Protection Tools

Business Email Compromise: The Checklist to Run Before Every Wire Transfer (2026)

BEC causes more reported dollar losses than any other cybercrime category, and the attack is often just one convincing email. Here's the exact checklist to run before you approve a transfer.

📅 Aug 12, 2026·⏱️ 6 min read·✍️ Cikal Studio Labs
💸

The most expensive cybercrime isn't the most technical one

Business Email Compromise (BEC) doesn't rely on malware, exploits, or sophisticated infrastructure — it relies on a well-timed email that looks routine enough to act on without a second thought. Despite that simplicity, BEC consistently produces more reported dollar losses than ransomware, data breaches, or any other cybercrime category tracked by federal fraud reporting agencies, because the average successful attack moves real money directly, in a single transfer.

The two patterns behind almost every BEC loss

  • Lookalike domain impersonation. An email arrives from a domain that's one character off from a real vendor, partner, or executive's actual domain — close enough to pass a fast read, wrong under a character-by-character check.
  • "Our bank details have changed." A vendor, contractor, or even an internal executive's compromised account sends updated banking information for an upcoming or recurring payment. This single sentence is responsible for a disproportionate share of BEC losses, because it doesn't require urgency or drama to work — it just requires someone updating a spreadsheet without calling to confirm.

Why urgency isn't even necessary

Unlike consumer phishing, effective BEC often skips manufactured urgency entirely, because urgency itself can trigger suspicion in a finance team trained to expect it. Many of the highest-value BEC losses involve a calm, professionally worded request that fits naturally into a normal payment cycle — which is precisely what makes a mechanical, checklist-based verification routine more reliable than relying on "this feels off."

Why callback verification has to use a known number

The single highest-leverage control against BEC is calling the requester back on a phone number your organization already had on file before the request arrived — never a number provided in the email itself, since an attacker controlling the email can just as easily control a phone number listed in its signature.

Dual approval catches what one person misses

Requiring a second, independent approver for any wire above a set threshold introduces a structural check that doesn't depend on any single person's vigilance on a given day. BEC attacks are frequently timed for when a key approver is traveling, in back-to-back meetings, or otherwise less likely to slow down — a second approver removes that timing advantage.

The mandatory hold period that costs nothing

A short, mandatory delay — 24 hours is common — before releasing funds to a first-time or newly changed set of payment details gives enough time for a callback to surface a problem before money actually moves. Because the delay only applies to new or changed details, it has essentially no cost on routine, already-verified payments.

Building this into a routine, not a one-time read

The organizations that hold up well against BEC don't treat this as security training people receive once — they build the verification steps into the actual approval workflow, so following them is the path of least resistance rather than an extra step someone has to remember to take under time pressure.

Frequently Asked Questions

Why does Business Email Compromise cause more losses than ransomware or data breaches?

BEC moves money directly in a single wire transfer, often for tens of thousands of dollars or more, and requires no malware or technical exploit — just one convincing email. That directness and low technical barrier is why BEC consistently produces more reported dollar losses than most other cybercrime categories combined.

What's the most common single sentence used in a BEC attack?

A request stating that bank details have changed for an upcoming or recurring payment. It doesn't require urgency or drama, which is exactly why it's effective against finance teams trained to be suspicious of dramatic, high-pressure requests.

Why does verifying by callback have to use a 'known' phone number specifically?

If an attacker controls the email, they can just as easily list a phone number in the signature that routes back to them. Calling a number your organization already had on file, from before the request arrived, breaks that control and reaches the real person or vendor.

Does a mandatory hold period slow down all payments?

No — it should apply only to first-time or newly changed payment details, not routine payments to already-verified accounts. That scoping keeps the cost close to zero while still creating a window for verification on exactly the transfers where BEC attacks concentrate.

Is there a tool that walks through BEC verification before approving a wire?

Yes — the Business Email Compromise Wire Checklist is a weighted 12-point checklist covering domain verification, callback confirmation, dual approval, and hold periods, with a live 0-100 score so you can see exactly how much verification a given transfer has received before you approve it.