Business email compromise cost U.S. companies over $3 billion last year, and it often starts with a routine-looking invoice. This Cybersecurity Awareness Month, learn the verification steps that can help stop fraud before it happens.
A familiar email thread can make new payment instructions seem routine. This Cybersecurity Awareness Month, consider how your business checks requests that look like ordinary work.
Key Takeaways
- A familiar sender can still make a suspicious or unauthorized request. Check what will change before sending money, sharing files, or granting access.
- Verify new payment instructions using contact details already in your records.
- Consider providing staff with a designated person to contact about a request, including when the usual contact is unavailable.
- If someone has already acted, report what happened promptly so the bank or security team can respond.
- Consider a supplier invoice your finance team needs to pay today. The amount matches the purchase order, and the request arrives in a familiar email thread. The only change is the bank account.
An employee who knows how to spot a suspicious link might see nothing unusual here. They are paying what appears to be a legitimate invoice to a familiar supplier. But someone still needs to confirm where that payment is going.
The FBI's 2025 Internet Crime Report lists more than $3 billion in reported losses under business email compromise. These schemes exploit business communications to influence transactions. Preventing them may involve finance teams and the people approving payments, as well as IT.
Knowing the Sender Is Only the First Check
A customer contact may need a project update without requiring access to every file in the client folder. A supplier's employee may handle invoices but have no authority over banking changes. Knowing someone’s identity answers one question, but the details of the request still require verification.
Sometimes the account itself may have been compromised. An attacker using a real mailbox can reply within an existing conversation, so the address and earlier messages look legitimate. Asking whether the email looks suspicious may not resolve that problem.
This is where a general phishing checklist may not be enough, The person checking a request needs enough knowledge of the work to spot a change in payment details or a request for files the recipient would not ordinarily receive.
Why a Plausible Request Can Be Hard to Question
The Verizon 2026 Data Breach Investigations Report identifies social engineering as the third most common breach pattern, representing 16% of breaches in its dataset. The pattern includes deception used to obtain credentials, transfer money, or achieve another objective.
Verizon also distinguishes email phishing from interactive social engineering, in which an attacker works through a conversation to persuade someone to act. The report notes the importance of business-specific rules and guidance that go beyond conventional email phishing simulations.
An employee trying to meet a payment deadline or restore a colleague's access has a reason to respond quickly. The request draws on pressure that already exists. Effective training exercises should reflect this reality: the finance team can practice verifying bank details, while the help desk can practice confirming the identity of access requesters.
Requests Worth a Second Check
Consider focusing on changes that move money, expose sensitive files, or give someone access to an account. Employees may benefit from clear verification steps for these situations, rather than instructions to treat every unusual message as an incident.
A Supplier Changes Its Bank Details
Consider confirming the change with the supplier contact responsible for payment details, using contact information already in your records. A number supplied in the email could lead straight to the attacker.
The FTC's 2025 phishing guidance recommends checking unexpected messages through a phone number, email address, or website known to be real. For a payment change, the person reviewing it may also want to confirm how the new details were verified. Two colleagues agreeing that an email looks genuine may not independently verify the bank account.
A Familiar Contact Asks for More Files
A customer asks for a document to finish a project, then suggests sharing the whole folder to save time. Before sending it, consider checking what else is in that folder. It may contain information about other customers, employees, or earlier work that the recipient does not need.
An open sharing link raises a further question: who else could use it? Consider sharing only the files needed for the task with named recipients, and reviewing their access when the work changes or ends. An approved sharing platform gives staff tools to control access, but the appropriate files and recipients still need to be selected.
An IT Support Caller Wants Access
A caller offers to fix a problem and asks an employee to install remote-support software. The employee recognizes the product name. That says nothing about who is calling.
Consider using the company's established IT contact method to confirm the request before installing software or granting access. During a genuine support session, staff should understand what the technician is requesting them to do and what they are being asked to approve. If an unexpected login prompt appears, consider checking it through the known IT contact rather than relying on the caller's explanation.
Use Cybersecurity Awareness Month to practice responding to a request your team might realistically receive.
Use Cybersecurity Awareness Month to practice responding to a request your team might realistically receive.
Make the Check Practical on a Busy Day
A payment deadline is approaching, and the supplier contact who typically confirms bank changes is away. What should the finance employee do now?
Consider planning for this before it happens. Keep trusted contact details easy to find and identify a backup for the usual contact. Managers may want to allow time for the check, especially when a senior colleague or important customer is waiting.
Consider being specific when requesting a second review. "Does this look okay?" invites only a quick glance at the message. Instead, explain what is changing and what has been independently confirmed.
Staff may also benefit from a straightforward way to explain the pause to the other person. "We verify bank-detail changes using the contact information already in our records" makes the check part of doing business. Employees should have a clear and consistent way to explain the verification process when a supplier is awaiting payment.
Back Up Employee Judgment with Technical Protection
Multifactor authentication can help protect accounts. Access permissions can limit which files a person or application can reach. Email and device protection, backed by monitoring and investigation, may help identify malicious content or suspicious activity.
These protections require ongoing attention. Someone should review account changes, investigate alerts, and remove access that is no longer needed. Business leaders should know who is responsible for this work and how to reach them when an employee reports a problem.
Payment checks remain important even when these tools are working. A genuine employee can sign in correctly and send money after being misled by a supplier email. The transaction may use normal business systems throughout, with the wrong bank details as the critical change.
If Someone Has Already Acted
Consider notifying the IT or cybersecurity team promptly and providing relevant details about what occurred. Entering a password, sharing a folder, approving an application, and allowing remote access may each require different response measures. Include when the incident occurred and which account or device was involved.
Consider using a known contact or the company's reporting method to share the original message. Avoid reopening its links or trying to clean up the device yourself. If money was transferred, consider contacting the bank immediately through a verified number and coordinating with the appropriate internal teams.
A password reset may be only part of the response. Microsoft's guidance for compromised business email accounts, updated in 2026, includes signing out active sessions and reviewing application access and email forwarding rules. These checks can help identify ways an attacker may retain access or continue receiving messages after a password change.
Managers may want to prioritize helping the employee report relevant information promptly. Any follow-up coaching can occur after the immediate response is underway.
Use Cybersecurity Awareness Month to Practice Realistic Scenarios
NIST's 2025 incident-response guidance places preparation within ongoing cybersecurity risk management. Use Cybersecurity Awareness Month this October to practice responding to a request your team might realistically receive.
Consider taking a routine task, such as updating a supplier's bank details or granting a colleague access to a folder. Present the scenario with believable context and a deadline. Avoid obvious spelling mistakes that may make the exercise easier than the real-world situations described here.
Ask the team:
- Who would you contact before making the change, and where would you find their details?
- What would you do if that person were unavailable?
- If someone had already acted, who would need to know first?
Listen for practical difficulties. A missing phone number or uncertainty about folder permissions may identify something specific to address. Consider updating the contact list or access instructions while the exercise is still fresh, then confirm that staff can locate them.
How Acrisure Cyber Services Can Help
Acrisure Cyber Services provides cybersecurity awareness training, email and device protection, and 24/7 threat monitoring and response.
ACS security analysts investigate suspicious activity across security tools and can take action to help contain identified threats, which may include isolating affected devices and revoking account sessions. Access to experienced responders can help businesses respond when an employee reports a possible compromise.
Talk with Acrisure Cyber Services about employee awareness and managed security for your business.
This content is provided for general informational purposes only. Cybersecurity risks and appropriate measures will vary based on an organization’s specific circumstances, systems, operations and risk profile.
Frequently Asked Questions About Business Cyber Risk
Does every unusual request become a security incident?
An unusual request may be genuine. Consider pausing the payment, file transfer, or access change while you check it. Contact IT or security if you suspect a compromised account, unexpected software, or access that should not have been granted. Employees who are unsure should know how and where to report a concern.
Does multifactor authentication protect against payment fraud?
It can help protect account access. However, multifactor authentication does not independently verify whether a supplier's new bank details are legitimate. Payment fraud can involve a compromised supplier account or a genuine employee following fraudulent instructions, so consider verifying payment changes separately.
What if a manager asks an employee to skip a check?
The manager can help complete the check or involve someone who can. A deadline or senior job title should not replace appropriate verification before money is sent or information shared.


