Phishing and Business Email Compromise

Most money lost by small and medium businesses to cybercrime does not go through anything sophisticated. It goes out because somebody in accounts paid an invoice that looked entirely legitimate, to an account number that had been quietly changed.

What actually happens

The dramatic version is a fake login page that harvests a password. That happens, and it matters. But the version that empties bank accounts is slower and much harder to spot.

An attacker gets into one mailbox, often through a password reused from an unrelated breach. They then do nothing visible for weeks. They read. They learn who authorises payments, who your suppliers are, how invoices are worded, when the finance person is on holiday.

Then they send an email that is correct in every respect - right supplier, right amount, right project reference, right tone - with different bank details and a plausible note about a change of account. Sometimes it comes from the genuine compromised mailbox, in which case there is nothing technical to detect at all.

This is business email compromise, and it works because nothing about it looks wrong.

Why training alone does not fix it

Awareness training is worth doing, and it will not stop this. The staff member who pays the invoice is not being careless. They are looking at a message that is genuinely indistinguishable from a real one, sometimes because it came from a real account.

Treating this as a human failure leads to blaming people for missing something that could not be spotted. The organisations that stop losing money change the process instead.

The controls that work

Verify bank detail changes out of band, always. Any request to change payment details is confirmed by phoning a number you already hold - not one in the email. No exceptions, including for the managing director, and especially when the request is urgent. Urgency is the tell.

Multi-factor authentication on email. This closes the most common entry route. It is not optional in 2026, and it is free with every mainstream mail platform.

Dual authorisation above a threshold. Two people approve payments over a set amount. Pick the threshold to fit the business; the point is that one compromised mailbox is not enough.

Alert on mailbox rules. Attackers routinely create inbox rules to hide their tracks, forwarding or deleting messages from a supplier so the real correspondence never appears. A rule appearing on a finance mailbox should be noticed.

Make it safe to report. Someone who thinks they clicked something needs to say so within minutes, not sit on it overnight because they are embarrassed. That is a culture decision made long before the incident.

If it has already happened

Speed is the only thing that helps. Contact your bank immediately - funds can sometimes be recalled if the report is fast enough. Change the password on the affected account and revoke active sessions. Check for inbox rules the attacker created. Report it to An Garda Siochana, or to Action Fraud in the UK. If personal data was exposed, data protection breach notification timelines start running from the point of awareness.

The uncomfortable conclusion

The technical defence is worth having and it is the smaller half. The larger half is a payment process that does not depend on any single person correctly identifying a message that was designed to be unidentifiable.

Related: backups and ransomware recovery.