What Is Business Email Compromise and How Can Nigerian Businesses Prevent It?
A business can lose money or expose sensitive information without an attacker ever breaking into its main server.
Sometimes, the attack starts with a convincing email, message, or phone call that appears to come from a trusted person.
This is known as Business Email Compromise (BEC).
BEC attacks target business communication and processes. Attackers may impersonate executives, finance staff, suppliers, contractors, or other trusted people to trick employees into transferring money, changing payment details, sharing sensitive information, or carrying out unauthorised actions.
Nigeria's Computer Emergency Response Team (ngCERT) issued a high-risk advisory on August 27, 2026, warning organisations about BEC, phishing, impersonation, fraudulent payment requests, credential theft, and AI-assisted impersonation.
What Is Business Email Compromise?
Business Email Compromise is a type of social engineering attack in which criminals use compromised, spoofed, or fraudulent accounts and identities to manipulate business processes.
The goal is often financial fraud, but attackers may also be trying to obtain credentials, sensitive information, or access to other systems.
A typical attack might look like this:
Attacker → impersonates trusted person → sends urgent request → employee trusts request → money or information is transferred
The request may appear to come from:
- A company director
- Finance manager
- Supplier
- Customer
- Lawyer
- Contractor
- Business partner
Because the message may use real names, information, email conversations, and business terminology, it can be difficult to recognise immediately.
How Business Email Compromise Happens
BEC does not always require an attacker to completely take over a business email account.
Attackers may use several methods, including:
Compromised email accounts
An attacker obtains an employee's password and gains access to the real email account.
They can then read conversations and send messages that appear legitimate.
Email impersonation
Attackers may create an address that looks similar to a real company or employee address.
A small change in the domain or spelling can be easy to miss.
Phishing
Employees may receive a fake login page designed to steal their email credentials.
Once the attacker obtains the credentials, they can use the account for further fraud.
For more practical protection against phishing and account takeover, see our guide on How Nigerian Businesses Can Protect Against Phishing and Account Takeovers.
Social engineering
Attackers may research a business, its employees, suppliers, customers, and public information before contacting someone.
This information can make the fraudulent request appear more convincing.
AI-assisted impersonation
Modern attackers can also use publicly available information and AI-assisted techniques to create more convincing communications and impersonation attempts. ngCERT specifically included AI-assisted impersonation in its August 27, 2026 BEC advisory.
Common Examples of Business Email Compromise
Fake payment request
An attacker impersonates a manager and asks the finance team to make an urgent payment.
Supplier bank-detail change
An employee receives an email saying that a supplier has changed its bank account.
The employee updates the payment information without independently verifying the request.
Executive impersonation
A message appears to come from a company director asking an employee to purchase something, send money, or provide confidential information.
Invoice fraud
An attacker modifies or creates an invoice and sends it through a compromised or fraudulent account.
Payroll fraud
An attacker attempts to change an employee's payment information so future payments go to an account controlled by the attacker.
Warning Signs Businesses Should Look For
A suspicious request may contain one or more warning signs:
- Unusual urgency
- Unexpected payment instructions
- Requests to change bank details
- Requests for passwords or verification codes
- Slightly different email addresses
- Requests for secrecy
- Unusual writing style or wording
- Requests that bypass normal approval procedures
- Unexpected attachments or links
- A request that does not match established business processes
One warning sign does not automatically prove that a message is fraudulent, but unusual requests deserve additional verification.
How Nigerian Businesses Can Prevent BEC
1. Independently Verify Payment Requests
Do not rely on email alone when approving unusual payments or bank-detail changes.
For example, if a supplier sends new banking information by email, contact the supplier using a trusted phone number or previously verified communication channel.
Do not use only the contact details provided in the suspicious message.
2. Enable Multi-Factor Authentication
Multi-factor authentication adds another layer of protection beyond the password.
NIST recommends enabling MFA for business accounts and using phishing-resistant authentication where appropriate.
MFA can reduce the impact of stolen passwords, although businesses should still train employees to recognise phishing and protect authentication factors.
3. Use Strong, Unique Passwords
Important business accounts should use unique passwords that are not reused across multiple services.
If one password is exposed, reusing it elsewhere can allow attackers to compromise additional accounts. ngCERT has warned that stolen credentials can contribute to account takeover and subsequent BEC attacks.
4. Create Approval Procedures for Payments
Businesses should establish clear procedures for financial transactions.
For example:
Payment request → independent verification → approval → payment
This is safer than allowing urgent email requests to bypass normal financial controls.
5. Protect Administrator and Finance Accounts
Accounts with access to financial systems, email administration, payment platforms, or sensitive information should receive stronger protection.
Businesses should limit privileged access and regularly review unused or unnecessary accounts.
6. Train Employees
Employees should know that attackers may use email, WhatsApp, SMS, phone calls, social media, or other communication channels.
Training should cover:
- Phishing
- Impersonation
- Payment fraud
- Password security
- MFA
- Suspicious links
- Verification procedures
- Incident reporting
NIST recommends teaching employees how to identify and report phishing attempts and recognising that phishing can occur through multiple communication channels.
7. Review Email Account Activity
Businesses should periodically review important accounts for unusual activity.
Look for:
- Unexpected login activity
- Unknown devices
- Suspicious forwarding rules
- New recovery addresses
- Unfamiliar applications
- Unauthorised permissions
Compromised accounts may be used to monitor conversations or maintain access for future attacks. ngCERT specifically warns about malicious mailbox rules and persistence following account compromise.
What Should You Do If You Suspect BEC?
Act quickly.
If an employee believes a business account has been compromised or a fraudulent payment request has been processed:
- Report the incident immediately.
- Secure the affected account.
- Change compromised passwords from a trusted device.
- Revoke active sessions where possible.
- Review MFA and recovery settings.
- Contact the bank immediately if money may have been transferred.
- Review recent account activity.
- Preserve relevant emails, messages, and other evidence.
- Check whether other accounts or employees were targeted.
Fast reporting can help limit the damage and prevent further fraudulent activity.
BEC Is Not Only an Email Problem
Although Business Email Compromise often involves email, attackers may combine several communication channels.
They may start with an email and then follow up through:
- SMS
- Phone calls
- Social media
- Fake websites
- Other messaging platforms
This is why businesses should verify unusual requests based on trusted processes, not simply because a message appears to come from a familiar platform.
A Simple BEC Protection Checklist
Businesses can start with these basic controls:
- Use strong, unique passwords.
- Enable MFA.
- Verify unusual payment requests independently.
- Verify supplier bank-detail changes through a trusted channel.
- Limit administrator access.
- Train employees regularly.
- Review important account activity.
- Protect finance and executive accounts.
- Maintain reliable backups.
- Have a clear incident-reporting process.
These controls cannot guarantee that a business will never experience fraud, but they can reduce common opportunities for attackers and make suspicious activity easier to detect.
How Tech Resonate Can Help
Tech Resonate provides cybersecurity awareness and safe digital practices for businesses and organisations alongside software development, AI and data solutions, digital marketing, technology training, laptops, and technology support.
Businesses can also use Tech Resonate Academy to develop practical technology and digital skills.
Cybersecurity is most effective when technology, people, and business processes work together.
Need help improving your organisation's digital security? Contact Tech Resonate to discuss your requirements.
Sources
- Nigeria Computer Emergency Response Team (ngCERT) — Business Email Compromise and Social Engineering Attacks
- ngCERT — Associated Risks of Stolen Email Passwords and Credentials
- [NIST — Phishing](https://www. nist.gov/itl/smallbusinesscyber/guidance-topic/phishing)
- NIST — Multi-Factor Authentication

