Business email compromise is the single most expensive form of cybercrime affecting South African businesses. It works by gaining access to a real email account and using it to redirect payments or extract information, with losses rarely recovered.
Business email compromise is not a virus. It is not ransomware. It does not encrypt your files or crash your systems. It is far more subtle than that, and it is the single most expensive form of cybercrime affecting South African businesses today.
A business email compromise attack works by gaining access to a real email account, or convincingly impersonating one, and using it to manipulate people into transferring money or sharing sensitive information. The emails look legitimate because they often are legitimate, sent from a real account that has been quietly taken over.
How an attack typically unfolds
The attacker gains access to a business email account. This usually happens through a phishing email that captures login credentials, a password that was reused from a breached service, or a brute force attack against an account without multi-factor authentication.
Once inside, the attacker does not act immediately. They watch. They read emails to understand the business relationships, the payment processes, who approves what and when large payments are expected. This reconnaissance phase can last days or weeks.
When the timing is right, the attacker strikes. They send an email that looks exactly like normal business communication because it comes from a real account or a near-identical address. The email changes banking details on an upcoming payment, requests an urgent transfer or asks for sensitive client information.
Because the context is perfect, the language is professional and the sender appears legitimate, the recipient acts on it without questioning it.
What the scenarios look like
The supplier invoice redirect. Your accounts team receives an email from a supplier they pay regularly. The email says the supplier has changed banks and provides new banking details for future payments. The email comes from what appears to be the supplier's address, references a real invoice number and is written in the supplier's usual tone. The next payment goes to the attacker's account instead.
The CEO request. A finance team member receives an email from the managing director asking them to process an urgent payment for a confidential deal. The email says not to discuss it with anyone else because it is sensitive. The pressure to comply quickly, combined with the authority of the sender, leads to the payment being made without the usual verification steps.
The client data request. A staff member receives an email from what appears to be a client asking for copies of their account records, contracts or financial statements. The email looks legitimate because the attacker has been reading the real email thread and knows the context. The staff member sends the documents, giving the attacker everything they need for identity fraud or further attacks.
Why it works so well
Business email compromise works because it exploits trust, not technology. There is no malware to detect, no suspicious attachment to scan and no link to block. The email is a normal business message sent through normal channels. The only thing different is the intent behind it.
Anti-virus software will not catch it. Spam filters will not flag it. Even advanced email security tools struggle with it because the email often comes from a legitimate, authenticated account.
The only defence that consistently works is human awareness combined with process controls. Staff who know what to look for and verification procedures that are followed every time, regardless of how urgent the request seems.
The financial impact
Business email compromise losses in South Africa run into the hundreds of millions of rand annually. Individual incidents regularly cost businesses tens of thousands, and in some cases hundreds of thousands, in a single attack. The money is almost never recovered because it is moved through multiple accounts and withdrawn before anyone realises what happened.
Beyond the direct financial loss, there are legal costs, client notification obligations under POPIA, reputational damage and the time spent investigating and recovering from the incident.
How to protect your business
The most effective protection against business email compromise is a combination of technology and process. Multi-factor authentication on every email account prevents attackers from gaining access with stolen passwords alone. If you are not sure how strong your current passwords are, our guide on how to create a strong password covers the fundamentals.
A strict policy of verifying any change in banking details by phone, using a number you already have on file rather than one provided in the email, would prevent the majority of successful attacks.
Training your team to recognise the warning signs, urgency, secrecy, unusual requests and changes to payment details, makes them part of the defence rather than the vulnerability.
The bottom line
Business email compromise is not going away. It is getting more sophisticated, more targeted and more damaging. The businesses that protect themselves are the ones that take it seriously before it happens to them.
At Recloud we implement the email security, authentication controls and monitoring that protect businesses against these attacks. If you are not confident your business would catch a well-crafted BEC attempt, get in touch and we will assess your exposure.