Fraud

Business Email Compromise: The Quiet Attack Costing African SMEs the Most

No malware, no encryption, no ransom note. Just a changed bank account on a genuine invoice, and a payment that cannot be recalled.

Finance team reviewing payment records

Ransomware gets the attention because it is visible. Business email compromise quietly costs organisations more, and small and medium businesses are hit hardest because the controls that stop it are process controls they have never been asked to implement.

How it works

There is no exploit. The attacker gains access to a mailbox — usually through phishing or credential reuse — and then does nothing for a while. They read. They learn who authorises payments, who your suppliers are, how invoices are phrased, when the finance cycle runs, and who is travelling.

Then they intervene at exactly the right moment: a genuine invoice, from a genuine supplier, with the bank details changed. Or a request from a director, sent from the director's real account, while the director is on a flight.

Why it defeats technical controls

The email is genuinely from your supplier's domain, or genuinely from your director's mailbox. There is no attachment, no malicious link, nothing for a gateway to detect. Every technical signal says legitimate — because, at the protocol level, it is.

The variants we see most

  • Supplier invoice fraud. A real invoice with altered banking details, often arriving as a "correction" to one already sent.
  • Executive impersonation. Urgent, confidential, from the top, timed for when verification is hardest.
  • Payroll diversion. An employee emails HR to change their salary account. The email is from the employee's real address.
  • Conversation hijacking. The attacker joins an existing thread mid-discussion, where trust is already established.

Controls that actually stop it

Verify every banking change out of band

Non-negotiable. Any change to supplier or payroll bank details is confirmed by phone, on a number you already hold from your own records — never a number in the email requesting the change. This one control stops most of these attacks outright.

Dual authorisation above a threshold

Two people, genuinely independent, for payments over an agreed amount and for all first-time payees.

Lock down the mailbox

MFA everywhere, alerting on forwarding rules, and review of mailbox delegation. The fraud starts with mailbox access; removing that removes the attack.

Train finance specifically

Generic awareness training does not cover this. Finance and accounts payable need the specific scenarios, and they need explicit authority to delay any payment pending verification without fear of consequences.

If it has already happened

Contact your bank immediately — recall is occasionally possible within hours, and almost never after that. Preserve the mailbox and its logs before anything is cleaned up; you need to know how long the attacker had access and what else they saw. Then assume other fraud is in progress and check for pending changes to other payees.