Business Email Compromise: Protect Your Business

Business email compromise (BEC) is one of the most financially damaging cyber threats facing UK businesses today. Unlike ransomware or malware attacks that overwhelm systems with brute force, BEC attacks are subtle, targeted, and often devastatingly effective. A single successful attack can cost a Manchester business tens of thousands of pounds – sometimes far more – with little realistic chance of recovering the funds.

At PC Express IT, we work with businesses across Manchester, Sale, and the wider Greater Manchester area. We see the damage BEC attacks cause first hand. This guide explains what business email compromise is, how it works, why local businesses are increasingly in the crosshairs, and – most importantly – how to protect your organisation.

What Is Business Email Compromise?

Business email compromise is a form of email fraud in which attackers trick employees into transferring money or sharing sensitive information by impersonating a trusted person. The attacker typically poses as a senior figure in your organisation – a CEO, finance director, or managing director – or as an external party such as a supplier, solicitor, or HMRC representative.

Unlike phishing attacks that cast a wide net, BEC is targeted and researched. Attackers study your business before striking. LinkedIn profiles, Companies House filings, press releases, and your website hand them the intelligence they need. The resulting emails contain no obvious red flags: no spelling mistakes, no suspicious attachments, just a convincing message from what appears to be a trusted contact.

How Business Email Compromise Attacks Work

BEC attacks follow recognisable patterns. Understanding each variant helps your team spot the warning signs before money leaves the business.

CEO Fraud

The attacker impersonates the CEO or another senior leader, typically targeting someone in the finance team. The email requests an urgent bank transfer – often framed as a confidential acquisition, a regulatory payment, or a time-sensitive supplier settlement. The pressure to act quickly is deliberate: it discourages the recipient from verifying the request through other channels. Manchester businesses with less formal internal structures are particularly vulnerable here.

Invoice and Payment Fraud

The attacker impersonates a supplier or business partner, either sending a convincing fake invoice or intercepting a genuine one and substituting their own bank details. By the time the legitimate supplier follows up on a missed payment, the money has already gone. Sale-based businesses that work with multiple contractors and subcontractors are frequently targeted using this variant.

Account Compromise

In more sophisticated attacks, criminals gain access to a real email account – often through phishing or credential theft – and operate from inside your organisation. They can monitor communications, learn about upcoming payments, and strike at precisely the right moment. This is the most dangerous variant because the emails arrive from a legitimate address that recipients already trust without question.

Solicitor and Legal Impersonation

Property transactions and legal settlements are common targets. Attackers intercept communications between businesses and their solicitors, then redirect funds at the critical payment stage. Property purchases across Greater Manchester – including Sale, Altrincham, Trafford, and the city centre – have been targeted using exactly this method. For any Manchester business involved in property or significant legal transactions, this risk is real and immediate.

Why Manchester Businesses Are at Risk

Manchester’s thriving business community makes it an attractive target. Attackers use publicly available information to research potential victims: LinkedIn profiles, Companies House filings, and business websites all reveal who the decision-makers are, who handles payments, and what relationships the business has with key suppliers and partners.

SMEs across Sale, Salford, Stockport, and Manchester city centre are disproportionately targeted because they often lack the formal payment verification procedures that larger corporates enforce. A smaller Sale-based business may process supplier payments without requiring dual authorisation, making it far easier for a convincing email to result in a fraudulent transfer.

Action Fraud consistently ranks BEC among the highest-cost fraud types reported by UK businesses. The true scale is almost certainly higher, because many organisations do not report incidents out of embarrassment or a belief that funds cannot be recovered.

Warning Signs of a Business Email Compromise Attempt

Train your team to slow down and verify when they notice any of these indicators:

  • Unusual urgency – pressure to act immediately, with a reason given for bypassing normal approval procedures
  • Requests for secrecy – the email stresses the matter must remain confidential, preventing verification with colleagues
  • Changed bank details – a known supplier suddenly requests payment to a new account, especially close to a scheduled payment date
  • Slightly wrong email domains – look carefully at the sender address (e.g. pcexpressit.co rather than pcexpressit.co.uk)
  • Out-of-character requests – a CEO who never emails about payments suddenly requesting an urgent wire transfer
  • Requests to bypass process – skipping purchase orders, second approvals, or asking you to transact outside your normal systems

How to Defend Against Business Email Compromise

Effective protection requires a combination of technical controls and robust human procedures. Technology alone is insufficient: BEC attacks are specifically engineered to bypass automated filters, which means your people and your processes are equally critical.

Implement Multi-Factor Authentication on All Accounts

MFA is non-negotiable. Account takeover BEC relies on stolen credentials – MFA stops attackers using those credentials even when they have them. Every Manchester business using Microsoft 365 or Google Workspace should enforce MFA across all user accounts without exception. Your IT support provider can configure and enforce this across your organisation within hours.

Configure SPF, DKIM, and DMARC on Your Domain

These three DNS records tell receiving mail servers how to verify that emails claiming to come from your domain are genuinely from your systems. A DMARC policy set to “reject” makes it significantly harder for attackers to spoof your domain name when targeting your suppliers, partners, and clients. Without DMARC, anyone can send an email that appears to come from yourcompany.co.uk. Your cyber security team should audit these settings – many Manchester businesses are surprised to find records missing or misconfigured.

Enable External Email Warning Banners

Configure Microsoft 365 or your email platform to display a prominent warning banner when an email arrives from outside your organisation. This low-cost measure helps staff immediately recognise when an email purportedly from the managing director is actually coming from an external address – a major red flag in almost every BEC scenario.

Establish Robust Payment Verification Procedures

Any request to transfer money or change payment details – regardless of who it appears to come from – must require verbal confirmation via a call to a known, independently sourced phone number. Not a reply to the email thread, and not to a number included in the suspicious message itself. This single procedural change stops the vast majority of BEC attacks before any money moves.

Sale and Manchester businesses that process regular supplier payments should implement dual authorisation for transfers above a defined threshold. UK banks now offer Confirmation of Payee for new payees – use it every time.

Run Regular Security Awareness Training

Your staff are the last line of defence against business email compromise. Regular security awareness training – including simulated BEC and phishing exercises – builds the scepticism and verification habits your team needs before a real attack arrives. PC Express IT provides security awareness programmes for Manchester and Sale businesses of all sizes as part of our managed IT support packages.

Reduce Your Public Information Footprint

Review what information about your team and internal processes is visible on LinkedIn and your website. Attackers use public sources to identify who handles finances and construct convincing scenarios around those individuals. You do not need to remove everything – but avoid publishing detailed org chart information or naming the specific staff responsible for processing payments.

If You Have Been Targeted: Immediate Steps

If you suspect your Manchester or Sale business has been the victim of a business email compromise attack, act immediately:

  1. Contact your bank immediately – speed is critical. Banks can sometimes freeze or reverse fraudulent payments if contacted within hours of the transfer.
  2. Report to Action Fraud – call 0300 123 2040 or report at actionfraud.police.uk. This creates a crime reference number you will need for your insurer.
  3. Notify the ICO if required – if personal data was accessed or shared as part of the attack, you may have a GDPR obligation to report to the ICO within 72 hours.
  4. Preserve all evidence – do not delete emails, chat logs, or any communications related to the incident. Investigators and insurers will need them.
  5. Engage your IT provider – if an email account was compromised, you need to establish the full scope of access immediately and revoke it. Contact PC Express IT for rapid incident response across Manchester and Sale.

BEC and Cyber Insurance: Read the Small Print

Many businesses assume their cyber insurance policy automatically covers business email compromise losses. In practice, insurers are increasingly excluding social engineering fraud or applying sub-limits that are a fraction of the main policy limit. Some policies require specific controls – such as DMARC configuration and documented security awareness training – to be in place before a BEC claim is accepted. Review your policy now, before you need to make a claim.

Get Expert Help in Manchester and Sale

Business email compromise is a sophisticated, evolving threat that requires both technical controls and strong internal procedures working together. If you are not confident that your Manchester or Sale business has the right protections in place, it is far better to address the gaps now – before an attack – than in the aftermath of a costly incident.

PC Express IT helps businesses across Greater Manchester configure email authentication, enforce MFA, deliver security awareness training, and establish clear payment verification procedures. We are based in Sale and support businesses throughout Manchester and the wider region. Get in touch to discuss a BEC risk assessment for your organisation.

What is business email compromise (BEC)?

Business email compromise is a targeted form of email fraud in which attackers impersonate a trusted person – such as a CEO, supplier, or solicitor – to trick employees into transferring money or sharing sensitive information. Unlike broad phishing campaigns, BEC attacks are researched and personalised to appear entirely legitimate to the recipient.

How common is business email compromise in the UK?

BEC is consistently one of the highest-cost fraud types reported to Action Fraud. UK businesses lose hundreds of millions of pounds to BEC attacks every year, and the true figure is higher because many incidents go unreported. Businesses across Manchester and Greater Manchester are targeted regardless of their size or sector.

How can I tell if I have received a BEC email?

Key warning signs include unusual urgency, requests to keep the matter confidential, a supplier suddenly requesting payment to a new bank account, slightly misspelled email domains, and requests to bypass your normal authorisation process. If anything feels unusual, always verify through a separate channel – call the person directly on a known number rather than replying to the email or calling a number provided in it.

Can technical controls stop business email compromise?

Technical controls significantly reduce the risk but cannot eliminate it entirely. SPF, DKIM, and DMARC prevent domain spoofing. MFA blocks account takeover. Email filtering catches many impersonation attempts. However, sophisticated BEC attacks are specifically designed to bypass automated filters, which is why staff training and robust payment verification procedures are equally critical to your defence.

What should I do immediately if money has been transferred fraudulently?

Contact your bank immediately – time is critical and banks can sometimes freeze or reverse transactions if notified within hours. Then report to Action Fraud on 0300 123 2040, notify your cyber insurer, and engage your IT support provider to determine whether any email accounts were compromised. Do not delete any evidence, including the original fraudulent emails and any related correspondence.

Does cyber insurance cover business email compromise losses?

Not always. Many cyber insurance policies either exclude social engineering fraud or apply a sub-limit that is far below the main policy limit. Review your policy carefully and speak to your broker about whether BEC is explicitly covered. Some insurers require specific controls – such as DMARC and documented security awareness training – as a condition of coverage for social engineering claims.

How can PC Express IT help protect my Manchester business from BEC?

PC Express IT configures email authentication (SPF, DKIM, DMARC), enforces MFA across all business accounts, delivers security awareness training including simulated BEC exercises, and helps businesses establish effective payment verification procedures. We are based in Sale and support businesses across Manchester and Greater Manchester. Contact us to arrange a BEC risk assessment for your organisation.