeeds, operations stall while you file reports, work with banks, and rebuild vendor trust. Finance teams lose 60-80 hours per incident on recovery, investigations, and damage control. Payment processes slow as confidence erodes, and every future transaction carries the weight of past failures. The operational drag compounds until controls are installed.

People

Finance teams feel violated and lose confidence in their own judgment after fraud succeeds. Trust erodes when employees realize systems failed to protect them, and turnover risk rises as high performers refuse to work in exposed environments. Morale drops when the team knows attackers exploited gaps leadership failed to close.

Customer

Vendor relationships deteriorate when payments go missing, and customers lose confidence when your business is publicly linked to fraud incidents. Delays in resolving fraud create payment backlogs that damage trust, and the reputational cost spreads as vendors warn others about your weak controls. Customer-facing fraud exposes your operational immaturity.


Operator Playbook

Assess, stabilize, advance

1

Assess

Map your current payment process to identify who initiates, approves, reconciles, and can change vendor details. Calculate monthly exposure by totaling payments over $5,000, wire transfers, and banking change requests. Document every gap where one person controls multiple steps, verification relies on email alone, or no monitoring exists. Quantify the potential loss if your largest monthly payment were fraudulent.

2

Stabilize

Install dual authorization for payments above your threshold, require verbal verification for all banking changes and new vendors, and configure real-time alerts through your banking platform. Train your team on BEC red flags and run your first fraud drill to test whether controls hold under pressure. Audit a sample of payments monthly to ensure designed controls match actual practice.

3

Advance

Expand controls to cover all payment types, integrate fraud detection into your accounting software, and automate segregation of duties through workflow approvals. Conduct quarterly fraud drills with escalating complexity, track control compliance as a performance metric, and build fraud prevention into onboarding for all new finance hires. Lock controls as permanent operating discipline, not temporary projects.


Your Next Move

Close the gap before it forces the decision for you

Book a Strategy Call Upper Echelon Consulting An Initiative Of Upper Echelon Consulting

Field Dictionary


Frequently Asked Questions


After Action Review

Run these four steps the week after you read this brief. They turn analysis into a decision you can act on before the next quarter starts.

1
Identify the most recent payment above $10,000 and trace who initiated, approved, verified, and reconciled it.
2
Ask which control should have caught fraud if that payment had been fraudulent: dual authorization, verbal verification, segregation of duties, or real-time alert.
3
Define one specific change to tighten that control, such as enforcing phone verification or adding a second approver to the workflow.
4
Schedule a 30-day review to verify the change is operational and repeat the exercise on the next high-value payment.

Sources & References

Association for Financial Professionals. (2026, January 12). New Study: Payment Fraud Hits 79% of Companies. Resourceful Finance Pro. https://www.resourcefulfinancepro.com/articles/payment-fraud-afp-study/

M&T Bank. (2025, August 26). Business Email Compromise: The most popular method of fraud. M&T Bank. https://www.mtb.com/library/article/business-email-compromise

Federal Reserve Financial Services. (2024, December 31). Classifying ACH and Wire Fraud. Federal Reserve Bank Services. https://www.frbservices.org/news/fed360/issues/121625/fraud-mitigation-classifying-ach-wire-fraud

Hoxhunt. (2025, March 2). Business Email Compromise Statistics 2026 (+Prevention Guide). Hoxhunt Blog. https://hoxhunt.com/blog/business-email-compromise-statistics

TitanHQ. (2025, December 1). The State of Email Security in 2025. TitanHQ. https://www.titanhq.com/email-security-2025/state-email-security-report-2025/

Eftsure. (2025, November 5). 20 Business Email Compromise Statistics 2025. Eftsure US. https://www.eftsure.com/statistics/business-email-compromise-statistics/

Better Accounting. (2025, June 8). Why SMEs Need Internal Controls to Prevent Fraud. Better Accounting. https://betteraccounting.com/internal-controls-to-prevent-fraud/

Brady Martz. (2025, September 8). Financial Fraud Prevention: Best Practices for 2025. Brady Martz. https://www.bradymartz.com/financial-fraud-prevention-best-practices-for-2025/


Field Intel & Operator Discussion

This is where the briefing gets sharper

Share what you are seeing in the field, what you tried, what worked, and what failed. Ask a direct question, challenge an assumption, or add a tactic that other operators can test this week. Keep it specific, real, and execution-focused.

If you post a claim, include the conditions: industry, team size, volume, and timeframe.

Leave a Reply

Your email address will not be published. Required fields are marked *

STRATEGIC CLARITY.
DELIVERED WEEKLY.

Join other business commanders receiving the Business Battlefield Briefing.

One tactical insight. No fluff. No drift.

Read by owners from all sizes of companies.