Business Email Compromise: Why MFA Alone Is No Longer Enough

Business email compromise is one of the most financially damaging cyber threats facing small and mid-sized businesses. Attackers can gain access to legitimate email accounts, hide their activity, monitor real conversations, and wait for the right opportunity to redirect a payment.
Recently, I was contacted by a local Victoria firm that lost approximately $150,000 after an email account was compromised. What stood out was that the account had multi-factor authentication enabled. MFA is still essential. We recommend it and use it as a core security control.
But MFA alone is no longer enough.
What Is A Business Email Compromise?
Business Email Compromise, or BEC, is a targeted form of financial fraud where an attacker gains access to a legitimate employee's email account and uses that access to manipulate normal business communications.
The goal is often to redirect money by changing banking details, approving a fraudulent payment, or convincing someone to send funds to the wrong account.
What makes BEC so effective is that the message may come from a real email account.
The sender address is correct. The signature looks normal. The conversation may already be in progress. That makes these attacks much harder to spot than a typical phishing email.
Attackers can also be patient. They may spend days or weeks studying email conversations, vendor relationships, payment processes, and writing styles before they act.
How Does the Attack Work?
A typical business email compromise often starts with a convincing phishing email containing a malicious link. It may look like a Microsoft 365 notification, shared document, invoice, or other routine business message.
If the employee clicks the link, they may be taken through a fake or manipulated sign-in process. In some attacks, the criminal can capture the employee’s authenticated session after the employee has already entered their password and completed MFA.
This is what makes these attacks so dangerous. The attacker may not need to defeat MFA directly. Instead, they steal the digital proof that tells the system the user has already been authenticated.
Think of it like entering a secure building. Your password and MFA get you through the front door. Once inside, you are given a temporary access badge so you do not have to prove your identity at every doorway. If an attacker steals that badge, they may be able to move around as though they were you.
From there, the attacker can monitor email conversations, create hidden inbox rules, and wait for the right opportunity to redirect a payment or send a fraudulent request.
MFA is still an essential security control. The key lesson is that it should be one layer of protection, not the only one.
What Happens Once the Attacker Is Inside?
A smart attacker may not act immediately. They learn which suppliers the company pays, who approves invoices, how employees communicate, and when large payments are expected.
Then they may create hidden inbox or forwarding rules.These rules can:
- move replies into another folder
- hide security notifications
- forward messages elsewhere
- delete or redirect certain emails
This helps the attacker stay hidden. For example, if a supplier replies to confirm a banking change, the attacker may create a rule that prevents the legitimate employee from ever seeing that response. That is why inbox rule monitoring is an important control.
Why Finance Teams Are High-Value Targets
Attackers are especially interested in people whose email accounts have financial authority. That often includes:
- accounts payable staff
- bookkeepers
- controllers
- procurement employees
- account managers
- executives
- business owners
Once inside one of these accounts, the attacker may be able to see invoices, payment schedules, supplier relationships, and internal approvals.
Vendors and clients can also become targets. If an attacker controls your email account and sends a customer new banking instructions, the customer may believe they are simply following your request. The real weakness being exploited is not just technology. It is trust.
One of the Best Defences Is a Simple Phone Call
One of the most effective ways to reduce BEC risk is also one of the simplest. Never change banking or payment details based only on an email.
If a supplier requests new banking information, call them and verify it. Do not use a telephone number included in the email requesting the change. Use a number you already have on file, from a previous invoice, your accounting system, or another trusted source.
The same process should apply to:
- vendor banking changes
- payroll deposit changes
- wire transfer requests
- refund instructions
- unusual executive payment requests
A two-minute phone call can prevent a six-figure loss.
What Security Controls Help Reduce the Risk?
There is no single control that eliminates BEC. Good defence depends on several layers working together.
Email link protection
Modern email security can inspect and block suspicious links before an employee reaches the malicious site. The goal is simple: stop the attack as early as possible.
Login anomaly monitoring
Businesses should monitor for unusual login behaviour such as access from unfamiliar countries, IP addresses, or devices. These signals do not always mean an account is compromised, but they should be investigated.
Inbox rule monitoring
If a new forwarding or hide rule suddenly appears in a mailbox, IT should know about it. These rules are often used to conceal fraudulent conversations and security alerts.
Conditional Access and device controls
Microsoft 365 environments can also use Conditional Access and device compliance rules to place additional restrictions around sign-ins.
This can reduce the usefulness of a stolen session if the attacker is connecting from an unmanaged or suspicious device.
The Two Controls We Prioritize Most
From an operational standpoint, two controls are especially valuable.
1. Better email link protection
Stop malicious links before employees interact with them.
2. Inbox rule monitoring
Alert IT when suspicious forwarding or hide rules are created. One tries to stop the compromise before it starts. The other helps expose the attacker after they get in. That is the value of layered security.
What Should You Do If You Suspect a Compromise?
Speed matters. If an employee notices suspicious activity, or a vendor reports an unusual banking request:
- Do not process the banking change until it has been independently verified.
- Contact IT or your security provider immediately.
- Call your bank or payment processor immediately if money has already been transferred.
- Preserve suspicious emails rather than deleting them.
A proper response may also include revoking active sessions, changing credentials, checking authentication methods, reviewing inbox rules, examining sign-in logs, and investigating affected devices.
Small Businesses Are Not Too Small to Be Targets
One of the most persistent cybersecurity misconceptions is that attackers are mainly interested in large companies. They are not. A criminal does not need to steal millions from one organization. A $20,000 payment can be worthwhile.
Small and mid-sized businesses can be especially attractive because employees often wear several hats. The same person may handle accounting, vendor communications, payroll, and payment approvals. That makes a compromised mailbox extremely valuable.
MFA Is Still Essential. It Just Cannot Stand Alone.
If your business has enabled MFA, that was the right decision. Keep it enabled. The lesson from modern business email compromise is not that MFA has stopped working. The lesson is that attackers have adapted.
Businesses now need multiple layers around email, including better link protection, suspicious login monitoring, inbox rule alerts, device controls, and strong payment verification procedures.
At Digital Sky Solutions, we help businesses in Victoria, Vancouver, and across British Columbia strengthen Microsoft 365 and email security through our Managed IT and Cybersecurity services.
If your current email security strategy is mainly "we have MFA, so we're covered," it is worth reviewing. When a compromised email account can redirect a six-figure payment without anyone noticing, finding out weeks later is far too late.



