Benchmark Benefits Consulting

Social Engineering & Fraud

Business Email Compromise Response: A Playbook for HR, Finance and Leadership

A coordinated response for suspicious payment, payroll, credential and sensitive-information requests—built around stopping the transaction, verifying through trusted channels, containing compromise and documenting decisions.

Published by Benchmark Benefits Consulting · Reviewed September 27, 2026

What is business email compromise?

Business email compromise, or BEC, is a form of impersonation and payment or information fraud in which an attacker appears to be a trusted executive, employee, vendor, adviser or business partner. The FBI describes BEC as a sophisticated scam affecting businesses and individuals who transfer funds, often involving compromise of a legitimate email account through social engineering or computer intrusion.

The name can be misleading: the contact may begin through email, but the attacker may continue by text message, telephone, voice memo, collaboration platform or a falsified document. The requested action may be a wire, invoice payment, gift-card purchase, payroll or direct-deposit change, release of tax or benefits data, credential entry, or a confidential task that bypasses normal review.

Compromised account and spoofed identity are different

In an account compromise, an attacker has access to a real mailbox or collaboration account. They may study message history, reply inside an existing thread, create forwarding or deletion rules, maintain active sessions, or impersonate the account owner convincingly. In spoofing or look-alike impersonation, the attacker may use a deceptive display name, altered domain, falsified sender information, personal mailbox, telephone number or synthetic voice without controlling the real account.

That distinction changes the technical response. A spoofed message still requires fraud response and review of how it passed controls, but a confirmed account compromise also requires session revocation, credential and authentication review, mailbox-rule inspection, connected-app review, scoping of accessed content, and assessment of whether other people or systems were affected.

Response boundary: a suspicious message is not automatically proof that an account, system or personal information was compromised. Preserve facts, label assumptions and let qualified responders determine scope.

What should an organization do when BEC is suspected?

Use two parallel tracks: stop the business action and investigate the security event. Neither should wait for perfect certainty when a payment, payroll change, credential or sensitive disclosure can still be prevented.

1. Stop or hold the requested action

  • Pause the transfer, invoice, direct-deposit change, account reset, data release or purchase.
  • Notify the person who controls the workflow so another employee does not complete the same request.
  • If funds moved, contact the organization’s financial institution immediately and ask about its fraud, recall or recovery process. Financial-institution procedures differ and recovery is not guaranteed.

2. Verify through an independent trusted route

  • Call a known number from an approved directory, contract or prior verified record.
  • Do not use a telephone number, reply address or link supplied in the suspicious message.
  • For vendor-bank or payroll changes, use the organization’s established dual-control procedure and document who verified what.

3. Activate the right internal responders

  • Alert security/IT, finance or payroll, HR, privacy/legal, communications, operations and leadership according to the facts.
  • Assign one incident lead and one decision record so teams do not act from conflicting versions of events.
  • Notify relevant vendors such as the email provider, managed service provider, payroll processor, insurer or financial institution through established contacts.

4. Preserve evidence

  • Retain the original message with headers where possible, attachments, links, envelope and bank details, timestamps, call logs, text messages and collaboration records.
  • Record actions already taken, people contacted, transaction identifiers and the time each decision occurred.
  • Do not forward suspicious content broadly; follow security-team instructions for safe collection.

These steps align with the broader employee data breach response-plan guide and the downloadable Employee Data Breach Response Checklist. For time-sequenced incident leadership, use The First 24–48 Hours After a Data Breach.

Give HR, payroll and finance scenario-specific instructions

BEC succeeds when a credible request reaches someone with authority to move money, change records or release information. Controls should protect the action—not depend on an employee noticing one perfect warning sign.

Executive impersonation

A message claims urgency, confidentiality or senior authority and asks for an unusual purchase, transfer or sensitive document. Require verification and normal approval even when the request appears to come from leadership. Executives should model that rule.

Vendor or invoice fraud

An attacker changes payment instructions, creates a look-alike invoice or joins a real conversation. Verify bank-detail changes using a known vendor contact and separate channel; compare the request with approved vendor records.

Payroll and direct deposit

A message requests a routing change or access to payroll information. Use authenticated employee self-service or a documented identity-verification procedure, notify the employee through a known channel and require secondary approval for high-risk changes.

Employee or applicant data

A request seeks tax forms, Social Security or Social Insurance numbers, benefits data, credentials or files. Stop the release, verify authority and purpose, and involve privacy/legal and security if information may already have been disclosed.

Credential theft

A message links to a false sign-in page, requests an MFA approval or asks an employee to share a code. Report the event, change affected credentials through a trusted path, revoke sessions and tokens, and investigate what the account could access.

Multi-channel pressure

An email may be reinforced by a text, call, voice memo or collaboration message. A second channel is not independent verification when the attacker controls or supplied it; return to an established contact route.

Payroll has both financial and identity consequences

A diverted paycheque is a financial incident for the employee and the organization. If payroll, tax, benefit or identity information was accessed or disclosed, add an employee-support and privacy assessment rather than treating the event only as a payment problem. Benchmark’s employer playbook for supporting employees after personal information exposure explains that separate workstream.

Finance should design controls for changes, not just invoices

Require independent verification for new beneficiaries, changed banking instructions, urgent deviations and executive exceptions. Use segregation of duties, transaction limits and documented approvals that cannot be waived by the person named in the message. Review whether a failed attempt exposed weaknesses in the workflow even when no money moved.

Contain a suspected account compromise without destroying evidence

Qualified IT or security personnel should tailor containment to the environment and preserve material evidence. Typical actions may include disabling or restricting the account; resetting credentials through a trusted administrative path; revoking active sessions, refresh tokens and app passwords; reviewing MFA methods and recent changes; inspecting sign-in, audit and message-trace logs; removing malicious forwarding, inbox or deletion rules; reviewing delegates and connected applications; checking recovery addresses and telephone numbers; and identifying other accounts or devices that may be affected.

Do not assume a password change ends the incident. An attacker may retain an authenticated session, registered authentication method, OAuth grant, forwarding rule or access to another compromised account. Conversely, do not make unsupported claims that an account was compromised merely because its name was spoofed.

Assess business and data exposure separately

Determine what actions were requested or completed, what messages or files may have been viewed, whether personal or confidential information was sent, what systems the account could reach, and whether the attacker contacted others. Build a timeline and distinguish confirmed facts, reasonable indicators, unknowns and ruled-out scenarios.

If employee personal information may have been involved, use Benchmark’s U.S. and Canadian breach-notification decision framework. Notification depends on applicable law and incident facts; a BEC report to law enforcement does not replace privacy or contractual analysis.

Address the human factors without blame

BEC messages commonly exploit authority, urgency, secrecy, helpfulness and fear of delay. Attackers may use familiar names, realistic context, an existing thread or a plausible exception. A blame-focused response discourages fast reporting and hides useful information. Employees should be thanked for pausing or reporting, even when an action was already taken.

Build a culture in which any employee can stop a sensitive transaction, seniority does not cancel verification, and reporting a mistake quickly is safer than concealing it. Training should use job-relevant scenarios and reinforce one clear reporting route. Controls should remain effective when people are busy, travelling or working across time zones.

AI can strengthen impersonation, but process remains the control

Official FBI alerts describe malicious use of AI-generated audio and other synthetic content to make impersonation more believable. That does not mean every convincing call or message is AI-generated, and employees should not be expected to identify synthetic media by intuition alone. Use an established callback, prearranged verification phrase or other independently maintained procedure for sensitive requests.

Do not let an apparent face, voice, writing style or caller ID override payment, payroll or data-release controls. A trusted process remains useful whether the attacker uses a compromised account, a look-alike domain, ordinary social engineering or AI-assisted impersonation.

Use the appropriate U.S. or Canadian reporting route

United States

Contact the financial institution and IC3 promptly

For a fraudulent transfer, the FBI advises victims to contact their financial institution immediately, request a recall and complete any required indemnification documents. The FBI also directs victims to file a detailed complaint with the Internet Crime Complaint Center at IC3.gov as soon as possible, regardless of the amount. Organizations may also contact local law enforcement and their FBI field office according to circumstances.

Report consumer-facing phishing or fraud to the FTC where appropriate. These routes do not replace sector, state, contractual or privacy obligations.

Canada

Contact the institution, police and official reporting services

The Canadian Anti-Fraud Centre directs victims to report fraud or cybercrime through the official Report Cybercrime and Fraud service or by telephone, and its victim guidance also directs people to local police. The Canadian Centre for Cyber Security accepts cyber-incident reports and provides security guidance. Contact the relevant financial institution immediately when funds or accounts are involved.

Applicable federal, provincial, sectoral, contractual and privacy requirements still need incident-specific review.

No universal sequence or recovery promise: coordinate reporting with counsel, insurers, financial institutions and responders as appropriate. Official reporting requirements, available recovery procedures and time sensitivity vary with the event.

Usable framework

Benchmark’s BEC response playbook

This eight-step sequence is a Benchmark-created operational framework, not an official government standard or a guarantee of recovery.

STOP

  • Hold the transfer, account change, disclosure, purchase or credential action
  • Warn workflow owners so the request is not completed elsewhere

VERIFY

  • Reach the requester through a known, independently sourced contact method
  • Apply dual control and record the verification result

CONTAIN

  • Secure affected accounts, revoke sessions, review authentication and connected access
  • Inspect mailbox rules, message traces and other relevant logs while preserving evidence

CONTACT

  • Immediately contact the financial institution when money moved
  • Activate security, finance/payroll, HR, privacy/legal, leadership and relevant vendors

ASSESS

  • Determine transactions, systems, messages and information affected
  • Separate confirmed compromise, spoofing, attempted fraud and unknowns

REPORT

  • Use appropriate official U.S. or Canadian fraud and cybercrime channels
  • Evaluate regulatory, contractual, insurer and privacy reporting separately

DOCUMENT

  • Maintain a timeline, evidence inventory, transaction details, decisions and contacts
  • Record the basis for scope, notification and recovery decisions

IMPROVE

  • Correct the exploited workflow and technical controls
  • Share lessons without blame, test the revised process and assign follow-up owners

For the broader program, connect this playbook to the Social Engineering & Fraud pillar, the employee data breach response plan and the Benchmark Knowledge Center.

Recover the process, not only the account

After urgent actions, confirm whether payments were stopped, recalled, recovered or remain unresolved; whether payroll or vendor records need correction; whether affected people require support; and whether operations can resume safely. Communicate only verified status. Do not imply that filing a report, recalling a payment or restoring an account guarantees recovery.

Hold a structured review covering the initial contact, trust signals, approvals, technical controls, response speed, evidence quality, vendor coordination and employee experience. Convert each lesson into an owner, due date and test. Useful measures include time from message to report, time to payment hold, percentage of sensitive changes independently verified, stale forwarding rules removed, completion of high-risk workflow exercises and closure of corrective actions.

Test realistic scenarios

Run tabletop exercises involving an executive request, vendor-bank change, payroll diversion and possible employee-data disclosure. Include after-hours contacts and a situation in which the apparent requester confirms the transaction through a compromised channel. The exercise should test whether staff can find a trusted contact, stop the action, escalate without blame and preserve a clear decision record.

Sources and official reporting resources

Primary government sources checked for this guide are listed below. Organizations should confirm current instructions and requirements for their circumstances.

Continue with practical protection

Make verification routine before the next urgent request.

Use this playbook with Benchmark’s breach-response resources and Social Engineering & Fraud guidance. Organizations addressing employee information exposure can also explore appropriate employee-protection support.

Request employee-protection information